Malware Help Please

Discussion in 'Malware Help (A Specialist Will Reply)' started by Lauren76, Jul 23, 2013.

  1. Lauren76

    Lauren76 Private E-2

    Have followed the removal advice. Malwarebytes looked ok, but some other errors were seen. I don't know whether there are still any problems lurking but hope somebody can advise. It would be much appreciated.


    Many thanks.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please Disable Spybot's TeaTimer --> Should have been done as per the R&R instructions!

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!


    Rerun Hitman and have it delete everything it finds. Attach a new log when done.

    Download OTL to your desktop.

    Double-click OTL.exe to start the program.

    • Copy and Paste the following code into the Custom Scans/Fixes textbox. Do not include the word Code

    Code:
    :processes
    :killallprocesses
    :files
    C:\Users\Lauren\AppData\Roaming\SSync
    C:\Users\Lauren\AppData\Roaming\SCheck
    C:\Users\Lauren\AppData\Roaming\DataMgr
    C:\Users\Lauren\AppData\Roaming\Intermediate
    C:\ProgramData\Babylon
    
    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "SSync"=-
    "SCheck"=-
    "DataMgr"=-
    "Intermediate"=-
    [HKEY_USERS\S-1-5-21-902560758-1637908631-278369674-1001\Software\Microsoft\Windows\CurrentVersion\run]
    "SSync"=-
    "SCheck"=-
    "DataMgr"=-
    "Intermediate"=-
    
    :commands
    [PURITY]
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    
    
    • Then click the Run Fix button at the top.
    • Click the OK button.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. Just close notepad and attach this log form OTL to your next message.


    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.

    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista ,Win7 or Win8, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. Lauren76

    Lauren76 Private E-2

    I couldn't find any sign of spybot on the pc?
     
  4. Lauren76

    Lauren76 Private E-2

    I still couldn't file any trace of spybot, but I completely uninstalled MSE, in case that affected the results. It was only disabled before.

    I've done the other things as suggested, and attached log files.
     

    Attached Files:

  5. Lauren76

    Lauren76 Private E-2

    I just realised I hadn't saved the log from hitman, sorry, so have re-run it and attached the new logfile.
     

    Attached Files:

  6. Lauren76

    Lauren76 Private E-2

    Update: I was just giving the PC a more detailed clear out of startup programs, and uninstalling some unused stuff, and found the spybot teatimer in the startup. I've got rid of it from the startup list, but couldn't find the actual spybot program itself at all.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What issues are you still having, if any?
     
  8. Lauren76

    Lauren76 Private E-2

    Hi,

    The pc doessn't appear to be as slow as it was.

    I'm still stuck on a windows update fail at the moment, and haven't re-installed Chrome yet.

    This is reporting an error of 800B0100 on the security update of KB2845187. Searches have thrown up that I should try various things, and I've done a few: the Windows Update-Reset (checksur), and the MS Fixit, the fix in aggressive mode, and the one before that, and it still won't install. I have read that it can be caused by malware, but don't know whether this is my current problem?

    edit: the other important updates installed ok.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I suggest that you post in the software forum for your updating issues.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix
      (This uninstall will only work as written if you
      installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows
          defaults.

    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and
      deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any
      others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the
      C:\MGtools\enableUAC.reg
      file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file
      to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush
        your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds