Yet another pc health fix

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by NJD, Jun 25, 2014.

  1. NJD

    NJD Private E-2

    Hello:

    Friend of mine picked up this gem 'while downloading an anti-virus program'.

    Here are the logs and my (and his) advance thanks for your help.

    Neil
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you deliberately set up to use a proxy?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In addtional to answering Kestrel13!'s question, continue on with the below.

    Uninstall the below programs. If you don't find them or they will not uninstall, just keep going and let me know later.
    Optimizer Pro v3.2
    PC HealthFix
    Search module ( also look for Goobzo )
    Shopper-Pro
    YTDownloader

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the JRT.TXTlog
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. NJD

    NJD Private E-2

    Hello Kestrel and ChasLang:

    Thanks for working with me on this.

    No, not intentionally running a proxy.

    Optimizer Pro v3.2 - Uninstalled
    PC HealthFix - Would not uninstall
    Search module ( also look for Goobzo ) - Uninstalled (no Goobzo found)
    Shopper-Pro - Would not uninstall
    YTDownloader - Would not uninstall

    Machine still infected with PC Health Fix

    Logs:
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you attach this file for me to look at please?

    • C:\Users\William\AppData\Local\proxy.log



    Uninstall the below using Revo Uninstaller. Let me know if you have any difficulties.


    • Shopper-Pro
    • SupraSavings
    • PC HealthFix
    • PC HealthFix


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:13810;https=127.0.0.1:13810
    • O2 - BHO: ShopperProBHO - {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} - C:\ProgramData\ShopperPro\ShopperPro.dll
    • O4 - HKLM\..\Run: [pcreg] C:\Program Files\pcmax\service.exe
    • O4 - HKLM\..\Run: [PC HealthFix] "C:\ProgramData\PC HealthFix\PCHealthFix.exe" /runscan
    • O4 - HKLM\..\Run: [SPDriver] C:\Program Files (x86)\ShopperPro\JSDriver\1.36.1.172\jsdrv.exe
    • O4 - HKCU\..\Run: [pcreg] C:\Program Files\pcmax\service.exe
    • O4 - HKCU\..\Run: [SPDriver] C:\Program Files (x86)\ShopperPro\JSDriver\1.36.1.172\jsdrv.exe
    • O4 - Startup: MyPC Backup.lnk = C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe
    • O23 - Service: pcmaxservice Service (pcmaxservice) - Unknown owner - C:\Program Files\pcmax\pcmax.exe

    After clicking Fix exit HJT.



    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.

    Code:
    :Files
    C:\Program Files\pcmax
    C:\ProgramData\PC HealthFix
    C:\Program Files (x86)\ShopperPro
    C:\Program Files (x86)\MyPC Backup
    C:\ProgramData\374311380
    C:\Users\William\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
    C:\ProgramData\PC HealthFix
    C:\ProgramData\PCDr
    C:\ProgramData\SearchModule
    C:\ProgramData\ShopperPro
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC HealthFix
    C:\Program Files (x86)\globalUpdate
    C:\Program Files\Common Files\system\SysMenu.dll
    C:\Program Files\Common Files\system\SysMenu64.dll
    C:\Windows\SysNative\ApnDatabase.xml
    C:\Windows\SysNative\drivers\WPRO_41_2001.sys
    C:\Windows\SysNative\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}Gw64.sys
    C:\Windows\SysNative\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}w64.sys
    C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job
    C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job
    C:\Windows\tasks\PC HealthFix Desktop Alert.job
    C:\Windows\tasks\PC HealthFix Desktop Warning.job
    C:\Windows\tasks\PC HealthFix Malware Alert.job
    C:\Windows\tasks\PC HealthFix Scan Results Alert 2.job
    C:\Windows\tasks\PC HealthFix Scan Results Alert.job
    
    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "pcreg"=-
    "SPDriver"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "pcreg"=-
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\windows\currentVersion\Run]
    "pcreg"=-
    "SPDriver"=-
    "PC HealthFix"=-
    [HKEY_USERS\S-1-5-21-2606278092-134880080-1092098883-1001\Software\Microsoft\Windows\CurrentVersion\run]
    "pcreg"=-
    "SPDriver"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PC HealthFix]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.




    Give Ccleaner a run. Not the reg scanner, just the cleaner itself to be rid of a chunk of temp files/folders.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  6. NJD

    NJD Private E-2

    Kestrel:

    Thanks so much for the reply. I appreciate your help!

    Proxy.log is an empty file; properties tab reports a size of 3 bytes.

    *******************************

    Revo Uninstaller results:

    Shopper-Pro -- uninstalled
    SupraSavings -- can't find this item to uninstall
    I also uninstalled YTDownloader which failed to uninstall earlier using Windows 'Programs and Features' uninstaller.
    PC HealthFix -- refused to uninstall - did not get past step 3 'running built in installer'
    I DID get Revo Uninstaller to uninstall PC Health Fix via booting to Safe Mode :)

    *********************************

    MGTools analyse.exe

    O4 - HKLM\..\Run: [pcreg] C:\Program Files\pcmax\service.exe
    Above item was in there twice - nuked both.

    O4 - HKLM\..\Run: [PC HealthFix] "C:\ProgramData\PC HealthFix\PCHealthFix.exe" /runscan
    O4 - HKLM\..\Run: [SPDriver] C:\Program Files (x86)\ShopperPro\JSDriver\1.36.1.172\jsdrv.exe
    O4 - HKCU\..\Run: [pcreg] C:\Program Files\pcmax\service.exe
    O4 - HKCU\..\Run: [SPDriver] C:\Program Files (x86)\ShopperPro\JSDriver\1.36.1.172\jsdrv.exe
    The 4 items above were not found in list.

    I have attached a log of what it looked like before and after.

    Other logs requested also attached.

    System seems relatively normal now but there is a remnant of YT Downloader in the system tray (YT Downloader is Off) and I get 3 windows in a row complaining that "SysMenu.dll" cannot be found.

    Thanks again for the help - any ideas on the two remaining items?
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run run MSconfig and put your PC into Normal Startup mode. Then exit MSconfig. You do not have to reboot right now as we will reboot later.


    Now run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Services
    pcmaxservice
     
    :Files
    C:\Program Files\pcmax
    C:\Program Files (x86)\YTDownloader
    C:\Program Files (x86)\AnyProtectEx
    :Reg
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "pcreg"=-
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{7F4EFF06-7032-458e-AE16-1C1D8255C28A}]
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{7F4EFF06-7032-458e-AE16-1C1D8255C28A}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D12C40DB-CD7D-4D86-9285-5E2FE23693E4}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. NJD

    NJD Private E-2

    chaslang:

    Good evening - thanks for dropping back into this thread!

    MSConfig / OTM / MGTools tasks done - logs attached.

    YTDownloader item in SysTray is gone.

    Machine still has the Run DLL window complaining of no SysMenu.dll found.
    It was 3 windows stacked on top of each other - down to just 2 now.
    See zipped .jpg attached.


    Thanks!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Some aspects of the last fix did not work properly. OTM did not remove a few items. It stated they could not be found but they are clearly present. So let's run a scan with another tool and then work up another fix.



    Please download OTL by OldTimer.
    • Save it to your desktop.
    • Double-click on the OTL icon on your desktopto run it. (Note: if using Vista, Win7 or Win8 use right-click and select Run as Administrator)
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the [​IMG] text-field.
      Code:
      activex
      netsvcs
      drives
      
    • Now click the [​IMG] button.
    • One report will be created:
      • OTL.txt <-- Will be opened
    • Attach OTL.txt to your next message. (How to attach)
    By the way the SysMenu.dll issue is due to Goobzo and YTDownloader
     
    Last edited: Jun 27, 2014
  10. NJD

    NJD Private E-2

    chaslang:

    Got it - Ran it - here it is.

    Second log 'Extras.txt' was produced too, attached that as well.

    Thanks!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    Now shut down your protection software (antivirus, antispyware...etc) to avoid possible conflicts.
    • Double-click OTL.exe to run. (Note: if using Vista, Win7 or Win8 use right-click and select Run as Administrator)
    • Copy the text in the code box below and paste it into the [​IMG] text-field.
    Code:
    :OTL
    DRV:[b]64bit:[/b] - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Goobzo\GBUpdate\smw.sys -- (SMUpdd)
    DRV:[b]64bit:[/b] - [2014/05/13 11:16:22 | 000,058,248 | ---- | M] (Search Snacks) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\ssnfd.sys -- (ssnfd)
    IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{7F4EFF06-7032-458e-AE16-1C1D8255C28A}: "URL" = [URL]http://www-search.net/search.aspx?s=E6Ezadku1,31fac211-17f1-4335-8778-7d607575166c,&q={searchTerms[/URL]}
    FF - HKLM\Software\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10: C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll File not found
    FF - HKLM\Software\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4: C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll File not found
    O2:[b]64bit:[/b] - BHO: (Shopper Pro) - {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} - C:\ProgramData\ShopperPro\ShopperPro64.dll File not found
    O4:[b]64bit:[/b] - HKLM..\Run: [pcreg] C:\Program Files\pcmax\service.exe File not found
    [2014/06/13 20:35:55 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Goobzo
    [2014/06/13 20:35:44 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\ShopperPro
    [2014/06/13 19:19:53 | 000,000,000 | ---D | C] -- C:\Program Files\SearchSnacks
    [2014/06/10 16:24:34 | 000,000,000 | ---D | C] -- C:\Users\William\Documents\PC Speed Maximizer
    [2014/06/09 20:07:51 | 000,608,351 | ---- | C] (Click Me In Limited) -- C:\Users\William\AppData\Local\AnyProtectScannerSetup.exe
    [2014/06/09 20:03:59 | 000,000,000 | ---D | C] -- C:\Users\William\AppData\Local\iLivid
    [2014/06/10 19:51:41 | 000,000,718 | ---- | M] () -- C:\Windows\PCHealthFix.INI
    
    :Services
    globalUpdate
    globalUpdatem
    
    :Files
    C:\Users\William\AppData\Local\AnyProtectScannerSetup.exe
    C:\Users\William\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
    C:\Windows\PCHealthFix.INI
    C:\Windows\TEMP\*.*
    C:\TEMP\*.*
    
    :Reg
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "pcreg"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D12C40DB-CD7D-4D86-9285-5E2FE23693E4}]
    :Commands
    [PURITY]
    [EMPTYTEMP] 
    [EMPTYFLASH]
    [REBOOT]
    • Now click the [​IMG] button.
    • If the fix needed a reboot please do it.
    • Click the OK button (upon reboot).
    • When OTL is finished, Notepad will open. Close Notepad.
    • A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    • Attach this log to your next message. (See: How to attach)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the log from OTL
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  12. NJD

    NJD Private E-2

    chaslang:

    Good morning!

    OTL and MGTools logs attached.

    Still getting window w/ SysMenu.dll not found message. (down to 2 stacked instead of original 3 stacked)

    Thanks again!
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Okay some progress. :) But not complete. When exactly does this happen? For example, does it only happen when you boot up your PC? Does it only happen when you open your browser? Does it happen at any other time?

    Also, please download SystemLook_x64 from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2
    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :regfind
      SysMenu
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. You can just close this notepad window since the log is already saved on your Desktop. Be patient! It may look like it is not doing anything, but it takes awhile for this to scan thru your whole system look for matches.
    • Please attach the SystemLook.txt log found on your Desktop to next reply.
     
  14. NJD

    NJD Private E-2

    chaslang:

    RunDLL window(s) will always pop up roughly 4 to 5 minutes after a "shutdown /r /f" reset.
    edit: after logging in and going to the desktop (not the Metro interface - not that this means anything - I don't spend much time with the Metro interface).

    As this computer has no anti-virus on it at the moment, and isn't mine, I have spent only a little time using it. I did have a RunDLL window popup after about 20 minutes of use last night (on a trusted website w/ Internet Explorer).

    When the machine is static - nothing actually running on it, I do not see the RunDLL window(s).

    Thanks for your efforts - it is appreciated.

    Neil
     

    Attached Files:

    Last edited: Jun 28, 2014
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now immediately reboot your PC. After reboot, rerun SystemLook similar to last time but use the below info now and attach the new log.

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :regfind
      020B1D4B-5738-4C77-9E19-4F173DD9B486
      SysMenu
      
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. You can just close this notepad window since the log is already saved on your Desktop. Be patient! It may look like it is not doing anything, but it takes awhile for this to scan thru your whole system look for matches.
    • Please attach the SystemLook.txt log found on your Desktop to next reply.
    Also reset Internet Explorer to defaults per the below:

    Reset Internet Explorer 9, 10, and 11 to Defaults

    Also check to see if it is still popping up.
     
  16. NJD

    NJD Private E-2

    chaslang:

    RegEdit reported success, reset IE, new log from SystemLook attached.

    Two RunDLL windows popped up right at 5 minutes after login. :(

    Thanks for hanging in there with this problem!!

    Neil
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • Right clisk on SystemLook.exe and select Run As Administrator to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :regfind
      pcmax
      PC HealthFix
      ShopperPro
      MyPC Backup
      SearchModule
      
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. You can just close this notepad window since the log is already saved on your Desktop. Be patient! It may look like it is not doing anything, but it takes awhile for this to scan thru your whole system look for matches.
    • Please attach the SystemLook.txt log found on your Desktop to next reply.


    Please download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
    Okay was this before or after having opened a browser window? Next time you reboot, don't run anything at all for about 20 minutes. Just reboot, login get to your Desktop and then wait 20 min and see what happens. Then if no RunDLL windows have appeared, open a browser window but don't surf. Just wait for upto 20 min again and see what happens.
     
    Last edited: Jun 28, 2014
  18. NJD

    NJD Private E-2

    chaslang:

    When / since you asked 'When' the RunDLL windows opened up I have done some testing.

    Do a restart, log in, switch to Desktop (or not - for test two), run no programs at all, start stopwatch. Within 10 seconds of 5 minutes the RunDLL windows popup, both times. There is a system sound played when the popups happen, so when I only login and stay at Metro I know they popped up in the Desktop.

    I have also opened IE after the popups and just let it set (no internet connection) - curiously, I let it run for > 20 minutes - no popup.

    I then, in the above session, connected to the internet and went to a page with no ads (no A/V on this machine at the moment) and let it set there well over 20 minutes - no RunDLL popup.

    So basically, I have been unable to duplicate the RunDLL popup, aside from the ones at 5 minutes after login, that I experienced last night.

    Here are your logs...

    Thanks! Neil
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that showed alot more leftovers hiding from this junkware.


    Right-click OTL.exe and select Run as Administrator to run.
    • Copy the text in the code box below and paste it into the [​IMG] text-field.
    Code:
    :OTL
    DRV:[B]64bit:[/B] - [2014/03/18 15:12:04 | 000,041,768 | ---- | M] (SecureAssist) [Kernel | Auto | Running] -- C:\Windows\SysNative\Drivers\SAWFP64.sys -- (SAWFP)
     
    :Files
    C:\Users\William\AppData\Roaming\aps.scan.quick.results
    C:\Users\William\AppData\Roaming\aps.scan.results
    C:\Users\William\AppData\Roaming\aps.uninstall.scan.results
    C:\Windows\System32\drivers\SAWFP64.sys
    C:\Windows\System32\SecureAssist.ini
    C:\Windows\System32\SecureAssistOff.ini
    C:\Windows\SysWOW64\SecureAssist.ini
    C:\Windows\SysWOW64\SecureAssistOff.ini
    C:\Program Files (x86)\Bench
    C:\Program Files\003
    C:\Users\William\AppData\Local\globalUpdate
    C:\Users\William\AppData\LocalLow\iWebar
    C:\Users\William\AppData\LocalLow\Object Browser
    C:\Users\William\AppData\Roaming\SupTab
    :Reg
    [-HKEY_CURRENT_USER\Software\pcmax]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\pcmax]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\pcmax]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{63290375-E943-45A5-BEF1-79365D8F491F}"=-
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{F10B19DE-6567-43DC-BDC5-089D981852FC}"=-
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{D8B6A1E0-1854-433F-8AC6-07326A55EBD3}"=-
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{F3BD6379-7CC8-4411-AD21-495E7B54F27D}"=-
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{63290375-E943-45A5-BEF1-79365D8F491F}"=-
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{F10B19DE-6567-43DC-BDC5-089D981852FC}"=-
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{D8B6A1E0-1854-433F-8AC6-07326A55EBD3}"=-
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{F3BD6379-7CC8-4411-AD21-495E7B54F27D}"=-
    [-HKEY_USERS\S-1-5-21-2606278092-134880080-1092098883-1001\Software\pcmax]
    [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
    "C:\ProgramData\PC HealthFix\PCHFUninstall.exe.FriendlyAppName"=-
    [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
    "C:\ProgramData\PC HealthFix\PCHFUninstall.exe.ApplicationCompany"=-
    [HKEY_USERS\S-1-5-21-2606278092-134880080-1092098883-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
    "C:\ProgramData\PC HealthFix\PCHFUninstall.exe.FriendlyAppName"=-
    [HKEY_USERS\S-1-5-21-2606278092-134880080-1092098883-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
    "C:\ProgramData\PC HealthFix\PCHFUninstall.exe.ApplicationCompany"=-
    [HKEY_USERS\S-1-5-21-2606278092-134880080-1092098883-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
    "C:\ProgramData\PC HealthFix\PCHFUninstall.exe.FriendlyAppName"=-
    [HKEY_USERS\S-1-5-21-2606278092-134880080-1092098883-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
    "C:\ProgramData\PC HealthFix\PCHFUninstall.exe.ApplicationCompany"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers]
    "C:\Program Files (x86)\ShopperPro\SPRemove.exe"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\ShopperPro.DLL]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShopperPro.ShopperProBHO]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShopperPro.ShopperProBHO\CurVer]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShopperPro.ShopperProBHO.1]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\ShopperPro.DLL]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\ShopperPro]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\ShopperPro.DLL]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}]
    [HKEY_USERS\S-1-5-21-2606278092-134880080-1092098883-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers]
    "C:\Program Files (x86)\ShopperPro\SPRemove.exe"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\SearchModule]
    [-HKEY_LOCAL_MACHINE\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}]
    [-HKEY_LOCAL_MACHINE\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}]
    [-HKEY_LOCAL_MACHINE\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShopperPro.ShopperProBHO]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShopperPro.ShopperProBHO.1]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\NewPlayer_RASAPI32]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\NewPlayer_RASMANCS]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
    [-HKEY_LOCAL_MACHINE\Software\NewPlayer]
    [-HKEY_LOCAL_MACHINE\Software\SupDp]
    [-HKEY_LOCAL_MACHINE\Software\SupTab]
    [-HKEY_LOCAL_MACHINE\Software\Tutorials]
    [-HKEY_LOCAL_MACHINE\Software\Wpm]
    [-HKEY_CURRENT_USER\Software\AnyProtect]
    [-HKEY_CURRENT_USER\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}]
    [-HKEY_CURRENT_USER\Software\AppDataLow\Software\Greener Web]
    [-HKEY_CURRENT_USER\Software\FreeSoftToday]
    [-HKEY_CURRENT_USER\Software\genesis]
    [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}]
    [-HKEY_CURRENT_USER\Software\Tutorials]
    [-HKEY_CURRENT_USER\Software\TutoTag]
    :Commands
    [PURITY]
    [EMPTYTEMP] 
    [EMPTYFLASH][REBOOT]
    
    
    • Now click the [​IMG] button.
    • If the fix needed a reboot please do it.
    • Click the OK button (upon reboot).
    • When OTL is finished, Notepad will open. Close Notepad.
    • A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    • Attach this log to your next message. (See: How to attach)
    Now reboot your PC and after reboot, run the exact same scans with SystemLook and AdwCleaner again as last time.


    Then attach the below logs:
    • the log from OTL
    • SystemLook
    • AdwCleaner
    Are you still getting the RunDLL popup?
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I hope you see this before running my last fix. I just added a bunch more registry items to the OTL fix. Click refresh to get them all.
     
  21. NJD

    NJD Private E-2

    chaslang:

    Here are the logs after the updated OTL fixes were applied.
    (the AdwCleaner as incremented because I had the scans done before I saw your 'update' post)

    Still have the RunDLL windows popping up at 5 min after log in.

    Thanks, Neil
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay run AdwCleaner again and allow it to fix all the items it finds.

    Then reboot the PC in safe boot mode and run the last OTL fix again.

    Then reboot in Normal mode and again run new scans with SystemLook ( same as last time ) and also AdwCleaner. Attach the new logs.

    I may have to have you do some manual registry editing since some keys are not getting removed using the tools.
     
  23. NJD

    NJD Private E-2

    chaslang:

    Seem to be paring the log entries down...

    The first run of AdwCleaner gave me two logs so there are those plus the log from the second run.

    Yes, there is still a RunDLL popup at 5 minutes.

    Manually editing the registry is OK with me.

    Thanks, Neil
     

    Attached Files:

  24. NJD

    NJD Private E-2

    chaslang:

    I use msconfig to reboot to safe mode and noticed the "Selective Startup" radio button is lit. I can change it to "Normal", but the 'apply' button is greyed out and after hitting OK and re-running MSConfig "Selective Startup" is still selected.

    Neil
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay this will be my last post for the night. Gotta get up early tomorrow.

    Run regedit.exe as administrator and navigate to the below keys and if found, delete them:


    [HKEY_LOCAL_MACHINE\SOFTWARE\pcmax]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\SearchModule]


    Then reboot after reboot download and run Autoruns and keep the Everything tab selected, then slowly scroll down thru the Image Path column. Do you see anything related to SysMenu.dll showing up?
     
  26. NJD

    NJD Private E-2

    chaslang:

    I'm about done for the night too.

    Deleted keys in RegEdit - they stayed deleted after reboot.
    Found two SysMenu.dll references in Autoruns, both in "Scheduled Tasks / Task Scheduler" area - File Not Found.

    Still have the popups.

    Thanks and Good night!! Neil
     
    Last edited: Jun 29, 2014
  27. NJD

    NJD Private E-2

    chaslang:

    Here is a log of the Autoruns - I hope.

    Neil
     

    Attached Files:

  28. NJD

    NJD Private E-2

    chaslang:

    Cleared the 'check' marks on the two SysMenu.dll entries in Autoruns. Rebooted.

    No more RunDLL popups.

    :) ?

    Neil
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that was what I was going to have you do next. The only reason I did not say to remove them was because I wanted to see what they were hooked into. I was assuming Windows Explorer but wanted to check.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    8. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  30. NJD

    NJD Private E-2

    chaslang:

    Thanks for all your hard work - it is appreciated.
    Here's to hoping I don't end up in this section of the forum again any time soon!!!

    Best regards,

    Neil
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds