Malware Logs

Discussion in 'Malware Help (A Specialist Will Reply)' started by shannonschow, Aug 22, 2013.

  1. shannonschow

    shannonschow Private E-2

    Thank you for your help. I have downloaded the icedragon browser and it works!!! omg. I am not sure what to do now. I have tried to uninstall mozilla but it will not uninstall. I do not know if I am still at threat Please see files attached. I am hoping I am posting the correct files. I can not find the txt file for rougekiller. Ugh Should I repost in Malware forum?
    thanks again.
    Here are the logs I was trying to load.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hello there, somehow you escaped our radar. I am very sorry. Do you still require assistance? Were you ever able to run MGTools? What happened with RogueKiller in the end?

    I'll link to our instructions for your reference. Everything needed can be found here. :)

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. shannonschow

    shannonschow Private E-2

    Re: Malware Logs MGTools and such attached

    Please see files attached.
    Computer is still running slow. Mozilla will not uninstall. I prefer using Mozilla but since it is not responding for the time being I will use Comodo
    Desktop PC Dell
    I have 2.25 gb ram
    Windows XP 2.6 ghz
    9.51 gb free space


    only browser that will respond and work is Ice Dragon Comodo
    I think I am still infected but not sure at this point.
    I have attached other files that you asked about.
    I did seek help elsewhere since I did not get a response her after a few days. I know you guys are super busy.
    Windows Exployer is a bit slow but is working

    See attached

    Thank you in advance for your help.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I know you ran Hitman before, but it's been a while, can you run it again and attach the log please?

    Also please run MSconfig and put your PC into normal startup mode. You should not use MSconfig as a permanent starup manager and you have issues with items trapped in MSconfig registry keys which include junkware and left over services from AVG. You have both AVG 2011 and Avast installed. This alone is enough to cause a slow PC. DO NOT attempt to uninstall AVG while you have MSconfig controlling startups and services!!!!
     
    Last edited by a moderator: Sep 3, 2013
  5. shannonschow

    shannonschow Private E-2

    I changed my startup as you requested.
    I noticed when I restarted search protect was listed in programs at startup tab in msconfig.
    I like using selective startup. I don't want 20 programs running when I start up my desktop. It is an old computer and I don't want those programs bogging down my performance. ??? what to do about that ???
    Should I just use CCleaner for a selective start up ?
    No one has ever told me I needed to change my msconfig settings before.

    I thought I only had one AV running. I thought I had uninstalled AVG before installing Avast. I will now uninstall AVG as requested.

    I just ran hitman pro and it found quite a bit more
    see file attached.

    Thank you for your time in this matter
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete these.

    • C:\Documents and Settings\Shannon\Local Settings\Application Data\Conduit
    • C:\Documents and Settings\Shannon\Application Data\SearchProtect


    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  7. shannonschow

    shannonschow Private E-2

    Documents and Settings\Shannon\Local Settings\Application Data\Conduit
    C:\Documents and Settings\Shannon\Application Data\SearchProtect

    These files were not listed.
    See JRT Attached and MGlogs
     

    Attached Files:

  8. shannonschow

    shannonschow Private E-2

    I could not find AVG in programs for uninstalling.
    I did a search and found "$AVG" folder and files. I have deleted those files.

    I forgot disable msconfig services and use normal startup. When I posted logs earlier

    I ran JRT and MGtools again after a reboot with "normal startup"
    Please see files attached.

    Please advise. :)

    My computer seems to be working good
    Hopefully I am clean now LoL
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    AVG needs to be uninstalled asap. Please use Revo Uninstaller to get rid if it.



    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • 04 - HKLM\..\Run: [SearchProtectAll] C:\Program Files\SearchProtect\bin\cltmng.exe
    • O4 - HKCU\..\Run: [SearchProtect] C:\Documents and Settings\Shannon\Application Data\SearchProtect\bin\cltmng.exe

    After clicking Fix exit HJT.



    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "SearchProtect"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "SearchProtectAll"=-
    
    :files
    C:\WINDOWS\system32\url(3).dll
    C:\WINDOWS\system32\wininet(4).dll
    C:\Program Files\SearchProtect
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  10. shannonschow

    shannonschow Private E-2

    When I go to use Revo AVG is not listed to uninstall.


    the two files you told me to fix are not listed

    Therefore I am not able to fix as you requested.

    I can run OTM (which I already have on my computer) but I am not sure if I sure if I should run it since I could not complete all steps you requested.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  12. shannonschow

    shannonschow Private E-2

    Ok I had to run an AVG remover. I am not sure if I have removed AVG.
    I am still not sure if I am malware or virus free.
    I am still having slow browser loading. computer seems to be slow again.
    I was able to copy and paste and press remove it.
    See files attached.
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete these files:

    • C:\WINDOWS\system32\url(3).dll
    • C:\WINDOWS\system32\urlmon(4).dll
    • C:\WINDOWS\system32\wininet(4).dll

    Please explain what operations are slow! For example answer the below:


    • Is boot up slow?
    • Is shutdown slow?
    • Is browsing/surfing slow?
    • Is downloading slow?
    • Is running any application?
    • Is it also slow in safe boot mode?
    • Also are any process showing in Task Manager to be using a lot of CPU time?
    • Anything else slow?
     
  14. shannonschow

    shannonschow Private E-2

    Is boot up slow? no
    Is shutdown slow? sometimes , only if there are updates, noticed recently that start up better now.
    Is browsing/surfing slow? yes and start up with browser is extremely slow, even with New browser comodo ice dragon. it takes alost 5 minutes for browser to load
    Is downloading slow? no
    Is running any application? in some instances yes. windows apps seem to work ok but another software such as gimp or paint shop pro is slower than normal
    Is it also slow in safe boot mode? safe mode is fast , (last time in safe mode was a week ago)
    Also are any process showing in Task Manager to be using a lot of CPU time?only process that are showing high cpu time is svc.host.exe and exployer.exe which i think are normal processes lol

    Anything else slow? only my internet browser is very very slow loading.
    thank you for all your help I really appreciate it
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You will have to post in the software forum about it. :)

    With regards to Mozilla Firefox, did you get that issue resolved?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds