Tricky Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by TheTick, Jun 28, 2014.

  1. TheTick

    TheTick Corporal

    Hi Guys

    Been having a bit of trouble over the last month with my computer taking up lots of memory. I am aware that keeping lots of tabs open uses lots of process but it seems to be getting worse for me.

    So last week I have ran basic scans including hitman pro and and they picked up some Malware (hit man pro picked up two pieces of Malware but as i have used the program once it would not let me act on the issues), my comp seemed to be working better, however it has started to happen again this week, Taking up lots of processing and working really hard.

    I have completed your scans on here and will attach the logs, i hope they got it all.

    My comp is:
    Dell Inspiron
    Intel i3 CPU 2.53ghz
    6 gb ram
    64 bit os
    Windows 7
    320 Gb HD.

    I recently upgraded the RAM to 6GB from 3 to help with the running of the system, this was working fine and dont seem to have had any issues.

    Cheers
    The Tick
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    All I am seeing is some junk:

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  3. TheTick

    TheTick Corporal

    Hi TimW

    Cheers for the response, its weird that there is only junk now as when i run the scans earlier in the week Hitman Pro picked up two malware remnants that i could not remove, and yesterday did not pick up any, maybe they got picked up by the scans i did yesterday, any whoo good news lol

    I have completed the Junkware scan and am attaching the log, chrome seems to be running smoother now i will monitor my machine in the coming week :D

    Cheers for your help

    Adam
     

    Attached Files:

    • JRT.txt
      File size:
      2.1 KB
      Views:
      2
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun Hitman and attach the new log, please.
     
  5. TheTick

    TheTick Corporal

    Hi Tim

    Here is the new log :)

    Cheers Again

    Adam
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    After a reboot, rescan with Hitman.
     
  7. TheTick

    TheTick Corporal

    Hi Tim

    Here is the new scan, i copied the bold writing, was i supposed to copy the REDEDIT4 bit? I did and double clicked on it and saved, i received a success message. The rebooted and ran hitman.

    Here is the log

    Cheers

    Adam
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
     
  9. TheTick

    TheTick Corporal

    Ok I have run the scan and got the report, the software still says pending so i guess its waiting for me to take some action.

    The only thing i am unsure of are in the folder section are:

    Folder Found : C:\Users\Adam\AppData\Local\Webinternetsecurity
    Folder Found : C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Browser Manager

    If these arent essential then they can go.

    As for the rest

    Files - I dont use firefox
    Registry, there is nothing that i recognise there
    Chrome - Dont need owt there.

    To be honest there is nothing i really recognise in all of it

    Here is the log

    Cheers

    Adam
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go ahead and have it fix what it found. Let me know how things are running.
     
  11. TheTick

    TheTick Corporal

    Hi Tim

    Things seem to be running ok as far as i can tell, programs opening quicker etc

    Can i just does Malwarebytes hog a lot of system resources? I ask as before we cleaned this machine it would take forever to open and kept saying 'not responding' just want to know if it is worth keeping running constantly or not.

    Everything else seems ok :D

    Cheers

    Adam
     
  12. TheTick

    TheTick Corporal

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should just run MBAM when you suspect issues.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds