unable to install anything

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by interclash, May 21, 2015.

  1. interclash

    interclash Private E-2

    Hi all,

    I have a pretty new pc (Windows 8.1, 64-bit), and from the beginning I've had trial versions of Norton and later Kaspersky antivirus installed. Nevertheless I've had unwanted extensions added to Chrome, but I was able to remove them by deleting several files and folders - or at least I thought I was, because the problems disappeared.

    Several days ago, the trial period of Kaspersky had expired and I decided to download AVG Free, which I had been using on my previous pc without any trouble. I noticed however that Chrome suddenly became very slow and websites wouldn't load correctly anymore. My AVG download would not finish until I canceled and retried it a few times. However, the downloaded file never went further than 'initiating installation' and it stopped after a few minutes (I should have written down the error it gave...).
    I downloaded it on my laptop without trouble and transferred it to my pc via a USB stick, but it still wouldn't install. Then I tried to download Avast!, but this could not be run at all, due to Windows saying it wasn't compatible. I found something on the Windows support website saying I should download DotNetClean, which I did, but this could not be run either.

    Oh yeah, and everytime I was using Chrome, clicking links (no matter what, just navigating trough websites) would sometimes become triggers to download files named 'download' and 'homepage' for example.
    I tried to use Internet Explorer, but encountered the same problems.
    I've scanned my pc twice with Spybot Search & Destroy (which I already had on my pc), but it couldn't find anything.

    I stumbled upon this forum and went step by step through the Malware Removal Guide. I downloaded all the tools on my laptop onto the USB drive, from which I ran them on my pc. That was yesterday, and today both my pc and laptop do not recognize that very USB drive anymore. As I don't want to destroy anything by recklessly removing things found by the tools, I am now asking for help.

    I hope I have described my problems clearly and provided enough information. I've attached the log files, but they are partly in Dutch. If that turns out to be a problem I can try to translate them, but I hope it will be clear this way as well.

    Thanks in advance,
    Timo
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You forgot the requested log from running Hitman Pro. We need this log file.

    Also your log from Malwarebytes shows that you either did not fix anything or you forgot to fix first and then save the log. Please run it again and this time fix what it finds. Then save a new log and attach it.

    Is the below CopyAgent program something that you knowingly installed?
    O4 - HKCU\..\Run: [Copy] "C:\Users\Timo\AppData\Roaming\Copy\CopyAgent.exe"
    O4 - HKUS\S-1-5-18\..\Run: [Copy] "C:\Users\Timo\AppData\Roaming\Copy\CopyAgent.exe" (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [Copy] "C:\Users\Timo\AppData\Roaming\Copy\CopyAgent.exe" (User 'Default user')


    Now we need to start by cleaning up the fact that you have too many security program installed and a lot of other junk too!

    Uninstall the below programs. If you do not find them or they will not uninstall, just keep going.
    bestadblocker
    DigiCOupooN
    DigiSaVoeR
    ExsstraaCoupon
    Extreme Blocker
    FuinodBBestuDeaL
    Java(TM) 6 Update 10
    Kaspersky Anti-Virus
    Norton Identity Safe
    Norton Security
    ReGuLarDeials
    SaleiPlus
    Spybot - Search & Destroy

    Now install the current version of Sun Java from:
    Make sure that when you install the new version of Java that you uncheck the Install the Ask Toolbar junkware checkbox. Also if it asks if you want to install McAfee Security Scan Plus that you uncheck this too. You do not need to add these unncessary items and to your PC. Also just in case Oracle changes the Java installation in the future to possibly install other junk, uncheck all but just installing Java.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.goodforsearch.info...hid=12799187677655581410&lg=EN&cc=NL&unqvl=86
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.goodforsearch.info...hid=12799187677655581410&lg=EN&cc=NL&unqvl=86
    O2 - BHO: SaleiPlus - {09d46f2b-783f-42a6-9270-00942e8289ba} - C:\Program Files (x86)\SaleiPlus\FsnFf2IIp6iCiG.dll (file missing)
    O2 - BHO: ExsstraaCoupon - {56718101-0c9c-4390-82d8-7acb225fb919} - C:\Program Files (x86)\ExsstraaCoupon\pMthjNAibItz1u.dll (file missing)
    O2 - BHO: DigiSaVoeR - {66288f36-76f3-43da-89bb-4f288e6de091} - C:\Program Files (x86)\DigiSaVoeR\Qo03EjaSThE9ts.dll (file missing)
    O2 - BHO: SalePlus - {9bb7aef7-e096-4a4f-a158-c69ed68ded9c} - C:\Program Files (x86)\SalePlus\7SyDyjRAZ6OFOl.dll (file missing)
    O2 - BHO: ReGuLarDeials - {aaa54a9b-5d79-4ed9-9a27-193877f51196} - C:\Program Files (x86)\ReGuLarDeials\iKXBRiQobvUmcq.dll (file missing)
    O2 - BHO: bestadblocker - {dd461210-1072-4064-ba2b-113fb14edea2} - C:\Program Files (x86)\bestadblocker\SXCFL5ExRJcDlm.dll (file missing)
    O2 - BHO: DigiCOupooN - {ecad5aae-b919-4e0e-9bee-2e701a8bf6b4} - C:\Program Files (x86)\DigiCOupooN\MzWZuk5mutgy10.dll (file missing)

    After clicking Fix, exit HJT.

    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\ProgramData\Kaspersky Lab
    C:\ProgramData\Norton
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Anti-Virus
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Identity Safe
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
    C:\Program Files (x86)\Kaspersky Lab
    C:\Program Files (x86)\Norton Identity Safe
    C:\Program Files (x86)\Norton Security
    C:\Program Files (x86)\NortonInstaller
    C:\Program Files (x86)\Common Files\Symantec Shared 
    C:\Windows\system32\tasks\Norton Identity Safe
    C:\Windows\system32\tasks\Norton Security
    C:\Windows\system32\tasks\Norton WSC Integration
    C:\Windows\system32\tasks\Safer-Networking
    C:\Program Files (x86)\SystemPromote
    C:\Users\Timo\AppData\Roaming\EZDownloader
    C:\Windows\TEMP\*.*
    C:\Users\Timo\AppData\Local\Temp\*.*
     
    :Reg
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{BB82DE59-BC4C-4172-9AC4-73315F71CFFE}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{BB82DE59-BC4C-4172-9AC4-73315F71CFFE}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXT log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. interclash

    interclash Private E-2

    I'm sorry, this time I've attached the Hitman Pro log, together with the ones from MalwareBytes, OTM, JRT and MGTools.

    Copy is a cloud storage service (much like Dropbox). I have not used it yet, but I did install it intentionally.

    Those junk files like DigiCOupooN and other misspelled names were the ones I thought I removed. They were still visible in the Control Panel program removal tool though, but at the same time Windows said they already had been removed, so I could not uninstall those.

    Besides that, I have done everything you said.
    Chrome now seems to work fine again, and I was able to download and install something (Avast!). Does this mean all problems have been fixed?

    Thanks
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No we have more to do since you had not posted your Hitman log the first time.

    Please run Hitman again and this time activate the free 30 day trial and have it remove all the junk it reported.

    Then reboot and run a new scan with Hitman and attach the new log.


    Also run the below to cleanup the rest of the items from things you could not uninstall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.


    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
    :Files
    C:\Program Files (x86)\SaleiPlus
    C:\Program Files (x86)\ReGuLarDeials
    C:\Program Files (x86)\MiniimUmPRicoE
    C:\Program Files (x86)\FuinodBBestuDeaL
    C:\ProgramData\Extreme Blocker
    C:\Program Files (x86)\ExsstraaCoupon
    C:\Program Files (x86)\DigiCOupooN
    C:\Program Files (x86)\DigiSaVoeR
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: May 23, 2015
  5. interclash

    interclash Private E-2

    I reran Hitman Pro after activating the trial version. It said it did not find any malicious software, but there were files to be removed, so I did. After rebooting it did not find anything anymore.

    I got a success message about adding the text from fixme.reg to the registry.

    I ran CCleaner and had it clean the things it found, and I ran OTM and GetLogs.bat as you said.

    The logs from Hitman, OTM and MGTools are attached.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. Please complete all of the below final instructions before running any other scans to avoid false detections of things we have already quarantined or left overs from system restore.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    8. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • For Windows 8 and 8.1 system restore see this link: Win 8 System Restore - How to enable/disable
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  7. interclash

    interclash Private E-2

    I did as you said.

    Now for my last two questions:
    1. I suddenly have a procdll.txt file on my desktop, created today. Does that sound familiar? Is there anything I could/should do with it?
    2. That USB drive which suddenly could not be recognized anymore, could that mean it got infected? Or would it rather be a hardware issue?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can just delete this leftover from MGtools. It could not be found and removed automatically because you have your Desktop located in a non-standard/unusual location.

    Not really sure but it seems like more of a hardware issue since you really did not have any serious malware problems. Just a bunch of junkware.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds