Trojan or Malware? Or where do I go from here, I'm stuck.

Discussion in 'Malware Help (A Specialist Will Reply)' started by PunchingBee, Nov 20, 2013.

  1. PunchingBee

    PunchingBee Private E-2

    The last issue I had resolved here concerned a relatively new computer with only a couple issues. Issues that I could pinpoint a little. This next computer came to me with many things already on it and I've only recently become a little more of a savvy surfer/downloader. This machine was pretty dirty, so I've been cleaning it as per many of the guidelines on this site and recommendations from Windows forums, but it's still crashing/running poorly. So I bring you this:

    I'm not totally sure what's wrong with it. I suspect malware and maybe a trojan? It wouldn't turn on for a long time, but once I got it running, I found I could use it pretty flawlessly in safe mode. I first did all the normal things to clean up/back up/repair through the system (Windows Vista Home Premium), but it hardly stays on in normal boot mode, won't open most programs and crashes once it's online for a minute or two.

    I followed all the READ & RUN ME FIRST, here are my logs
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi PB,

    Re run Hitman Pro and have it delete Potential Unwanted Programs.


    Are you deliberately set up to use a proxy? If NOT then please follow the below fix: (The Hijackthis - analyse.exe part) - follow all other instructions regardless.


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;127.0.0.1:9421;<local>

    After clicking Fix exit HJT.



    Download and run OTM.


    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\Users\desktop\AppData\Roaming\Microsoft\Windows\Templates\20xYJkS83BHk4
    C:\Program Files (x86)\GUM3800.tmp
    C:\Program Files (x86)\GUM4A39.tmp
    C:\Program Files (x86)\GUT3820.tmp
    C:\Program Files (x86)\GUT4A3A.tmp
    
    :reg
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{7640302B-72B3-4D12-A219-B8B2F0ACE831}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{7640302B-72B3-4D12-A219-B8B2F0ACE831}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
    Last edited: Nov 20, 2013
  3. PunchingBee

    PunchingBee Private E-2

    Alright, so I got up this morning and turned the beast on. It worked through me clicking "Safe Mode with Networking", then the screen went black and I had to restart. This happened once more, and now it won't even get that far. The fan runs, there's two really soft clips and beeps but the keyboard does not flash like it usually does right before it loads the OS. The screen stays black and I turn it off to try again. I usually give it 5-10 minutes on the black screen before I turn it off.

    I found this thread:
    http://forums.majorgeeks.com/showthread.php?t=281571

    I too run a HP Pavilion with Windows Vista (similar, right?). Do you think I should mess with the CMOS battery? It doesn't look out of my ability, I just don't want to do anything to change things up on you/further mess up my PC.

    or I can let it sit for awhile and see if it works again. I let it sit for a few months once it stopped working reliably, then it booted up with no problem for the past 5 days.

    What do you think?
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you cannot get it to boot up, then I would suggest that you should post in the software forum and then return here for malware removal if necessary. :)
     
  5. PunchingBee

    PunchingBee Private E-2

    man oh man,

    OK, so I got it to boot after letting it sit unplugged for a few hours, not sure why that worked, ha! But, I got the logs. Here they are.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did you have Hitman delete the PUP's?
     
  7. PunchingBee

    PunchingBee Private E-2

    Aw crap, I did not delete the PUPs, The default was set to ignore and I did not change it. should I do that and run everything beyond again? I have kept the computer on in safe mode since posting this, by the way.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just delete the PUP's and then rescan again, and attach log. :)
     
  9. PunchingBee

    PunchingBee Private E-2

    Alright, here's the log, thank you!!
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So how are things running now at this point, PB?
     
  11. PunchingBee

    PunchingBee Private E-2

    Everything seems to be running smoothly. I wll let you know if there are any further issues... I'm gonna sit with it a few days and find out, but it looks good! Thank you again!
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK PB, you can follow these steps when you're sure all is still running smoothly. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds