Seeking Help with Possible Malware infectionm

Discussion in 'Malware Help (A Specialist Will Reply)' started by mbdiener, Jan 8, 2014.

  1. mbdiener

    mbdiener Private E-2

    I suspect a Malware infection on my Windows 7 Home Premium 64 bit system. Symptoms are extremely slow browser operation especially when clicking on links and receiving long connects which often result in a "cannot contact the server" message coupled with a retry which is often successful. Other PCs not behaving this way and network tests yield no issues.

    Logs are attached. I had run a number of the recommended programs previously, resulting in items to delete or quarantine. This time some came back with no threats but Rogue Killer came back with some hits and issue still remains. Please not that there is no Hitman Pro log because it came up clean.

    Assistance is appreciated. Thanks.

    Mickey
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    Nope! It is clean as are the rest of your logs. You need to look at things you are running. Perhaps the below would be a good starting place

    O4 - HKLM\..\Run: [SOSUAUI] "C:\Program Files (x86)\SOS Online Backup\sosuploadagent.exe" -showui
    O4 - HKLM\..\Run: [SMessaging] "C:\Program Files (x86)\SOS Online Backup\SMessaging.exe"
    O4 - HKLM\..\Run: [AccountCreatorRunner] "C:\Program Files (x86)\SOS Online Backup\AccountCreatorRunner.exe"
    O23 - Service: Offsite Online Backup Service (sagentservice) - SOS Online Backup - C:\Program Files (x86)\SOS Online Backup\SAgent.Service.exe
     
  3. mbdiener

    mbdiener Private E-2

    Thanks very much for the review. The items you note looks like they're part of the SOS Online Backup program that I run to auto backup to the cloud. I'll uninstall temporarily to see if that's causing the issues.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. There may be several other necessary startups that you could remove. You will have to reasearch which really need to load at startup. Most can just be run when you want to use them. Research the below:


    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds