Malware Cleanup Still Shows "your Updater" Pop Up

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by thekops, Sep 13, 2016.

  1. thekops

    thekops Private E-2

    I'm helping a friend who allowed his son to install something on his work laptop several weeks ago (doesn't know or won't tell me what), and noticed popups wanting to do scans. I followed the great READ ME details and his major issues look fixed. But I continue to see the "Your Updater" popup box by "Installer Tech" showing in the lower-right corner after starting up.

    I successfully did "Fixing Google Redirection/Hijacking Problems" and will attach JRT log, then continued on with the rest of the malware cleanup. Had a little trouble getting MGtools to save to the C: drive at first, but was able to save it in a new folder C:\AJMKUser\ then move it to the root C:\ drive. All tools ran OK and I will attach their logs too.

    It looks like he has no antivirus protection! Someone on staff thought it should have had Microsoft Security Essentials but I will work with them after your help to get antivirus protection. His laptop was upgraded to Windows 10 in July.
     
  2. thekops

    thekops Private E-2

    1 of 6 files.
     

    Attached Files:

    • JRT.txt
      File size:
      5.6 KB
      Views:
      1
  3. thekops

    thekops Private E-2

    Remaining files.
     

    Attached Files:

  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, thekops

    The supported operating systems for Microsoft Security Essentials are Vista and Windows 7. Windows Defender is already included in Windows 8/8.1/ 10 and provides built-in protection against viruses and malware.

    It is still shown as being installed. Isn't it listed in "Programs and Features"?

    Why are all of the logs dated 5 days ago?

    *Other than the tools our guide instructed you to save there, I strongly recommend that you clean up this account's Desktop immediately leaving only shortcut links. [ C:\Users\Jeff Andrini\Desktop ] Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least - it can have an effect on your PCs performance.

    Now re-scan with Hitman Pro and have it delete everything under the headings of
    • Malware
    • Potential Unwanted Programs
    Ignore all other detections.
    Afterwards, click the Next button.
    Now reboot the PC in order for the changes to take affect.

    After reboot and when you are back in Windows, rescan with HitmanPro and attach the new log.

    Re-run RogueKiller.exe. (Vista/Windows7/8/10 users should right-click and select "Run as Administrator")
    After it finishes the scan, under these tabs select and then click the Delete button these items.
    Registry <=== All PUP
    Then immediately reboot your PC.

    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Upload RKreport[2].txt to your next message.
    After uploading RKreport[2].txt, now run a new scan with RogueKiller and save a log as in the original instructions and upload that new log also.

    Next download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • When it's done you'll see: Pending: Please uncheck elements you don't want removed.
    • Now click on the Report button...a logfile (AdwCleaner[S#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • Upload this log to your next reply.
    NOTE: Please re-read Using MGtools and make sure you accept the TrendMicro HijackThis license agreement by clicking the Accept button twice, as it is missing from your logs and does not show as being installed. Upload a fresh MGLogs.zip, please.
     
  5. thekops

    thekops Private E-2

    Sorry for the log dates confusion. I started cleaning and got almost done when I had to stop due to personal emergency. So shutdown laptop and finished several days later.

    Moved items, totaling 10.7 GB, off his desktop as suggested.

    Ran Hitman Pro (twice as instructed), but new log still shows the Malware and PUP items. Got "Hitman Pro is not activated" message both times. I recall reading something about computers that are part of an active directory domain cannot use it? His laptop is part of a domain for his work in a non-profit church. Should I remove it from the domain and start the re-scans?

    Or do you want me to continue on with your instructions, with re-running RogueKiller.exe?
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;) This is true but I can create a registry patch instead of using Hitman Pro. Please continue with my other instructions.

    Also - I was just curious about the delay after the logs were produced.
     
  7. thekops

    thekops Private E-2

    Sorry, since I did the reboot immediately after the delete, I did not get the RKreport[2] log. But I continued your instructions and ran it again for the new scan with RogueKiller.

    AdwCleaner ran fine and I uploaded log.

    MGTools, I must have messed this one again. So very sorry. Downloaded to desktop this time, since it would not save to C:. Then on the first User Access Prompt I answered wrong, so ran again. But no TrendMicro was ever prompted.
     

    Attached Files:

  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    re:Vista & Windows 7,8,10 Malware Removal/Cleaning Procedure
    Step 2: Disabling User Account Control
    " 8. Keep UAC disabled until malware cleanup is complete and you have been given the okay to enable it. "

    I noticed no prompt during my testing of a fresh MGTools download. We'll use another tool then, as a substitute.

    Now copy the bold text below to notepad. (Do not include any space above the word "REGEDIT4"). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" . Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me whether or not you receive a success message about adding the above to the registry. If you do not get a success message, it definitely did not work.

    Using AdwCleaner.exe previously downloaded:

    • Double click on AdwCleaner.exe to run the tool. (Vista, Win7/8/10 users should right-click and "Run As Administrator")
    • Click on the Scan button.
    • When the scan has completed, click on the Clean button.
    • Press OK when asked to close all programs and follow the on-screen prompts.
    • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
    • After rebooting, a logfile report (AdwCleaner[C#].txt) will open automatically (where the largest value of # represents the most recent report).
    • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
    • Upload this log to your next reply.
    Please download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version ( 32 bit or 64 bit ) for your PC. Only the correct version will run so if you make a mistake and download the wrong one, go back and get the other.

    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press the Scan button and wait.
    • The first time the tool is run it makes two logs, FRST.txt and Addition.txt in the same directory the tool is run.
    • Please upload them in your next reply.
    ALSO - please re-run Hitman Pro and upload a fresh log.
     
  9. thekops

    thekops Private E-2

    I did not get a success message; instead got: "Cannot import c:\Users\Jeff..\Desktop\fixME.reg: The specified file is not a registry script. You can only import binary registry files from within the registry editor". But the desktop icon shows the "registry blocks" icon since I saved it per instructions changing Save as to All. Could this be another Windows 10 Pro upgrade issue (like several others)?

    AdwCleaner ran OK.
    Farbar ran OK, but gave warning when first started: "Windows protected your PC. Windows Smartscreen prevented an unrecognized app from starting. Running this app might put your PC at risk." I clicked More Info and it showed "App: FRST64.exe Unknown Publisher" so I clicked Run anyway button and continued your instructions.
    Hitman Pro ran OK.
     

    Attached Files:

  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Temporarily turn off SmartScreen Filter
    http://www.tenforums.com/tutorials/5520-microsoft-edge-smartscreen-filter-turn-off-windows-10-a.html

    Delete the old reg patch and recreate it while verifying:
    • Did you use Notepad?
    • Did you include the header REGEDIT4 and inserted the blank line afterwards?
    • Was "Save as" type set to "all files" ?
    • Was the Encoding set to ANSI?
    • No blank line at the bottom before saving it?
    REPEAT the instructions for merging the patch and tell me if you received a successful merge message.

    Uninstall the below software using
    GeekUninstaller 1.4.0.88, a portable appl.
    Your_Updater

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.
    • Save the attached (fixlist.txt) to your desktop.
    • Right-click FRST(x32/64) and select Run as Administrator.
    • Click the FIX button once.
    • Wait while FRST processes fixlist.txt
    • A report should pop up named Fixlog.txt, please upload it here in your next reply.
     

    Attached Files:

  11. thekops

    thekops Private E-2

    Turned off SmartScreen Filter for now.

    Reg Patch "has been successfully updated"!
    No. :oops:

    Ran GeekUninstaller OK (watched video, very slick, little, but powerful tool).
    Ran FRST64 OK and restarted PC when prompted; uploaded log.

    Wow, do things look and run a whole lot better; but I will wait for your next instructions.
     

    Attached Files:

  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)

    Your logs look good! If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, Win 7/8/10 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7/8/10, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work through the below link:
    You can turn SmartScreen Filter back on now.
    Safe surfing! [​IMG]
     
  13. thekops

    thekops Private E-2

    Completed final steps and all is running well. Thank you so much for your expertise and patience once again.
     
  14. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;) You're very welcome!
     
    thekops likes this.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds