sudden malware symptoms/logs

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by robert707, Dec 9, 2013.

  1. robert707

    robert707 Corporal

    Hi I'm prety sure I have malware of some kind messing up my system. I had just downloaded an image in the previous sesion off a website I had never been before (normally I'm more careful)...The internet connection started acting very wierd. The icon that indicates your net connection in Win7, the little screen with the cable next to it? It kept disconnecting and trying to reconnect, before disconecting again. After rapidly spazing out like this for a few sessions it changed to having a net connection for about a minute and then just almost no internet traffic even though it says it's connected. Or it's connected for a few minutes before the little yellow triangle shows up and says 'no connection'. While trying to fix things out myself with AVG (found nothing) and rebooting/cleaning things out, I had 2 sudden blue screen shut downs...wich I've never had on this PC before. Also, the dial-up dialogue box has come up a few times when firefox is closed indicating that something keeps trying to use my net connection.

    My PC is connected to a wired router which is connected to another PC were the internet is fine. Also, when I switch the router cable that is usually hooked up to my PC to my game console the internet is fine. Which make's me think it must be my PC not my ISP. I've also tried unplugging the modem and reconnecting which gets me my internet back for about 30 seconds, if all at.

    Ok so I went through all the Read-Me+Win7 instructions. Logs attached. Rougue Killer: a few red colored entries came up on the driver tab.


     

    Attached Files:

    Last edited by a moderator: Dec 9, 2013
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. You can rerun Hitman and remove that one item.

    I suggest you post in the software forum for further assistance.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.


    After doing the above, you should work thru the below link:

     
  3. robert707

    robert707 Corporal

    What about those two entires in the RogueKiller results? I mentioned there were two entries in the drivers tab that were marked red. But the intructions on the Win7 page said to wait for feedback before touching anything so I wan't sure if it was safe to delete those entries.

    Also before these symptoms started my AVG said i wasn't fully protected, I looked in the menue and it said my 'indentity protection' wasn't activated, when clicking on 'fix' it said it couldn't fix the component.....if that might have anything to do with an infection of some kind.


    Thanks for feedback.
     
  4. robert707

    robert707 Corporal

    ....about my logs not finding any malware....if I have most of jy files saved to an external hard drive could something be hidding in there that the scans may have missed? Is there a scan that I would have had to direct it's attention to the drive?

    Thanks for feedback.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am sure your external is fine. You can have RogueKiller fix the driver issues, but they are not significant.

    What issues are you still having?
     
  6. robert707

    robert707 Corporal

    Got something....

    re-ran Rougue Killer to get those driver issues I mentioned and the report was different this time. Not sure why. There were several more listings in the driver section although none of them were highlighted in red like the last time. Also it said it found 8 'bad processes". I checked the previous log in case you already saw those and thought they were nothing and the previous scan I posted had 0 'bad processes'.

    So do these mean anything? Do I just have Rougue killer delete them or how should I deal with these?

    And I thought the external hard drive was significant because the file I downloaded before these symptoms started was downloaded to the external hd. I was wondering if I get rid of whatever's going on if it will just come back if something is still lurking in the external.

    Thanks for any feed back.

    (symptoms are still net going very slow after about 1 minute of connection and then eventually halting, or saying 'not connected' with the little yellow triangle on the connection icon even though other devices on same cable+modem are fine. Like it's fine at first and then something slowly brings it down. No streaming of any kind will work.)
     

    Attached Files:

    Last edited: Dec 10, 2013
  7. robert707

    robert707 Corporal

    my mistake...I mixed up the 'Bad Processes' part with 'registry entires'. both logs say '0 Bad processes'
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The log is clean. I suggest you post in the software forum for issues with your internet connection.

    Since you are not having any malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.


    After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds