Malware Everywhere

Discussion in 'Malware Help (A Specialist Will Reply)' started by brian kerber, Mar 18, 2016.

  1. brian kerber

    brian kerber Private E-2

    I have downloaded all or the requested software in the readme and executed as requested.

    two issues - I forgot to run CCleaner and the MGTools seems to be hung up, the last message displayed is "Getting System Information". This is a Windows 10 machine, my daughters, I am struggling with getting around in it.

    Is there something I should do, cancel MGTools run CCleaner and then start over?

    thanks for you help
     
  2. brian kerber

    brian kerber Private E-2

    it finally finished, don't think it looks correct but here is the MG log.
    Let me know what i did wrong

    thanks
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. :) Then can you please upload all of the other requested logs. Thanks.
     
  4. brian kerber

    brian kerber Private E-2

    i think these are it.. thanks again
     

    Attached Files:

  5. brian kerber

    brian kerber Private E-2

    i don't see a TDSSKILLER log right now sorry
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    And the Malware Bytes log, please?
     
  7. brian kerber

    brian kerber Private E-2

    found the tdskiller but it was empty, seems odd. will look for other one now
     
    Kestrel13! likes this.
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The Tdsskiller log is included in the MGlogs.zip so don't worry about that. Just upload the Malware Bytes log.
     
  9. brian kerber

    brian kerber Private E-2

    i found the malware log as well, really odd, it keeps telling me it is empty on the upload a file button but i can see it has data and is about 300 kb, the tdskiller log has data as well, i just was trusting the upload a file button when it said it was empty
    not sure what to do at this point...
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just run Malware Bytes again, let it remove anything it finds. Let me know.

    Re run Hitman Pro, activate/enable the free trial and let it remove all that it finds.


    Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [PUP] (X64) HKEY_LOCAL_MACHINE\Software\Essentware -> Found
    • [PUP] (X64) HKEY_LOCAL_MACHINE\Software\PCValidator -> Found
    • [PUP] (X64) HKEY_LOCAL_MACHINE\Software\Reimage -> Found
    • [PUP] (X64) HKEY_LOCAL_MACHINE\Software\WebBar -> Found
    • [PUP] (X86) HKEY_LOCAL_MACHINE\Software\Jawego -> Found
    • [PUP] (X86) HKEY_LOCAL_MACHINE\Software\PC -> Found
    • [PUP] (X86) HKEY_LOCAL_MACHINE\Software\Trymedia Systems -> Found
    • [PUP] (X64) HKEY_USERS\S-1-5-21-317729607-3718617820-10671929-1001\Software\Microsoft\Windows\CurrentVersion\Run | PCKeeper Antivirus : "C:\Program Files\Essentware\PCKAV\PCKAV.exe" /autorun [x][x] -> Found
    • [PUP] (X86) HKEY_USERS\S-1-5-21-317729607-3718617820-10671929-1001\Software\Microsoft\Windows\CurrentVersion\Run | PCKeeper Antivirus : "C:\Program Files\Essentware\PCKAV\PCKAV.exe" /autorun [x][x] -> Found
    • [PUM.Proxy] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NlaSvc\Parameters\Internet\ManualProxies | (default) : -> Found
    • [PUM.Proxy] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NlaSvc\Parameters\Internet\ManualProxies | (default) : -> Found

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.

    ...and the same for this entry on the tasks tab please...

    • [Suspicious.Path] \Component System\Component -- "C:\Users\pcker\AppData\Local\Component\com.exe" -> Found

    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    What is in this folder? (Don't click on anything)

    C:\ProgramData\d1e11b7a


    Give Ccleaner a run, not the reg scanner, just the cleaner itself to be rid of a chunk of temp files.


    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    • Now rerun Hitman Pro (just a scan) and upload new log
    • Same for RogueKiller.
    • Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    • Let me know how things are running!
     
  11. brian kerber

    brian kerber Private E-2

    running much better now.
    malware bytes turned up nothing.
    i have attached all logs as requested - nothing from hitman

    thanks
    look forward to hearing what you see now.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You did not answer me about this:

    C:\ProgramData\d1e11b7a
     
  13. brian kerber

    brian kerber Private E-2

    i don't see that folder anymore. i did a search on the C drive
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The logs look good! How are things running?
     
  15. brian kerber

    brian kerber Private E-2

    Running good. Do you think we are clear?
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I do indeed. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  17. brian kerber

    brian kerber Private E-2

    Thanks for all of your help

    I will follow your steps to protect her computer to hopefully avoid this again.

    Much appreciated
     
    Kestrel13! likes this.
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Most welcome. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds