Can't install Malwarebytes think i might be infected.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Khole, Sep 25, 2014.

  1. Khole

    Khole Private E-2

    Every time i try to install malware bytes i get this error: Internal error: Expression error ' runtime error ( at 79:177 ) External exeption E06D763.

    I've tried clean install. I cleared all my programs folders and such of any malware byte remnants. Still no luck. Any help would be appreciated.

    Attached files below.
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

  3. Khole

    Khole Private E-2

    After i did all those scans recleaned my files even hidden ones that had malware bytes still left over i restart and got it to install. After installed it ran fine.

    If there is any scans i should do to check let me kno other wise you can close this thread and say its solved.

    I can post the malware scan log now if you want.
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hi!

    There are a few things to do and was about to post a fix. Please go ahead and attach the MalwareBytes' log.

    dr.m
     
  5. Khole

    Khole Private E-2

    This should be the right logs. Let me know if it isn't.

    To answer your earlier question i did use the malwareclean.exe to remove my software.
     

    Attached Files:

    Last edited: Sep 25, 2014
  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    NOTES: Looks like you also picked up something unwanted from using P2P online file sharing.
    AND you need to rerun MalwareBytes' and atleast quarantine those PUPs.

    Using "Programs and Features" uninstall this outdated software.
    Java 7 Update 67

    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Files
    C:\Users\Mustain\AppData\Roaming\Azureus\plugins\aznettor\AzureusTor.exe
    C:\Users\Mustain\AppData\Roaming\Azureus
    C:\Users\Mustain\Documents\Soukou_Kijo\LBK-30027\program files\lilith\SKI_dl\SKI_dl.exe
    C:\Users\Mustain\Documents\Soukou_Kijo\LBK-30027\program files\lilith
    C:\Users\Mustain\Documents\Vuze Downloads\[Fuwanovel] Yandere\YANDERE.eXe
    C:\Users\Mustain\Documents\Vuze Downloads\[Fuwanovel] Yandere
    C:\Windows\TEMP\*.*
    C:\Users\Mustain\AppData\Local\Temp\*.*
    :Reg
    [-HKU\S-1-5-21-1097050232-1752783380-1331776974-1000_Classes\Wow6432Node\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}]
    [-HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550055345591}]
    [-HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660066346691}]
    [-HKLM\SOFTWARE\Classes\Record\{05660A04-00F1-3A04-AB3B-BC1074B84D67}]
    [-HKLM\SOFTWARE\Classes\Record\{37AC0F3B-749F-3B22-811B-5A019EED2E85}]
    [-HKLM\SOFTWARE\Classes\Record\{4392A6CC-7940-310E-8E16-799A8D93A438}]
    [-HKLM\SOFTWARE\Classes\Record\{66DF7821-ED6D-3534-893C-0E89E74B0F91}]
    [-HKLM\SOFTWARE\Classes\Record\{755CAFCC-F016-3B06-8F22-945EAA3AD10D}]
    [-HKLM\SOFTWARE\Classes\Record\{76552F88-640C-314D-82B6-0D8A740907F7}]
    [-HKLM\SOFTWARE\Classes\Record\{903F9872-E87F-3B74-83B0-DBE10073B29D}]
    [-HKLM\SOFTWARE\Classes\Record\{9558EEB4-CDA6-3778-B53B-98076F0A1E90}]
    [-HKLM\SOFTWARE\Classes\Record\{B25AA9BA-FD52-3E5E-BFE3-9B106779DA6E}]
    [-HKLM\SOFTWARE\Classes\Record\{C852CF9F-37DC-35AC-926A-7E6CFFF7C501}]
    [-HKLM\SOFTWARE\Classes\Record\{C9777796-4378-3C90-B52D-7238FFFC2A5C}]
    [-HKLM\SOFTWARE\Classes\Record\{DB1BC8B2-FDBF-30E7-BE1C-AFF9160059E6}]
    [-HKLM\SOFTWARE\Classes\Record\{F3D5729C-7DEB-3850-A026-D0E323ECFEF5}]
    [-HKLM\SOFTWARE\Classes\Record\{FEC70973-CB8B-351C-8047-CAE1274CE249}]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Browsersafeguard_RASAPI32]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Browsersafeguard_RASMANCS]
    [-HKU\S-1-5-21-1097050232-1752783380-1331776974-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975}]
    [-HKU\S-1-5-21-1097050232-1752783380-1331776974-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{98889811-442D-49DD-99D7-DC866BE87DBC}])
    [-HKU\S-1-5-21-1097050232-1752783380-1331776974-1000\Software\Microsoft\Internet Explorer\TabbedBrowsing\bProtectNewTabPageShow]
    [-HKU\S-1-5-21-1097050232-1752783380-1331776974-1000\Software\Microsoft\Internet Explorer\TabbedBrowsing\bProtectShowTabsWelcome]
    [-HKU\S-1-5-21-1097050232-1752783380-1331776974-1000_Classes\Wow6432Node\CLSID\{80922ee0-8a76-46ae-95d5-bd3c3fe0708d}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Make sure to shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now install the current version of Sun Java from:
    Make sure that when you install the new version of Java that you uncheck the Install the Ask Toolbar junkware checkbox. You do not want to add the stuff junk that most people consider malware to your PC. Also just in case Oracle changes the Java installation in the future to possible install other junk, uncheck all but just installing Java.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXT log
    • updated MalwareBytes' log.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. Khole

    Khole Private E-2

    I'm running malware anti again to quarantine those pups i'll do the otm after thats finished.
     
  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Sounds good. ;)
     
  9. Khole

    Khole Private E-2

    C:\Users\Mustain\Documents\Soukou_Kijo\LBK-30027\program files\lilith\SKI_dl\SKI_dl.exe
    C:\Users\Mustain\Documents\Soukou_Kijo\LBK-30027\program files\lilith

    These files are from a game i bought. How could they be malware?
     
  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    If you would look in the HitmanPro log, it's found listed under Malware. I only have logs that I review, but not software source information. *Your choice as to what cleaning you do, ultimately.
     
  11. Khole

    Khole Private E-2

    Not gonna ask for help and just do the opposite. A couple of bucks isn't worth potentially losing my whole computer. Just got done with otm on to jrt i'll post the logs after the last step with magic tool.
     
  12. Khole

    Khole Private E-2

    Heres everything except MGtools. I just have an exe on my desktop should i run that? Forget last i'm running it i'll post mgzip when its finished.
     

    Attached Files:

    Last edited: Sep 25, 2014
  13. Khole

    Khole Private E-2

    Here is the last file.
     

    Attached Files:

  14. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Your logs are clean.

    How is the machine running now?
     
  15. Khole

    Khole Private E-2

    Everythings running fine. No problem installing programs or uninstalling.

    Thanks for all your help :)
     
  16. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;) You're welcome!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, Win 7/8 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7/8, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work through the below link:
    Safe surfing! [​IMG]
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds