Not sure if I'm still having problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by miki.fromchenko, Apr 14, 2015.

  1. miki.fromchenko

    miki.fromchenko Private E-2

    Okay so I got this computer from a friend after he gave up on it.
    I have no idea when his problems started but clearly there were viruses and other types of malware on it..

    I ran the READ AND RUN ME and honestly I'm not sure if I'm still having problems. I did see some findings in the scans that I'm not sure were addressed (the procedure always said just get the log and see later :/)

    anyway, attached are the logs.

    Thanks so much,
    Miki
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun Hitman and have it remove all it found.

    Now rerun RogueKiller and have it fix these items:
    Code:
    ¤¤¤ Registry : 30 ¤¤¤
    [PUP] HKEY_CLASSES_ROOT\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B} (C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.5\bh\BabylonToolbar.dll) -> Found
    [PUP] HKEY_CLASSES_ROOT\CLSID\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} (C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll) -> Found
    [PUP] HKEY_CLASSES_ROOT\CLSID\{E46C8196-B634-44a1-AF6E-957C64278AB1} (C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.5\bh\BabylonToolbar.dll) -> Found
    [PUP] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} (C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll) -> Found
    [Suspicious.Path] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | NLProtect : C:\Windows\System32\config\systemprofile\AppData\Roaming\385767425.exe  -> Found
    Now fix these items:
    Code:
    ¤¤¤ Files : 1 ¤¤¤
    [ZeroAccess][Junction] $NtUninstallKB39697$ -- C:\Windows\$NtUninstallKB39697$ [JUNCTION@ 0] >> ERROR 5 -> Found
    Reboot and rescan with both RogueKiller and Hitman and attach the new logs.

    Be sure to tell me how things are running.
     
  3. miki.fromchenko

    miki.fromchenko Private E-2

    Hey, thanks so much.

    2 really basic questions -
    I'm having trouble removing the things 'hitman' has found.
    I get to the 'result' page and by each thing it found there's a delete button but it seems that it just doesn't do anything at all when I choose delete.

    and the second question - well I haven't got there yet, but how exactly do I run this code you gave me in rouguekiller? Where do I enter this code?

    You guys are great. Endless appreciation.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You don't enter the "code"...you just delete the items that I put in the code box.
     
  5. miki.fromchenko

    miki.fromchenko Private E-2

    Like I said, I couldn't actually do nothing with the findings of hitman no matter what I tried. But it did say zero threats, all of the things it found were "roots" or something like that.
    Thanks again for the help.
    miki
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please rerun Hitman and have it remove all the items under:
    Potential Unwanted Programs

    Then rerun RogueKiller and remove this item under the Registry tab:
    [PUP] HKEY_CLASSES_ROOT\CLSID\{E46C8196-B634-44a1-AF6E-957C64278AB1} (C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.5\bh\BabylonToolbar.dll) -> Found

    Reboot and rescan with both Hitman and RogueKiller and attach the new logs.
     
  7. miki.fromchenko

    miki.fromchenko Private E-2

    Since I can't remove those items from inside hitman (like I wrote before), should I manually delete these from windows?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, but I don't know why you can't uninstall using Hitman.
     
  9. miki.fromchenko

    miki.fromchenko Private E-2

    I don't know too. I choose 'delete' from the options on each found unwanted object, and nothing happens.
    do you have any idea why would that happen?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It's possible your AV software is getting in the way. Disable all protection software and try again.
     
  11. miki.fromchenko

    miki.fromchenko Private E-2

    :/ still doesn't work.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download OTM by Old Timer and save it to your Desktop.




    Code:
    :Processes
    explorer.exe
    
    :files
    C:\Program Files\Babylon\ 
    C:\Users\Yaniv\AppData\Local\Conduit\ 
    
    :reg
    [-HKLM\SOFTWARE\Classes\AppID\BabylonIEPI.DLL\]
    [-HKLM\SOFTWARE\Classes\AppID\escort.DLL\]
    [-HKLM\SOFTWARE\Classes\AppID\{B16632F1-24E0-4D99-A68D-70BFB6447C48}\]
    [-HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\]
    [-HKLM\SOFTWARE\Classes\BabylonIEPI.BabylonIEBho.1\]
    [-HKLM\SOFTWARE\Classes\BabylonIEPI.BabylonIEBho\]
    [-HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1\]
    [-HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr\]
    [-HKLM\SOFTWARE\Classes\Interface\{5F339F0B-716F-408F-A627-DEEB5DEB4020}\]
    [-HKLM\SOFTWARE\Classes\Prod.cap\]
    [-HKLM\SOFTWARE\Classes\TypeLib\{A1489C85-4F6F-48C4-AC9E-18B63AF4703E}\]
    [-HKLM\SOFTWARE\Conduit\]
    [-HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478}\] 
    [-HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\]
    [-HKU\S-1-5-21-2127588766-2863769350-2903456372-1000\Software\Microsoft\Internet Explorer\LowRegistry\Extensions\CmdMapping\{F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478}]
    [-HKU\S-1-5-21-2127588766-2863769350-2903456372-1000\Software\Microsoft\Internet Explorer\MenuExt\Translate this web page with Babylon\]
    [-HKU\S-1-5-21-2127588766-2863769350-2903456372-1000\Software\Microsoft\Internet Explorer\MenuExt\Translate with Babylon\]
    [-HKU\S-1-5-21-2127588766-2863769350-2903456372-1000\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\]
    [-HKU\S-1-5-21-2127588766-2863769350-2903456372-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}\]
    [-HKU\S-1-5-21-2127588766-2863769350-2903456372-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}\]
    [-HKU\S-1-5-21-2127588766-2863769350-2903456372-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}\]
    [-HKU\S-1-5-21-2127588766-2863769350-2903456372-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F72841F0-4EF1-4DF5-BCE5-B3AC8ACF5478}\]
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]

    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.


    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.

    Reboot and rescan with Hitman and attach the new log.

    Tell me how things are running.
     
  13. miki.fromchenko

    miki.fromchenko Private E-2

    okay wow. this is pretty amazing. i've done what you asked with OTM and since it worked the computer works SO MUCH FASTER.. i'm blown away.
    these are the new logs from hitman and from OTM.

    there is still something i have to do in rougekiller, should i do this now or did OTM was a replacement?

    thanks so so much
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download AdwCleaner by Xplode and save to your Desktop.

    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.



    Then rerun RogueKiller and attach that new log.
     
  15. miki.fromchenko

    miki.fromchenko Private E-2

    hey, it seems that my computer is back to its old -slow- self, sadly :(
    these are the logs you requested..

    thanks.
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have ADW clean what it found. Now explain what is slow.

    A slow computer is not always due to malware:

    Please explain what operations are slow! For example answer the below:

    * Is boot up slow?
    * Is shutdown slow?
    * Is browsing/surfing slow?
    * Is downloading slow?
    * Is running any application?
    * Is it also slow in safe boot mode?
    * Also are any process showing in Task Manager to be using a lot of CPU time?
    * Anything else slow?
     
  17. miki.fromchenko

    miki.fromchenko Private E-2

    Okay, so-
    it seems that things have improved after I had adclean remove what its found.
    the computer is still a bit slower than how it was after I first ran old timer, but much better than five minutes ago.

    i think what is slow is the response time for any action I do. I don't know if that's to general, but I mean every app I run, even right clicking an icon when nothing's running will open the drop down menu after 10 or 20 seconds sometime. Every app runs slow and reacts slowly, and also the boot time takes a long time until the computer is "ready" for use.

    Should I run anymore scans? by the time I finished writing this the computer definitely feels in much better shape. But as I said it felt this way before and then got worse again.
     
  18. miki.fromchenko

    miki.fromchenko Private E-2

    also - the first in the 'commit size' column of the processes in the task manager is mbamservice which I downloaded for the purpose of this cleaning process of course. it takes 200,000 k. After that are two google chrome processes - one takes 135,000 k and the other about 67,000 k. I have no idea if this has any meaning.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  20. miki.fromchenko

    miki.fromchenko Private E-2

    this is what i got..
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I suggest you pursue this in the software forum.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  22. miki.fromchenko

    miki.fromchenko Private E-2

    done. everything seems to work much much better now.

    thank you so so much. you were of amazing help and I am so grateful.
    this place is awesome.

    miki
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing! ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds