malware thread followed logs attached

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by future_don8, Jan 3, 2015.

  1. future_don8

    future_don8 Private E-2

    Hi Guys

    Great site thanks up front for any help.

    Problems aren't that major i don't think. I have run all the malware removal stuff and got all the logs sorted and attached as per instructions.

    I have only ran the scan for Rougekillers and not 'fixed' anything yet. There were a few issues on there as you will see. I didn't really have any major problems i don't think, i have just followed the advice of a friend to run your protocol.

    I think my main problems are

    1. I only have about 8 GB of space left on my hardrive (have one coming but went to wrong abode and is list in post somewhere)

    2. I was running Spybot search and destroy which i think was slowing things down a little seems to be a bit better since i removed it???

    3. I have foolishly managed to download a "Globasearch" addon or whatever it is, a quick search didn't reveal a resolution to this one. I've had stuff like this before but figured i'd follow the instructions of the experts.

    So my guess is i run Rougekiller again and fix problems as there aren't any major threats on my system. I hope anyway.

    Then go and have a proper look to get rid of the globasearch BS.

    Any further direction you can provide from looking at the logs or to help clean my system and remove the globasearch will be gratefully received my knowledge is certainly limited.

    Peace

    Don
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun RogueKiller and have it remove these items:
    Code:
    [PUP] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} -> Found
    [PUM.HomePage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : [URL]http://www.globasearch.com/?serie=32[/URL]  -> Found
    Now Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Reboot and rescan with RogueKiller and attach the new log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Attach the new C:\MGLogs.zip and be sure to tell me how things are running.
     
  3. future_don8

    future_don8 Private E-2

    Hi TimW

    Thanks for helping out.

    So followed instructions word for word, worked fine on the Rouge killer scan however when i ran the C:\MGtools\analyse.exe the line you had listed were no where to be found.

    I carried on and produced the logs attached however the globasearch is stil in place.

    FixME.reg said it worked fine

    Please find attached logs

    Big love
    Don
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What browser is affected?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Firefox. See The RogueKiller and MGtools logs. ;)
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  7. future_don8

    future_don8 Private E-2

    Thanks Chaslang it is indeed firefox
     
  8. future_don8

    future_don8 Private E-2

    just got back online will give it a go now thanks
     
  9. future_don8

    future_don8 Private E-2

    That seem to be the one, will run it for a couple of days and give you an overall of the system

    thanks for you help so far h:-D
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome. Let me know if you have any other issues. I will give you clean up instructions if you are ready.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds