Kuroneko Posted September 18, 2017 ID:1164815 Share Posted September 18, 2017 Hello, i have a problem with the process g**.tmp.exe, it automatically generated in the temp folder. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted September 18, 2017 Root Admin ID:1164824 Share Posted September 18, 2017 Hello @Kuroneko and Please run the following steps and post back the logs as an attachment when ready.STEP 01 If you're already running Malwarebytes 3 then open Malwarebytes and check for updates. Then click on the Scan tab and select Threat Scan and click on Start Scan button. If you don't have Malwarebytes 3 installed yet please download it from here and install it. Once installed then open Malwarebytes and check for updates. Then click on the Scan tab and select Threat Scan and click on Start Scan button. Once the scan is completed click on the Export Summary button and save the file as a Text file to your desktop or other location you can find, and attach that log on your next reply. If Malwarebytes won't run then please skip to the next step and let me know on your next reply. STEP 02 Please download AdwCleaner by Malwarebytes and save the file to your Desktop. Right-click on the program and select Run as Administrator to start the tool. Accept the Terms of use. Wait until the database is updated. Click Scan. When finished, please click Clean. Your PC should reboot now if any items were found. After reboot, a log file will be opened. Copy its content into your next reply. STEP 03 Please download the Farbar Recovery Scan Tool and save it to your desktop.Note: You need to run the version compatible with your system. You can check here if you're not sure if your computer is 32-bit or 64-bit Double-click to run it. When the tool opens, click Yes to disclaimer. Press the Scan button. It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply. The first time the tool is run, it also makes another log (Addition.txt). If you've, run the tool before you need to place a check mark here. Please attach the Additions.txt log to your reply as well. Thanks Ron Link to post Share on other sites More sharing options...
Kuroneko Posted September 18, 2017 Author ID:1164827 Share Posted September 18, 2017 Malwarebytes and AdwCleaner don't run, he say "The app has been locked for security purposes" FRST.txt Addition.txt Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted September 18, 2017 Root Admin ID:1164829 Share Posted September 18, 2017 Please read and follow the directions from here. Your computer is infected with a rootkit Post back the logs when ready Thanks Link to post Share on other sites More sharing options...
Kuroneko Posted September 18, 2017 Author ID:1164831 Share Posted September 18, 2017 Before starting MBAR he give me this error and after that it started mbar-log-2017-09-18 (22-56-32).txt Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted September 18, 2017 Root Admin ID:1164836 Share Posted September 18, 2017 Are you able to run the regular Malwarebytes now? Link to post Share on other sites More sharing options...
Kuroneko Posted September 18, 2017 Author ID:1164837 Share Posted September 18, 2017 no, always the same error Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted September 18, 2017 Root Admin ID:1164838 Share Posted September 18, 2017 Please download the attached fixlist.txt file and save it to the Desktop.NOTE. It's important that both files, FRST or FRST64 and fixlist.txt are in the same location or the fix will not work. NOTICE: This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause damage to your operating system. Run FRST or FRST64 and press the Fix button just once and wait. If the tool needs a restart please make sure you let the system restart normally and let the tool complete its run after restart. The tool will make a log on the Desktop (Fixlog.txt). Please attach or post it to your next reply. Note: If the tool warned you about an outdated version please download and run the updated version. fixlist.txt Thanks Ron Link to post Share on other sites More sharing options...
Kuroneko Posted September 18, 2017 Author ID:1164845 Share Posted September 18, 2017 Fixlog.txt Always same error if i try to open malwarebyte, but now i can open it there Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted September 18, 2017 Root Admin ID:1164847 Share Posted September 18, 2017 Please run the following steps and post back the logs as an attachment when ready.STEP 01 If you're already running Malwarebytes 3 then open Malwarebytes and check for updates. Then click on the Scan tab and select Threat Scan and click on Start Scan button. If you don't have Malwarebytes 3 installed yet please download it from here and install it. Once installed then open Malwarebytes and check for updates. Then click on the Scan tab and select Threat Scan and click on Start Scan button. Once the scan is completed click on the Export Summary button and save the file as a Text file to your desktop or other location you can find, and attach that log on your next reply. If Malwarebytes won't run then please skip to the next step and let me know on your next reply. STEP 02 Please download AdwCleaner by Malwarebytes and save the file to your Desktop. Right-click on the program and select Run as Administrator to start the tool. Accept the Terms of use. Wait until the database is updated. Click Scan. When finished, please click Clean. Your PC should reboot now if any items were found. After reboot, a log file will be opened. Copy its content into your next reply. STEP 03 Please download the Farbar Recovery Scan Tool and save it to your desktop.Note: You need to run the version compatible with your system. You can check here if you're not sure if your computer is 32-bit or 64-bit Double-click to run it. When the tool opens, click Yes to disclaimer. Press the Scan button. It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply. The first time the tool is run, it also makes another log (Addition.txt). If you've, run the tool before you need to place a check mark here. Please attach the Additions.txt log to your reply as well. Thanks Ron Link to post Share on other sites More sharing options...
Kuroneko Posted September 18, 2017 Author ID:1164849 Share Posted September 18, 2017 Scan stops at 12 seconds without scanning scan.txt Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted September 18, 2017 Root Admin ID:1164851 Share Posted September 18, 2017 Please move on to the next steps Link to post Share on other sites More sharing options...
Kuroneko Posted September 18, 2017 Author ID:1164853 Share Posted September 18, 2017 Can't open AdwCleaner FRST.txt Addition.txt Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted September 18, 2017 Root Admin ID:1164856 Share Posted September 18, 2017 Those are the old logs. Please delete your old logs. Then restart the computer again. Then run FRST again, make sure you place a check mark in the Additions.txt check box and post back both new logs. Thanks Ron Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted September 18, 2017 Root Admin ID:1164860 Share Posted September 18, 2017 Also, can I get the system-log.txt file from the Malwarebytes Anti-Rootkit scanner? Thanks Link to post Share on other sites More sharing options...
Kuroneko Posted September 19, 2017 Author ID:1164959 Share Posted September 19, 2017 I restarted but the logs seems the same FRST.txt Addition.txt system-log.txt Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted September 19, 2017 Root Admin ID:1164971 Share Posted September 19, 2017 Odd. Can you please try running Malwarebytes Anti-Rootkit again. Make sure it updates the rules. Late for me so I'll have to check this tomorrow and get back with you again. Let me have the Research people take a look too and see what they say. Thank you again Ron Link to post Share on other sites More sharing options...
Kuroneko Posted September 19, 2017 Author ID:1164974 Share Posted September 19, 2017 mbar-log-2017-09-19 (10-22-09).txt I can start adwcleaner from cmd, do i go for the second step? Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted September 19, 2017 Root Admin ID:1164977 Share Posted September 19, 2017 Please hang tight. We're trying to check why this is not being detected. Normally this is easily detected and removed to allow our other tools to run but something looks to have changed on the version you have. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted September 19, 2017 Root Admin ID:1164993 Share Posted September 19, 2017 Okay, it's about 3 AM here for me so I'm heading out. I still have our Research Team checking on this though (some of them are in Europe so they're still up) and I'll check back on you again tomorrow. Thank you again Ron Link to post Share on other sites More sharing options...
TwinHeadedEagle Posted September 19, 2017 ID:1164996 Share Posted September 19, 2017 We have found the problem. New database will be published in 2-3 hours that should detect the cause of the problem. I will notify you when it is done. Link to post Share on other sites More sharing options...
TwinHeadedEagle Posted September 19, 2017 ID:1165065 Share Posted September 19, 2017 (edited) @Kuroneko Can you please update and run MBAR scan? Edited September 19, 2017 by TwinHeadedEagle Link to post Share on other sites More sharing options...
Kuroneko Posted September 19, 2017 Author ID:1165103 Share Posted September 19, 2017 @TwinHeadedEagle mbar-log-2017-09-19 (16-04-26).txt Link to post Share on other sites More sharing options...
TwinHeadedEagle Posted September 19, 2017 ID:1165107 Share Posted September 19, 2017 Did you uncheck some scan options? They should all be checked before you start a scan. Link to post Share on other sites More sharing options...
Kuroneko Posted September 19, 2017 Author ID:1165146 Share Posted September 19, 2017 Sorry, i uncheck sectors and system mbar-log-2017-09-19 (16-23-41).txt Now the g**.tmp.exe no longer appears but i still can't open malwarebytes Link to post Share on other sites More sharing options...
Recommended Posts