malware/trojan problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by mindgames, Oct 16, 2012.

  1. mindgames

    mindgames Private E-2

    Hi there
    I've had some great assistance on this forum before, so I'm hoping that one of you kind souls can help me again, please?!

    PC has been running a bit "slow", quite sluggish. The other day I was unable to turn the PC on - the fan would start up, but then stop after a few seconds, and the monitor would be blank. Eventually, after taking out power leads, USB leads etc, and plugging back in, I got it to turn on. Adaware - strangely - starting running and told me that it had found Win32 Trojan agent, and Win32 Pup Bandoo (800). I'm always a bit suspicious of Adaware, so I ran Avira and Malware Bytes but nothing was showing up as dodgy. Anyway I let Adaware remove the files - but had the same problems turning the computer on again the next time I tried to reboot.

    Again Adaware is showing these problems, but my usual scans are not. So I've followed all the steps you suggest and am attaching all the necessary logs.

    I have to say that after I've run all these things, the PC does now seem to be running a lot smoother/quicker, and I don't seem to be having boot-up problems. But if any of you could have a look to reassure/advise me if there's anything else I need to do it would be very much appreciated!

    Thanks
    M
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like you have hardware issues that need to be addressed. This may be a warning sign. Get everything backed up now while you can.

    Adaware is not recommended anymore. We actually suggest removing it especially since they install junkware on your PC like Blekko Toolbar that no one wants! And in addition, your PC running slow is due to all the stuff you installed:

    Adaware - is this the free or paid version? And is does this include their antivirus. I see you have an email scanner from them so I suspect it is an antivirus too and you already have Avira.
    WinPatrol
    Windows Defender
    Malwarebytes - is this the free or paid version ?
    Avira - already has antivirus plus antispyware so you don't really need or want the above to do any protection.
    ZoneAlarm - sometimes can be quite a pig and you again installed more than just the firewall. You install firewall, antivirus, antispyware, their junk toolbar, their spy blocker!

    Too many protection programs can be worse than none!

    My proposal which will include a fix for some junk noticed in Hitman. In fact, run Hitman and allow it to fix all those items it showed. Do this right now and then reboot before continuing.

    Now uninstall ALL of the below
    Ad-Aware Email Scanner for Outlook
    Ad-Aware
    Ad-Aware
    Browser Address Error Redirector
    uTorrentControl2 Toolbar
    Wincore MediaBar
    Windows Defender
    WinPatrol 2009
    ZoneAlarm Firewall
    ZoneAlarm Free Firewall
    ZoneAlarm LTD Toolbar
    ZoneAlarm Security
    ZoneAlarm Spy Blocker

    Then reboot your PC after the last is uninstalled. You may get prompted at intermediate points to reboot too. If requested after uninstalling anyone of these then do the reboot and then continue.

    After reboot, run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. mindgames

    mindgames Private E-2

    Thanks very much, I will do all these things today.

    I am worried about uninstalling the ZA firewall though - forgive my ignorance but is it definitely ok to be connected to the Internet with no firewall running?

    Everything I have is a free version, by the way, except Malwarebytes which is paid.

    Thank you!
     
  4. mindgames

    mindgames Private E-2

    Hi

    OK have done everything you suggested.

    I realised that Windows Firewall is turned on if ZA is uninstalled.

    The only thing I couldn't do was uninstall a couple of the ZA components you listed, as they weren't listed in "add/remove programs" - they were:

    ZoneAlarm LTD Toolbar
    ZoneAlarm Security
    and one of the Zonealarm Firewall options - I can't remember which one.

    Anyway all done - PC does seem faster!

    MG Logs.zip attached. Many thanks!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then that is even more reason for your PC being slow. You had way too many programs with active protection running.

    Okay one component of ZA is still there even though you cannot see it. ZoneAlarm LTD Toolbar is still in your logs. We will removal it manually since ZA did not cleanup after itself.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    You also need to run CCleaner as requested in the READ & RUN ME to cleanup Temp folders.

    So how are things running now with all of those excess programs removed?
     
  6. mindgames

    mindgames Private E-2

    Hi

    Yes - I got a success message so it looks like it's worked.

    Thank you.

    It seems to be running more quickly/smoothly - no apparent problems.

    Do I need to do anything else? Shall I post up any new logs?

    Thanks again
    M
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Nope. Just do the below.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  8. mindgames

    mindgames Private E-2

    Thanks a lot.

    I've done all this and everything seems to be ok.

    Quick question - when you say "uninstall" Roguekiller etc - they aren't showing up in my programs list, or in "add/remove programs". Do I just delete the exe files?

    Also - I have Spybot Search and Destroy, and Spyware Blaster installed from long ago - should I get rid of these?

    Thanks again.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes if they still exist after running MGclean.bat you can delete them. MGclean should take care of quite a bit of cleanup.

    No you can keep these. Just DO NOT use Spybot's Teatimer. Also you most likely need to update Spybot as I can see you are way out of date with SpywareBlaster. You have 4.3. You need to uninstall it and install this one SpywareBlaster
     
  10. mindgames

    mindgames Private E-2

    Thanks. The PC is running ok, doesn't seem to have any issues other than it seems very slow again. I can't really work out why - especially as we have uninstalled loads of stuff.

    Also - Malwarebytes didn't load correctly this morning, it came up with an error message. I had to open it myself.

    And, Windows Firewall isn't coming on automatically - I'm getting a warning message each time the PC boots up saying that I need to "click the balloon" to solve this problem. As soon as I do that though, it shows that Windows Firewall is on.

    Just still a bit nervous that something's not quite right - is there one or two more scans with programs I could do?

    Thanks again.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We can always find more scans to run, but nothing related to malware had been showing. Many of your problems may just be residual damage from installing too many protection programs.

    Try running a full scan rather than a quick scan with Malwarebytes and attach the new log.

    Now run ESET per the below and attach the log from ESET.

    Using ESET's Online Scanner

    Note that if you still have MGtools installed ESET will detect the process.exe file in the MGtools folder as a problem. ESET is wrong.
     
  12. mindgames

    mindgames Private E-2

    HI

    Thanks. I've run the full Malware and am attaching the log. No detections found.

    But I can't run the ESET scanner. When it starts to download the database, it gets to 2%, but then says: "can not get update. Is proxy configured?"

    Not sure what that means?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Shutdown ALL protection software including your firewall and try again.

    If that does not work, make sure that you are using Internet Explorer and not Chrome!!!!!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds