Malware Removal Guide

Discussion in 'Malware Help (A Specialist Will Reply)' started by Diamond6, Sep 7, 2014.

  1. Diamond6

    Diamond6 Private E-2

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks!

    I also need the requested logs - C:\MGlogs.zip and the latest dated C:\TDSSKiller_log.txt.

    dr.m
     
  3. Diamond6

    Diamond6 Private E-2

    Here are the 2 attachments you asked for.
     

    Attached Files:

  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Please download aswMBR ( 511KB ) to your desktop.
    • Double click the aswMBR.exe icon to run it
    • Click the Scan button to start the scan
    • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
     
  5. Diamond6

    Diamond6 Private E-2

    Here is the log you requested.
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Diamond6

    ;) I'm digging because of the "Unknown MBR code" could totally be harmless... or not.

    Your MGlogs.zip file is very incomplete. Did you have a problem running MGtools? Did you follow all instructions ( like disable UAC, disable protection software, use Right Click and Run As Administrator )? Did you wait for it to tell you it was finished before attaching the log?

    Please run this online scan, now.
    Using BitDefender Online Scan

    Please re-run HitmanPro and fix/delete all Potential Unwanted Programs
    Ignore all other detections.
    Afterwards, click the Next button.
    HitmanPro may want to reboot the PC in order for the changes to take affect, please do so.
    After reboot and when you are back in Windows, run another scan with HitmanPro and then attach the latest HitmanPro log

    Please download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
    http://imageshack.us/a/img841/7292/thisisujrt.gif Now download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach the JRT.txt to your next message.

    * If you still had no success in running MGTools.exe
    Please download OTL by OldTimer.
    • Save it to your desktop.
    • Double-click on the OTL icon on your desktopto run it. (Note: if using Vista, Win7 or Win8 use right-click and select Run as Administrator)
    • Check the "Scan All Users" checkbox.
    • Set the "Output" to "Minimum Output".
    • Change the setting of "Drivers" and "Services" to "Use Safelist"
    • Copy the text in the code box below and paste it into the http://img14.imageshack.us/img14/66/otlcustomfix.png text-field.
      Code:
      activex
      netsvcs
      drives
      
    • Now click the http://img171.imageshack.us/img171/2405/runscanotl.png button.
    • One report will be created:
      • OTL.txt <-- Will be opened
    • Attach OTL.txt to your next message. (How to attach)

    How is your pc running?
     
  7. Diamond6

    Diamond6 Private E-2

    Yes I did follow all the instructions.The BitDefender online scan won't run.
     
  8. Diamond6

    Diamond6 Private E-2

    Got the bitdefender scan to work
     
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Where are the logs that I requested?
     
  10. Diamond6

    Diamond6 Private E-2

    When Bitdefender finished the results came up as no active viruses found. Here are the other logs you requested. Sorry it took so long.
     

    Attached Files:

    Last edited: Sep 12, 2014
  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    If you have not already, please click on run MSconfig and put this machine back into "Normal Startup Mode".

    We recommend an absolute MINIMUM of 2 GB for Windows XP and a MINIMUM of 3 GB for Vista or Windows 7 but the more memory you can add the better.
    Uninstall this outdated software:
    Java 7 Update 67

    Re-run AdwCleaner.exe
    • Click on the Scan button
    • When the scan is ready click on the Clean button
    • A log file will automatically open after the scan has finished
    • Please attach the log file, located at C:\AdwCleaner[S0].txt

    Now install the current version of Sun Java from:
    Make sure that when you install the new version of Java that you uncheck the Install the Ask Toolbar junkware checkbox. You do not want to add what most people consider malware to your PC. Also just in case Oracle changes the Java installation in the future to possible install other junk, uncheck all but just installing Java.

    Tell me what malware problems you are experiencing!
     
  12. Diamond6

    Diamond6 Private E-2

    Here is the log you asked for. My problem is windows security update keeps closing.
     

    Attached Files:

  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Your logs are clean of malware. The below is not very helpful in diagnosing the problem.
    * If the below doesn't solve the issue, please create a new thread in our Software forum.

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7/8, use right-click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
    ______________________________________

    * If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. It provides no "real-time" protection unless you purchase it and does not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 4 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. If running Vista or Win 7, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. Go to add/remove programs and uninstall HijackThis.
    5. Go to the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and/or deleted.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work through the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds