Quick Question About R&RMF Procedure

Discussion in 'Malware Help (A Specialist Will Reply)' started by Mulsiphix, Mar 18, 2015.

  1. Mulsiphix

    Mulsiphix Private E-2

    So I finished step 3 of the Run & Read Me First thread. Step 4 asks me if I am still having problems. The primary problem was that ads were being injected at the top of all my google search results. This is not happening now. I don't understand why though. Malwarebytes is the only step where you actually quarantine files and that scan came back with no results. Hitman Pro reported 82 results which I haven't touched.

    So at this point do I just say I'm cured and walk away until those ads return, if they return? Just want to be sure.
     
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Mulsiphix

    If you wish for your pc to be checked for any remaining malware, please attach the five requested logs.
     
  3. Mulsiphix

    Mulsiphix Private E-2

    1. I only had one problem during the R&RMF scanning. RKRemoval boots up, sits there for a bit Initializing, blue screens, and then Windows reboots. Yes, I made sure to right-click and choose Run As Administrator. Here is a screenshot RogueKiller. It stays like this till the blue screen.
    2. Malwarebytes found no malware. Created log "malwarebytes_log.txt"
    3. TDSKiller found no rootkits. Created log "TDSSKiller.3.0.0.44_18.03.2015_13.34.16_log.txt"
    4. HitmanPro found 82 malware. Created "HitmanPro_20150318_1358.log"
    5. MGTools ran without issue. Created "MGlogs.zip"
     

    Attached Files:

  4. Mulsiphix

    Mulsiphix Private E-2

    I forgot to add this to the post above. Not sure if this helps, but here is some basic info about the RogueKiller BSOD.
     

    Attached Files:

  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Did you attempt to run it with your protection software disabled? Tried in Safe Mode w/networking?

    Please re-run Hitman Pro and have it to cleanup all the Malware remnants and Potential Unwanted Programs that it reported. Reboot immediately after.

    Now shut down your protection software (antivirus, antispyware...etc) to avoid possible conflicts. *Re-enable them before physically reconnecting to your ISP.

    Using "Programs & Features" uninstall: (If you do not find it or it will not uninstall, just keep going.)
    Java 8 Update 31

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    • R3 - URLSearchHook: (no name) - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - (no file)
    • O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    • O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe

    After clicking Fix, exit HJT.

    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Files
    C:\Program Files (x86)\50CoiUpons
    C:\Program Files (x86)\BesstSavEForuYoiu
    C:\Program Files (x86)\DeaalExprEss
    C:\Program Files (x86)\EnjoyaCoupoN
    C:\Windows\TEMP\*.*
    C:\Users\Cyndispug\AppData\Local\Temp\*.*
    :Reg
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Make sure to shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Next download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • When it's done you'll see: Pending: Please uncheck elements you don't want removed.
    • Now click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • Look over the log especially under Files/Folders for any program you want to save.
    • If there's a program you may want to save, just uncheck it from AdwCleaner.
    • If you're not sure, post the log for review. (all items found are either adware/spyware/foistware)
    • If you're ready to clean it all up.....click the Clean button.
    • After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
    • Attach that logfile to your next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which are created when running the tool.

    Now install the current version of Sun Java from:
    Make sure that when you install the new version of Java that you uncheck the Install the Ask Toolbar junkware checkbox. You do not want to add the stuff junk that most people consider malware to your PC. Also just in case Oracle changes the Java installation in the future to possible install other junk, uncheck all but just installing Java.

    Next, re-run Hitman Pro (just a scan) and attach that updated log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select "Run As Administrator").

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXT log
    • C:\MGlogs.zip
    • AdwCleaner[S#].txt
    • RogueKiller log.txt <- if it did run
    • updated HitmanPro log
    Make sure you tell me how things are working now!
     
  6. Mulsiphix

    Mulsiphix Private E-2

    1. Disable System Protection & Internet
      Disabled kaspersky, comodo, hostman, peerblock, and internet adapter
    2. Uninstalling Java 8 Update 31
      Followed Instructions.
    3. RogueKiller
      Still a BSOD with above applications disabled. Booted into Safe Mode and it started up successfully this time. I ran a scan but it did not create the "RKreport[1].txt" on my desktop that Step 3 of the Vista, Win 7 and Win 8 Malware Removal/Cleaning Procedure guide said it would. However, when I clicked on the Report button it opened a scan log that was stored in C:\ProgramData\RogueKiller\Logs\. I have attached that scan log: "RKreport_SCN_03202015_110014.log".
    4. Re-Ran HitmanPro
      I thought I had followed your instructions, but now that I am doing the second scan (at the end of all your instructions) it occurs to me that I only hit the Next button this morning. I failed to mark any of its scan results for quarantine. I saved a log on the next screen and it still shows all of the files in tact. Though now that I've run a second scan, it seems all the other tools cleaned up all of HitmanPro's previous scan results. I apologize for making this mistake. I should have been paying closer attention.
    5. Ran Analyse.exe
      R3 and 02 were present, but 04 was not. I could not find it in the list. Followed your instructions to remove R3 and 02.
    6. OTM
      Followed instructions. Required a reboot. Obtained log: "03202015_120232.txt". Renamed to "MovedFiles.log".
    7. Junkware Removal Tool
      Followed instructions. Obtained log: "JRT.txt"
    8. AdwCleaner
      Followed Instructions. Obtained log: "AdwCleaner[S0].txt"
    9. Installing Java 64-bit
      Followed instructions, though there was no AskToolbar or any other Junkware available, so no boxes required unticking. Just a straight installation of Java. I used the link you provided to obtain the installer.
    10. HitmanPro Re-scan & Enable Internet Adapter
      Opened program and the next button was greyed out. It said there was no internet connection. Eventually it stopped looking for one and I had to close the program. Re-enabled internet adapter and was able to scan. Followed instructions. Obtained log: "HitmanPro_20150320_1709.log"
    11. MGTools GetLogs.bat File
      Followed instructions. Obtained zip: "MGlogs.zip"
    12. Re-enable Disabled Protection Software
      Re-enabled Kaspersky, Comodo, Hostsman, and Peerblock.
     

    Attached Files:

  7. Mulsiphix

    Mulsiphix Private E-2

    Couldn't add all logs to the last post. Here is the RogueKiller log file.
     

    Attached Files:

  8. Mulsiphix

    Mulsiphix Private E-2

    :cry I'm so sorry. I'm not trying to bump the thread, I promise. I forgot to tell you how the system is running now. I tried to edit the above two threads but too much time had passed.

    How is the system doing?
    As I mentioned before I'm not really seeing any evidence of adware anymore. I was concerned with the HitmanPro results that there was still bad stuff on my system. This computer has had issues with connecting to the internet for some time, though I'm not sure if it is related to malware or not. When the system boots up it will take 5 full minutes before I am able to access any websites.

    If I use MSConfig to ensure that only System Services load with Windows, this time is cut down to 2:30 minutes. If I boot into Safe Mode w/Networking this time is cut down to 0:30 seconds. Obviously there is something going on but since I can't say for certain that it is malware, I didn't plan on bringing this up. I have another Windows 7 HP 64-bit laptop and it gains access to the web within 30 to 60 seconds, pretty much as soon as I can get a web browser open.

    I'm visiting my parents and I promised to take a look at their laptops. If this were my own system it would be easier to describe these issues with more certainty. I plan to take a closer look at her networking issue tomorrow. Thank you so much for your help. I sincerely appreciate your time and assistance :-o ;).
     
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    No problems with the additional posts for logs and a pc health update. :)

    I'm not finding that the above is caused by malware. I suspect the system's slow bootup is caused by the large number of services loading as shown in the MGlogs.zip log.

    Please ask for help with trimming them down in our Software Forum.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, Win 7/8 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Go to the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7/8, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work through the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
  10. Mulsiphix

    Mulsiphix Private E-2

    Thank you so much for your help. I sincerely appreciate your time and efforts. Thank you!!! :celebrate
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds