PC had light BlueScreen/no connection - malware?

Discussion in 'Malware Help (A Specialist Will Reply)' started by matt8911, Dec 16, 2012.

  1. matt8911

    matt8911 Private E-2

    Hi all I have a secondary PC that has suffered some unknown fate. A renter here at the house was using my PC till the wee hours of the morning. I suspect He went to some "Hot Spots" on the net and got an infection. He may have cleaned it with the MS antivirus on the PC. All this is speculation as I was not there when it happened, I was asleep.

    The next morning I turned on the PC and then tried to go online then 10 - 15 minutes later the PC went into a Light Blue screen and froze (or locked up). I had to press the power button the reset the PC then the PC worked but no internet and could not open "Netgear Genie" (only a quick flash then nothing).

    At this point I said the wireless NIC is bad so I tried it on my other PC and it works flawlessly.

    So to narrow it down I thought if the PC was exposed to dangerous sites, then its a malware infection. The problem is the renter, I'll call Him Latume, was using a Guest account at the time, so I thought not much damage could be done, guess I was wrong.

    I can not elevate to account to administrator as well. I have not tried to run any scans in the guest account yet(guess they will not run or fix anything).

    Also one scan will not run as I could not get an internet connection to read the guide. But I did copy the read and runme guide to the other PC via USB drive.
     

    Attached Files:

    Last edited: Dec 16, 2012
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. Additionally, all your network services are running, though it reports that your media is disconnected. I suggest you post in either the software or the networking forums.

    Since you are not having any malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link
    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  3. matt8911

    matt8911 Private E-2

    Well I hope that its clean, but I do have a few questions before moving on. At first I thought I could not run these programs in the guest account, but I can if I use an Admin credentials(right click the program and select "run as"). All programs ran fine and I'll bet the logs are clean as well.

    I did reconnect the wireless adapter to the PC and it did work again-amazing!!! when I opened Firefox I did get a oops page in my admin account, Ill upload a copy soon. While I am talking about browsers and such I do recall getting a browser redirect problem after installing a video program called "Ilivid" My search page was changed to a search page called searchnu or something I lost my Bing search and google too (only searchnu) I belive this post tells it all though I only had one browser crash on me, so far.
    http://www.techsupportforum.com/forums/f112/multiple-browser-failures-650224.html

    I am working through the remaining steps of you reply right now and writing to you from the so called "healed PC". I do recall resetting some of my browsers to dafault to get rid of the redirecting problem and then the crash. Maybe I caused the crash? More later, if needed and will report to the networking or browser forums later.
    Thank you big time.
     
    Last edited: Dec 19, 2012
  4. matt8911

    matt8911 Private E-2

    The Ilivid program is being described as a valid program with malware attached to the download and is recomended by CNET website. I did not install the toolbar but a new browser called torch was installed with it all. I did uninstall all the programs and reset the browser's setting as mentioned earlier. Here is a screenie of the oops page.

    As stated before I am doing a clean up now...
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just let me know.
     
  6. matt8911

    matt8911 Private E-2

    Right now I thought I was clean/fixed but I recently got info to the contrary.

    I finished cleaning up from the scans on the admin account as requested(but not guest account as I thought it could not be done-wrong). I was trying to continue using the pc as normal and then I got a complete white screen upon trying to run Battlefield Play4Free. I did run the game before this with no problem. I also did experience a problem with the internet and the software that controls the wireless NIC. I did put it in a different USB port and it worked fine again. I am starting to suspect failing hardware or software problems for the NIC (Netgear Genie SW ver 2.0 up to date). Granted this machine has had some freezing problems in the past during gaming sessions but not like this type.

    I ran some more scans and will probably post them before going to the software/hardware forums.
     
  7. matt8911

    matt8911 Private E-2

    These scans are from the Guest account that may have some problems. Also while checking my system further I saw a entry for "The Weather Channel toolbar" which did not uninstall completely before my last problem with the searchnu always popping up in place of google and bing etc.
    I am having trouble finding one scan again, but there may be no need as the system may be clean. I will look for it still as I am curious.

    Can you tell me which forum to post in next please software for MS? networking?
    Thanks
     

    Attached Files:

    Last edited: Dec 22, 2012
  8. matt8911

    matt8911 Private E-2

    I also tried running the "Call of Pripyat" benchmark and got mostly a black screen with little rectangles of color and other artifacts of grey and red etc. I tried to get a screen shot but alas no dice PC was frozen. Also have a suspicion that my CPU may have a problem as I recall having bluescreens when I had it in the other Mobo GA-EP45-DS3R. So maybe its a hardware problem rolleyes
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Other than the Potentially unwanted programs listed in the Hitman log, I suggest you post in the software forum for further assistance. Also, if you keep getting screens with artifacts, you may want to post in the hardware forum.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link
    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  10. matt8911

    matt8911 Private E-2

    Really appreciate your help Tim
    Matt
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem. Good luck. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds