VOPackage.exe and other

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by davidm_uk, Jan 23, 2015.

  1. davidm_uk

    davidm_uk Private E-2

    Just installed PSPad from here http://www.pspad.com/en/
    and despite declining the optional extras that the installer offered I've ended up with two programs I'm suspicious of, listed at today's date in Contol Panel - Programs and Features:

    Remote Desktop Access (VuuPC), Published by CMI Limited, Version 1.0.0.0
    Spyware and Virus Blocker [8086], no publisher or version.

    There's also a new folder on the Start - Programs menu called "VO Package", with one entry, "Configure" which links to VOPackage.exe /deploy

    (and no, I've not run that, just looked at the link)

    I've not seen any problems yet, only used Chrome browser to Google VOPackage.exe and lots of hits, most suggesting things to download and run - but I don't really trust them, hence coming here first.

    Chrome seems ok, opening a new instance of it doesn't reveal any problems, I have the AdBlock addin installed.

    Running W7 64bit (with Jan 2015 updates), Avast Free (anti virus only), Win firewall, no other AV or firewalls and no Disk emulation software. Avast hasn't flagged any problems yet.

    I've read the READ ME FIRST post, but not yet tried to run or clean anything in case that causes a problem. Thought it best to ask first.

    Should I be worried, if so what next?
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. :) Yes go ahead and run the procedures, sounds like you've ended up with some adware.
     
  3. davidm_uk

    davidm_uk Private E-2

    OK, I've run through the whole cleaning process:

    RogueKiller: run as soon as I open the program, freezes at 40% complete while analyzing atkexComSvc.exe, waited 3hrs, no activity (mouse, kb, clock frozen, no disk activity). Had to power off to get out of it. Tried a second time, same result. No log file.

    Malwarebytes: runs ok, items quarantined, Log file attached.

    TDSSKiller: run ok, no threats found. Log file attached.

    HitmanPro: run ok, no threats found. Log file attached.

    MGTools: run ok, no probelms reported. Log file attached.

    The offending entries have now gone from the Start - Programs list, however in Control Panel - Programs and Features I still have the entry for Spyware & Virus blocker [8086] with yesterday's date.

    I've not tried removing it, checking back here first.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hello, I've been out for the day...checking logs now and will write up a response.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman Pro and have it remove all that it finds...

    Also do this to take care of the garbage still insralled...

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Re run Hitman Pro and attach new log.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running!
     
  6. davidm_uk

    davidm_uk Private E-2

    HitmanPro: no threats detected, deleted all items marked as "delete" (had to register for trial license to do this), system restore point created by HitmanPro, and rebooted following deleting of items.

    Success message received re adding registry keys.

    Re run HitmanPro: nothing found, new log attached.

    MGtools\GetLogs.bat: new log attached as MGLogs 2.zip

    The Spyware and Virus Blocker [8068] item has now gone from the Control Panel - Programs and Features list. So far everything seems to be running OK although I've not by any means checked every program that I have installed. I'll post back again if I find anything.

    Thanks very much for your help and time Kestrel13!
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Excellent. The logs look good! :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds