comodo system cleaner shows issues that nothing else sees

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by n2zcars, Feb 26, 2014.

  1. n2zcars

    n2zcars Private E-2

    Could anyone tell me if they trust this program. I am not having major issues. Mouse dropping off and cpu and memory usage is kinda high. I have done the first steps in the Malware Removal Guide and will post that info but wanted to see if Comodo system cleaner should have it's log posted also or just ignore it

    Moose
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Attach the logs that we request and also attach the log from Comodo so that we can see what exactly it is complaining about.
     
  3. n2zcars

    n2zcars Private E-2

    From what I can see Comodo does not show you in log form anything but what it deleted and cannot find that log. I have attached a log of Malwarebytes operations done a few days ago and jpgs of what it is showing in Comodo. These were done after doing all the steps needed to request formal assistance but I am not sure if these are relevant in any way or not. I am not sure if Comodo is showing me wolves in sheep's clothing as in some cases it was doing cleans that said successful but then issues were posted again before rescanning.


    Here are screen shots of current issues it sees with explanation added as to what happened after cleaning and rescan and what didn't. The last is a log of what was found by Hitman yesterday.

    I am going to await any concerns or questions and will post the package of logs after making sure they are/were done correctly

    Thanks in advance

    Moose
     

    Attached Files:

  4. n2zcars

    n2zcars Private E-2

    I verified I had done these properly and so here are a pair of addl logs of the system in question. Let me know if any other actions or question need to be answered.
    The system has not acted up today other than the mouse wouldn't open the toolbar which is hidden on the bottom of the screen while running Comodo system cleaner but it opens in other programs...

    thanks again

    Moose


    QUOTE=n2zcars;1862471]From what I can see Comodo does not show you in log form anything but what it deleted and cannot find that log. I have attached a log of Malwarebytes operations done a few days ago and jpgs of what it is showing in Comodo. These were done after doing all the steps needed to request formal assistance but I am not sure if these are relevant in any way or not. I am not sure if Comodo is showing me wolves in sheep's clothing as in some cases it was doing cleans that said successful but then issues were posted again before rescanning.


    Here are screen shots of current issues it sees with explanation added as to what happened after cleaning and rescan and what didn't. The last is a log of what was found by Hitman yesterday.

    I am going to await any concerns or questions and will post the package of logs after making sure they are/were done correctly

    Thanks in advance

    Moose[/QUOTE]
     

    Attached Files:

  5. n2zcars

    n2zcars Private E-2

    here is a new item that came up that Comodo wants to delete after web browsing for 30 min. The added on items shown in pics before have grown also but only by two.

    thanks again

    Moose
     

    Attached Files:

    Last edited by a moderator: Feb 27, 2014
  6. n2zcars

    n2zcars Private E-2

    I AM SO STUPID I didn't follow the prompt to scan so
    the RK log test was done incorrectly as it only showed the results of a prescan.

    I have attached the scan from RK below and still am not having any problems.

    Sorry for the inconvenience.

    Moose
     
    Last edited by a moderator: Feb 27, 2014
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is only a little bit f junkware to cleanup. Nothing real serious.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - (no file)
    O2 - BHO: (no name) - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - (no file)
    O3 - Toolbar: (no name) - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - (no file)
    O4 - HKLM\..\Run: [SearchSettings] "C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe"
    O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe

    After clicking Fix, exit HJT.

    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
    :Services
    Application Updater
     
    :Files
    C:\Program Files\Common Files\Spigot
    C:\Program Files\Application Updater
    C:\Windows\Temp\*.*
    C:\Users\user\AppData\Local\Temp\*.*
    
    :Reg
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{087D5083-0F8C-4677-B348-D87055FF50BF}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{03EB0E9C-7A91-4381-A220-9B52B641CDB1}"=-
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXTlog
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. n2zcars

    n2zcars Private E-2

    I only see MGtools.exe in root volume and a log which contains hijackthis and a log showing entries you noted. I will DL addl software listed and await response. At this point system seems to be working well.

    as always, my thanks in advance
    Moose
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I did not ask you to run MGtools.exe. I asked you to run the analyse.exe program which is inside of the C:\MGtools folder. That is what C:\MGtools\analyse.exe means. ;)
     
  10. n2zcars

    n2zcars Private E-2

    i do not see it i see this when opening MGtools
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I repeat..... I did not ask you to run MGtools.exe.

    Delete the MGtools.exe file. You do not need it anymore. Then look for the C:\MGtools folder and enter that folder. Inside that folder locate the analyse.exe file and run it as requested.
     
  12. n2zcars

    n2zcars Private E-2

    I deleted MGTools and downloaded it again and was able to find a file folder that said MGTools and ran it per instructions. The 2 screen shots show 2 missing entries you wanted me to delete but couldn't find.
    I ran OTM.exe per instructions and then JTR. logs are attached.

    system seems to be working fine but when OTM logged me off and attemped to restart it would not shut down on it's own. restarted fine.


     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should not have needed to do this. The MGtools folder was created the first time you ran MGtools inorder to post your first log. So unless you had deleted it, it would still have been on your PC. You could not have gotten your first log without that folder existing.

    You did not attach the follow up MGlogs.zip file that I requested, but if you are not having problems then I do not need it.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  14. n2zcars

    n2zcars Private E-2

    Thanks for your help. My system seems to be doing well other than delayed shut downs. I am going to reinstall GIMP on system then run Malwsrebytes and cccleaner. Anything else I should do?
    Thanks for your help and I have alwaysobserved this site now iI will participate

    Moose
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Just the final instructions that I gave. It is important to cleanup after what we have done and for your to work thru the process of properly protection your PC.
     
  16. n2zcars

    n2zcars Private E-2

    all's working fine, clean up work done


    . when checking for outdated Java I found this:Java(TM)Platform SE binary I assume if needs to stay

    I run the Windows Security essentials should i be using something else? I is supposed to be an all in one. I run Malewarebytes and Comodo on a regular basis thus was my original question about all the stuff Comodo finds.

    I am finishing up on antiautorun now.

    Thanks again,

    Jeff

     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would have suggested uninstalling all the Java related items you saw and then just installed the 51 update but I believe that you already had the current version of Java.

    It is okay. Not the greatest but it is acceptable.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds