Windows 8 Meh

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by livekarl, Oct 1, 2014.

  1. livekarl

    livekarl Private E-2

    Hi, Having a problem with what I think is a redirector bug of sorts, and went directly to the redirector page, and started with go to Java cache....so how come I can't find the java icon in control panel, Am I looking for love in all the wrong places. I didn't want to bother anybody till I ran through the steps I've been through before, but this is the first time with windows 8 ( I don't Like It yet) And I'm already stuck , Thank you kind Geeks for your help in this endeavor!:-o
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just skip that step and continue on. ;)
     
  3. livekarl

    livekarl Private E-2

    Thanks for your reply, I'm not sure if you got mine, so I did skip the java, can't find firefox and cleared IE cache now to what's driving me nuts is windows 8.1 I'm supposed to go to Start>run and then type, Well when I hit start I see no run dialogue box, and thats when I want to start throwing comp around. Is there a different Start menue I can set up? do I just keep skipping steps? Thank you for your time and energy.
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Attached Files:

  5. livekarl

    livekarl Private E-2

    Hello Again, I have include what logs I could, and now I am stumped, It'll be a day before I can get back to this computer, but I went to follow thw remove malware article /log, and there is no mention of windows 8 so I will await further instructions, and Yes I'm still being redirected every time I click on something it goes elsewhere, Thank you again for your help.
     
  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    No logs have been attached by you, and you should be following the link that I posted. (The title merely needs a edit)
     
  7. livekarl

    livekarl Private E-2

    I want to apologize, My job has kept me from working on the computer for the past week or so, I'm usually not home before Midnight and leave at 7 am so I am working on it now and will post logs and get started on cleaning /fixing this thing, Thanks for your patience.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem, I'll be floating around somewhere. ;)
     
  9. livekarl

    livekarl Private E-2

    Hello again, the attachment manager says the tds log is too large and that I have already attached the mg logs. I couldn't find the RK report so ran it again, If that screws things up I apologize. The redirector was working full force, in Google but has not interrupted me in IE, trying to get me to download Java then MacAfee, then some live tech help mostly Java though. Don't know why the TDS file is so large (470kbs), This all I have at the moment Thank you again for your help!!
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What happened to the MGlogs.zip? I need to see that too please.
     
  11. livekarl

    livekarl Private E-2

    Hello , Each time I try to upload it says I have already attached to this thread and then says possible Trojan? suggestions? Thank You,
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to run MGTools.exe again and attach the new MGLogs.zip that it will produce.
     
  13. livekarl

    livekarl Private E-2

    Hi, I keep getting the same message this file already posted to this thread, possible Trojan, I'll try again.
     
  14. livekarl

    livekarl Private E-2

    Looks like it worked this time. thanks for your patience!!:)
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The Malware Bytes log is not showing you took action on what it found. Please rescan with it, if it finds anything let it remove it, and attach the new log for me to see.


    Uninstall the below using Revo Uninstaller.

    • AnyProtect
    • Optimizer Pro v3.2
    • ShoopupaeerMaSTer
    • suaaveuitKeep.




    Download and run OTM.


    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.
    Code:
    :Files
    C:\Users\Kaileigh Blessing\Downloads\flv_installer.exe
    C:\WINDOWS\system32\drivers\{8ac13c32-b1f4-495e-8b0b-4bd4fd38c6b5}Gw64.sys
    C:\WINDOWS\system32\drivers\{e9629596-2cbd-4eea-9329-7470e8b0fdae}Gw64.sys
    C:\Program Files (x86)\Optimizer Pro
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2
    C:\Users\Karl\AppData\Roaming\Optimizer Pro
    C:\Users\Karl\Documents\Optimizer Pro
    C:\Windows\System32\Tasks\Optimizer Pro Schedule
    C:\Users\Karl\AppData\Local\nsc7932.tmp
    C:\Users\Karl\AppData\Roaming\aps.scan.quick.results
    C:\Users\Karl\AppData\Roaming\aps.scan.results
    C:\Users\Karl\AppData\Roaming\aps.uninstall.scan.results
    C:\ProgramData\edec8c2e545b7f48
    C:\ProgramData\Microsoft Help
    C:\ProgramData\Package Cache
    C:\ProgramData\ShoopupaeerMaSTer
    C:\ProgramData\suaaveuitKeep
    C:\Program Files (x86)\AnyProtectEx
    C:\WINDOWS\tasks\APSnotifierPP1.job
    C:\WINDOWS\tasks\APSnotifierPP2.job
    C:\WINDOWS\tasks\APSnotifierPP3.job
    
    :reg
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{1989B5DE-F9B7-4B95-AA6F-224D71D38826}]
    [-HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}]
    [-HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}]
    [-HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Optimizer Pro Schedule]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1]
    [-HKLM\SOFTWARE\Wow6432Node\{1146AC44-2F03-4431-B4FD-889BC837521F}]
    [-HKLM\SOFTWARE\Wow6432Node\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}]
    [-HKLM\SOFTWARE\Wow6432Node\{6791A2F3-FC80-475C-A002-C014AF797E9C}]
    [-HKU\.DEFAULT\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}]
    [-HKU\S-1-5-18\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}]
    [-HKU\S-1-5-21-436145245-980046301-1230193741-1001\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}]
    [-HKU\S-1-5-21-436145245-980046301-1230193741-1001\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com]
    [-HKU\S-1-5-21-436145245-980046301-1230193741-1001\Software\Microsoft\Internet Explorer\SearchScopes\{05B1BF1C-D6EB-4ECA-A7E9-363249F06023}]
    [-HKU\S-1-5-21-436145245-980046301-1230193741-1001\Software\Optimizer Pro]
    [-HKU\S-1-5-21-436145245-980046301-1230193741-1004\Software\Microsoft\Internet Explorer\SearchScopes\{102B9889-ED1A-4867-8B30-2BCA67E9E3FB}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{cca2e567-1987-4100-a3c6-5b4267084510}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{05B1BF1C-D6EB-4ECA-A7E9-363249F06023}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.




    Follow the instructions below to reset Chrome to defaults...

    Reset Google Chrome to defaults



    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Now re run Hitman (just a scan) and attach log.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now! And don't forget the log from Malware Bytes.
     
  16. livekarl

    livekarl Private E-2

    Hi, I am having the devil's own time with the malwarebytes log. The attachment manager keeps rejecting saying I have uploaded the file already. The last scan showed no threats, the one prior to that had threats and I quarantined according to instructions, I have a done a file search for malwarebyteslog.txt and have only come up with the Oct 12 scan. and two references to shortcuts, that point to the same log.. I will follow your instructions today, now that I have a few moments to sit in front of this darn machine., Thank you again for your help and time.
     
  17. livekarl

    livekarl Private E-2

    Hello again, I ran the malwarebytes and hopefully got the right log. but no threats were found so no action taken. Thank you again.
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, continue on with the rest of the instructions. :)
     
  19. livekarl

    livekarl Private E-2

    Hello Kestrel13!, Two things, First is when I used revo it only found one of the programs you indicated for removal "Any Protect" I switched to IObit uninstaller it found evidence of three other programs that revo did not but indicated they were not installed. lastly, the JRT tool seems stuck on chrome for the last hour and a half, is this normal?Thanks Again
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run JRT in safe mode. :)
     
  21. livekarl

    livekarl Private E-2

    Hello Again, please be patient with me. I have no idea how to get to safe mode with win8.1, Thanks
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  23. livekarl

    livekarl Private E-2

    I have not yet gone into chrome or opened it. I would like to know can you identify the source of the infection and how I can best avoid this happening in the future, is my anti virus program good enough? Should I switch my firewall, Etc. Thank you for all your help, and your patience, you are wise beyond your years.
     

    Attached Files:

  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Take time to carefully uninstall this below list of garbage, you already have Revo Uninstaller, use that, and do let me know if you have any issues!!
    • LLuckyCoupOn
    • LTCM Client
    • ShoopupaeerMaSTer
    • suaaveuitKeep.



    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.
    Code:
    :Files
    C:\ProgramData\PC Drivers HeadQuarters
    C:\ProgramData\PicRec
    C:\ProgramData\ProductData
    C:\ProgramData\UAB
    C:\Program Files (x86)\PC Drivers HeadQuarters
    C:\Program Files (x86)\PicRec (x86)
    C:\Windows\System32\Tasks\Optimizer Pro Schedule
    
    :reg
    [-HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}]
    [-HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Optimizer Pro Schedule]
    [-HKU\S-1-5-21-436145245-980046301-1230193741-1004\Software\Microsoft\Internet Explorer\SearchScopes\{102B9889-ED1A-4867-8B30-2BCA67E9E3FB}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{1989B5DE-F9B7-4B95-AA6F-224D71D38826}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{cca2e567-1987-4100-a3c6-5b4267084510}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.




    I believe you will have to go into each of the following accounts now and reset Google Chrome to defaults.

    • Kaileigh Blessing
    • Karl
    • Kitty Blessing

    Instructions on how to do so are here: Reset Google Chrome to defaults


    Did you forget to attach the JRT log? :confused


    Now that you have reset Chrome on each of those accounts, from your own account (as we have been doing all along) re run Hitman Pro and attach log.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running!
     
  25. livekarl

    livekarl Private E-2

    Hi, I'm not finished yet with instructions but I was only able to find LTCM client and remove it, Revo does not show the other garbage being present. Neither does iobit uninstaller. Should I try windows add and remove? Thank you.
     
  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If Revo does not show those programs then try basic add/remove yes. If that fails, let me know...
     
  27. livekarl

    livekarl Private E-2

    Greetings Wise One, While I was home this AM I tried revo, IO bits uninstaller and add/remove. only the one LTCM client, Showed up and I uninstalled it. suaaveuitKeep. Showed up in IObits but said it was not installed, so I couldn't do anything with it, is there another way to run revo,I ran as administrator, Thank You again.
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, there is another way. But for now, just continue on with other instructions and skip that step. ;)
     
  29. livekarl

    livekarl Private E-2

    Greetings again, Nothing comes easy, was unable to access Kitty's Chrome cause I don't have her password( I don't think she knows it either), but she always uses my screen, I've attached, I think, everything, haven't actually tried to use google yet. this also affected( Infected) IE, but has been quiescent for a while. Here's to you, Let 'er rip. Thanks again!
     

    Attached Files:

  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to uninstall and reinstall Google Chrome (using Revo) on the accounts you can access please.


    Delete this if it shows:
    C:\Windows\System32\Tasks\Optimizer Pro Schedule

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Re run Hitman Pro again and attach log.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  31. livekarl

    livekarl Private E-2

    Hokay, So it was successful, with the regedit, IObit poped up and said there was some shoop.... leftover, and the logs are posted as per your instructions. Things are definitely better, completely fixed I dunno . I suspect you'll let me know, and once again I thank thee!
     

    Attached Files:

  32. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Where? At what location? Can a log from Iobit be attached?

    Okay, I think it didn't work because you need to be in the Kaileigh Blessing account to follow these instructions.


    Delete this:
    • C:\Windows\System32\Tasks\Optimizer Pro Schedule


    How do you feel about going into the Windows Registry, again staying on the Kaileigh Blessing account, and deleting these manualy yourself? Let me know if not.

    • HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
    • HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Optimizer Pro Schedule
    • HKU\S-1-5-21-436145245-980046301-1230193741-1004\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
    • HKU\S-1-5-21-436145245-980046301-1230193741-1004\Software\Microsoft\Internet Explorer\SearchScopes\{102B9889-ED1A-4867-8B30-2BCA67E9E3FB}

    Now unfortunately to fully put Google Chrome back, you will need to uninstall all of these (using Revo) on each of the accounts on this machine:

    • Google Chrome
    • Google Drive
    • Google Update Helper

    Now rescan with Hitman before you reinstall Google Chrome.

    Attach log.
     
  33. livekarl

    livekarl Private E-2

    OK Optimizer pro....has been deleted from Kaileigh's acct, should I go into Karl and look for it there. I have no idea how to go into registry, MY brother( an IT guy) always told me not to play with the dirty registry. but if you're willing to give me more instructions. I'll give it a try. I'm going to follow the rest of your instructions, I could not get a log from IOBit. Thanks again Oh sage one.
     
  34. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, might as well check all accounts for uninstallables.

    With the Windows Registry, you would just click start > type regedit
    Regedit.exe will pop up, right click it and run it.
    It's just a case of navigating to the bolded items I listed, using the Registry much like Windows Explorer.
     
  35. livekarl

    livekarl Private E-2

    The operation was unable to start correctly (0xc0000142) ? uh now what?
     
  36. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I'm sorry...what? What were you trying to do at the time when you got that message? :confused
     
  37. livekarl

    livekarl Private E-2

    Hi, been a long week sorry haven't got back to you all week, I was trying to get into regedit. wrong file /program, I can get in now, though I cannot find the entries you have listed, does it matter if I enter the registry through Kaileigh, or Karl, and are there any tricks to finding these lines I need to remove? Thanks again
     
  38. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I did say Kaileigh. ;)

    No tricks, it's just navigating through a folder like structure until you get to what I want you to remove, much like following a file path to find a file or foder.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds