malwarebytes, superantispyware wont update

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cody123, Mar 27, 2015.

  1. cody123

    cody123 Private E-2

    hello, first off I'd like to say I am not good with computers at all. So my computer has been acting up. Sometimes my browser will not load any pages. But what has be shook is when I try to use avast to update or scan, it freezes and even using control alt delete and trying to close the program it will not. I have to restart the computer. I have tried uninstalling, and it does the same thing. My superantispyware will not update. It checks connection and says its fine, then will not update. I just uninstalled it, and now when I try to install it will not let me. It gets to about 90% and says "the superantispyware.exe download was interrupted", when I click "resume" it says "The signature of SUPERantispyware.exe is corrupt or invalid. The programs I have for security are panda cleaner, panda antivirus, avast free edition 2015, superantispyware, and malwarebytes. The panda cleaner is acting up as well. It just freezes when I try and use it. What should I do? My computer is a HP desktop
     
  2. cody123

    cody123 Private E-2

    forgot to say that my malwarebytes will not update either. it shows that it is downloading the update but when it is done it says unable to access update server or something like that. So it is not updating. Please help. I use this computer for my small business and need it to be safe.
     
  3. cody123

    cody123 Private E-2

    Ok, so I am pretty sure I got the panda cleaner program to update. I scanned and copied the details of the scan for you guys to see. Please help me!


    Malware. FILE: C:\USERS\EASTER BROS PREOWNED\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\ILVEBOOA.TXT to be deleted.

    Malware. FILE: C:\USERS\EASTER BROS PREOWNED\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\0OI0HUXH.TXT to be deleted.

    Malware. FILE: C:\USERS\EASTER BROS PREOWNED\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\7CYJ3BR5.TXT to be deleted.

    Malware. REGKEY: HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM[DISABLEREGISTRYTOOLS]. Value: DISABLEREGISTRYTOOLS To be deleted.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    NOTE: You mentioned several antivirus programs in your first message. You MUST uninstall all but one!
    You should never install multiple antivirus protection programs.

    Please read ALL of this message including the notes before doing anything.

    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual update Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only RogueKiller and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run the rest of the READ & RUN ME FIRST instructions on the infected account.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  5. cody123

    cody123 Private E-2

    Thanks for the reply. Which antivirus should I leave installed? I have avast, panda, malwarebytes, and superantispyware. I am pretty sure that I cannot uninstall Avast. Im not for sure about the others. So i assume I should uninstall the ones that I can? I will try and follow the instructions the best I can. Like i said I am not good with computers at all, but I will do my best to follow exactly like it says. Also I see a few of the steps don't apply to me such as step one. My browser seems ok. So from what i understand I should delete all antiviruses but one which will most likely be Avast since I cannot uninstall it, then I should follow the directions on the link you gave me, and post the results of the scans that it makes me run, correct?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just uninstall Panda. Keep the rest, do the scans and upload them when you are done. ;)
     
  7. cody123

    cody123 Private E-2

    Hello,
    Sorry I haven't responded I have been out very sick. Anyway, I am trying to do this and I cannot save the programs roguekiller and tdskiller to my desktop. It just says "tds killer couldn't be downloaded" "retry, cancel or view downloads." I can get it to download by pressing retry but it isn't saving it to my desktop like the intructions say to. Like I said I am horrible with computers and I am really struggling doing this. I guess I will run the programs the only way it will let me until I hear from you guys otherwise.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Disable your protection software and try again.
     
  9. cody123

    cody123 Private E-2

    what protection software? I am midway through running the programs now. I will post the logs here very shortly. Hopefully I get this right
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I have to go out for a little while, but I will be back to check your logs. ;)
     
  11. cody123

    cody123 Private E-2

    Ok, so I ran all the programs the last MG tools one was very confusing. I found the mgzip file and when I pushed extract all files it shows like 24 different files. Do I post all them?
     
  12. cody123

    cody123 Private E-2

    10:32:04.0822 0x02a4 TDSS rootkit removing tool 3.0.0.14 Oct 15 2013 15:35:38
    10:32:07.0209 0x02a4 Perform update action was selected
    10:32:07.0209 0x1184 Deinitialize success
     
    Last edited by a moderator: Apr 7, 2015
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach your logs....do not post them inline.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't need to extract anything. You just need to attach MGlogs.zip as stated in the instructions in the READ & RUN ME FIRST.
     
  15. cody123

    cody123 Private E-2

    I cannot figure this out...
     
  16. cody123

    cody123 Private E-2

    hopefully this is correct
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would like to see the log from running Hitman.
    '
    In the meantime, rerun RogueKiller and have it fix these items:
    Code:
    ¤¤¤ Registry : 26 ¤¤¤
    [PUP] (X64) HKEY_CLASSES_ROOT\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209} (mscoree.dll) -> Found
    [PUP] (X64) HKEY_CLASSES_ROOT\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E} (mscoree.dll) -> Found
    [PUP] (X64) HKEY_CLASSES_ROOT\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358} (mscoree.dll) -> Found
    [PUP] (X64) HKEY_CLASSES_ROOT\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7} (mscoree.dll) -> Found
    [PUP] (X64) HKEY_CLASSES_ROOT\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301} (mscoree.dll) -> Found
    [PUM.Proxy] (X64) HKEY_USERS\S-1-5-21-4237742438-1424443218-2435228694-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1  -> Found
    [PUM.Proxy] (X86) HKEY_USERS\S-1-5-21-4237742438-1424443218-2435228694-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1  -> Found
    You have multiple AV software installed. We need to remove them.

    Download OTM by Old Timer and save it to your Desktop.


    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Paste the following code under the [​IMG] area. Do not include the word Code.


    Code:
    :Processes
    explorer.exe
    
    :files
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Cloud Antivirus
    C:\ProgramData\F-Secure
    C:\ProgramData\Panda Security
    C:\ProgramData\panda_url_filtering
    C:\Program Files (x86)\Panda Security
    C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\*.*
    C:\Windows\SysWOW64\shoED79.tmp
    C:\Users\Easter Bros Preowned\AppData\Local\Temp\*.*
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]

    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.


    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.

    Tell me how things are running.
     
  18. cody123

    cody123 Private E-2


    I can't get hitman to run. When I click on it, it comes up asking me to choose a program to open it with.
     
  19. cody123

    cody123 Private E-2

    ok I reran roguekiller and deleted what you told me to. I downloaded the old timer program and copied and moved exactly what you said. When I rebooted the computer it took a long time to come back on, and before I saw any icons or anything and the screen was still black a security warning came up asking me if I wanted to allow a program to run. I declined and it started up fine.

    I cannot find the C:moved files file you asked me to post. I looked under my computer , under C drive and can't find it.
     
    Last edited: Apr 9, 2015
  20. cody123

    cody123 Private E-2

    also forgot to mention that when I moved the list of things you asked me to move on the old timers program. When it made me reboot and I got back in the program there is nothing there to copy and post...
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun RogueKiller and attach the new log.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Attach the new C:\MGLogs.zip.

    Tell me how things are running.
     
  22. cody123

    cody123 Private E-2

    how do I find the new roguekiller file that I need to attach? and how do I find the mgbats file? Do I just go to "start" then search for the file?
     
  23. cody123

    cody123 Private E-2

    here is the new roguekiller log I just ran

    im trying to run the MG file. I have a hard time with it. it is confusing to me. I will post the results in just a minute
     

    Attached Files:

    Last edited: Apr 9, 2015
  24. cody123

    cody123 Private E-2

    Ok I ran the MGtools file, and here is the zip file
     

    Attached Files:

  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What issues are you still having, if any? If you are still not able to update MBAM and SAS, have you tried uninstalling and after a reboot, reinstall?
     
  26. cody123

    cody123 Private E-2


    superantispyware will not update still. I uninstalled and reinstalled and it sill will not update. It verifies the connection then just says failed to update which is what it did before. Avast still is acting up. It will freeze if I try to scan or uninstall, then it will not close. Even if I use control+alt+delete and try to close avast that way, it will not close. I have to restart for the window to close. If I do not try and scan or uninstall it seems to run fine. The computer seems to be a tad faster (although this could be placebo).
     
  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sounds like issues for the software forum. Is anything else not working?
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    @TimW

    Since there had been multiple protection programs running previously, I would suggest uninstalling ALL of them. Even SAS, MBAM, Avast....etc. Then reboot. Get a new MGtools log to make sure everything was removed properly! Make sure all folders for each program are deleted!!!! If not then manually remove. Afterwards, I suggest running Windows Repaid and rebooting.

    Then just download and reinstall SUPERAntiSpyware and see if it works before going any further.
     
  29. cody123

    cody123 Private E-2

    Avast isn't working right (it freezes when I try to uninstall, and will freeze during a scan sometimes right at first sometimes not until its almost done) Superantispyware wont update, it will run a scan but will not update. Im pretty sure that is all that I have noticed although I do not use many programs and would not notice a lot of things not working correctly like you guys would.

    Now that I have ran the scans and so fourth, should I delete any of the programs I've downloaded? Or is there anything I should switch back or change back?


    I cannot uninstall Avast. Anytime I try the program freezes and I cannot exit out of it. I have to restart the computer for the frozen window to disappear. Also, I wouldn't know how to manually delete any files, and I do not know what running Windows Repaid means. Im sorry I am so computer dumb. I try to learn I just can't for some reason. It took me half an hour to figure out how to quote both of you guys so I can reply to both of you in the same message. It also took me forever to find out how to edit a message. How sad , I know right...
     
  30. cody123

    cody123 Private E-2

    Sorry to post 2 messages in a row but it won't let me edit the previous message.

    So I am trying to uninstall avast. I finally got it to start uninstalling. It now freezes after I click uninstall and the window comes up that shows the progress of the removal. It just won't do anything. The bar never moves, and I have to restart the computer to be able to close the window. Anyway, as the window is still up when I click on the internet I get this message

    There is a problem with this website’s security certificate.








    The security certificate presented by this website was not issued by a trusted certificate authority.





    Security certificate problems may indicate an attempt to fool you or intercept any data you send to the server.

    I copied that right off my browser. It gives me the option to go ahead to the website (which is my homepage of google), or to leave. When the window for uninstalling avast is not up it does not do this. I don't know If this matters or has anything to do with my issues but I figured I would let you guys know.

    When I have the avast uninstallation window up there is a question mark tab right beside the minimize and exit tabs in the top right corner. When I click on the question mark tab it opens google chrome to take me to what I assume to be a help website and this is what I see.......



    Your connection is not private

    Attackers might be trying to steal your information from ipm-provider.ff.avast.com (for example, passwords, messages, or credit cards).

    Back to safetyAdvanced
    NET::ERR_CERT_AUTHORITY_INVALID

    Subject: *.avast.com
    Issuer: avast! Web/Mail Shield Root
    Expires on: Dec 21, 2017
    Current date: Apr 15, 2015
    PEM encoded chain: -----BEGIN CERTIFICATE-----
    MIIGHzCCBQegAwIBAgIQOiRc3058mE+q2BkhTzpMIzANBgkqhkiG9w0BAQsFADCB
    hDE7MDkGA1UECwwyZ2VuZXJhdGVkIGJ5IGF2YXN0ISBhbnRpdmlydXMgZm9yIFNT
    TC9UTFMgc2Nhbm5pbmcxHzAdBgNVBAoMFmF2YXN0ISBXZWIvTWFpbCBTaGllbGQx
    JDAiBgNVBAMMG2F2YXN0ISBXZWIvTWFpbCBTaGllbGQgUm9vdDAeFw0xNDEyMTcw
    MDAwMDBaFw0xNzEyMjExMjAwMDBaMFUxCzAJBgNVBAYTAkNaMRAwDgYDVQQHEwdQ
    cmFoYSA0MR4wHAYDVQQKExVBVkFTVCBTb2Z0d2FyZSBzLnIuby4xFDASBgNVBAMM
    CyouYXZhc3QuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAupIb
    FQ0CDSfMPM6YBUDqNQi/WezPttA9vBKE4JBZqy8W39P58ygyOCRptXq97guvGCkZ
    /gnu8pWSinpRzHDuI/POHXF/OoRZquubD1rke44wu4fS6ATX0HqrmJt+4ZDqLeFU
    WaOq3pytAXmInEqusOx+uXDSNh1drEj6HG9oNQttCybPMn5kXONPbuKrRl1qCt1H
    Y2bKbDeUSB9UWvCtwKAhtpxCszpeXUlN7y8tdWuqjcBpizGxzBr3iY6Jbvrsn1bl
    omclVcc8x0fvnkHuE4KGyKMQPByX2zFTIATnSmh6af2mf9BH/RP8YxwMX092AGZl
    EboYPh/9/qAmr2dafwIDAQABo4ICuTCCArUwHwYDVR0jBBgwFoAUV1TIWqv393LX
    w0bt6vQesjlLwJ0wHQYDVR0OBBYEFP+XSr+icQT6xMwYyFIWDEGMby+MMHAGA1Ud
    EQRpMGeCCyouYXZhc3QuY29tgglhdmFzdC5jb22CGWlwbS1wcm92aWRlci5mZi5h
    dmFzdC5jb22CH2lwbS1wcm92aWRlci1zdGFnZS5mZi5hdmFzdC5jb22CEXByb2dy
    YW0uYXZhc3QuY29tMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcD
    AQYIKwYBBQUHAwIwQgYDVR0gBDswOTA3BglghkgBhv1sAQEwKjAoBggrBgEFBQcC
    ARYcaHR0cHM6Ly93d3cuZGlnaWNlcnQuY29tL0NQUzAMBgNVHRMBAf8EAjAAMIIB
    fgYKKwYBBAHWeQIEAgSCAW4EggFqAWgAdgCkuQmQtBhYFIe7E6LMZ3AKPDWYBPkb
    37jjd80OyA3cEAAAAUwnCjQPAAAEAwBHMEUCIF1Z1uvgys+a9G2qibZwXJl/OVvi
    h4C43dPRyGDGH8O2AiEA4xbQ3wknUQB+LeBQcmRxMDBUCT+kRVH9xYzpholo3oAA
    dgBo9pj4H2SCvjqM7rkoHUz8cVFdZ5PURNEKZ6y7T0/7xAAAAUwnCjPcAAAEAwBH
    MEUCIHxlh9d9b44USKMz2c8Drejn7s2PzeaHMYsM4+iDnsCbAiEA5AdSqIO2tMJw
    XcttfmHkupodNDmZE/oqdyfnym6ZT7UAdgBWFAaaL9fC7NP14b1Esj7HRna5vJkR
    XMDvlJhV1onQ3QAAAUwnCjQnAAAEAwBHMEUCIQCibOkyUew3QI/xza4zsAQS48CN
    OuCslQqC9u5kr3pgkwIgI6WKFX8tUpE+/XyX8Yg1YjZhOi21Zk8/AOBOIAY1HSAw
    DQYJKoZIhvcNAQELBQADggEBAALL0Umrh64eHI20afSbNs3OSkx/+cCIjLo+15ty
    a1VWQbKjS5LOq+mdzp6UpVN3Fp+DnEpQ+/0G9VW2hP7iNMYaOxYJtkbtd5Hx3nUR
    OBE/BkR6qCZ3ZhHUOYAS+wDlNG8AnS4LWB65n8p7tDPNYdQWh2I1Qupi7NMguwV2
    Ixf/M4RGOuGNsdd8TIPDqq5RCOasH3rOLwFlxX2gQIA6DALz1GcZLnYvsPgQIFIb
    Y+T0iFeQh2soBYHnV8blZbqfuTR3pBTTonJzbqCt8Zg+sTHiYp6IkakulmROxmqv
    JRVfLo3hapM1IJC9uJq5VFiYpuiTSKARsd8Sc7J6jPld5gU=
    -----END CERTIFICATE-----
    -----BEGIN CERTIFICATE-----
    MIIECTCCAvGgAwIBAgIQm2qJ2hxiFU2Za/ZjfcXSsjANBgkqhkiG9w0BAQsFADCB
    hDE7MDkGA1UECwwyZ2VuZXJhdGVkIGJ5IGF2YXN0ISBhbnRpdmlydXMgZm9yIFNT
    TC9UTFMgc2Nhbm5pbmcxHzAdBgNVBAoMFmF2YXN0ISBXZWIvTWFpbCBTaGllbGQx
    JDAiBgNVBAMMG2F2YXN0ISBXZWIvTWFpbCBTaGllbGQgUm9vdDAeFw0xNTA0MTUx
    NzExNTZaFw0yNTA0MTIxNzExNTZaMIGEMTswOQYDVQQLDDJnZW5lcmF0ZWQgYnkg
    YXZhc3QhIGFudGl2aXJ1cyBmb3IgU1NML1RMUyBzY2FubmluZzEfMB0GA1UECgwW
    YXZhc3QhIFdlYi9NYWlsIFNoaWVsZDEkMCIGA1UEAwwbYXZhc3QhIFdlYi9NYWls
    IFNoaWVsZCBSb290MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwg/I
    29OVSOrCTMwNpaqBGakx3Q7cIE2wMpoghVcIJaGM/LsnHwukRLXYc9zgMh51/qAl
    O+gxDh+J+9/44FQERhOlDHdiKFjqbdNVk9SeQQg9r1n2lPo4MQ2AlpkZTFF6rf+/
    XfvW9YByBbycAqGhR0U2SgBZFmcKEw8fkS45Noej7KW2+0MZDJoZ64sWwSh+cK+G
    r3WSE7ahlSUWOTMnfwRxl1KWV9zOC7Xii4MNQ+W1S3sJCRFiy9pY2E3A/W/y3/OY
    7VxWsUcMOVtBYNg+qOdB8X7APrx/R4h44cUHKMITQRtFV1cdWWlihG3yt8gvfSRl
    TMHzp5QhD2pcMS4b4wIDAQABo3UwczAPBgNVHRMECDAGAQH/AgEAMAsGA1UdDwQE
    AwICBDATBgNVHSUEDDAKBggrBgEFBQcDATAdBgNVHQ4EFgQUV1TIWqv393LXw0bt
    6vQesjlLwJ0wHwYDVR0jBBgwFoAUV1TIWqv393LXw0bt6vQesjlLwJ0wDQYJKoZI
    hvcNAQELBQADggEBACQF9I05PxKylNBwmWhu//fXp/m+55qFRkj3OL9pFmXLk1Us
    CSnviykzfLc+exFLlsXOONeHw33xpHYXFJ3Jljk7GbLljum6btuzrr6R+YJh3MiO
    L8oEmjLzfyqy7/uHsnRPnlvCTeH7BRvg/qwb5IVdouJff8tcN08AZNmDxa180Gnu
    f0AVSzhbhVYZkKCC0r718a1VAQy/F+b1Izvdt5Tcf6B1zCKlB7+iBAQ1L06KMSBP
    O7xLAzJphCRJvV1yIMoGsGVqwk2IWE3VXgfaGonhuNmC5ziE4CDa0GeGFMh9oxnW
    s66QS43Wmk/Jm3I/agLb/x0ZodKWxZTfhEKgWS4=
    -----END CERTIFICATE-----
     
    Last edited: Apr 15, 2015
  31. cody123

    cody123 Private E-2

    3 posts in a row im sorry guys I don't know any other way though...

    So good news, I finally was able to uninstall Avast! I got it off, as well as malwarebytes and superantispyware. So as of right now I have no antivirus programs installed. I noticed when I restarted the computer after finishing uninstalling the above programs, that the computer started quite a bit quicker than it did before. After I put in my windows password the computer used to turn black screen for about 20 seconds before it would show the normal background wallpaper and icons. Now after I put my password in the screen doesn't turn black at all and it shows my icons and wallpaper background within 5 seconds of putting my password in.

    So just to rundown what I did again, I uninstalled all my antivirus programs including avast which I could not do before. Please give me instructions on what to do now as im sure it's not very safe to not have antivirus installed. Thanks a lot in advance fellas!!
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now download the current version of MGtools and save it to your root folder or to your Desktop. Overwrite any previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista, Win7, or Win8, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:

    • C:\MGlogs.zip
     
  33. cody123

    cody123 Private E-2

    ok im running the mgtools now. ill post the zip file shortly
     
  34. cody123

    cody123 Private E-2

    new mg log

    and im not sure what UAC is but I followed the directions as best I could. im assuing that is the defogger thing I downloaded that disabled UAC? I haven't changed anything since I followed the directions
     

    Attached Files:

  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    UAC is User Account Control and is part of Windows. This was in the READ & RUN ME FIRST.


    Uninstall the below programs. If you do not find them or they will not uninstall, just keep going.
    Java 7 Update 17

    Now install the current version of Sun Java from:
    Make sure that when you install the new version of Java that you uncheck the Install the Ask Toolbar junkware checkbox. Also if it asks if you want to install McAfee Security Scan Plus that you uncheck this too. You do not need to add these unncessary items and to your PC. Also just in case Oracle changes the Java installation in the future to possibly install other junk, uncheck all but just installing Java.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/s...mepage/index.jsp?lg=en&pid=NIS&pvid=21.5.0.19
    O3 - Toolbar: (no name) - {A057A204-BACC-4D26-D298-35EFC2A62DD7} - (no file)
    O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O4 - HKUS\S-1-5-18\..\RunOnce: [panda4_2dn] reg.exe delete "HKCU\Software\AppDataLow\Software\panda4_2dn" /f (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [panda] reg.exe delete "HKCU\Software\AppDataLow\Software\panda" /f (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [panda_XP] reg.exe delete "HKCU\Software\panda" /f (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\RunOnce: [panda4_2dn] reg.exe delete "HKCU\Software\AppDataLow\Software\panda4_2dn" /f (User 'Default user')

    After clicking Fix, exit HJT.

    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    C:\Windows\tasks\GoogleUpdateTaskMachineCore1cfef05a093cbcd.job
    C:\Windows\tasks\GoogleUpdateTaskMachineCore1cfffaca7ec4f29.job
    C:\Windows\tasks\GoogleUpdateTaskMachineCore1d041d0b93ae0a9.job
    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    C:\Windows\tasks\Toolbox.exe_{28DE2F2A-E7DB-45C4-A017-50B16F6DDD44}.job
    C:\Windows\tasks\Toolbox.exe_{FE062FB5-A5F5-4C9B-8AFF-AD612918C4D9}.job
    C:\Windows\system32\tasks\Norton Internet Security
    C:\Users\Easter Bros Preowned\Desktop\Norton Installation Files.lnk
    C:\ProgramData\AVAST Software
    C:\Program Files (x86)\Web Protect
    C:\Windows\TEMP\*.*
    C:\Users\Easter Bros Preowned\AppData\Local\Temp\*.*
    
    :Reg
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{B7A07B81-92BB-4AD1-9C63-16B6636CF3CC}]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "swg"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "HP Software Update"=-
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\windows\currentVersion\Run]
    "HP Software Update"=-
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "panda4_2dn"=-
    "panda"=-
    "panda_XP"=-
    [HKEY_USERS\S-1-5-21-4237742438-1424443218-2435228694-1000\Software\Microsoft\Windows\CurrentVersion\run]
    "swg"=-
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Remove Policies Set By Infections
      • Repair Windows Updates
      • Repair MSI (Windows Installer)
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished. If it does not then reboot it yourself.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  36. cody123

    cody123 Private E-2

    im on the windows repair step, I have it downloaded but there is no "start repair" tab. There Is a "repair" tab, which once I click on there is no "start" button? Am I missing something?
     
  37. cody123

    cody123 Private E-2

    here you go,


    so I reinstalled superantispyware, and it will update now! Is my computer safe now? What antivirus should I use , I assume I had too many before? and what programs do I need to delete that you guys had me download?
     

    Attached Files:

  38. cody123

    cody123 Private E-2

    what do we think guys? Am I fixed? If so, what programs should I delete, or what do I need to change back if there's no more fixing to be done?
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes your logs look fine now.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • For Windows 8 and 8.1 system restore see this link: Win 8 System Restore - How to enable/disable
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  40. cody123

    cody123 Private E-2

    my dofogger program is not working. when I click on it it just comes up as a notepad with a bunch of words? Also, I cannot figure out how to do this system restore thing. Im afraid im going to mess something up. The instructions for "how to disable and enable system restore" are very vague. What exactly am I restoring or what do I need to do? I have no clue
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't need defogger. You had no disk emulation software running.

    Just follow the instructions for your version of Windows. You are not restoring anything. You are simply disabling system restore and then renabling it inorder to remove infected restore points.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds