Rocket Tab \ Client.exe popups

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mistermike40, Aug 29, 2014.

  1. mistermike40

    mistermike40 Private E-2

    After trying to install a flash player (I know, bad idea) my computer has issues. When I boot up a black text box "Taskeng.exe" appears and the message "can't find Rockettab\Client.exe". I followed the instructions though I'm not sure MGTools ran correctly. I'm attaching the files (I zipped all the MGTools files, again not sure if this is a typical MGtools output).

    Any help is greatly appreciated!!!

    P.S. My computer has over a dozen Google Chrome's running, and in the uninstall programs list some icons/names have changed (e.g. Roller Coaster Tycoon now has a generic icon and is simply titled "roll"
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nope! See the instructions. The log from MGtools.exe is C:\MGlogs.zip It is not a file you create. If it is not in C:\ then look on your Desktop or watch for error messages while MGtools.exe is running and report what you see.


    Normal if you have lots of tabs open. Even with only one tab open, Chrome typically shows 3 processes.
     
  3. mistermike40

    mistermike40 Private E-2

    MGLogs didn't create a zip file... it ran, but the command prompt window closed before I could read what it said (which makes me think it didn't run properly)
     
  4. mistermike40

    mistermike40 Private E-2

    Re: Rocket Tab \ Client.exe popups - *CORRECT MGLOGS.ZIP ATTACHED*

    Sorry about my initial post... I thought I ran MGLogs correctly the first time but obviously I didn't. This (the attached MGLogs.zip) should be what you need.

    Again, I really appreciate the help!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below programs. If you do not find them or they will not uninstall, just keep going.
    Idle~_~Crawler
    SpyHunter

    Now run MSconfig and put your PC into normal starup mode so that we can properly analyze your PC. You should not be using MSconfig as a long term startup manager.
    Read this to better understand why not to use MSconfig: Dealing with Startup Process



    Now please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    :Services
    gupdate
    gupdatem
     
    :Files
    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1385485374-1575447589-2629669108-1001Core.job
    C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1385485374-1575447589-2629669108-1001UA.job
    C:\TDSSKiller_Quarantine\04.05.2014_18.55.42
    C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\fla*.tmp
    C:\TDSSKiller.*.*
    C:\Users\Carter\AppData\Local\Idle~_~Crawler
    C:\Windows\TEMP\*.*
    C:\Users\Carter\AppData\Local\Temp\*.*
     
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Idle~_~Crawler]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXT log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. mistermike40

    mistermike40 Private E-2

    Hi Chaslang - thanks for getting back to me. I did what you said up to the OTM step... I d/l the file, installed and opened it, cut and paste the code and hit the Move It button... it seemed to work fine, but after two hours its still running. It executed all the code but for the past 90 minutes its *very* slowly emptying the Windows Temp Files. Should it take that long for this step? BTW the green progress bar does move slowly... when it gets to the end it goes back to the beginning and starts moving again... slowly!

    Thanks again for your help!
     
  7. mistermike40

    mistermike40 Private E-2

    Well, I had to terminate the OTM program... it was making no progress after three hours. I ran JRT and MGLogs and attached those logs.

    When I rebooted, it still has the same issue as before: black text box called "Taskeng.exe" appears and the message "can't find Rockettab\Client.exe"
     

    Attached Files:

  8. mistermike40

    mistermike40 Private E-2

    One other thing I forgot to mention: when I tried to run OTM, my antivirus program (AVG) deleted it, saying it was a Trojan virus. I had to disable AVG and re-download OTM to run it (though again, it never finished running).
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    AVG is just getting in the way of cleanup which is quite common. I suggest that you boot in safe boot mode and then try to follow my previous instructions with OTM.

    When you boot your computer up, if the warning from taskeng.exe shows up again can you take a snapshot of it and also if possible do not shut it down leave it open and ry to run C:\MGtools\GetLogs.bat while the notice is still present. Make sure that you always run GetLogs.bat by using right click and select Run As Administrator.
     
  10. mistermike40

    mistermike40 Private E-2

    I ran OTM in safe mode... same thing happened, it wouldn't finish. When I first ran it the file from last night appeared... I saved that (dated August 30) as well as today's (August 31). I also re-ran MGlogs (right click as administrator). The log from August 30 shows some file activity; the one from tonight didn't (maybe they were already moved?).

    It still has the popup upon booting. It wouldn't let me run MGlogs or anything else while it was on screen, but I was able to do a screen capture... it's included in the attachments.

    Thanks again for your help.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download and run Autoruns and keep the Everything tab selected, then slowly scroll down thru the Image Path column. Do you see anything related to this Rocket Tab startup showing up?
     
  12. mistermike40

    mistermike40 Private E-2

    Yes... in "task scheduler" there is an entry for RocketTab Update Task... it says "File not found: C:\Program Files (x86)\RocketTab\uninstall.exe

    in the description at the bottom of Autoruns, when I highlight the RocketTab entry it says:

    "C:\Program Files(x86)\RocketTab\uninstall.exe" /CheckUpdate=true

    Does this help?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Remove that entry.
     
  14. mistermike40

    mistermike40 Private E-2

    That stopped the popup, thanks! Two more things I'm not sure about:

    - last night I also removed "Gigiclicks Crawler" from task scheduler. Today it was still there. I removed it again (this time both tasks)... am I ok, or do I still have Crawler on my PC?

    - there is still a popup that opens and closes immediately when I boot up. I think this started when I installed one of the scan programs (I thought MGlogs but I notice there's still an Autoruns entry in red for hitmanpro... it looks like it created a registry entry?

    Thanks again for your help chaslang!!
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Not based on your logs. These were just left over tasks like RocketTab.

    - there is still a popup that opens and closes immediately when I boot up. I think this started when I installed one of the scan programs (I thought MGlogs but I notice there's still an Autoruns entry in red for hitmanpro... it looks like it created a registry entry?[/QUOTE]In our instructions for using Hitman we asked you to put it on your Desktop and run it from there. Since you did not follow those instructions it is likely the cause of your problems with running Hitman and also likely the reason the service for it shows in red. Your last logs showed it was trying to run from what appears to be a removeable drive ( drive G ) and thus it is not available all the time.
    Since we are finished, you can just uninstall Hitman while completing the below.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  16. mistermike40

    mistermike40 Private E-2

    Hi chaslang - thanks again for your help.

    Regarding HitmanPro, I did follow your instructions and saved/ran the program from my desktop. I had to you Hitman Pro earlier in the year when my PC was held for "ransom" by some malware trying to extort money from me... the directions were to run hitmanpro from a flash drive. It took care of the problem but I didn't realize it created a registry entry.

    That registry entry must have been from then (not now). There was no uninstall program for hitman... I could only delete it.

    - is there a way to locate/remove the old registry entry referencing hitman pro (from the G:\ drive) so the popup stops?

    I did all the other cleanup you mentioned.

    You were right about Crawler - I checked again and its completely gone.
     
  17. mistermike40

    mistermike40 Private E-2

    Hi chaslang - I looked at Autoruns again, there are a lot of registry errors (references to programs/printers that no longer exist, etc). I also read your link on why I shouldn't use MSConfig as a startup manager. It made me think: when I switched to normal startup mode, that's when the non-RocketTab popup(s) began... I suspect there are some orphaned registry entries that are now being referenced again at startup.

    Do you think I should back up my registry, then use a cleaner like CCleaner or Comodo to clean up my registry? Thanks!
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No not really. We quite frequently recommend doing any registry cleaning unless it is really deemed necessary for some particular reason. Registry cleaning is known to be the cause of many problems including but not limited to problems with Windows Updates and many more.

    You may be able to delete the service entry for Hitman Pro on drive G by finding it in AutoRuns. If not, we can manually make use of a DOS level type command to delete the service entry.
     
  19. mistermike40

    mistermike40 Private E-2

    I tried unchecking it but that didn't work. Do you want me to right-click and actually delete it?

    What about the other "file not found" entries... should I just leave them alone?

    I scanned the registry and there are 20-30 hitmanpro entries... maybe I should delete those? Or just the one that shows up on autoruns?

    Thanks again!
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes.

    Yes.

    Your original Hitman Pro did not show any problems so I don't know why you would have any now unless you have been downloading/installing anything other than what we have requested. Many things reported by Hitman ( and also other tools like RogueKiller ) are not problems. It is just information.
     
  21. mistermike40

    mistermike40 Private E-2

    I haven't downloaded or installed anything other than what you requested. I deleted the hitmanpro G:\ entry in Autoruns... but the black text box still pops up every time I boot up (it disappears in less that a second, I can't tell what it is).

    Do you have any idea what other program might be causing it? Thanks!
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is just a temporary command prompt window that is opening to run some application that your PC loads during startup. It could be related to anything you are running. For example, any of the below items that run at startup ( and you have more than this ) could cause it
    I suggest that you complete all of my final instructions if you have not done so already.
     
  23. mistermike40

    mistermike40 Private E-2

    OK, should I just ignore the popup window then? My computer runs fine, there's nothing wrong with it other the the bootup window.
     
  24. mistermike40

    mistermike40 Private E-2

    Hi chaslang - great news! Using Autoruns, I disabled (unchecked) the two logon entries that stated "file not found". I figured disabling them wouldn't be a big issue since the file didn't exist anymore.

    Result: the popup is gone!! My computer is running great :) I appreciate all of your help and patience.

    I did the final instructions... the only program I still have on my computer is Autoruns. Thanks again!
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Yes keep Autoruns. As you saw in the link I gave you about Dealing with Startup Processes, Autoruns is something I recommend.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds