My scan logs

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by chrisp8778, Dec 22, 2014.

  1. chrisp8778

    chrisp8778 Private E-2

    Hi,

    I just completed all the steps in Read and Run ME thread and am still having issues with whatever is infecting my computer. Attached are the logs from the scans.

    December 21, very early in the morning I was playing a game and they offer to give you free currency for that game if you just complete one of their offers. These offers are not monitored by the company. Choices were for example to complete a survey or download and install a program. And that's exactly what I did. I downloaded and installed some free media player and afterward Google Chrome (my default browser) was not going to any other pages. I closed it and reopened it but it would not reopen. Internet Explorer is also not working. I'm able to surf the web with TorBrowser. Also, any game clients i've downloaded are still full functional and i dont notice a slow down. Spotify and Yahoo Messenger also work for me. Netflix App does not work.

    Thank you.
     

    Attached Files:

  2. chrisp8778

    chrisp8778 Private E-2

    Sorry. I neglected to explain the situation very well. tried editing first post but couldnt.

    December 21, very early in the morning I was playing a game and they offer to give you free currency for that game if you just complete one of their offers. These offers are not monitored by the company. Choices were for example to complete a survey or download and install a program. And that's exactly what I did. I downloaded and installed some free media player.

    After I installed the software the offer asked me to install, ZoneAlarm popped up saying it had to do an advanced disinfected because it found malicious malware and needed to reboot. so I did. Afterward Google Chrome (my default browser) was not reopening. Internet Explorer is also not working. It opens but I cant go to any other webpages. I'm able to surf the web with TorBrowser. Also, any game clients I've downloaded are still full functional and i don't notice a slow down. Spotify and Yahoo Messenger also work for me. The Netflix App does not work.

    So I proceeded to have ZoneAlarm run a full scan with Archive files included. It found 1 so I told it to delete it. And it supposedly did. Afterward, I downloaded Malwarebytes and ran a scan. It found some malicious software though I'm not sure of the exact number. I believe it was 8. I had Malwarebytes delete them. I then uninstalled Malwarebytes, thus losing whatever log was created when it did that scan. I then uninstalled Chrome and tried to reinstall it but it would get stuck on "connecting to the internet" even though I was. So i did a system restore to 2 days before (December 19th) and Chrome was still not opening.

    I called my mom up, told her the situation, and she suggested me to run Norman Malware Cleaner and then follow the MajorGeeks Malware removal (why didn't I think of that before?). Norman found 11 different instances of Malware. One of them is from a game galled PerfectWorld and its a .dll file which I'm almost certain is benign. It said it supposedly cleaned those files. 2 of them having to do with Google Chrome and 2 having to do with Internet Explorer. I tried opening them and still they were not working. After I tried all this, then I went ahead and did everything suggested in the READ AND RUN ME thread. I will attach the Norman log in the 2nd post.

    Thank you for your time.
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks

    Please attach the requested C:\MGlogs.zip so I can begin the log review.
     
  4. chrisp8778

    chrisp8778 Private E-2

    Right. There you go. my bad. I thought I had uploaded all 5. Pardon the late response.
     

    Attached Files:

  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)
    No problem, chris

    Now please download Junkware Removal Tool to your desktop.
    • Make sure to shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Next download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • When it's done you'll see: Pending: Please uncheck elements you don't want removed.
    • Now click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • Look over the log especially under Files/Folders for any program you want to save.
    • If there's a program you may want to save, just uncheck it from AdwCleaner.
    • If you're not sure, post the log for review. (all items found are either adware/spyware/foistware)
    • If you're ready to clean it all up.....click the Clean button.
    • After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
    • Attach that logfile to your next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which are created when running the tool.

    Now Copy the bold text below to notepad. (Do not include any space above the word "REGEDIT4")Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" . Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me whether or not you receive a success message about adding the above to the registry. If you do not get a success message, it definitely did not work.

    Please download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version for your PC. Only the correct version will work.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • NOTE: The first time the tool is run, it makes also another log (Addition.txt), please attach it also to your reply.
     
  6. chrisp8778

    chrisp8778 Private E-2

    All right so I'm sending you the JRK log and the 2 logs from Farbar Recovery. The fixME.reg file was successful. I was asked for confirmation to excute it when i double-clicked it and a confirmation saying it was successful. I ran ADW after I ran JRK, got the log, clicked "clean" then I received a log. I then rebooted like I was told to and when I rebooted, I received the log with files were deleted. I accidently closed that log without confirming that it had saved it to my desktop. Should I run the scan again?
     

    Attached Files:

  7. chrisp8778

    chrisp8778 Private E-2

    Oops. found it. Attached is the AdwCleaner log AFTER I ran the scan and cleaned the files.
     

    Attached Files:

  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    I did find some leftovers from Kaspersky Lab's anti-virus to include.

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.

    Download Fixlist.txt (see attached)

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply.

    Please re-run HitmanPro and perform a scan only. Attach the updated log to your next reply.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Please attach:
    • Fixlog.txt
    • updated C:\MGlogs.zip
    • updated HitmanPro log
     

    Attached Files:

  9. chrisp8778

    chrisp8778 Private E-2

    I have done as requested and attached the 3 logs you asked for.
     

    Attached Files:

  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    I'll review your logs in the morning -

    How's your pc running?
     
  11. chrisp8778

    chrisp8778 Private E-2

    Google Chrome still closes as soon as I open it. The window doesn't even come up. just the highlighted icon on my taskbar because i have it pinned to it. Task Manager says I have 5 Google Installer processes going, 2 Google crash handler processes going, one being (32bit).

    Internet Explorer window opens up but is unable to load the Google homepage. So I take it to runescape.com and it loads just fine. I take it to the game through the website and i get a white screen trying to load it. Loading the game client I have downloaded, I notice no delay and it runs fine. I then try to go to Netflix through Internet Explorer and I have the perpetual white screen after I click. I try to go to Facebook. Same result. The Netflix App is also perpetually stuck trying to load.

    As far as the rest of my computer processes, I don't notice any slowdowns. Boot time is slow as always even though this is a new computer (bought in May) because of its HDD. Like I said, what seems to be affected are my browsers and trying to go to the above-mentioned websites.

    I appreciate your time by the way.
     
  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome!

    It does seem that you have quite a few services running. You can get some help trimming those down in our software forum.

    Using Programs and Features, uninstall this outdated software
    Java 7 Update 67

    Now Copy the bold text below to notepad. (Do not include any space above the word "REGEDIT4")Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" . Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me whether or not you receive a success message about adding the above to the registry. If you do not get a success message, it definitely did not work.

    Okay for problems with Internet Explorer, run the below while no other browsers are running:

    Reset Internet Explorer 9, 10, and 11 to Defaults

    For problems with Chrome, run the below while no other browsers are running:

    Reset Chrome to Defaults

    Now install the current version of Sun Java from:
    Make sure that when you install the new version of Java that you uncheck the Install the Ask Toolbar junkware checkbox. You do not want to add the stuff junk that most people consider malware to your PC. Also just in case Oracle changes the Java installation in the future to possible install other junk, uncheck all but just installing Java.

    Please run another Farbar Recovery Scan Tool scan as instructed in post#5 and attach the updated log.

    Any improvement with your browsers' performance?
     
  13. chrisp8778

    chrisp8778 Private E-2

    I uninstalled Java from Programs, though I was always told uninstalling it from CCleaner was better. I saved the quoted text to fixMe.reg and the changes were successful.

    I reset Internet Explorer. It asked me it needed to do a reboot of the computer so I did that. I then tried google.com and facebook.com and instead of getting the white screen, there was a blip and it stayed firmly on the msn homepage. Though when i type in runescape.com, it goes there without delay.

    I was unable to reset Google Chrome because I can't even open the browser window. I will be attaching a debug log I found in the Google Chrome folder C:\Program Files (x86)\Google\Chrome\Application.

    I did not install Sun Java just yet or run the Farbar scan to await further instructions.
     

    Attached Files:

    Last edited: Dec 23, 2014
  14. chrisp8778

    chrisp8778 Private E-2

    So I had the idea to boot into Safe Mode with Networking to see what if any results I might see. Internet Explorer loaded up fine with the MSN home page showing up. I type in google.com and it took me straight to it. I didn't do a Google search, though probably should have. Next I try facebook.com. it takes me straight to it. I log in and am able to interact with it as usual. I try netflix.com and it loads perfectly. I sign in and pick a random show to watch and it gets stuck on loading it. After, I go to runescape.com, which loaded fine as well as expected. Going to play the game through the browser did not work as I had guessed because it needs Java to run. The game client does not.

    I then try the Netflix app. It does not let me due to the fact that i'm using the "built-in administrator account" if my memory serves me well.

    I then try running Google Chrome as Administator. Nothing. I load it normal just by left-clicking it and I get a message. I took a screenshot which I will provide attached.
     

    Attached Files:

  15. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    We might need to uninstall your anti-virus program that may be getting in the way. Were these all one program and is freeware?
    ZoneAlarm Antivirus
    ZoneAlarm Firewall
    ZoneAlarm Security​
    Please download OTL by OldTimer.
    • Save it to your desktop.
    • Double-click on the OTL icon on your desktopto run it. (Note: if using Vista, Win7 or Win8 use right-click and select Run as Administrator)
    • Check the "Scan All Users" checkbox.
    • Set the "Output" to "Standard Output".
    • Change the setting of "Drivers" and "Services" to "Use Safelist"
    • Copy the text in the code box below and paste it into the [​IMG] text-field.
      Code:
      activex
      netsvcs
      msconfig
      drives
      
    • Now click the [​IMG] button.
    • One report will be created:
      • OTL.txt <-- Will be opened
    • Attach OTL.txt to your next message. (How to attach)
     
  16. chrisp8778

    chrisp8778 Private E-2

    It's all 1 program. And yes it is freeware. ZoneAlarm was recommended to me but I am willing to switch because I'm told it's no longer as good as it once was. Ran the OTL scan as instructed. Here are the results.

    Also Merry Christmas :) hope you had a wonderful Christmas eve and Christmas.
     

    Attached Files:

    • OTL.Txt
      File size:
      136.2 KB
      Views:
      4
  17. chrisp8778

    chrisp8778 Private E-2

    Done as requested above. Awaiting further instruction.
     
  18. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Sorry to be late in replying, chris. I hope that you had a nice holiday.
    I'm leaning towards software corrupt being the cause of this "chrome.exe - Application Error" message. Have you tried an un-install > re-boot > re-install of chrome?

    Now we need to use OTL by Old Timer.
    • Double-click OTL.exe to run (Vista and Win7 right-click and select Run as administrator)
    • When OTL opens, copy the text in the code box below and paste it into the [​IMG] text-field.
      Code:
      :OTL
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{79A70FE7-E53D-46CA-9391-59EE3A735EED}: DhcpNameServer = 75.75.75.75 75.75.76.76
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EC77D564-3DCE-405F-AB09-5BE5FFD76ADA}: DhcpNameServer = 75.75.75.75 75.75.76.76
      @Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:5C321E34
      :commands
      [purity]
      [EmptyTemp]
      [start explorer]
      [Reboot]
    • Now click the [​IMG] button.
    • OTL may ask to reboot the machine. Please do so if asked.
    • Click the OK button.
    • When complete, Notepad will open.
    • Close Notepad.
    • A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    • Attach this log to your next message. (How to attach items to your post)

    What malware problems are you having?
     
  19. chrisp8778

    chrisp8778 Private E-2

    Apologies for my late reply. Thank you for your prompt one.

    I did as requested to uninstall Chrome, reboot, and reinstall. When I uninstalled it, I rebooted the computer in safe mode FIRST and uninstalled from CCLeaner. I then rebooted into safe mode with networking.

    I did this because before I even contacted Major Geeks about this, I had uninstalled, did not reboot, but tried to install again from the download file I already had. But the installation process couldn't even begin because the window Chrome opened, in a grayish box said "connecting to the internet" perpetually.

    So I redownloaded the file from the google website. I search "google chrome" from google.com and click the first link right below the ad. I install it and Google Chrome opens for me to sign into it. But it doesn't load properly. So I open up another tab and from the "open menu" button to the right of the address bar and select "sign in to chrome" and was able to do it that way. I am unable to type in "google.com" and go there. I am unable to go to "youtube.com", every time if i don't interfere it says the connection times out. I am unable to go to Facebook either. I even try going to the Major Geeks website and only the top ribbon with the links to different parts of the website shows up. It says its still loading but it gets stuck right there. I go to "runescape.com" and it loads fine. I go to a news article that contains a youtube video element attached, the element doesn't load. another website I frequent "runescape.wikia.com" and the page loads fine, but the picture elements do not load. I try to go to "notdoppler.com" and it doesn't load. the connection times out. the only websites that seemed to load without delay were runescape.com and runescape.wikia.com. "amazon.com" loads fine for me.

    Something else to note, and I don't know if it's because I downloaded a Chrome look-a-like or this is simply 1 of their new features. To the left of the first opened tab, it shows a little outline of a person. I right click it and it says "first user" next to that figure. below it is another "person" with the name "Shady". With either one, i'm given the option to sign into Chrome. The version of Chrome i'm running is Version39.0.2171.95 m.

    So essentially, I still have very limited browser function. Also, Internet Explorer will not let me go to Google or Youtube, from the MSN homepage. it loads as if it go to the page but then stays on MSN. I still have internet access but not through the browsers, which I find strange to me. I can access game clients on my desktop. I can load and play Spotify.

    2 days ago, I was trying to connect my computer to the first time through HDMI to my Samsung SmartTV and I was messing with the resolutions to try to make it fit well, I was also trying to figure out how to get the sound to come out of my tv instead but after searching, I was able to just reboot with my computer already connected to the tv and sound came. The reason I mention this is because after I disconnected my computer from the tv I notice my taskbar, window borders, icons, and all essentially "blown up" to be oversized. I checked all my settings, especially resolution, and it was at it's native 1600x900 for my laptop screen. So I don't know what could be going on. I was going to use the Refresh option that's available on Windows 8, but did not want to mess up anything you've had me do. Also its alot of data to get back. having to re-install programs and game clients and such.

    I've attached the OTL log as requested.
     

    Attached Files:

  20. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Please download from our site:
    Now unzip(extract) the contents of geek.zip, locate and right-click the .exe and "Run as Administrator".
    • Once the installed programs listing is populated > left-click to high-light "Chrome"
    • Then right-click and choose Delete.
    • Follow the prompts to remove any program left-overs
    • When finished > re-boot > make sure these folders are also gone
      • C:\Users\Christian\AppData\Google
      • C:\Program Files (x86)\Google

    Be patient while doing the below. The fixes can take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and go to bed or do something else. It is better not to run anything while the repairs are going on.

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    Next install your Chrome download and again - - re-boot!

    Lastly, re-run HitmanPro as per our original instructions and perform a new Scan only. Then attach the updated log.

    Any problems with your browsers now?
     
  21. chrisp8778

    chrisp8778 Private E-2

    Downloaded Chrome and GeekUninstaller from that link. Uninstalled Chrome from GeekUninstaller and rebooted the computer. Found nothing of Chrome except Crash reports under ProgramFiles(86x). I then downloaded Windows repair and I read in that program that it was recommended to run it as soon as I booted the computer, but I had to open up Tor first to access the next set of instructions, and I opened another program as well, but then I closed all available programs, even ZoneAlarm since Windows Repair said it may interfere. I set Windows Repair to reboot after it finished and that's just what I found this morning.

    I then went to install Google Chrome from my downloads folder and the white box Chromeupdate.exe opens to connect to the internet, was stuck STILL on "connecting to the internet" i confirmed to see if there was any internet traffic through Task manager, and I wasn't streaming or doing anything else. Send/Receieve were both at 0kbps. I ran Hitman and I've attached the log. Apart from Chrome not wanting to install from normal boot, Internet Explorer still wont go to majorgeeks.com or google.com. So nothing resolved on that front.

    One thing to note is after I ran the OTL fix last time you instructed, but before I replied with the log attached, I went to putlocker through Google Chrome which I had installed via Safe mode with networking, and since I was unable to access Chrome extensions, I was unable to re-install Adblocker plus, which I normally have, and it prevents alot of pesky things from popping up on sites like putlocker. Well, when I went to putlocker that day, it opened up a tab to an ad for FVL player for Chrome download. I clicked the "exit tab" button and it downloaded it. I was shocked. but at the same time ZoneAlarm caught it and says it treated it. Just something to note. Does Adblocker really do a good job in keeping me safe from viruses and malware obtained from ads such as those?

    Also, I'm not sure what Windows Repair was meant to fix, but I still have oversized windows and taskbar and icons on my desktop. My icons are set to small. and my resolution is native to the screen I use. I don't know what could be the problem.

    I'm doing the best I can following your instructions and I still seem to be stuck at square one.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't appear to be having malware problems based on your logs. I suggest that you totally disable ZoneAlarm or even uninstall ( would be best ) and then see if you still have this problem.

    No! It is only an ad blocker not a true malware blocker.

    I suggest that you post in the Software Forum. This is not a malware problem.
     
  23. chrisp8778

    chrisp8778 Private E-2

    So I don't know if you've been following my thread or not much, but do you know if from the perspective of malware, I'm still infected based on the logs? I was told ZoneAlarm is no longer effective as an Antivirus or Firewall. What would you recommend? Also, even when I had exited out of ZoneAlarm, I still couldn't install Chrome from normal boot. Was there perhaps some background process from ZoneAlarm possibly running that prevented me?

    I will look into resolving my other issues in the software forums by the way.

    Thanks a bunch Chaslang!
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As stated in a previous message, I suggest that you uninstall ZoneAlarm and leave it uninstalled. Also for now uninstall Chrome. Then reboot. After reboot run the below so we can check to make sure they both really fully got removed. Do not reinstall Chrome.... at least not yet.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).



    Please attach:
    • updated C:\MGlogs.zip
    Also repeat your previous scan with OTL ( see message # 15 ) and attach the new log from OTL.
     
  25. chrisp8778

    chrisp8778 Private E-2

    Attached is MGlogs.zip and the updated OTL log run as specified in post #15.

    I received your reply late because by the time I read it, I had already uninstalled ZoneAlarm with the ZoneAlarm clean-up tool provided by MajorGeeks. I had then proceeded to install Private Firewall, and then Avast! Antivirus. While selecting the installation options for Avast! I unchecked the Google toolbar for Internet Explorer but left the "Install and set Google Chrome as the default browser" option checked to see if it would install. And after Avast! finished installing, it installed Chrome. I went to google.com, facebook.com, and youtube.com and they all worked, whereas previously they didn't. I apologize for getting ahead of myself.

    I didn't think to check in with you first since we're still in the malware removal process. I hope I didn't mess anything up. The Netflix app which had come pre-installed with my computer was also working again, which prior to me installing Private firewall and Avast! antivirus was not working.

    Something to note. Don't know if it has to do with the malware removal process or the culprit to my lowered resolution, but i have 2 files called desktop.ini on my desktop, and I notice they're configuration settings. What are they for?
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well it sounds like my suspicion that ZoneAlarm was the problem was correct. ;)

    They are part of Windows and are normally just hidden files. Our process allowed hidden files to be seen so that real malware files would not be hidden.

    Just one left over from ZoneAlarm to remove.

    Now please click Start, and type cmd.exe into the search box.
    • You should see a cmd.exe black icon appear in the Programs area of the Start Menu.
    • Right click on cmd.exe and select Run As Administrator.
    • A command prompt window will open.
    • Enter the below commands in this window. Do both commands even if you receive an error on the first. Follow each by the enter key. Note there are spaces after the sc and after the stop and after the delete.

      sc stop ZAPrivacyService
      sc delete ZAPrivacyService


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    8. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  27. chrisp8778

    chrisp8778 Private E-2

    ZAPrivacyService deleted successfully. Completed the final steps though I have a question on what programs it might benefit me to keep. They are
    GeekUninstaller​
    AdwCleaner​
    I already have CCleaner where I by default uninstall programs. Also, what is the purpose of downloading the malware removal/scanning programs? So malware is not able to infect it if it is in a folder?

    Thanks again Dr. Moriarty for your help in ridding me of the pesky malware, and Chaslang for buttoning up! :)
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


    You can keep GeekUnintaller if you wish but would not use as your everyday uninstall program. Use the Windows Uninstaller first. Remove AdwCleaner. It should only be used as recommended by an expert as it shows many things that are not problems and that should not be removed. Also you always need to use the current version.

    Don't use CCleaner for this. It just runs the Windows Uninstaller. Use Ccleaner as a disk cleaner only.

    I'm not sure I follow your question! How are we suppose to clean your PC if we don't have your download the tools we need to clean it?
     
  29. chrisp8778

    chrisp8778 Private E-2

    I neglected to say, to the desktop. why download to the desktop instead of for example to the downloads folder where the rest are.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We need you to download where we request for several reasons:
    • So that our final cleanup programs know where to look to find things we need to automatically remove when finished. Most of what we have you download is not supposed to be kept on your PC.
    • Things not located where suggested can be assume to be malware copies of programs
    • Some tools may only work properly when run from specific locations
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds