can't get rid of ins_shopperpro.exe

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jbtalk2me, Feb 16, 2015.

  1. jbtalk2me

    jbtalk2me Private E-2

    I have Kaspersky AV-2015 legal copy running on windows 7 pro.

    Yesterday I opened an exe for a program (after scanning it) and my pc went nuts! My av started alerting me every few seconds... 24 hours later after several scans with kaspersky, running Malwarebytes premium and then coming here to run the "read me first" malware removal thread actions I'm still getting alerts like this:

    C:\Users\Johns\AppData\Local\Temp\Install_189\ins_shopperpro.exe

    Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item.

    Also Kaspersky and Malwarebytes keep alerting/blocking/removing instances of this damn ins_shopperpro.exe. Apparently I have a serious issue and could use some help.

    In the attached files I have included all the requested logs as directed EXCEPT the Malwarebytes log. I have included a zip file for the malwarebytes logs including the logs from my scans/quarantined (then deleted) files before I started the majorgeeks malware removal thread.

    Thanks in advance for any help you can offer!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I will check your logs and get back to you. Hang in there. ;)
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun RogueKiller and have it fix these items:
    Code:
    ¤¤¤ Tasks : 2 ¤¤¤
    [Suspicious.Path] \\Installer_shopperpro -- C:\Users\Johns\AppData\Local\Installer\Installshopperpro_1301\DCytdieamo_amodc_setup.exe (/S /SCHEDULE /MAG=AMODC /pn=shopperpro /pixGuid=464a5ecc-630b-4dd3-98be-9d83b95eb6ee /sub=8699 /Reason=Version) -> Found
    [Suspicious.Path] \\Inst_Rep -- C:\Users\Johns\AppData\Local\Installer\Install_26318\DCytdieamo_amodc_setup.exe (/S /REPORT /NUM=10 /AFF=amodcI08699_0_0_0_0,464a5ecc-630b-4dd3-98be-9d83b95eb6ee,/S /SCHEDULE /MAG=AMODC /pn=shopperpro /pixGuid=464a5ecc-630b-4dd3-98be-9d83b95eb6ee /sub=8699 /Reason=Version) -> Found
    Download OTM by Old Timer and save it to your Desktop.


    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Paste the following code under the [​IMG] area. Do not include the word Code.


    Code:
    :Processes
    explorer.exe
    
    :files
    C:\Windows\system32\tasks\Installer_shopperpro
    C:\Users\Johns\AppData\Local\Temp\*.*
    
    :Commands
    [purity]
    [ResetHosts]
    [emptytemp]
    [start explorer]
    [Reboot]

    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.


    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.

    Reboot and rescan with RogueKiller and attach the new log.

    Be sure to tell me how things are running now.
     
  4. jbtalk2me

    jbtalk2me Private E-2

    Thanks for your help.

    This is what happened when I followed your instructions.

    First I had my Kaspersky enabled after running RK the first time. Disabled it while running MGTools the first time (only time so far), then enabled it after. During this time it tried to fix things a few times. I think it is interfering with the clean up, so I have it off (disabled now and will keep it off until you say otherwise.

    So when I ran RK as per your instructions, it did not find anything under task, so i could not have it fix them so I just saved the log for you. I continued to run OTM and have attached the log. The ran RK again and attached that log.

    I'm still infected though because it tripped Kaspersky's alerts after doing this but before I disabled it. I may have to run all scans again for you, but as of now I'm waiting for your response and will do nothing. Kaspersky is still disabled so I'm doing nothing until I get your response, just watching my inbox and this thread for a reply.
     
    Last edited: Feb 16, 2015
  5. jbtalk2me

    jbtalk2me Private E-2

    Is there a limit on attachment per thread? My files did not attach.
     
  6. jbtalk2me

    jbtalk2me Private E-2

    Sorry, wasn't uploading attachments properly. Here they are.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download SystemLook from one of the links below appropriate for your operating system and save it to your Desktop.
    Download 32 Bit

    Download 64 Bit

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :folderfind
      shopperpro
      :Filefind
      shopperpro
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  8. jbtalk2me

    jbtalk2me Private E-2

    I've run system look and attached the log, it found nothing.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Paste the following code under the [​IMG] area. Do not include the word Code.


    Code:
    :Processes
    explorer.exe
    
    :files
    C:\Program Files\Common Files\ShopperPro    
    C:\Program Files (x86)\ShopperPro
    C:\Users\Public\Documents\ShopperPro
    
    :Commands
    [purity]
    [ResetHosts]
    [emptytemp]
    [start explorer]
    [Reboot]

    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.


    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.
     
  10. jbtalk2me

    jbtalk2me Private E-2

    Ran OTM. It asked to reboot so I could not copy items under the green bar. I suppose those are in the log. The log is attached.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That should have done it. What issues remain, if any?
     
  12. jbtalk2me

    jbtalk2me Private E-2

    Don't know. I'll restart kaspersky and monitor it. Thanks for your help.
     
  13. jbtalk2me

    jbtalk2me Private E-2

    Should I or can I delete those _OTM files?
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, but if all is running fine, I will give you the final clean up procedures.
     
  15. jbtalk2me

    jbtalk2me Private E-2

    It's all running good.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds