Probably Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by userofcomputers, Feb 18, 2016.

  1. userofcomputers

    userofcomputers Private E-2

    Hi there,

    So I'm helping out a friend with their computer. They've had loading problems, it won't let them install Avast, and Chrome is wayyy on the fritz. They have been downloading free movies by just Googling random sites, so I figure I should mention that. Here you go. Thanks!

    Userofcomputers
    p.s. I ran RogueKiller, but it wouldn't let me get a log before closing out. Should I run it again?
     

    Attached Files:

  2. userofcomputers

    userofcomputers Private E-2

    Ran it again; it completed this time. Here is the log--there was no option to extract as txt (maybe because I have the Spanish language version?), so I copied the .json and renamed it as a .txt. Hope this works!
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, userofcomputers


    I need a RogueKiller log exported in TXT format - NOT .JSON. Please re-read the RogueKiller instructions to produce an updated log in the correct format.
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Additional instructions -


    Did you have Malwarebytes' fix everything that was detected? If not, please do so and upload that log.

    Please re-scan with Hitman Pro, activate the Trial License and have it delete everything under the heading(s) of
    • Malware
    • Potential Unwanted Programs
    ..ignore any other findings.
    Afterwards, click the Next button.
    HitmanPro may want to reboot the PC in order for the changes to take affect, please do so.
    After reboot and when you are back in Windows, run another scan with HitmanPro and then attach the latest HitmanPro log.

    Please download the 32-bit version of the below, run it twice with a reboot in-between.
    AVG Remover 1.0.0.8

    Uninstall your outdated Java 8 Update 65 using GeekUninstaller 1.3.5.56, a portable appl.

    Next, copy the bold text below to notepad. (Do not include any space above the word "REGEDIT4")Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" . Once you have saved it double click it and allow it to merge with the registry.
    *Make sure that you tell me whether or not you receive a success message about adding the above to the registry. If you do not get a success message, it definitely did not work.

    Now please download Junkware Removal Tool to your desktop.
    • Make sure to shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Upload JRT.txt to your next message.

    Next download Farbar Recovery Scan Tool (FRST) and save it to your Desktop.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press the Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run from.
    • The first time the tool is run, it also makes another log (Addition.txt).
    • Upload both log files to your next reply.

    Now install the current version of Sun Java:
    Java Runtime Environment 32-Bit 8 Update 74

    Then upload the below logs:
    • the JRT.TXT log
    • updated MBAM log.txt
    • updated Hitman Pro log
    • FRST.txt and Addition.txt
    Make sure you tell me how things are working now!
     
  5. userofcomputers

    userofcomputers Private E-2

    Ok, will do!

    Also, I'll run RogueKiller again, but I promise there wasn't an export .txt button! I really swear I'm not being lazy, I really appreciate you guys and I read all the directions. Please see my screen shot, it was from after the scan.

    I'll get the scans and other stuff up later tonight or tomorrow morning, don't worry about replying. I just wanted to let you know what was going on.
     
  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;) Referring to your screen shot ->
    • After the scan has completed, click on "Report"
    • A new GUI opens - at the bottom far right-hand corner, click on the "Export TXT" radio button.
     
  7. userofcomputers

    userofcomputers Private E-2

    Aahhhhh OK. In Spanish, 'reportar' is when you report something, like a crime, so it didn't occur to me that that might be what I click for a report, or informe. ...at least, that's my excuse! haha. Here's the RogueKiller log, and meanwhile, I'll be working on what you gave me in the post before.
     

    Attached Files:

  8. userofcomputers

    userofcomputers Private E-2

    OK, done.

    Computer performance is much better, without a doubt. I haven't gotten the chance to roam around too much, but boot up and general operation are great, and the browser is working much smoother. Also, the computer isn't making that grinding sound all the time. Added bonus.

    I did get the "correctly loaded" message when I added fixME.reg to the registry. :)

    As for the second mwb log, I did delete everything the first time I ran it, so I ignored the direction at the beginning. I ended up running it again at the end so you would have the log.

    I also downloaded and installed Avira after running all of the scans and such. (The other antivirus was wiped out as a PUP, haha... I was going to change it anyway.)

    So here you go! Thanks again, hope you're having a good weekend.
     

    Attached Files:

  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome and I hope your weekend is going well.

    Now re-run RogueKiller and run a scan. After it finishes the scan, select the following tabs and then select any of the below that exist and then click the Delete button.
    *Make sure you select the Click to Expand text ( if present ) at the bottom of the quote box to see the whole fix.
    Then immediately reboot your PC.

    After reboot, run a new scan with RogueKiller and save a log as in the original instructions and upload the new log.

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.
    • Save the attached (fixlist.txt) to your desktop.
    • Right-click FRST(x32/64) and select Run as Administrator.
    • Click the FIX button once.
    • Wait while FRST processes fixlist.txt
    • A report should pop up named Fixlog.txt, please upload it here in your next reply.
    Please download ZHPcleaner to your desktop.
    • Close all applications (including your web browsers and antivirus)
    • Double-click on ZHPCleaner to run the tool.
    • If you are using Windows Vista, 7/8/10; instead of double-clicking, right-mouse click ZHPCleaner and select "Run as Administrator".
    • Please click the "J'accepte/I agree" button.
      • First press the "Scanner" button. Be patient, the scan takes longer than 5mins.
      • Then press the ''Repair'' button.
    • Browsers will automatically shut down.
    • A logfile will automatically open after the scan has finished.
    • Please upload that logfile with your next reply.
     

    Attached Files:

  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Are you still with me, userofcomputers? :)
     
  11. userofcomputers

    userofcomputers Private E-2

    Hi there, I'm sorry! My personal computer broke down and I had to take care of that before I got to someone else's. I'm working on the last instructions now!
     
  12. userofcomputers

    userofcomputers Private E-2

    Here you go! Thanks!
     

    Attached Files:

  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome.

    Your logs look good! If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, Win 7/8 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Go to the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7/8, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work through the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds