Malware? Random Re-boot/b.s.o.d.

Discussion in 'Malware Help (A Specialist Will Reply)' started by juntuo, Jun 4, 2016.

  1. juntuo

    juntuo Private First Class

    Neighbor asked me to help with his laptop. Shutting down randomly/ B.S.O.D. I seem to have some of that at bay, I am still getting pop ups and web pages load slow. Thank you for any and all help you can send our way.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun RogueKiller and have it remove these items:

    ¤¤¤ Registry : 21 ¤¤¤
    [PUP] (X64) HKEY_LOCAL_MACHINE\Software\SmartPCFixer -> Found
    [PUP] (X86) HKEY_LOCAL_MACHINE\Software\Conduit -> Found
    [PUP] (X86) HKEY_LOCAL_MACHINE\Software\SmartPCFixer -> Found
    [PUP] (X64) HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser | {D4027C7F-154A-4066-A1AD-4243D8127440} : -> Found
    [PUP] (X86) HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser | {D4027C7F-154A-4066-A1AD-4243D8127440} : -> Found
    [PUP] (X64) HKEY_USERS\S-1-5-21-347766847-3249236811-148564012-1000\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser | {4B3803EA-5230-4DC3-A7FC-33638F3D3542} : -> Found
    [PUP] (X64) HKEY_USERS\S-1-5-21-347766847-3249236811-148564012-1000\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser | {D4027C7F-154A-4066-A1AD-4243D8127440} : -> Found
    [PUP] (X86) HKEY_USERS\S-1-5-21-347766847-3249236811-148564012-1000\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser | {4B3803EA-5230-4DC3-A7FC-33638F3D3542} : -> Found
    [PUP] (X86) HKEY_USERS\S-1-5-21-347766847-3249236811-148564012-1000\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser | {D4027C7F-154A-4066-A1AD-4243D8127440} : -> Found
    [PUP] (X64) HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser | {D4027C7F-154A-4066-A1AD-4243D8127440} : -> Found
    [PUP] (X86) HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser | {D4027C7F-154A-4066-A1AD-4243D8127440} : -> Found
    [PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-347766847-3249236811-148564012-1000\Software\Microsoft\Internet Explorer\Main | Search Bar : Preserve -> Found
    [PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-347766847-3249236811-148564012-1000\Software\Microsoft\Internet Explorer\Main | Search Bar : Preserve -> Found

    Then rerun Hitman and have it remove all that it finds.

    Reboot and rescan with both RogueKiller and Hitman and attach the new logs. Be sure to tell me how things are running.
     
  3. juntuo

    juntuo Private First Class

    Followed instructions to running Hitman and remove all that it finds... I Rebooted, machine will not boot just hangs on Starting Windows splash screen.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Nothing that was removed would have made your system not boot. Can you do a restore? Have you tried getting into safe mode?
     
  5. juntuo

    juntuo Private First Class

    Yeah I know and things were going well too. Safe mode hangs. \Windows\System32\Drivers\aswRvrt.sys
    I did try restore still would not boot, still hangs at Starting Windows
     
  6. juntuo

    juntuo Private First Class

    Okay, back up and running. explorer opens and file access is much faster. Web pages load fast and no pop ups.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun RogueKiller and have it fix this item:
    ¤¤¤ Registry : 10 ¤¤¤
    [PUP] (X86) HKEY_LOCAL_MACHINE\Software\Conduit -> Found

    Then rerun Hitman and have it fix all it finds.

    Reboot and rescan with both RogueKiller and Hitman and attach the new logs.
     
  8. juntuo

    juntuo Private First Class

    Everything still seems to be running well.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just remove the PUP's in Hitman and you should be good to go. Tell me what issues remain.
     
  10. juntuo

    juntuo Private First Class

    All seems to be going well, thank you so much!
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8 or 10, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds