Loads Of Pup's And High Cpu Usage

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by texasharper, Feb 2, 2018.

  1. texasharper

    texasharper Corporal

    High CPU usage. Lots of PUP's.
    Toshiba Satellite C75
    Win OS 8.1
    Logs attached
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Rerun RogueKiller and fix these detections:
    Registry :
    [PUP.ByteFence|PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\ByteFence -> Found

    Tasks :
    [VT.Detected] %WINDIR%\Tasks\{544FF0B8-5EF6-A93D-9261-6069192EB10B}.job -- C:\Users\HANNAH~1.TYR\AppData\Local\544FF0~1\Fakefo.exe (/Check) -> Found
    [VT.Detected] \{544FF0B8-5EF6-A93D-9261-6069192EB10B} -- C:\Users\HANNAH~1.TYR\AppData\Local\544FF0~1\Fakefo.exe (/Check) -> Found

    Re-boot , run RogueKiller again to generate an updated log..... upload that log, please.

    Delete these using Windows Explorer/ File Explorer:
    C:\Users\Hannah.TYRONEPC\Downloads\Installer.exe
    C:\Users\Tyrone\AppData\Roaming\IronSetup\IronSetup.exe

    Please download Farbar Recovery Scan Tool 64-Bit and save it to your Desktop.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press the Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run from.
    • The first time the tool is run, it also makes another log (Addition.txt).
    • Upload both logfiles to your next reply.

    Please upload the requested AdwCleaner Scan log also.
     
  3. texasharper

    texasharper Corporal

    I was unable to access
    C:\Users\Hannah.TYRONEPC\Downloads\Installer.exe
    C:\Users\Tyrone\AppData\Roaming\IronSetup\IronSetup.exe
     

    Attached Files:

  4. texasharper

    texasharper Corporal

    So after I was denied permission this AVG message popped up then I managed to find the PATH and deleted the folder called IronSetup.
     

    Attached Files:

  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    The only minor issue I see is to delete this left-over folder -
    C:\Program Files (x86)\Norton Internet Security

    How is the PC running?
     
  6. texasharper

    texasharper Corporal

    It's running pretty good. May I ask why I was asked to not just let RK clean all the files it found, the same is asked on the Hitman scan. I'm just curious. So now, do you want me to proceed with step or wait for a day or so?
     
  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You can remove the PUM's that Hitman Pro shows if you wish - RK often shows a detection on a Default browser homepage modification, even if changed to something you want.... fix it if you didn't set it yourself.

    Your logs look good! If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    3. If running Vista, Win 7/8/10 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. Go to the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. After doing the above, you should work through the below link:
    Safe surfing!
     
  8. texasharper

    texasharper Corporal

    Attempted step 6 and I encountered this. Why? And what should I do?
     

    Attached Files:

  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

  10. texasharper

    texasharper Corporal

    Thank you sir. That worked great!
     
  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :) You're welcome!
     
    texasharper likes this.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds