Trojan Virus

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Nancy A, May 10, 2020.

  1. Nancy A

    Nancy A Private E-2

    I downloaded reimage pc scan and repair from major geeks.com. I spoke to the rep named Alvin. I had trouble installing your program. So I called. Alvin, took over my computer with my permission, scanned, found a Trojan Virus. I tried to copy & paste the name of the virus and was not able to as Alvin not only removed the page so I could not copy it, he didn't even install the program for which I paid for.

    Today is Mother's day. With the lockdown here in New York I can't spend the day with my children and grandchildren. This was the last thing I needed.

    Please know that your support has been invaluable in the past under a different email (ngazzar@gmail.com)

    If there is any assistance you can provide at this time, please help.

    In gratitude,
    Nancy A Cirasola
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Reimage was your first mistake. Your second was putting your trust in one of their reps!! I am moving you to the expert forum and request that you do the Read and Run First instructions and attach the requested logs.
     
    satrow and Eldon like this.
  3. Nancy A

    Nancy A Private E-2

    Good Morning...
    On a bright note, I got a refund from Reimage. Thank you.

    Please know that I followed the instructions on Read and Run. When it came to Rogue Killer, I was asked for a licence key. Am I supposed to pay for this? I followed this procedure years ago on a desktop and don't remember having to pay for any of the recommended downloads.

    Attached is the log from AdwCleaner, there was no log created from Malwarebytes.

    I am running an HP laptop with Windows 10, only 5 months old. I only weekends to work on this as I work in the medical field and I am too tired to address this in the evenings. With that said, if there is any suggestion you have to move this along more quickly, please advise.

    As always, thank you immensely for your assistance.

    Nancy
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    RogueKiller states it is an option that you can skip...just click next. As to MalwareBytes....did it not find anything? That would explain no log. But please, still run Rogue, and Hitman as well as MGTools.exe and attach those logs.
     
  5. Nancy A

    Nancy A Private E-2

    Nothing is working. I tried to use Rogue Killer again w/o success. I went on to Hitman. I received a message saying that the version I downloaded was 32 bit and my computer required 64 bit. I uninstalled the 32 bit version and tried to install the 64 bit version. I kept getting a pop-up asking for permission for the software to make changes. Choosing 'yes' or 'no' was not a viable option. The message kept popping up and would not subside until I restarted. Several attempts have been made to accomplish the Read & Run w/o success.
    Suggestions?
    TY
    Nancy
     
  6. Nancy A

    Nancy A Private E-2

    from the Hitman Pro temp to install - it would not let me attach
    [.ShellClassInfo]
    LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21769
    IconResource=%SystemRoot%\system32\imageres.dll,-183
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download the latest version of FRST the below link.
    Farbar Recovery Scan Tool and save it to your Desktop.


    Note: Make sure you download the proper version ( 32 bit or 64 bit ) for your PC. Only one will run, the correct one. So it you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  8. Nancy A

    Nancy A Private E-2

    Rogue Killer still would not run. I finally got Hitman Pro to run. No logs from Hitman or Malwarebytes. Attached are the logs from MGTools
    Should I still download & install farbar recovery scan tool?
    Thank you
    Nancy
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That is not the full MGLogs.zip


    Yes, please run the Farbar instructions now.
     
  10. Nancy A

    Nancy A Private E-2

    The attached is a result of running Farbar Recovery Scan
    The first file for MGtools was saved on my desk top. The one included here is from my c drive. Hopefully this is complete.

    Thank You
    Nancy
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The MGTools.exe would produce an MGLogs.zip not a single text document.

    How many anti-virus programs are you running? Looks like AVG, Avast and McAfee.....with Defender running in the background. You should only have ONE AV program installed.

    What issues are you currently having?
     
  12. Nancy A

    Nancy A Private E-2

    I didn't know that. I had a McAfee trial when I bought my laptop. As far as I know it ended in Jan 2020. I have no idea how Avast that came into play. I don't know what Defender is. I thought I did not have protection, so I installed AVG.
    I had a laptop from my job. After I shutdown one day, for some reason, all the information that was on that laptop appeared on this one. I am lost as to why or how. I had my google mail set up so that I didn't have to sign in each time I brought up google browser, now I do. I don't know where the sync icon came from saying I am on pause. I don't know how to fix that. I always used my debit card to buy online and now the vendors are not accepting it anymore. A number of unexplained issues have been happening. Whatever happened even affected my router which is also new. I tried a system restore but that didn't help any and would not let me choose a back date. I am truly at a loss.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I can only speculate that you somehow synced your two computers. I suggest you post in the software forum for further assistance. But it would really help if you could run MGTools to its conclusion.

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The red is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.

    Attach the two logs.
     
  14. Nancy A

    Nancy A Private E-2

    Even though I chose 64 bit download a pop up said:
    The progam feature "\???\MGTools\locate.com cannot start due to incompatibility with 64 bit versions of windows.
    Please contact the software vendor to ask if a 64 bit Windows compatible version is available.

    This is the result of what you asked me to do:

    Microsoft Windows [Version 10.0.18363.836]
    (c) 2019 Microsoft Corporation. All rights reserved.

    C:\Users\NACir>cd\MGtools

    C:\MGtools>GetRunKey


    GetRunKey.bat - 02/28/2016 Version 2.76

    NOTE: Ignore any error messages about not finding registry keys!
    Just wait for the program to finish running!!

    ERROR: Access is denied.
    ERROR: Access is denied.
    ERROR: Access is denied.
    ERROR: Access is denied.
    ERROR: Error accessing the registry.
    This version of C:\MGTools\ltime.exe is not compatible with the version of Windows you're running. Check your computer's system information and then contact the software publisher.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Curious-er and curious-er....

    Please go here > https://www.zemana.com/Download
    their program is no longer free, but you can use the demo version for this cleaning.

    It auto updates, and you click scan. After it's finished, click on the icon that looks like Cell phone strength bars. High-light the report (by date log was produced) and click on the "Open Report" icon. (looks like a folder). That notepad.txt can then be copied/pasted into another .txt doc and saved. Upload that, please.
     
  16. Nancy A

    Nancy A Private E-2

     
  17. Nancy A

    Nancy A Private E-2

    So, I scanned with Zemana. No threats were found. I saved the report in a word document. When I tried to upload that doc, it was nowhere to be found. If I open explorer, it shows up.
    After the scan a window pops up reporting that my trial period has ended. Cannot close or minimize this window.
    In thinking that my computer might have synced with my old one, please know that I copied some files on a thumb drive. I did not copy them to this computer. I received this on in mid Dec and returned the old one to my x-boss shortly after. This mishap occured only about 2 weeks ago. Should it have taken that long to affect my system?
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, this further convinces me that this is a software issue. Please post in the software forum for further assistance.
     
  19. Nancy A

    Nancy A Private E-2

    Tim.
    One more question, please.....How can I transfer this thread to the software forum?

    Thank you so much for all your help. I am sure you'd rather spend your weekends enjoying yourself.

    Nancy
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would be best to just start a new thread in the software forum rather than move this thread which might result in confusion. Just create a thread and explain what is happening and you will get advice which might not come if people thought the thread had already been worked.
     
  21. Nancy A

    Nancy A Private E-2

    Great! Again, Thank you. You have been most helpful.
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Good luck. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds