![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Hi,
There was something preventing programs from opening on my Dad's laptop, Live security platinum was installed and regwork I think. Those were the most recent ones, and I figure there were other malware. I couldn't access anything, so I booted in safe mode, and uninstalled Live security platinum and regwork. Then I restarted in normal mode and ran all the programs. I'm getting a red shield with an X (Windows Security center) on the taskbar icons with a balloon popup that says "The Security Center Service is not running". I tried turning it on, and it says "The security center can't be started". I've attached the logs, I thank you for your help in advance. |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
There was nothing of major significance in your logs. Just MyWebSearch adware. Let's try a few things.
First a question. Did you install the below? Cupid ToolBar CupidChat (beta) 0.4.1 Uninstall the below ( yes I'm asking for AVG to be uninstalled as it could be impacting security center ): Ask Toolbar AVG 2012 Java(TM) 6 Update 31 Java(TM) SE Runtime Environment 6 After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry. Quote:
to the registry. If you do not get a success message, it definitely did not work. Please download OTM by Old Timer and save it to your Desktop.
Code:
:Processes explorer.exe :Files C:\WINDOWS\Temp\TMP000000695D07C0CBB1D98035 C:\WINDOWS\Temp\TMP0000003EE18EC6FEADAEE1F3 C:\Users\Alex\AppData\Local\Temp\91b47cfce271ba2f.exe C:\Users\Alex\AppData\Local\Temp\CRX_75DAF8CB7768 C:\Users\Alex\AppData\Local\Temp\nslB1D1.tmp C:\Users\Alex\AppData\Local\Temp\V.class :Commands [purity] [EmptyTemp] [start explorer] [Reboot]
saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message. Now install the current version of Sun Java from: Sun Java Runtime Environment Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#3
|
|||
|
|||
|
Thanks for the response. Before I follow your instructions, I have to tell you that I ran windows repair as per these instructions:
"Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop. Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator) Now select the Start Repairs tab. The click the Start button. Create a System Restore point if prompted. On the next screen, click the Unselect All button to first deselect all repairs. Now select the following repair options: Reset Registry Permissions Reset File Permissions Register System Files Repair WMI Repair Windows Firewall Remove Policies Set By Infections Repair Winsock & DNS Cache Repair Proxy Settings Repair Windows Updates Set Windows Services To Default Startup Now on the lower right side check the box to Restart/Shutdown System When Finished Then make sure the Restart System radio button is enabled. Shutdown any other programs that you are running now before continuing. Now click the Start button. Be patient while the tool repairs the selected items. It should reboot automatically when finished." After this, the red shield was gone from the task bar. I also uninstalled avg12. Do I still have to follow your instructions or will they change now? And to answer your question, YES I installed "Cupid ToolBar & CupidChat (beta) 0.4.1. Thanks again for the help. |
|
#4
|
||||
|
||||
|
You're welcome.Yes and attach the new logs.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#5
|
|||
|
|||
|
Ok, I've followed your instructions, the only thing is the OTM report did not appear in Notepad after the reboot.
I've attached the logs. You guys are awesome by the way! |
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
You're welcome. Your logs are good now.
If you are not having any other malware problems, it is time to do our final steps:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#7
|
|||
|
|||
|
Thanks again! I really appreciated the help.
Cheers |
|
#8
|
||||
|
||||
|
You're welcome. Surf safely!
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Need Help Laptop still infected | Xnitro67 | Malware Removal | 4 | 07-18-12 14:17 |
| Is this laptop infected? | SEGA | Malware Removal | 5 | 05-24-12 03:23 |
| Infected laptop | rexer | Malware Removal | 5 | 12-15-08 14:19 |
| I think my laptop is still infected- can anyone help please? | EmA | Malware Removal | 6 | 05-07-08 15:11 |
| Infected laptop | daselko | Malware Removal | 1 | 01-16-06 00:43 |