Malware Removal Assistance Needed

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by CDabney, Jul 3, 2020.

  1. CDabney

    CDabney Private E-2

    Thanks for your help.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your RogueKiller logs is scrambled. Please run it again and attach a new log.

    You need to tell me what issues you are having.

    Please have ADWCleaner remove these:
    PUP.Optional.Legacy C:\Users\Rhonda\Documents\TotalAV
    PUP.Optional.PCProtect C:\ProgramData\SecuritySuite
    Trojan.Agent C:\Windows\rss

    In your installed program list, it has this: McAfeer Total Protection (This is not the correct spelling for McAfee. )

    How confident are you to edit your registry? I am asking because of these two entries:

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run\???c???????]
    @="??????????????????????????????????????e"

    [HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\windows\currentVersion\Run\???c???????]
    @="??????????????????????????????????????e"

    I would like you to run one more scan:

    Please download the latest version of FRST the below link.
    Farbar Recovery Scan Tool and save it to your Desktop.


    Note: Make sure you download the proper version ( 32 bit or 64 bit ) for your PC. Only one will run, the correct one. So it you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  3. CDabney

    CDabney Private E-2

    Thanks for getting back to me on this.



    1. ADWCleaner removed:pUP.Optional.Legacy C:\Users\Rhonda\Documents\TotalAV, PUP.Optional.PCProtect C:\ProgramData\SecuritySuite, Trojan.Agent C:\Windows\rss
    2. Roguekiller ran. log attached.
    3. FRST ran. logs attached
    4. Yes, I'm comfortable with registry editing.
    5. The "r" in McAfee I believe is the registered trademark symbol.
    6. Issues include:
      1. Google browser returned a blank (white) page when searching (bookmarks seemed to work, otherwise it's useless).
      2. Pop-up windows on Google browser
      3. There was also an app called "hide me fast" that appeared as a running app in Google task manager I did not recognize. I tried stopping it using Google task manager, but it would turn itself back on with a message saying the program is being restarted per administrator settings..? I've uninstalled Google browser and reinstalled...still a problem.
      4. Sudden slowdown of computer processing.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please have Roguekiller remove everything except the two MGTools items.

    Warning about cracked software Cracked Software.

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)

    Reboot and then run:
    Please go here > https://www.zemana.com/Download
    their program is no longer free, but you can use the demo version for this cleaning.

    It auto updates, and you click scan. After it's finished, click on the icon that looks like Cell phone strength bars. High-light the report (by date log was produced) and click on the "Open Report" icon. (looks like a folder). That notepad.txt can then be copied/pasted into another .txt doc and saved. Upload that, please.
     

    Attached Files:

  5. CDabney

    CDabney Private E-2

    1) Removed files with Roguekiller.
    2) Disconnected Internet
    3) Ran FRST64 as administrator. Created fixlog.txt (attached)
    4) Ran Zemana...says I"m safe.
     

    Attached Files:

  6. CDabney

    CDabney Private E-2

    Also...using Google browser. At time redirects me to bing....wait...it stopped. Google looks like google again. No redirects, no suspicious looking stuff.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    aIf you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    3. If running Vista, Win 7 or Win 8, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 or 10 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    5. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    6. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds