Query Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by clixto, Dec 29, 2014.

  1. clixto

    clixto Specialist

    Been having issues with my browser clicking the back button and my comp just doesn't seem to running correctly

    Following the read me &run protocol
    Hitman found something as well as MG tools found: Steel werx

    Attached are my scans. I believe tds didn't find anything nor did MB

    My Sys:
    Mobo: GIGABYTE GA-870A-UD3 AM3 AMD 870 SATA 6Gb/s USB 3.0 ATX AMD
    BIOS: AMD 870 BIOS for GA-870A-UD3 F2
    CPU: AMD Phenom II X4 965 HDZ965FBGMBOX
    RAM: OCZ3SOE1600LV4GK
    Vid: XFX Radeon HD 5770
    PSU: stock with Sonata III case
    HDD: Western Digital Caviar Black WD1002FAEX 1TB 7200 RPM 64MB Cache SATA 6.0Gb/s 3.5"
    OS: 64 bit Win 7 ultimate
     

    Attached Files:

    Last edited: Dec 29, 2014
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Most likely not a malware problem. More likely due to googleads or similar cluttering up your browser's ability to click back. If using IE this happens a lot due to the fact that Google Chrome is in competition with IE

    You will have to be significantly more descriptive especially since your logs are clean.

    Nope! Just Asktool bar which is installed and used as part of Avira.

    Nope! This was not a report of malware. It is a report of a tool being used by MGtools which was designed by Steelwerx.
     
  3. clixto

    clixto Specialist

    I only use firefox. I don't believe I installed the ask toolbar with avira. I'll double check.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    At one point in time, you did not have any choice. Supposedly in 2014 Avira was to stop using AskToolbar and was going to add their own browser extension.

    AskToolbar gets installed by many free applications on the internet. Sometimes you can say no and sometimes you cannot.

    You can just have Hitman remove those items then. You can also check Firefox for any addons from Ask.com
     
  5. clixto

    clixto Specialist

    Re-run hitman and remove? Can I re-enable UAC and defogger afterwards? Also I have ini files on my desktop now..how do I remove or replace? Hitman pro says my trial license expired and I cannot delete.
    thx
     
    Last edited: Dec 30, 2014
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes. If your trial has not expired. Otherwise you will have to manually remove those registry items.

    Addressed in final instructions below.

    They are part of Windows and were always there but were invisibile before. When we enabled viewing of hidden files, they showed up. Also addressed in the below. MGclean.bat should rehide. If not, you can reverse the settings we had you make in the READ & RUN ME FIRST.




    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     
  7. clixto

    clixto Specialist

    Thanks again for your help.Happy New Year!!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely! And Happy New Year to you too thanks!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds