need help removing winrscmde

Discussion in 'Malware Help (A Specialist Will Reply)' started by trippenlatin, Aug 9, 2012.

  1. trippenlatin

    trippenlatin Private E-2

    I have read through the forum rules and am posting my RougeKiller log to see if I can get some help in getting rid of the winrscmde. The process just continues to build and eat up the CPU until the computer crashes. Thank you for your help.
     

    Attached Files:

  2. trippenlatin

    trippenlatin Private E-2

    Well, I ran hitman and didnt realize it but when i clicked next it deleted the files that I wasn't supposed to delete... I hope it doesnt jack everything up. Here is the log.
     

    Attached Files:

  3. trippenlatin

    trippenlatin Private E-2

    Here is the MG Tools zip file.
     

    Attached Files:

  4. thisisu

    thisisu Malware Consultant

    Welcome to MajorGeeks, trippenlatin

    http://img196.imageshack.us/img196/3557/tdsskiller.gif Please download and scan with TDSSKiller
    • Do not use the Change Parameters button
    • When the scan is finished, a log will be created in the root of your C: drive
    • Example: C:\TDSSKiller.2.7.47.0_25.07.2012_15.06.22_log.txt
    • Attach this to your next message. (How to attach)

    http://3.bp.blogspot.com/-tH5H1icUyOc/T1XP6r4puoI/AAAAAAAAAQE/jLwmqQECjCg/s1600/hitmanpro.gif - Now rescan with HitmanPro
    Attach its latest log (How to attach)
     
  5. trippenlatin

    trippenlatin Private E-2

    Here are the logs. I think MBAM took care of the issue...but just to be sure here are the two logs.
     

    Attached Files:

  6. thisisu

    thisisu Malware Consultant

    Hi, these logs look clean.

    Do you have the log for MBAM so I can review?
    Are you having any other problems now?
     
  7. trippenlatin

    trippenlatin Private E-2

    i think everything looks good. I even had some virus on my other computers and ran through this process and it cleaned them up...thanks for the help. Here are the logs
     

    Attached Files:

  8. thisisu

    thisisu Malware Consultant

    You're welcome.

    If you are not having any other malware related problems, it is time to do our final steps:
    • Any programs we had you download and/or install can be removed at this time.
    • If we had you download and run ComboFix, here is how to uninstall it:
      • Press and hold the Windows key http://i1106.photobucket.com/albums/h363/debojyotidas/Windows_Logo_key.gif and then press the letter R on your keyboard.
      • This opens the Run dialog box.
      • Copy and paste the below text inside the text-field:
        • "%userprofile%\desktop\ComboFix" /uninstall
      • Now press ENTER
      • ComboFix will extract its files one last time and you should receive a notification that ComboFix has been uninstalled shortly after.
    • You can re-enable your Disk Emulation software at this time via DeFogger.
    • If we had you create or download a registry patch or "fix" script, these can be deleted at this time.
    • Go into the C:\MGtools folder and run the MGclean.bat file to remove additional traces of our tools.
    • Now we will toggle System Restore to remove any infected system restore points.
    • Lastly, here is a guide to protect you from future infections: How to Protect yourself from malware!
    • Be safe :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds