Malware Removal Help Win7 32

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by JoFi, Jul 15, 2016.

Tags:
  1. JoFi

    JoFi Private E-2

    I have read the Malware removal guide but had some questions first before I run it.

    I have four admin uses accounts. My current account is JGF2 where I see most of the issues.

    JGF1 Previous account no longer used suspected of account corruption
    JGF2 Current active account
    JGF3 Account used only to transfer files from JGF1 to JGF2
    JGF4 New account created to see if the current problem was an account corruption or on all accounts.

    My question is which account should I run the scan on or should I create a new account to do it?

    Background

    My problem is suspected malware. It seems to be able to detect and disable super antispyware Spybot search and destroy seems to run but it may be hiding from it also.

    One of the key manifestations has been setting the IE cache to 0. I do not care about IE so much but that cache affects outlook which I run daily. I can boot into safe mode and restore the cache. Running outlook seems to trigger the malware but I am sure other things will as well. Another symptom is the Nvida driver has stopped working. This will happen a number of times then the screen will go black with windows still running. I have tried numerous different drivers and diagnostics failed to find any graphic card faults.

    My PC is nine years old. It was one of the original HP Windows Media PCs M9000t. It was upgraded from Vista to WIN7 32. My primary use is to run WMC and use the disks as a DVR most recordings are encrypted from cable using DRM. I also use this as my home PC for bills and email. I have removed most of the optional disks while trouble shooting. In April I was having freezing problems and seeing some smart errors. I replaced one of the disks then it started happening on the C:Drive. Windows rebooted and tried to do recovery for me and I lost access to the drive. As I was busy at the time I sent the drive out for recovery. I got all my data back. I loaded it onto a new SSD, made it bootable and that is what I am using today.

    Firefox runs fine. I am running outlook 2007 and office 2007. If the cache is 0 IE will not load. Outlook can not load web images and sometimes tries to connect the original web site going into a loop.

    I am reluctant to reinstall windows as I know I will lose access to all my encrypted content. Besides having to reload all my other applications. If I have to do this I might as well get a new PC with more memory and load Win7/64. Hope you can help get this fixed and access to my content.
    internet setting.PNG
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi and welcome. :)

    Please run the scans on the account where you are having the most trouble with.
     
  3. JoFi

    JoFi Private E-2

    Here are the requested Logs
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there, I apologise for the late response. Been run off my feet lately.

    Have you set these configurations yourself?

    • [PUM.Proxy] HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-22-b0-cb-34-d4 -> Found
    • [PUM.Proxy] HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{2673ACC5-7C9C-42AD-89F3-62C8F7A95B11}_{838246DB-2DD6-484E-ABD1-2A62297CC800} -> Found
    • [PUM.Proxy] HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{838246DB-2DD6-484E-ABD1-2A62297CC800} -> Found
    • [PUM.Proxy] HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{838246DB-2DD6-484E-ABD1-2A62297CC800}_{D605BD01-23F7-4FA8-9BD2-B8EAE25C608E} -> Found
    • [PUM.Proxy] HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{F52BE49F-EF99-4CCC-AF1D-464EFFD32C8E} -> Found
    • [PUM.Proxy] HKEY_USERS\S-1-5-21-1817913746-3816255476-1236712266-1017\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-22-b0-cb-34-d4 -> Found
    • [PUM.Proxy] HKEY_USERS\S-1-5-21-1817913746-3816255476-1236712266-1017\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{838246DB-2DD6-484E-ABD1-2A62297CC800} -> Found
    • [PUM.Proxy] HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-22-b0-cb-34-d4 -> Found
    • [PUM.Proxy] HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{2673ACC5-7C9C-42AD-89F3-62C8F7A95B11}_{838246DB-2DD6-484E-ABD1-2A62297CC800} -> Found
    • [PUM.Proxy] HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{838246DB-2DD6-484E-ABD1-2A62297CC800} -> Found
    • [PUM.Proxy] HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{838246DB-2DD6-484E-ABD1-2A62297CC800}_{D605BD01-23F7-4FA8-9BD2-B8EAE25C608E} -> Found
    • [PUM.Proxy] HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{F52BE49F-EF99-4CCC-AF1D-464EFFD32C8E} -> Found
     
  5. JoFi

    JoFi Private E-2

    Kestrel, thanks for the help, hope you feel better.

    I have changed some reg setting mostly trying to get the ie cache to work right but I never changed or added any WPAD settings.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi JoFi, can you re run RogueKiller, have it fix all those entries that I highlighted.
    Once done, rescan with RogueKiller, upload new log. Explain how things are running.
     
  7. JoFi

    JoFi Private E-2

    I reran RK but It did not come with any WPAD entries here is the LOG I did not clean anything yet.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    HI,

    Have RogueKiller fix these entries on the Registry tab:

    • [Suspicious.Path] HKEY_CLASSES_ROOT\CLSID\{0AA8B942-6B69-4370-A257-99FFBB4AF721} (C:\Windows\TEMP\{6E7BF6EC-C3E7-43A7-8A03-0D204E3EC01B}\InstallerSupport.dll) -> Found
    • [Suspicious.Path] HKEY_CLASSES_ROOT\CLSID\{210D8F0C-EDA1-4DD2-B3AF-1E9F0545B557} (C:\Windows\TEMP\{6E7BF6EC-C3E7-43A7-8A03-0D204E3EC01B}\InstallerSupportPS.dll) -> Found
    • [Suspicious.Path] HKEY_CLASSES_ROOT\CLSID\{B80B5599-9D25-48BF-B488-96457BF68B89} (C:\Windows\TEMP\{6E7BF6EC-C3E7-43A7-8A03-0D204E3EC01B}\InstallHelper.dll) -> Found
    Once done, rescan with RogueKiller, upload new wlog and explain how things are running.
     
  9. JoFi

    JoFi Private E-2

    I left RK up overnight on the results screen and it crashed. Rerunning scans but need to go to work will post results tonight.

    PC is running better no longer is the internet cache being affected. I now can run outlook and IE which was the first problem I encountered. I did unload all addins and options. I have seen a few Nvidia driver failures and recover but I am beginning to think based on the event log that is due to the system protection running out of space. Unlike before the screen does not stay off but recovers.

    Super anti spyware still has not run. It may have something t0o do with too many installation attempts or spybot may have been running. I have uninstalled and cleaned up the remnants in the program files directory. Watching it start up and then get shut down was one of the alarm bells that malware may be running. Let me know if you want to me try and install again.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, when you get back from work, continue on with the RogueKiller instructions and then we'll take it from there and try and sort Superanti Spyware out, too.
     
  11. JoFi

    JoFi Private E-2

    RK crashed again, reinstalled and ran scan same results RK3.log cleaned temp keys and reran scan log attached RK4.
     

    Attached Files:

    • RK4.txt
      File size:
      6.1 KB
      Views:
      2
    • RK3.txt
      File size:
      7.1 KB
      Views:
      2
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Is Superantispyware currently installed? If so please use Revo Uninstaller to carry out a thorough uninstall.
    Reboot the machine and download the latest version from here.
    Let me know how you get on.
     
  13. JoFi

    JoFi Private E-2

    I uninstalled spybot search and destroy, installed superantispyware and ran it. In idle it got shut down. I uninstalled superandtispyware with revo and reinstalled.
    Seems to be more stable but the only thing it finds is tracking cookies.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are there any other outstanding issues?
     
  15. JoFi

    JoFi Private E-2

    Sorry for the delay was in NYC yesterday. I am not sure. I can install and run Super antispywear once, all it finds are tracking cookies. If I try a second scan or reboot and scan it gets an error and shuts down. I disabled Microsoft Security essentials in case that had an impact but the results was the same. Outlook and IE are working and I am not seeing any other strange behavior.

    Faulting application name: SUPERAntiSpyware.exe, version: 6.0.0.1222, time stamp: 0x578e75de
    Faulting module name: SUPERAntiSpyware.exe, version: 6.0.0.1222, time stamp: 0x578e75de
    Exception code: 0xc0000005
    Fault offset: 0x0009005c
    Faulting process id: 0x3ac
    Faulting application start time: 0x01d1e418692d124a
    Faulting application path: C:\Program Files\SUPERAntiSpyware2\SUPERAntiSpyware.exe
    Faulting module path: C:\Program Files\SUPERAntiSpyware2\SUPERAntiSpyware.exe
    Report Id: b3a72193-500f-11e6-85bb-001d60e13123
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run this please.

    Please download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version for your PC. Only the correct version will work.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  17. JoFi

    JoFi Private E-2

    Here are the FarBar logs
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode. Any other mode is primarily used for troubleshooting and diagnostic purposes. You should look into some third party software to control start up's such as Autoruns

    Now that you are in normal mode, let's continue with the below:

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.

    Download Fixlist.txt

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.


    • You should now have both fixlist.txt and FRST.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
    Then attach the below log:



      • Fixlog.txt
    Next...
    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Now run FRST again as follows:

    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
    Is SUPERantispyware now able to run?



     

    Attached Files:

  19. JoFi

    JoFi Private E-2

    I was a little worried about starting normal as I usually have a number of startup items disabled. I was not expecting this problem. All I did was change the boot from selective to normal and restarted.

    "0xc000000e The boot selection failed because a required device is inaccessible,"

    Looking for advice since it will not boot up into windows checked BIOS and SSD is still the priority boot device. All I can think to do is put in the windows CD and run a repair. That is what I did originally to make this SSD bootable,

    Your guidance please.
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I would say at this point, you should post about your issues in the software forum. You may need to unplug any external devices and try rebooting. Check to see if you are indeed able to boot into "safe mode" But I think I have done all I can in this forum, very best of luck sorting out the non malware issues.
    This may be exactly what you have to do.
     
  21. JoFi

    JoFi Private E-2

    Repaired boot, here are the first FARBAR and MGTools log.
     

    Attached Files:

  22. JoFi

    JoFi Private E-2

    Here is the 2nd run of FARBAR testing superantispyware now.
     

    Attached Files:

  23. JoFi

    JoFi Private E-2

    Superantisypware is still closing down. You may be right it just may be a software incompatability with that software, W32 and my machine. I was just running it as an attempt to check for malware when I kept losing the IE cache which has been fixed. I was worried that some software was shutting it down because it scans. If the scan are clean and you think the machine is clean of malware I will try to put it back into production.

    What software do you recommend I run for antivirus and anti-malware.
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  25. JoFi

    JoFi Private E-2

    I tried all them before and spent Sunday trying them again, Almost all are geared to getting the SuperAntiSpyware package to install. That is not my problem it installs fine and will even run a scan it then errors out. I even tried the HTML scan and it did the same thing installed the package and then error-ed out. The only one that seemed like stand alone was the com file SASSAFERUN.com but all it did was display an definitions out of date and took you to the web page.

    I notice this is a new version 6 which need some updates to work with my old W32 system at this point I am not thinking it is a malware issue.

    Here are the errors again

    The SASDIFSV service failed to start due to the following error:
    Cannot create a file when that file already exists.

    Faulting application name: d296f234-4887-4fa8-a30b-edf7cfa54024.com, version: 6.0.0.1222, time stamp: 0x578e75de
    Faulting module name: d296f234-4887-4fa8-a30b-edf7cfa54024.com, version: 6.0.0.1222, time stamp: 0x578e75de
    Exception code: 0xc0000005
    Fault offset: 0x0009005c
    Faulting process id: 0x17fc
    Faulting application start time: 0x01d1e5c1cad5ef24
    Faulting application path: C:\Program Files\SUPERAntiSpyware\d296f234-4887-4fa8-a30b-edf7cfa54024.com
    Faulting module path: C:\Program Files\SUPERAntiSpyware\d296f234-4887-4fa8-a30b-edf7cfa54024.com
    Report Id: 0ff2e1fe-51b5-11e6-971c-001d60e13123
     
  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK go ahead and post in the software forum about it if you like. Are there any other issues I can deal with in this forum?
     
  27. JoFi

    JoFi Private E-2

    If I have issues I will post in software first. Looks like the PC is clean now. Any recommendations of software to run to keep it clean.

    I also want to express my appreciation for all the help, guidance and patience you have provided me on this issue. This support is outstanding.
     
    Kestrel13! likes this.
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are so very welcome. ;) When I post final steps, it should include some choices for protection software.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds