Trying to read a RogueKiller log

Discussion in 'Malware Help (A Specialist Will Reply)' started by userofcomputers, Sep 27, 2013.

  1. userofcomputers

    userofcomputers Private E-2

    I have the remnants of some malware that have been stubborn through MalwareBytes, Hitman, and MalwareBytes Anti-Rootkit software, so I finally used RogueKiller on it... I just don't know how to read the log. I set up a restore point, so worst case... I restore everything. But any input would be greatly appreciated.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, if you suspect malware then you are going to have to attach all of the requested logs. Or if you are happy with the situation, and just wanted to ask about the RK log, there's nothing in there to remove.

    It would be best to go thru these procedures: READ & RUN ME FIRST. Malware Removal Guide
     
  3. userofcomputers

    userofcomputers Private E-2

    Hokay, here they all are. I had delta search at one point, so I already removed a lot of what was there... these didn't pick up much.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode. You should be using a third party start up manager to control start ups. MSCONFIG is primarily used for troubleshooting and diagnostic purposes.



    Delete this:
    C:\ProgramData\DSearchLink



    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Tell me what issues remain.
     
  5. userofcomputers

    userofcomputers Private E-2

    Ok, I changed the startup mode, I deleted the file folder for DSearchLink in ProgramData, and here's the log. I haven't noticed anything yet; it'll take some use of my browser (I've been having the most issues with Firefox) for me to say whether or not it's all better.
     

    Attached Files:

    • JRT.txt
      File size:
      3.1 KB
      Views:
      5
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let me know how Firefox is behaving today.
     
  7. userofcomputers

    userofcomputers Private E-2

    No more delay issues (yay!), but I do get these pesky drop-down ads in the upper right hand corner of my screen. I have an ad blocker... not to mention, some have come up while on this site. Any thoughts?
     
  8. userofcomputers

    userofcomputers Private E-2

    I spoke too soon... it just crashed. :(
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We are going to be uninstalling your old version of FireFox and installing the new version. (Except we will use Revo Uninstaller to do the job. So do the below to save bookmarks:

    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.
    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:
    • C:\Program Files\Mozilla Firefox
    • C:\users\UserAccount\AppData\Roaming\Mozilla\Firefox

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).

    ---------------

    Any better?
     
  10. userofcomputers

    userofcomputers Private E-2

    Yes, much better! I'd like to de-clutter my desktop, though. I'd like to keep CCleaner, MBAM, and Hitman, but when I try to uninstall the other programs, they don't have installation packages. If you recommend keeping them I can, but at the very least I have a version of Rogue Killer that's not compatible with my computer.

    Again, thank you so much!
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    These last steps should cover all your questions. :)


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  12. userofcomputers

    userofcomputers Private E-2

    That got a lot of them, but I still have hitman, a 64-bit version of Rogue Killer (my comp is 32. :( ), and mbar, the mbam anti-rootkit software. I don't see any options to uninstall them anywhere.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You should be able to simply uninstall Hitman. As to RogueKiller, simply delete it, and it's quarantine folder.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds