Suspect Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by enathe3, Oct 9, 2015.

  1. enathe3

    enathe3 Private E-2

    I have read all information on the read first pages and downloaded all scanners. I have run all the scans and this is my first time posting. Computer started a month ago with the Task manager not displaying Explorer. Everything seemed fime but high memory usage. Computer began slowing with a number of Internet Explorer and Mozilla crashes. Some crashes while running program files, delayed openings. After three seperate System restores MG suggested a tool, AVIRA. I eliminated Bullgaurd and ran AVIRA with it finding "TR/Spy.2951336" and "TR/Crypt.XPACK.Gen7" and quarenteend them. I disabled that program and followed all your instructions.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there :)

    Still need to see the log from Hitman Pro and the MGlogs.zip from running MGTools.exe please.
     
  3. enathe3

    enathe3 Private E-2

    Hello and thanks!
    I put the Hitmanpro in the wrong spot. I made a number of mistakes when first running Hitmanpro, I hope this is the right information this time. I never got any windows identifying a virus. I just screwed up the last MGtools log. It is running again. I will send again but now its out of sequence. Sorry:confused
     

    Attached Files:

  4. enathe3

    enathe3 Private E-2

    Hello again,
    I reread the instructions on MGTools and I am attempting to send it again. Tell me if I screw it up again.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode. Any other mode is primarily used for troubleshooting and diagnostic purposes. You should look into some third party software to control start up's.

    Is there anything you wish to keep that Hitman is finding? (Coupons and Yahoo toolbar)


    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know about what Hitman is finding....
     
  6. enathe3

    enathe3 Private E-2

    Good day.
    Once I double click I get a warning window about proceeding with caution but when I say go ahead I get this Error Msg. " Cannot import C:\users\Mom n Dad\Desktop\fixME.reg. The specified file is not a registry script. You can only import binary registry files from within registry editor."
    Did I do something wrong? I copied to notebook saved as fixME.reg, all files and desktop. Tried second time and included *REGEDIT4 but got the same result.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just continue on with the other instructions ;)
     
  8. enathe3

    enathe3 Private E-2

    Attached two items. I couldn' remember how to do MG files.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I told you how to run MGTools. I'd like to see a FRESH MGLogs.zip please.

     
  10. enathe3

    enathe3 Private E-2

    OK. Got it this time. My desk top had three zip files so I looked for the one just created. this should be it. I will watch for your repliy. I thank you very much for all the time you have given me.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to let me know about what Hitman Pro is finding when you scan with it. Is there anything you want to keep?
     
  12. enathe3

    enathe3 Private E-2

    No there is nothing I want to keep that Hitman Pro has found. (coupons and yahoo tool bar) Definitely no. Nothing.:-D
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall Coupon Printer for Windows and Yahoo Toolbar then re run Hitman Pro again and attach log.
     
  14. enathe3

    enathe3 Private E-2

    Done. No entries. Clean scan I think. I had to use a third party uninstaller to remove the coupon printer (revo uninstaller).
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Excellent. :) How are things running now?
     
  16. enathe3

    enathe3 Private E-2

    Things have been running much better. The computer starts faster, not so sluggish. I havent received any errors. Everything seems to run smoother. Again, Thanks. Whats next?
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're most welcome :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  18. enathe3

    enathe3 Private E-2

    Malwarebytes Anti-Malware, I will keep. What about an antivirus recommendation. I loaded Avira before contacting you. It keeps loading ad's, if there is an equivelant or better one I would switch. Though I liked some features its not a shoe in. Meantime I will go to work on your latest.
    Note* FYI even though I am fixed income and my family relies heavily on the computer for school, you can bet I will continue to support MG. And I tell everyone. I don't trust anyone else out there for advice and tested software/advice.
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I would go with Comodo free version. :)

    Thankyou for the compliment on our website :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds