Needing To Have Scan Files Read, And Suggested Fix(es)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ellen46240, Mar 3, 2018.

  1. ellen46240

    ellen46240 Private First Class

    Hi..
    I try to avoid being here, but DO appreciate when needed: Win Vista Business, FireFox 52.6.0, Avast Internet Security, and MWB Premium. From the looks of things, I down loaded a PDF for a older camera.. and didn't notice the scabs. Symptoms: I found the computer running twice after turning it off, w/no scheduled tasks. (I usually don't turn off my modem.. guess I should!) The Task scheduler may be broken, or disabled, as I could not use the STD Vista pgms to do a back up.. found one on here, and saved files). When browsing a very "busy" (on-line shopping catalog) web site, FF would be super slow, then announce it was not responding, but would then usually pick up and continue. Task Manager typ shows about 50% with normal FF browsing.. it was at 100%. Two different svchost pgms were also pulling 50%. I had Ended one.. (1160?), and then also halted 4568. Not certain if those were really updates, or "UFOs".

    Before I thought this was malware, I unloaded MANY PDF files which I had saved from a previously safe site.. and some photos.. all from a crowded Desktop. A few were deleted, most just organized and moved to mem stick. I left the rest, but also did a separate copy/back-up, onto a different USB memstick. So let me know if I have to delete something from them, or, if they also need to be scanned.

    All scans loaded and ran as prescribed, with a few things showing as pups. (or worse?) Files attached.
    THANKS in advance for the look! Jerry
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not seeing any malware... I can only suggest you reset FF and if issues persist, post in the software thread.

    Reset Mozilla Firefox to defaults

    Since you are not having any malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Re-enable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8 or 10, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 or 10 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     
  3. ellen46240

    ellen46240 Private First Class

    No concerns with the few issues found?? Leave them? Or Delete them? And since I do have two USB sticks loaded now, do I need to scan them? Or if so, with which programs? Will proceed with the follow-up shortly. Again.. THANKS!!
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Leave them. As to USB:
    For the external Hard Drive and a USB stick.

    Insert your flash drive before you begin. Hold down the Shift key when inserting the flash drive until Windows detects it to bypass the autorun feature. This will keep the autorun.inf from executing automatically.

    Please have all your removable storage devices ready for disinfection.

    Download Flash Disinfector by sUBs and save it to your desktop.

    * Double-click Flash_Disinfector.exe to run it.
    * Your desktop and icons may disappear. This is normal.
    * It will do a cleanup of removable storage devices, and write a protected Autorun.inf file to help prevent re-infection.
    * Follow any prompts that may appear.
    * The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
    * Wait until it has finished scanning and then exit the program.
    * There will be no GUI interface or log file produced.
    * Reboot your computer when done.

    Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder. It will help protect your drives from future infection.
     
  5. ellen46240

    ellen46240 Private First Class

    It's been a little while, watching for problems, since I did all the scans. I'm just now doing the follow up steps. However, I don't remember if I used Defogger or not, and can't even FIND "Step 4:".. So my question is how do I determine if I had run Defogger or not?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Don't worry about it. They are general instructions to cover various systems.
     
  7. ellen46240

    ellen46240 Private First Class

    Just to be clear.. do I need to unFog? reFog? DeFog? Or none of the above, and just move onto doing system restore, etc. Thanks for your help Tim,
    Jerry
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    None of the above....:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds