Alureon.J - please help - tool logs attached

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Luvss2ride, Sep 19, 2014.

  1. Luvss2ride

    Luvss2ride Private E-2

    My infected computer is an HP a6312p 32 bit running Windows Vista Home premium. It's been running sluggish / odd for a few months. Only in the last couple of days did Microsoft Security Essentials find the trojan: DOS/Alureon.J
    I had already performed some tasks - as suggested by other websites/videos - before finding your website/forums. But most of it was done while the computer was in safe mode (delete temporary files, delete suspicious registry, etc). I have not, however, had any pop ups, or disabling of internet, or redirecting of home pages, etc. It's really not running bad at all ... but, I know I've got a serious problem.
    And, please know that I am not knowledged in computer terms; but, I can usually follow basic instructions fairly well. :p
    I appreciate your time and efforts to help me fix my 'ole girl ... I'm quite attached to her. :drool

    I am attaching the files / logs requested in the Vista, Win 7 and Win 8 Malware Removal/cleaning procedure thread. I did not have any issues running any of the tools. But, I cannot attach the MGlogs.zip because it is almost twice the allowed size for attachment (3917kb)
    I need to get moving to work and will be unable to work on the desktop until late this afternoon/early evening.
    Thank you, again, for your help

    View attachment RKreport_SCN_09192014_080536.log

    View attachment MalwareBytesLog.txt

    View attachment TDSSKiller.3.0.0.40_19.09.2014_08.45.23_log.txt

    View attachment HitmanPro_20140919_0909.log
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Really?? Just do this (although we do not usually allow it-)

    Upload the logs to mediafire.com or something and give me the link.
     
  3. Luvss2ride

    Luvss2ride Private E-2

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode.


    Uninstall this junk:
    • My Web Search (Webfetti)


    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Web Browsers tab and locate these detections:

    • [PUP][IE:Addon] System : DVDVideoSoftTB Toolbar [{872b5b88-9db5-4310-bdd0-ac189557e5f5}] -> FOUND
    • [PUP][FIREFX:Addon] ujadx9sg.default : DVDVideoSoft YouTube MP3 and Video Download [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] -> FOUND
    • [PUP][FIREFX:Addon] ujadx9sg.default : SweetPacks Toolbar for Firefox [{EEE6C361-6118-11DC-9C72-001320C79847}] -> FOUND
    • [PUP][CHROME:Addon] Default : OfferMosquito [gbmdkmlcnbapgegninelmjbfibaghdmk] -> FOUND

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.





    Re run TDSSKiller and have it remove this what you previously skipped:



    Re run Hitman and have it remove all that it finds.



    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    • O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
    • O2 - BHO: ShopAtHome - {66516A07-F617-488A-90CF-4E690CFB3C5F} - C:\Users\Mom and\AppData\Roaming\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll (file missing)
    • O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:\Program Files\SGPSA\BHO.dll
    • O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
    • O3 - Toolbar: ShopAtHome.com Toolbar - {311B58DC-A4DC-4B04-B1B5-60299AD3D803} - C:\Users\Mom and\AppData\Roaming\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll (file missing)
    After clicking Fix exit HJT.




    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.
    Code:
    :Files
    C:\Users\Mom and\Local Settings\Application Data\24n5l270a1daj5c70b7ii
    C:\Users\Mom and\Local Settings\Application Data\6o1fpxf5dlxq47de5jb1600yp8m4cy5xnp3yiv
    C:\Users\Mom and\AppData\Roaming\Microsoft\Windows\Templates\24n5l270a1daj5c70b7ii
    C:\Users\Mom and\AppData\Roaming\Microsoft\Windows\Templates\6o1fpxf5dlxq47de5jb1600yp8m4cy5xnp3yiv
    
    :reg
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{09a5b2e9-9203-46f5-8a4f-b417a23b8a8a}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{33414CD4-57A8-461E-8B4B-1F95A57A6B58}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{D0B81197-C875-4BF3-B266-F93A46F165A9}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. Luvss2ride

    Luvss2ride Private E-2

    To help save you a little typing ... I am using a separate machine to view your instructions ... so I don't have to have any browsers open while following your instructions.:)

    Just starting your requests ... so, before I forget ... I have tried many many times to uninstall that stupid webfetti ... gives me this warning:

    Error loading C:\PROGRA~1\MYWEBS~2\bar\1.bin\mwsbar.dll
    The specified module could not be found.

    (I'm sorry ... I'm not very good with the quote option)

    Using the RogueKiller ... the following did not show up:

    [PUP][FIREFX:Addon] ujadx9sg.default : SweetPacks Toolbar for Firefox [{EEE6C361-6118-11DC-9C72-001320C79847}] -> FOUND
    [PUP][CHROME:Addon] Default : OfferMosquito [gbmdkmlcnbapgegninelmjbfibaghdmk] -> FOUND

    After rebooting from putting it back in Normal Startup and using RogueKiller: the following error:

    Error loading C:\PROGRA~1\MYWEBS~2\bar\1.bin\mwsbar.dll
    The specified module could not be found.

    _________________________________________________________

    OTM did not finish it's run ... warning posted that OTM stopped running. Desktop was black, so I had to reboot.
    Ran OTM again. It finished this time and did require a reboot. OTM actually created the log, which opened up after the machine rebooted and I was able to save it from there.
    View attachment RKreport_DEL_09202014_064242.log

    View attachment TDSSKiller.3.0.0.40_20.09.2014_06.52.39_log.txt

    View attachment HitmanPro_20140920_0711.log

    View attachment MGHijackThisLog.txt

    View attachment OTM_09202014_074333.log
     
  6. Luvss2ride

    Luvss2ride Private E-2

    The following is for the MGtools log... which, again, would not attach ..

    https://www.dropbox.com/s/26rauei3lkkw97n/MGlogs.zip?dl=0


    I hope I haven't forgotten anything ... I'm running very late and won't be back on the desktop until later tonight. There is also another reply I posted prior to this one, but it said it would need to be approved first. It has all the other attachments you requested.
    Thank you, again, for your time and help

    Machine is running about the same - although - I do not see any current finds of the Alureon.j in MSE's window ... will have to check on this after I get home tonight :)
     

    Attached Files:

    • JRT.txt
      File size:
      11.2 KB
      Views:
      4
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Rescan with TDSSKiller (just a scan) and attach log.

    MyWebSearch appears to have uninstalled. Do you still get an error about it upon start up?

    Let me know if your antivirus complains anymore about anything.
     
  8. Luvss2ride

    Luvss2ride Private E-2


    1. TDSSKiller log attached. It found the same item. I skipped since you said scan only.

    2. There was no WebSearch/webfetti error upon start up!!! Yayyyy!! Woot woot wiggle wiggle!! {That thing has annoyed me for a longggg time!!}

    3. The last couple days, my antivirus would throw up little windows that it found a threat and was taking care of it. Then I would have to go in to the program and "delete" them out. Tonight, there was no "window" popup .. but, it did still find the trojan. A couple days ago, my antivirus would find this about every 30 seconds; so, having just one now is a huge improvement!
    I was told this virus creates its own small partition and would be hard to find it ....

    Here is the information:

    Trojan:DOS/Alureon.J (Severe) (9/20/2014 8:53 pm) (Quarantined)
    The following error occurred: Error code 0x80508023. The program could not find the malware and other potentially unwanted software on this computer.
    Category: Trojan
    Description: This program is dangerous and executes commands from an attacker.
    Recommended action: Remove this software immediately.
    Items: boot:\Device\Harddisk0\DR0


    The only other thing to mention might be ..... it seemed to take extra time for the computer to start up. But, I wonder if that's because it's starting in Normal mode (which starts a lot of programs I don't use very often) ?

    Again .. and again .. Thank you Thank you!!
    Good grief ... 'Kestrel13' ... do you ever sleep?! ;):-D

     

    Attached Files:

    Last edited by a moderator: Sep 28, 2014
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I don't sleep much :-D



    Do you have your Vista boot CD? If not:

    If you don't have your Vista disc, you can create a Recovery Environment disc for your system here:

    32bit Vista Recovery Environment

    64bit Vista Recovery Environment

    You can use ImageBurn to create the disc.

    Once the disc is created, boot into the bios and change the boot order to CD/DVD as first boot device. Put in the disc and reboot. Once in the RE, type this:

    Bootrec.exe /fixmbr

    Note the space after the exe.

    Exit out when done and boot back into normal mode. Re-run TDSSKiller and attach the new log.
     
  10. Luvss2ride

    Luvss2ride Private E-2

    Unfortunately my machine did not come with a CD (that has always concerned me)
    And....also unfortunately ..... the link you provided to digiex didn't work. This is what the web page said:


    Anti-Leech Protection - Download Blocked


    Oh no, it look's like your trying to download from Digiex.net from another site which isn't authorised.

    We're sorry we can't complete the download for you, it's not your fault. It's just some pretty crappy webmaster or user who has just stolen our content that we worked hard on.

    The fact you got this message means the file does actually exist on Digiex.net, it's just a case of finding it on our site which you can use the search bar at the top left, the categories on the top right or the Google Search below:

    So, I search for 32bit Vista Recovery Environment in their search bar and it found another link. Unfortunately, on that page I found this:

    Download Windows Vista 34-bit (x86) Recovery Disc
    Edit: Sadly we received a DMCA Takedown request for this and can no longer provide download mirrors. Sorry about that.

    Any other suggestions for the Recovery download?
    Thank you
     
    Last edited by a moderator: Sep 21, 2014
  11. Luvss2ride

    Luvss2ride Private E-2

    Hopefully this isn't a repeat. I sent a reply, but I don't see it posted (and I don't remember seeing the 'warning' that it needs to be reviewed).
    The link for the vista recovery download no longer works. I tried to search for another, but it doesn't seem available anymore.
    I did find this information from the HP website... should I try to use this instead?


    https://www.raymond.cc/blog/how-to-burn-downloaded-windows-vista-to-dvd/
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I apologise. Very old link.


    Please download aswMBR.exe ( 511KB ) to your desktop.

    Double click the aswMBR.exe to run it.

    [​IMG]

    Click the "Scan" button to start scan

    [​IMG]

    On completion of the scan click [FixMBR].
    Note: You may have to [Scan] first in order for this button to appear.

    ----------------

    Now re run TDSSKiller and attach log.
     
  13. Luvss2ride

    Luvss2ride Private E-2

    Ran aswMBR.exe the first time it shut computer off worked the second time
     

    Attached Files:

    Last edited by a moderator: Sep 21, 2014
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    How are things running now? :)
     
  15. Luvss2ride

    Luvss2ride Private E-2

    I'm going to bake a cake in your honor! You are da chit! {happy dance} :wave

    My husband was the one home earlier today and followed your last instructions. I hadn't been on the computer to see for myself.

    First thing I checked was Microsoft Essentials. And there was noooooo Alureon.J!!
    Then I checked Windows mail to be sure it was running ok.
    Then checked a couple websites and everything seems to be running just dandy!

    So, the only thing I found odd ... was when I turned the computer back on just before it finished booting up, all the icons on the desktop turned white - and then they turned back to normal. And after I thought it was done booting up, the screen flashed, but only for a second.
    And, it's still booting up pretty slow. Can I stop some of the programs from start up now? :)
     
    Last edited by a moderator: Sep 22, 2014
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    This might help increase performance upon start up. (Not topic for the malware forum really)

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe" -delete
    • O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
    • O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
    • O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
    • O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
    • O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    • O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
    • O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    • O4 - HKLM\..\Run: [PivotSoftware] "C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe"
    • O4 - HKLM\..\Run: [Philips Device Listener] "C:\Program Files\Philips\Philips Songbird Resources\Autolauncher\PhilipsDeviceListener.exe"
    • O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
    • O4 - HKLM\..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide
    • O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
    • O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    • O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
    • O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
    • O4 - HKLM\..\Run: [EKStatusMonitor] C:\PROGRAM FILES\KODAK\AIO\STATUSMONITOR\EKStatusMonitor.EXE
    • O4 - HKLM\..\Run: [EasyHomeDecorating_73 Browser Plugin Loader] C:\PROGRA~1\EASYHO~2\bar\1.bin\73brmon.exe
    • O4 - HKLM\..\Run: [EasyHomeDecorating Search Scope Monitor] "C:\PROGRA~1\EASYHO~2\bar\1.bin\73srchmn.exe" /m=2 /w /h
    • O4 - HKLM\..\Run: [DT HPW] C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe -HPW
    • O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    • O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    • O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    • O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    • O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    • O4 - HKCU\..\Run: [HP Deskjet 3510 series (NET)] "C:\Program Files\HP\HP Deskjet 3510 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN26812JZQ05R7:NW" -scfn "HP Deskjet 3510 series (NET)" -AutoStart 1
    • O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
    • O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\StartRegistryBooster.exe
    • O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    • O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
    • O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
    • O4 - HKCU\..\Run: [HPADVISOR] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
    • O4 - HKCU\..\Run: [Google Update] "C:\Users\Jerry\AppData\Local\Google\Update\GoogleUpdate.exe" /c
    • O4 - Startup: Dropbox.lnk = AppData\Roaming\Dropbox\bin\Dropbox.exe
    • O4 - Startup: Socialbox.lnk = C:\Program Files\Socialbox\Socialbox.exe
    • O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    • O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
    • O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    • O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    • O4 - Global Startup: Snapfish Media Detector.lnk = C:\Program Files\Snapfish Picture Mover\SnapfishMediaDetector.exe
    After clicking Fix exit HJT.

    Any better?
     
  17. Luvss2ride

    Luvss2ride Private E-2

    I am sorry the start up question turned the topic off malware ... but not super sorry .... because it starts like lightening now!!
    :-D:):p

    I can't thank you enough, Kestrel13!, for the time you spent and your help! I was sure, before I found this website, that I would have to clean out the HD and start over.
    {bowing in your greatness} :cool
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Glad to hear it's running so well. ;)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  19. Luvss2ride

    Luvss2ride Private E-2


    All complete ... per your instructions.

    Again ... I thank you so much!!
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome L2R! :)
     
  21. Luvss2ride

    Luvss2ride Private E-2


    Kestrel .... if I purchase the full version of Malwarebytes .... will it run together with the Microsoft Essentials?
    Or should I just use the simplified freeware and scan now and then?
     
  22. Luvss2ride

    Luvss2ride Private E-2

    Computer was having issues again this morning.
    Booted up just fine but then some programs either wouldnt load or took forever.
    I only had time to run M . essentials and malwarebytes.
    ME didn't find anything.
    MB disappeared while running so i had to reopen it. It found 10 PUPs that i told it to quarantine.
    I'll look further when i get home tonight.
    Only wanted you to know I think something else is wrong...
    I'm sorry to be a nuisance. ...
    :-/
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    There shouldn't be any issues using the combo of MBAM Pro and MSSE.

    Just re run Malware Bytes again and if it still finda anything have it remove it and then attach the log.
     
  24. Luvss2ride

    Luvss2ride Private E-2


    1. I turned off UAC (I'd always had it off prior to this). I think it was a big part of the problem of computer locking up / being slow.

    2. I'm also going through my programs and uninstalling some of the junk I don't use anymore (yahoo messenger, for one).

    3. I ran Malware Bytes again and attached the log. It found the same things that it found this morning (I wonder if I didn't click the right thing to clean it out this morning). More of that stupid toolbar crud (that sneaks in on me now and then from updating adobe and java) :-/

    4. Internet Explorer wasn't working at all this morning. It's working now, although still acting kinda slow. It's my favorite of the 3, but I can use Firefox and Chrome ...if I have to ... lol

    I'm really sorry to keep bothering you ... I truly appreciate your time!!
    :wave
     

    Attached Files:

  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Malware Bytes log shows junk it found but you did not have it remove it by the looks! :) Remove what it finds....rescan AGAIN, and attach that log too please.
     
  26. Luvss2ride

    Luvss2ride Private E-2

    I haven't purchased the full version of Malware Bytes yet ... the only options I have when it finds stuff is:

    quaranine
    add exclusion
    ignore once

    So I quarantine all and then it says:
    Finished cleaning items! View log for more details

    This morning, however, I decided to look at the "history" tab. And that tab gives me an option to "delete" all the quarantined items. So, I've done that.

    I'll do another scan tonight and see if that did the trick. Unfortunately, I don't have time this morning .... busy busy busy ... lol

    thank you! :)
     

    Attached Files:

  27. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, that log is clear, if the next log is too then it looks like all is well. ;)
     
  28. Luvss2ride

    Luvss2ride Private E-2

    Good morning,
    So, MalwareBytes found the same 10 entries this morning. I did a little research and found most of those (if not all) were from

    Mindspark (The Mindspark Toolbar it’s technically not a virus, but it does exhibit plenty of malicious traits, such as rootkit capabilities to hook deep into the operating system, browser hijacking, and in general just interfering with the user experience. The industry generally refers to it as a “PUP,” or potentially unwanted program)

    I ran HitmanPro and JRT again. And then MalwareBytes 2 more times.
    I've attached MalwareBytes log from the last run this morning. (It didn't find anything at all on the last run).

    I still think that stupid Mindspark is lingering somewhere in the machine. But, I'll purchase the full MalwareBytes (if you think it's worth it) and use it along with MSE (unless you prefer another antivirus?)

    Thank you, Kestrel13!
     

    Attached Files:

  29. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Does this folder exist? C:\Users\Jerry\AppData\LocalLow\EasyHomeDecorating_73

    If JRT and Malware Bytes no longer detect these problems then I think it would be safe to say they are not on the machine or lingering.
     
  30. Luvss2ride

    Luvss2ride Private E-2

    I don't see it... and all this nonsense because I downloaded something when I was sleepy.... lol

    Lesson learned : never, ever download anything when you're sleepy
    :-D

    Thank you, Kestrel13!
     
  31. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Most welcome. ;) Safe surfing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds