Please Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by mata112, Mar 17, 2016.

  1. mata112

    mata112 Private E-2

    I have done all scans that you said in post and still I have problems . The virus wants to delete everithing that I click on . Here are resaults of scanig . I appologise for my english . I even gave comp for new windows and its still here.
     

    Attached Files:

  2. mata112

    mata112 Private E-2

    This I forgoten since it was in recycle bin.
     

    Attached Files:

  3. mata112

    mata112 Private E-2

    And this also I forgot. Sory .
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. Please explain exactly what is happening.
     
    mata112 likes this.
  5. mata112

    mata112 Private E-2

    So if I left clik on eniting wants to delete if I go on mail adress it will transfer all my mails in trash bin and it slows my laptop and blocs it totaly . I know it dosent show anything because I tried with everything and its not delete buton stock because when I delete temp files stops and after some time it starts again. Thanks for repli. And I found some eula.rtf files wittch I deleted that also slow the malware down.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Nothing that I can see to be the cause. Let's do this:

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Processes
    explorer.exe
    
    :Files
    C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\*.*
    C:\Windows\Temp\*.*
    C:\Users\Satellite Pro\AppData\Local\Temp\*.*
    
    :Commands
    [emptytemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.

    Now do this:
    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Please download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

    Reboot and attach the requested logs.
     
  7. mata112

    mata112 Private E-2

    Thank you so much
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Remove wnat ADW found and be sure to tell me now things are running now.
     
  9. mata112

    mata112 Private E-2

    Still here somewhere and still f... me up . I will take a hamer and delete once for all time . Thank you so much for helping me . Son the comp made a reboth it started to delete the tekst mesage from advcleaner.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download the latest version of FRST the below link.
    Farbar Recovery Scan Tool and save it to your Desktop.

    Note: Make sure you download the proper version ( 32 bit or 64 bit ) for your PC. Only one will run, the correct one. So it you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  11. mata112

    mata112 Private E-2

    here and once more thank you
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. Can you do a system restore to a time prior to your issues>?
     
  13. mata112

    mata112 Private E-2

    and combofix .
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No malware in that log. I suggest you post in the software forum as I am not finding any malware that could be causing your issues.

    Since you are not having any malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8 or 10, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     
  15. mata112

    mata112 Private E-2

    I am not mocking or doing anything like that but I still have a problem and thank you anyway.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me consult with my colleagues.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I want you to try two things.....a new keyboard and a new mouse. Borrow them if you can and report back if there is any improvement. Next we will try doing a Windows fix if it persists.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let;s try one other thing. Right click the start button and choose Command Prompt(Admin) and copy and paste this into the window and then hit enter:
    regsvr32 /i shell32

    Close the prompt and tell me if that helped.
     
  19. mata112

    mata112 Private E-2

    I must say now is unpredictebale little bit its on little bit its off. I realy dont know what to say . Now I am runin CCleaner , Zemana antimalware , Malwarebytes , Hitmanpro , and all off keeping it under control
     
  20. mata112

    mata112 Private E-2

    and now its totaly on and my touchpad is totaly out I can not use it and moust of laptop is blocked
    Now is totaly jedi skils to use and to open anything
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you able to operate in safe mode?
     
  22. mata112

    mata112 Private E-2

    Yes I have more control over in safe mode so I run hitman scan and this is log
     

    Attached Files:

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the + Repairs tab.
    • Then click the + Open Repairs button down on the bottom right.
    • This will automatically begin a registry backup, so wait for it to complete and when it finishes, you will see a list of many possible different repairs and they are all selected by default. At the bottom of this form there is a not so obvious Unselect All Repairs check box which is to the right of a check box with a green check mark in it. Please click the Unselect All Repairs box. The green check mark box is to Select All Repairs. The ony way you see what these boxes are is when your mouse hovers over them.
    • Now select the following repair options ( the numbers at the begin are the current repair numbers but this is subject to change.)
      • 01 - Reset Registry Permissions
      • 02 - Reset File Permissions
      • 03 - Reset Service Permissions
      • 04 - Register System Files
      • 05 - Repair WMI
      • 06 - Repair Windows Firewall
      • 10 - Remove Policies Set By Infections
      • 13 - Network
      • 14 - Repair Proxy Settings
      • 15 - Repair Windows Updates
      • 21 - Repair MSI (Windows Installer)
      • 23 - Repair File Associations (12 )
      • 26 - Restore Important Windows Services
      • 27 - Set Windows Services To Default Startup
    • Now on the right side under the When Repairs Complete title, check the box for Restart/Shutdown System and then make sure the Restart System radio button is enabled not the Shutdown System button.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start Repairs button at the lower right.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished. If it does not then reboot it yourself.
     
  24. mata112

    mata112 Private E-2

    done what you told still . My laptop is mocking to me I swear. When I turn on its like 10 minutes is not working and then starts working properly I really dont know what to say. thank you
     

    Attached Files:

  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are not having a malware issue. I suggest again that you post in the software forum for further assistance.
     
  26. mata112

    mata112 Private E-2

    thank yu for help and sorry for your time
     
  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem. Good luck. You mentioned that things work better in safe mode. I suggest you go to Run and type in msconfig. When that opens, go to the last tab and stop all start up items. Reboot and see how it runs.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds