![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Can't uninstall programs. Getting CoCreate Instance Failed when I try to install MalwareBytes. Outlook can't get online mail. Script error when trying to open Outlook Today window. Was able to download RogueKiller here is the RK text attached as instructed. Thanks for any help in advance.
|
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
Welcome to Major Geeks!
In order for us to properly determine if you are having malware problems, we need the other 4 logs requested in the READ & RUN ME FIRST procedure. Please attach logs from the below: Malwarebytes Hitman Pro TDSSkiller MGtools
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#3
|
|||
|
|||
|
Thanks for the reply. Here are the Hitman Pro, TDSSkiller, MGtools logs. Am not able to install, nor run MalwareBytes. I changed the exe name and tried loading it from the root drive, but get a run time error "372" failed to load control "Web Browser" from ieframe.dll when I click on the exe file. thanks
|
|
#4
|
||||
|
||||
|
Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.
Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now: O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O3 - Toolbar: (no name) - {4322A444-92F8-4C3E-BD4C-013BA51E2871} - (no file) O4 - Global Startup: Driver performer.lnk = C:\Documents and Settings\Administrator\Local Settings\Temp\7ZipSfx.000\dp.exe O9 - Extra button: (no name) - {6ED0A312-78F5-493C-A90C-5DAF321D0BF8} - C:\Documents and Settings\All Users\Application Data\WeCareReminder\IEMenuItem.dll (HKCU) O9 - Extra 'Tools' menuitem: We-Care Add-on - {6ED0A312-78F5-493C-A90C-5DAF321D0BF8} - C:\Documents and Settings\All Users\Application Data\WeCareReminder\IEMenuItem.dll (HKCU) O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - O23 - Service: BasicSeek Service - Unknown owner - C:\Program Files\BasicSeek\basicseek.exe After clicking Fix, exit HJT. Uninstall the below software: BasicSeek 1.0 build 111 CWA Reminder by We-Care.com v4.1.21.3 Java(TM) 6 Update 37 Now install the current version of Sun Java from: Sun Java Runtime Environment Please download OTM by Old Timer and save it to your Desktop.
Code:
:Processes
explorer.exe
:Services
BasicSeek Service
:Files
C:\Program Files\BasicSeek\basicseek.dll
C:\Program Files\BasicSeek
C:\Documents and Settings\Administrator\Local Settings\Application Data\Wajam
C:\Documents and Settings\Administrator\Local Settings\Application Data\Wajam
C:\Documents and Settings\All Users\Application Data\BasicSeek
C:\Documents and Settings\All Users\Application Data\WeCareReminder
C:\Documents and Settings\Administrator\Local Settings\Temp\*.*
:Reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=-
[HKEY_USERS\S-1-5-21-2052111302-2147143089-725345543-500\Software\Microsoft\Windows\CurrentVersion\run]
"MSMSGS"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BasicSeek]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{4322A444-92F8-4C3E-BD4C-013BA51E2871}"=-
[-HKEY_USERS\S-1-5-21-2052111302-2147143089-725345543-500\Software\Crossrider\215AppVerifier]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{80922ee0-8a76-46ae-95d5-bd3c3fe0708d}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp]
[-HKEY_USERS\S-1-5-21-2052111302-2147143089-725345543-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}]
[-HKEY_USERS\S-1-5-21-2052111302-2147143089-725345543-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{793FD0DF-FA0F-4094-AE25-4D1196A98CFD}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{F42D4712-298F-4502-8668-7B9940C3FB00}]
:Commands
[purity]
[EmptyTemp]
[start explorer]
[Reboot]
saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message. Now please download Junkware Removal Tool to your desktop.
Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#5
|
|||
|
|||
|
Thank you chaslang, I successfully did everything you suggested up until the uninstall of CWA Reminder by We-Care.com v4.1.21.3 and Java(TM) 6 Update 37. Error message says "Windows Installer Service cannot be accessed." Should I continue the procedures anyway?
|
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
Yes. Continue anyway. Are you in normal boot mode ( i.e, not safe boot mode) ?
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#7
|
|||
|
|||
|
Yes I'm in normal boot mode. I will continue and report back, thanks
|
|
#8
|
|||
|
|||
|
Also wasn't able to install SJRE. Same message "Windows Installer Service cannot be accessed" OTM asked if I wanted to reboot as you said so I selected yes but nothing happened and I had to restart manually.
Attached is the OTM log. |
|
#9
|
||||
|
||||
|
Okay continue on with the rest of my instructions.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#10
|
|||
|
|||
|
Here you go. thanks for your time.
|
| Sponsored links |
|
|
|
#11
|
||||
|
||||
|
How are things running now?
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#12
|
|||
|
|||
|
No change or improvement
Can't load software from the internet including MS updates (Internal Error code Service Pack did not load) and Internet Explorer 8 (Hangs at the download stage) Can't open helpctr.exe, notepad, search or MS word Can't uninstall programs especially the programs you asked me to remove previously. Unable to receive or send emails through Outlook (when I tested the connection with my internet provider the test was successful yet nothing comes into Outlook or leaves) Any other ideas? Again, I appreciate your attention. |
|
#13
|
||||
|
||||
|
It does not look like there issues you are mentioning are related to malware. We only found some miscellaneous adware/junkware to remove. These may be issues that you will have to work in the Software Forum, but let's try a couple of fix tools first.
Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on. Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
Did the above help? If not, I suggest that you check out the below to see if it can help with any of your problems. http://support.microsoft.com/fixit/
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#14
|
|||
|
|||
|
Chaslang, I can't thank you enough for all this help. The culprit was that CWA We-Care.com program. It was so attached to my system. It was finally removed by Revo Uninstaller. Removed Java update also. I was able to restore my mail delivery in Outlook. Thanks to your Windows Repair I have downloaded Windows Updates and IE. Some programs still don't load from the Start Menu and Outlook Today start screen is not loading due to a script error, but I'm grateful you got me this far. Why didn't Verizon Internet Security Suite catch these damaging files and how can I keep this from happening again? Thanks again
|
|
#15
|
||||
|
||||
|
You're welcome.
Quote:
You and any other people using the PC need to be more vigilent in how you use the PC. Where you surf! What you download? What you install? Read license agreements in detail and don't just click OK on eveything without reading what you are getting. This and more is touched on the link in the below final instructions. If you are not having any other malware problems, it is time to do our final steps:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| Sponsored links |
|
|
|
#16
|
|||
|
|||
|
chaslang, thanks for the tough love advice and your help at restoration. Lessons learned.
|
|
#17
|
|||
|
|||
|
Chaslang, as one final action I was finally able to run Malwarebytes Anti-malware. For some reason the paperclip icon isn't working and I am not able to attach this file so I'll just post it here, Thanks again!
Malwarebytes Anti-Malware (Trial) 1.70.0.1100 www.malwarebytes.org Database version: v2013.01.04.06 Windows XP Service Pack 3 x86 NTFS (Safe Mode/Networking) Internet Explorer 8.0.6001.18702 Administrator :: USER-6E2D366951 [administrator] Protection: Disabled 1/4/2013 10:57:19 AM MBAM-log-2013-01-04 (11-36-06).txt Scan type: Full scan (C:\|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 256086 Time elapsed: 32 minute(s), 51 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 1 HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\qword.com (Adware.QWO) -> No action taken. Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 3 HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Search Page (Hijack.Homepage) -> Bad: (http://www.qword.com/?s=1) Good: (http://www.Google.com/) -> No action taken. HKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken. HKLM\SOFTWARE\Microsoft\Security Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken. Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) |
|
#18
|
||||
|
||||
|
No real problems there. I saw the qword items earlier in your logs and left them because I figured you chose to use it. It is not really an problem unless you did not set them. In that case, just have Malwarebytes fix them.
The items showing (PUM.Disabled.SecurityCenter) are not problems at all. They are just changes from Windows defaults which for most people is always different then Windows defaults.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#19
|
|||
|
|||
|
Never heard of qword.com until I saw this. Will remove. Thanks again!!
|
|
#20
|
||||
|
||||
|
You're welcome. Surf safely!
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| Sponsored links |
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Suspected malware(im new to this, please help) | eggbap | Malware Removal | 15 | 10-04-12 16:50 |
| Suspected Malware | fizz190 | Malware Removal | 2 | 10-01-12 22:58 |
| Suspected Malware???? | Farbro | Software | 2 | 07-02-09 08:51 |
| Suspected Malware? | stone773 | Malware Removal | 9 | 04-14-07 14:39 |
| Malware suspected please help! | cooldegri | Malware Removal | 1 | 08-10-06 23:42 |