Laptop Down! Ps4ux Plus Others Attacking In Force!

Discussion in 'Malware Help (A Specialist Will Reply)' started by programmer04, Nov 5, 2016.

  1. programmer04

    programmer04 Private First Class

    I'm attempting to send this on my iPhone since both IE11 and Chrome will not bring up a text box so I can type my message nor will it show a button to attach files.

    I just bought a Toshba laptop from my son who is heavy into gaming but a bit naive when it comes to the internet. It is running Windows 10, 64-bit. It had both AVG and McAfee until I deleted them both (pretty sure McAfee was bad). I also installed java, which it didn't have before.

    The problems I'm currently having are messing with my browsers. Just clicking anywhere on a page brings a new page warning me about my infected computer and that I should download or call to get rid of it. There were similar issues occurring outside the bowsers (on the home screen), but that seems to have gone away after I deleted AVG and McAfee.

    The only way I can attach files right now would be to take screen shots of each log (I emailed them to myself). That would take a while with MGlogs zip file. Any suggestions would be great.
     
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, programmer04

    Have you ran the tools linked to in the READ & RUN ME First Guide yet? Then also run the following and upload the results-

    Please download ZHPCleaner to your desktop.
    • Close all applications (including your web browsers and antivirus)
    • Double-click on ZHPCleaner to run the tool.
    • If you are using Windows Vista, 7/8/10; instead of double-clicking, right-mouse click ZHPCleaner and select "Run as Administrator".
    • Please click the "J'accepte/I agree" button.
    • First press the "Scanner" button. Be patient, the scan takes longer than 5mins.
    • After the scan has completed - press the Repair button.
    • Browsers will automatically shut down.
    • A logfile will automatically open after the scan has finished.
    • Please upload that logfile with your next reply.
     
  3. programmer04

    programmer04 Private First Class

    Ahh, that's better. I can now send messages and attach files through my laptop.

    I did go through all of the READ & RUN FIRST, including the browser hijack removal tutorial, but ZHPCleaner seems to have fixed the problem (at least for now). So far, I haven't seen any pop-ups or re-directions.

    I may have screwed up when I ran Malwarebytes, though. I unintentionally installed the trial version when I ran it. After the scan, the results showed 1,310 issues but it quarantined 0 (nada, zip, none). I can try to run it again, if you'd like.

    I have two more files to attach along with these.
     

    Attached Files:

  4. programmer04

    programmer04 Private First Class

    The other one file (can't seem to get TDSSKiller attached. Getting error that says the file doesn't contain any content, even though it's 78.1 KB and does contain text):
     

    Attached Files:

    • JRT.txt
      File size:
      4.5 KB
      Views:
      0
  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Yes, please re-run Malwarebyte's Anti-Malware and fix all detections.

    Re-run Hitman Pro, activate/enable the free trial, then remove all detections. Reboot and rescan with Hitman Pro, upload an updated log.

    Now download Malwarebytes Anti-Rootkit 1.09.3.1001 Beta to a new folder on your Desktop.
    • Then open the folder, extract its contents and double-click on the mbar.exe to start the program.
      • If you receive a DDA driver message like could not load DDA driver, click on the Yes button and Malwarebytes Anti-Rootkit will now restart your computer and will start automatically.
    • Follow the prompts and be sure to update the definitions when it asks. When the update has finished, click on the Next button.
    • Make sure the Drivers, Sectors, and System scan targets are selected before you click on the Scan button.
    • Allow the program to remove any infections and reboot your computer when prompted.
    • Upload any log the program produced showing detections afterwards.

    Then download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version ( 32 bit or 64 bit ) for your PC. Only the correct version will run so if you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press the Scan button and wait.
    • The first time the tool is run it makes two logs, FRST.txt and Addition.txt in the same directory the tool is run.
    • Please upload them in your next reply.
     
  6. programmer04

    programmer04 Private First Class

    here's the latest
     

    Attached Files:

  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.
    • Save the attached (fixlist.txt) to your desktop.
    • Right-click FRST(x32/64) and select Run as Administrator.
    • Click the FIX button once.
    • Wait while FRST processes fixlist.txt
    • A report should pop up named Fixlog.txt, please upload it here in your next reply.

    Tell me how the PC is running now!
     

    Attached Files:

  8. programmer04

    programmer04 Private First Class

    PC appears to be running fine now.
     

    Attached Files:

  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    The only task remaining is to get rid of these AVG remnants:

    C:\Users\Frostman141\AppData\Roaming\AVG
    C:\ProgramData\Avg
    C:\Program Files (x86)\AVG
    C:\$AVG
    C:\Users\Frostman141\AppData\Local\Temp\avg_a08720
    Please run this product removal tool, then check that the above files/folders have been removed.
    AVG Remover 1.0.1.2

    Then manually delete these McAfee leftovers -
    C:\ProgramData\McAfee
    C:\Program Files (x86)\McAfee​

    * And now, the final cleanup steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, Win 7/8/10 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Go to the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7/8/10, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work through the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
  10. programmer04

    programmer04 Private First Class

    ALL DONE!

    I have completed all the steps and everything seems to be running smoothly now.
    I also bought a 24 month subscription for Malwarebytes Anti-Malware.

    THANK YOU, dr. moriarty, FOR ALL OF YOUR HELP!
     
  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;) You're very welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds