Someone Is Logged Into My Computer When I Try To Shutdown

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by stuhaz, Mar 13, 2018.

  1. stuhaz

    stuhaz Private E-2

    Hi.
    On my study PC I run Windows 10 with Bitdefender Total Security 2018, and Malwarebytes Premium. I changed my anti-virus from Avast to Bitdefender early December 2017.
    Since about Xmas, we have noticed that, when I boot up my computer, login as me, do some work, browse internet etc, when I come to shutdown I get a pop-up stating that someone else is logged into my computer and shutting down may cause loss of data. When I check, it says my wife is logged in. But, she has not logged in since I booted up the computer that day. When I login to her account, there appears to be no windows open.
    The same happens when my wife boots up the computer, logs in etc, and then tries to shutdown - on occasions the computer will say I am also logged in when I had not.
    I am presuming that when the computer is shutdown all login accounts are logged out; that is to say, if I don't first logout then shutdown, but I just shutdown whilst logged in, the computer will have me logged out and will require me to log back in again on next re-boot.
    I have followed your Read and Run Me First Malware Removal Guide, and, also changed all my passwords for logging into my computer (my login, my wife's and admin login passwords); at first it seemed to work but after 1 week we are now back to where we were before.
    I attach my logs.
    Thanks, Stuart
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I do not think your issue is malware related. However, let's remove some junk.

    Please remove these items in ADWCleaner:
    PUP.Optional.SpyHunter, C:\Program Files\Enigma Software Group
    PUP.Optional.SpyHunter, C:\sh4ldr
    PUP.Optional.SpyHunter, C:\sh4ldr
    PUP.Optional.SpyHunter, [Key] - HKLM\SOFTWARE\EnigmaSoftwareGroup
    PUP.Optional.SpyHunter, [Key] - HKLM\SOFTWARE\EnigmaSoftwareGroup
    PUP.Optional.DriverSupport, C:\ProgramData\UAB
    PUP.Optional.DriverSupport, C:\Windows\System32\rnd_chunk.bin
    PUP.Optional.DriverSupport, C:\Windows\SysWOW64\rnd_chunk.bin
    PUP.Optional.DriverSupport, [Key] - HKLM\SOFTWARE\ActiveOptimization

    Then use Hitman to remove these items:
    ¤¤¤ Registry : 17 ¤¤¤
    [PUP.Conduit|PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-4202826809-1449890687-2335414762-1006\Software\Conduit -> Found

    ¤¤¤ Files : 2 ¤¤¤
    [PUP.Gen1][Folder] C:\Users\Admin\AppData\Roaming\Easeware -> Found
    [PUP.Gen1][Folder] C:\Program Files (x86)\Driver Detective -> Found

    Reboot and rerun both ADWCleaner and Hitman and attach the new logs.

    If you want a drive updater, I suggest you use Drive Booster.

    Your MGLogs.zip is from 2015 ....please run it anew and attach a current zip.
     
    Last edited: Mar 13, 2018
  3. stuhaz

    stuhaz Private E-2

    OK - I ran ADWCleaner OK and deleted the items you indicated (Windows 10 forced through an update on reboot, mind -- grrr).

    I re-ran Hitman Pro but could only find:

    HKU\S-1-5-21-4202826809-1449890687-2335414762-1006\Software\Conduit\ (Conduit)

    which I deleted; I could not see the 2 Files you mentioned.

    However, on my Roguekillerlog.txt from 1wk ago, I did see:

    [PUP.Conduit|PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-4202826809-1449890687-2335414762-1006\Software\Conduit -> Found

    and
    ¤¤¤ Files : 2 ¤¤¤
    [PUP.Gen1][Folder] C:\Users\Admin\AppData\Roaming\Easeware -> Found
    [PUP.Gen1][Folder] C:\Program Files (x86)\Driver Detective -> Found

    Did you mean for me to use Roguekiller?

    Anyway, as directed, I have used ADWCleaner and Hitman, and rebooted, re-ran both again and have attached the new logs.

    I had the devil of a job downloading MGTools to my C:\ drive as it kept requiring Administrator permissions even though I was in Admin; anyway I eventually saved it to my Admin desktop, ran it and it has put a new zip file on my C:\ drive, which I also attach.

    Stuart
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry...too much going on at once....yes I did mean Roguekiller.

    Please have ADW remove these items:
    ***** [ Folders ] *****

    PUP.Optional.DriverDetective, C:\Program Files (x86)\Driver Detective


    ***** [ Files ] *****

    PUP.Optional.DriverAgent, C:\Windows\System32\drivers\DRVAGENT64.SYS

    ***** [ Tasks ] *****

    PUP.Optional.Legacy, Driver Detective-RTMRules
    PUP.Optional.Legacy, Driver Detective-RTMScan
    PUP.Optional.Legacy, Driver Detective-RTMUpdater

    ***** [ Registry ] *****
    PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\DriversHQ.DriverDetective.Client.exe

    Even though you were on an Admin account, did you still right click MGTools.exe and run as Admin? Your log is basically empty. Please do it again and also get me a new RogueKiller log.
     
  5. stuhaz

    stuhaz Private E-2

    OK - ADW re-run and items you listed removed.

    I enabled Administrator Login, downloaded MGTools and saved at C:\. Ran that with Administrator privileges.
    Also re-ran RogueKiller (updated version). Logs attached.

    Stuart
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use RogueKiller to remove these:
    ¤¤¤ Tasks : 1 ¤¤¤
    [PUP.Gen1] \Driver Detective -- C:\Program Files (x86)\Driver Detective\DriversHQ.DriverDetective.Client.exe (/applicationMode:systemTray /showWelcome:false) -> Found

    ¤¤¤ Files : 1 ¤¤¤
    [PUP.Gen1][Folder] C:\Users\Admin\AppData\Roaming\Easeware -> Found

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The red is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.

    If it all runs successful, attach the two logs.
     
  7. stuhaz

    stuhaz Private E-2

    I ran RogueKiller and deleted the 2 items specified.

    I opened cmd as Administrator and ran your commands.
    Error message on running GetRunKey = "Access is denied"
    Error message on running ShowNew = "'ShowNew' is not recognised as an internal or external command, operable program or batch file"

    I forgot to save RogueKiller log, so re-ran after deletion without re-booting; subsequent log attached.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's do one more thing to be sure, then I am going to send you to the software forum where you can explore your login options ( my suggestion would be to make sure each user sign out of their session).

    Please download the latest version of FRST the below link.
    Farbar Recovery Scan Tool and save it to your Desktop.

    Note: Make sure you download the proper version ( 32 bit or 64 bit ) for your PC. Only one will run, the correct one. So it you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  9. stuhaz

    stuhaz Private E-2

    OK scan done, logs attached
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
     

    Attached Files:

  11. stuhaz

    stuhaz Private E-2

    Sorry - where do I find fixlist.txt to save to my Desktop?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is attached to my last reply.
     
  13. stuhaz

    stuhaz Private E-2

    OK; I originally ran FRST without admin privileges.

    I have repeated the scan, this time re-run as admin, and have appended the files.
    I think fixlist.txt needs to be made by cut and paste into a Notepad file (fixlist.txt) but not sure what to do.
     

    Attached Files:

  14. stuhaz

    stuhaz Private E-2

    OK just realised what you said.

    Will disconnect internet & re-run FRST as admin.
     
  15. stuhaz

    stuhaz Private E-2

    OK - all done (sorry about the confusion).
    Log attached.
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok...now I can say you are malware free. As per my recent suggestion:
    I am going to send you to the software forum where you can explore your login options ( my suggestion would be to make sure each user sign out of their session).

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Re-enable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8 or 10, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 or 10 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     
  17. stuhaz

    stuhaz Private E-2

    Thanks for all your help!
    Bye!
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are very welcome.
     
  19. stuhaz

    stuhaz Private E-2

    Sorry to come back to you, but I have now noticed that MGtools was blocked by my Bitdefender Antivirus hence my negative results in #7 above.
    Is this something I need to re-run?
    Thanks,

    Stuart
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No...got what I needed with Farbar.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds