Add/Remove Malware Programs?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by shanrene123, May 10, 2007.

  1. shanrene123

    shanrene123 Private First Class

    These programs seem suspicious to me, but are not listed in sticky thread: "Uninstall Malware via Add/Remove Programs". Does anyone know if they are safe? Here they are: "Frontier Browser Assistant", "Frontier Search Helper", "RegistryCleaner Version 4.0", "URL Assistant", "Weather Services", "SpamBlockerUtility Browser, Weather and Wowpapers Tools", and "SpamBlockerUtility Email Toolbar".

    Thanks in advance for any help! Shanrene
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The uninstall list is updated all the time with real malware items and also rogue tools. It is just hard to keep up because there are so many and the creators constantly change names of tools just to make it hard to keep list like this current.

    "Frontier Browser Assistant", "Frontier Search Helper", "URL Assistant" - You probably have a Dell PC and this crud was probably install on it when you got it. Frontier is related to the MyWay family which has long been on the malware list of things to remove. It is not a major problem (i.e., not really malicious) but it is not something most people really want. Uninstall it. The URL Assistant (from Dell) may just come back. Try uninstalling and see what happens.


    "RegistryCleaner Version 4.0" - This may be a valid tool. Did you install it? Did it come with the PC? What company name appears to be associated with it?

    The below items are classified as malware (and are added to the list now) and you should uninstall and then run the READ & RUN ME and attach all 6 logs.
    "Weather Services", "SpamBlockerUtility Browser, Weather and Wowpapers Tools", and "SpamBlockerUtility Email Toolbar".
     
  3. shanrene123

    shanrene123 Private First Class

    Thanks, Chaslang! My friend's PC (yes, a Dell Dimension B110, running WinXP Home) went crazy while removing programs, esp...the SpamBlockerUtility...ones. It starting restarting & error messages coming up... I didn't get a chance to write them down. Haven't been able to download CCleaner yet, as IE7 or something is telling me security settings won't allow...even after I changed security settings to medium & put majorgeeks in "Trusted Zone". When changed Run/Msconfig back from Selective Start-up (which I had done earlier) back to Normal Start-Up, I couldn't get online at all, PC froze, then more error messages, & then restarted itself. Finally had to just do a cold shutdown & disconnect from HighSpeedModem/Router Network. Any ideas? I was thinking SafeMode (maybe with Networking support)? But really have very few, if any, ideas of my own at this point. Do I need to troubleshoot hardware at all yet? Thanks in advance! Shanrene (now more confused than ever!!)
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the below instead.

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.


    Yes try safe mode with networking to see if it works.

    Is there an antivirus application installed? Did you run a full scan with it (in either normal or safe boot mode)? If not, try that.

    Get the below logs preferably from normal boot mode but safe mode is okay if that is all you can do.

    Download GetRunKey.Zip and ShowNew.Zip from the below links and extract all files from both ZIP files into a folder of their own. You can extract both ZIP files into the same folder. Like C:\MGTools While these tools will run from your Desktop, we strongly recommend that you DO NOT extract them to your Desktop. Please install them where recommended. Do not run the scans yet!!!

    Also install HijackThis properly and rename as requested in step 7 of the READ ME and attach a log from it too.
     
  5. shanrene123

    shanrene123 Private First Class

    Was able to get both ATF as well as CCleaner (by downloading to another PC & copying onto a CD) ... got them both to run in both safe mode & normal mode.

    There was no active anti-virus or firewall on this Dell PC...so with some work, was able to get AVG installed...but only got short way finished in normal mode, before PC shut itself down. Did note that AVG had found 1 virus to that point, called "Downloader.Tibs".

    PC keeps shutting itself off & getting a blue screen saying:
    "PAGE_FAULT_TN_NONPAGED_AREA"
    Errors vary...last one noted was: "STOP: 0X00000050 (0XE1433000, 0X00000000, 0X30502289, 0X00000001)" ...
    Then ends by saying, "Beginning dump of physical memory. Physical memory dump complete."

    So have not been able to continue to work thru READ & RUN ME, & still cannot download any major geek files directly onto this PC.

    Thanks so much for further instructions! Shanrene
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does the PC run without shutting down if you stay in safe mode?

    Try to get the logs I asked for in message # 4.
     
  7. shanrene123

    shanrene123 Private First Class

    Finally able to run through all "Read & Run Me" scans. I was unable to uninstall "Weather Services" through Ad/Remove Programs, as it seems to be connected to "Weather Channel Desktop", which was on Dell PC at purchase. I think that CounterSpy in SafeMode may have gotten some of it off. I am attaching 6 logs with this post & next one. Hope I've done all scans as directed. Thanks so much in advance for further direction! :) Shanrene
     

    Attached Files:

  8. shanrene123

    shanrene123 Private First Class

    Here are other 3 log files. Thanks!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay it looks like CounterSpy removed your remaining malware issues.

    Let's just fix a few other unnecessary items!


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O3 - Toolbar: (no name) - {A93A3CC9-BA23-4d0d-9440-6A0148362B7E} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe

    After clicking Fix, exit HJT.

    Delete the below folder if found:
    C:\Documents and Settings\Carmen Omstead\Application Data\Registry Cleaner

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Are you have any malware problems now? If not, do the below to remove the CounterSpy trial software.

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software
     
  10. shanrene123

    shanrene123 Private First Class

    Thanks Chaslang! All done & PC is running well. Getting rest of maintainence & protection completed & added on, etc... Appreciate you & all the Major Geeks!:major Shanrene
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds