My Friends Vista Filled With Viruses!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Techwoman, Feb 26, 2016.

  1. Techwoman

    Techwoman Specialist

    My friends have a Vista home premium 32 bit 3 gigs memory. They had tons of viruses the computer in slow and often freezes. I tried to even sfs/scannow and it said it has corrupt files it could not repair. So I thought I would start here. I will do the rest of the scans now

    Here is the MBM Text.
     

    Attached Files:

    • MBM.txt
      File size:
      2.6 KB
      Views:
      1
  2. Techwoman

    Techwoman Specialist

    Roguekiller
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there.

    You have not uploaded the correct log for Malware Bytes, please recheck the instructions carefully and get the right one for me to see pelase.
    You have also failed to upload logs from:

    Hitman Pro
    TDSSKiller
    MGTools --- MGlogs.zip

    I would like to see those, too please.
     
  4. Techwoman

    Techwoman Specialist

    I know I am still working on it. I will have them up today. I did TDSKiller it showed nothing.

    Thanks for your help.
     
    Kestrel13! likes this.
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. We like to see all logs regardless or not of if anything was 'found' ;)
     
  6. Techwoman

    Techwoman Specialist

    Oh okay sorry. Here is the log from MBAM
     

    Attached Files:

  7. Techwoman

    Techwoman Specialist

    TDSkiller
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No that's still not the correct log. (Malware Bytes)
     
  9. Techwoman

    Techwoman Specialist

    HitmanPro
     

    Attached Files:

  10. Techwoman

    Techwoman Specialist

    I always have problems with this. Argh! I will try again with Malwarebytes
     
    Kestrel13! likes this.
  11. Techwoman

    Techwoman Specialist

    MGlog
     

    Attached Files:

  12. Techwoman

    Techwoman Specialist

    Okay here is the problem with Malwarebytes it only shows the Protection logs and not the scan log. Not sure I will try and run it again.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, run it again and let it remove anything it finds. Then run once more until you are sure it detects nothing... let me know.
     
  14. Techwoman

    Techwoman Specialist

    Okay here you go
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode. Any other mode is primarily used for troubleshooting and diagnostic purposes. You should look into some third party software to control start up's.


    Re run Hitman Pro, enable/activate the free trial, and allow it to remove all that it finds.


    Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Tasks tab and locate these detections:

    • [Suspicious.Path] \4816 -- wscript.exe (C:\Users\THOMAS~1\AppData\Local\Temp\launchie.vbs //B) -> Found
    • [Suspicious.Path] \winupd -- C:\Users\THOMAS~1\AppData\Local\Temp:winupd.exe -> Found

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.

    ...same for this entry on the files/folders tab please...

    • [Hj.Name][File] C:\Users\Thomas and Kim's\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk [LNK@] C:\Users\Thomas and Kim's\AppData\Local\Temp\explorer.exe C:\Windows\explorer.exe -> Found

    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.




    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.




    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    Now re run Hitman Pro (just a scan) and upload fresh log.
    Same for RogueKiller.
    Explain how things are running.
     
  16. Techwoman

    Techwoman Specialist

    I did not find this in files and folders just a bunch of pup files. Not sure if I should go on. I do want to mention when I run RKiller a webpage pops up in Spanish that says how to get rid of pup conduit.Weird



    [Hj.Name][File] C:\Users\Thomas and Kim's\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk [LNK@] C:\Users\Thomas and Kim's\AppData\Local\Temp\explorer.exe C:\Windows\explorer.exe -> Found
     
  17. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Continue on with the remainder of Kestrel13's instructions.
     
    Kestrel13! likes this.
  18. Techwoman

    Techwoman Specialist

    JRT log
     

    Attached Files:

    • JRT.txt
      File size:
      5.2 KB
      Views:
      1
  19. Techwoman

    Techwoman Specialist

    MGtool
     

    Attached Files:

  20. Techwoman

    Techwoman Specialist

    Hitman pro
     

    Attached Files:

  21. Techwoman

    Techwoman Specialist

    Attached Files:

  22. Techwoman

    Techwoman Specialist

    I am still having issues shut down is slow and startup takes forever. I did the speed up computer forum. Also what is strange is I set startup to "normal" but it went back to "Selective startup" automatically and it had the programs running. That is frustrating because I think that is why it takes forever to startup. I am going to run sfc/scannow and see if it will repair corrupt files. It could not do that at all in the beginning.
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    In future can you please upload logs all at once, or as many in one go as the forum will let you. ;) Thanks.
    The pop up from RogueKiller is fine.

    You will have to post about the PC feeling 'slow' in the software forum- same for the machine keep reverting to selective start up mode.

    You should let RogueKiller fix this entry in the registry tab:

    [PUP] HKEY_LOCAL_MACHINE\Software\ShopAtHome -> Found

    Then rescan afterwards and upload the new log please.
     
  24. Techwoman

    Techwoman Specialist

    Oh okay no problem! I was not sure how you wanted the uploads. Now I know thanks for letting me know. ;):) I appreciate all your help so much.... Running scan now.
     
  25. Techwoman

    Techwoman Specialist

    I tried to fix one entry in Rouge killer but could not find it in folders and files like you asked me. The guy you work with or whatever said, you said just to continue on.
     
  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just to be clear because we have had 2 rounds of RogueKiller now... is this the entry you cannot see? It will be on registry tab if it is there...

    [PUP] HKEY_LOCAL_MACHINE\Software\ShopAtHome -> Found
     
  27. Techwoman

    Techwoman Specialist

    I found it. Here is the Rkiller scan
     

    Attached Files:

  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Looks good. :)


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds