Please review logs -SearchBrowse/SearchProtect etc..

Discussion in 'Malware Help (A Specialist Will Reply)' started by axlmastr, Mar 11, 2015.

  1. axlmastr

    axlmastr Private E-2

    Please advise any further actions. It feels and acts better from what I started with. This is a college student's second machine that I received to look at as a friend because I am familiar with Malware and your wonderful forum. The second machine (with Vista) also trashed will be posted as well. I offered a loaner until these are cleaned.

    Owner is 8 weeks from graduating and has struggled with this for close to 6 months with "IT" people telling her they couldn't help her! This machine was purchased because the Vista machine couldn't connect to Charter WiFi in residence so the tech told her she need to buy a new machine!

    I have run required programs twice with one System Restore toggle. I removed a good portion of the trash with the required programs and the addition of Adwcleaner & Junkware Removal Tool. The following logs represent running the required programs with Malwarebytes and Hitman removing the majority of the trash on the second round. The first round only yielded a little positive result. from Malwarebytes. McAfee did quarantine some files and I deleted those before starting the process.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to rerun Malwarebytes and have it fix what it found. Your logs shows you did not fix anything. Then immediately reboot the PC.

    After reboot, rerun Hitman Pro and have it fix all the Malware, Malware remants and Potential Unwanted Programs it finds. Again immediately reboot.

    After this second reboot run a new scan with Hitman Pro and attach this new log.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  3. axlmastr

    axlmastr Private E-2

    Okay I got the logs confused because i had to run them twice before posting. The second time was the charm but the creation of logs used to be simpler before .xml logs. I now get a scan log and a protection log. I had mentioned in my initial post that I did run JRT prior to posting, but decided to run it again. Anyway, I am posting the requested logs and all look fairly clean correlating with my comment that this machine is running better.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks good.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  5. axlmastr

    axlmastr Private E-2

    Thanks again Chaslang you have come through as always. The owner will be very happy to have this machine back to finish out college We together have averted a disastrous effect on her final grades for graduation in 8 weeks. I will get my loaner back too.

    I like the fact that you can help me help others. I just do this because many people don't have knowledge of your site or the know how to tackle the issues even when I refer them here. I am a volunteer outside of here speaking praises of your quest. :major

    I still have the Vista machine so I will post its logs next.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Thanks. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds