Trojan.KillAV - Windows Explorer & PC Hanging

Discussion in 'Malware Help (A Specialist Will Reply)' started by danarmstrong, Mar 23, 2014.

  1. danarmstrong

    danarmstrong Private E-2

    Dell M6400 - 32 bit XP pro SP3
    I noticed a few weeks back my machine was taking a long time to open items like My Computer and when I open windows explorer.
    Then I have had issues with it locking up when my 8 yr old son is playing online games.
    Yesterday I removed some programs to free up space and ran CCleaner, including the registry cleaner, then I ran Malwarebytes. Malwarebytes found "Trojan.KillAV" last night.
    This morning I came to Majorgeeks for help. I have been using CCleaner for years and malwarebytes thanks to you guys and didn't follow the read me until this morning.
    I attached the Malwarebytes log from Sat Night and the new one today where I renamed it and re scanned. I did allow it to attempt removal of the trojan and the second scan didn't detect it. The first scan was a full scan.
    I wrote down the file name if you need it let me know.

    I will post again to insert the 6th log file.

    Thanks,
    Dan
     

    Attached Files:

  2. danarmstrong

    danarmstrong Private E-2

    Final log file.
    Thanks,
    Dan
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not appear to be having malware problems. You just have a little bit of junkware to cleanup, but I don't think it is the cause of your problems.

    First, I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep anything we asked you to save there for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.


    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    :Files
    C:\Documents and Settings\dan\Local Settings\Application Data\Conduit
    C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
    C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
    
    :Reg
    [-HKEY_USERS\S-1-5-21-454730022-1475068793-2312188003-1124\Software\Escolade]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{82461a82-a251-49a1-bde5-a16a4cca02e2}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{82461a82-a251-49a1-bde5-a16a4cca02e2}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXT log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. danarmstrong

    danarmstrong Private E-2

    Okay Chaslang,
    First thanks for your help.
    I have been at work all day and was able to clean up my desktop and run all that you asked.
    I did screw up and only disconnected from the network and ran junkware remover without disabling my AVG. So I ran it again with it disabled.
    The log named with a "1" was the first one.
    I am shutting down to head home and haven't had a chance to see how it seems to be acting now. I opened my computer and browsed some and it didn't lock up or not responding so far.

    BTW - I am an engineer and work from home a lot and that was the large desktop files. I created a new folder on the C drive (C:\PROJECTS). Will this be a better location or do you have any suggestions.

    Thanks for your time,

    Dan
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    This is fine!

    Your logs are good now.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  6. danarmstrong

    danarmstrong Private E-2

    I certainly appreciate your time Chaslang. I have been coming here on and off for years and you have always been here.
    I'm guessing 10 or more years right?

    My machine seems to be better, however just yesterday I got a "not responding" window while browsing folders in explorer.
    I have a question about that.
    When I am at the office I log in to our server and work on files directly on the server. When I plan to work from home I copy the project folder and just update the server when I get back.

    Is there something I should do to keep my machine from looking for all of the plotters, printers, and multiple drives on the server. We have partitions for Quickbooks, scanners, personal storage, job folders, etc...

    My theory was it may be constantly trying to connect to these when I am home.

    Your thoughts if you don't mind.

    Thanks again and have a great day,

    Dan
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Yep! Just past a decade. ;)

    Nothing should be necessary. I do similar and never have a problem. Just don't try to print to an office printer. ;)

    Mappped drives can sometimes cause some initial slow downs when first starting up. But once the system realizes the drives are not there to connect, it should be okay.

    However you can inquire about issues like this in the Software Forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds