Can't Run Any Anti-malware Applications

Discussion in 'Malware Help (A Specialist Will Reply)' started by keeferj2, Jan 26, 2018.

  1. keeferj2

    keeferj2 Private First Class

    I downloaded Acrobat Reader DC a couple of days ago and started to experience a lot of issues with slowness, missing text and the like. When I opened a PDF I'd get a few pop up screens saying the application couldn't run. I'd click ok and another would pop up, behind the pop up the PDF had already opened.

    I'm running windows 10 Home Version 1709 Build 16229.192. I ran a quick scan using Norton Security and found nothing. I then ran a full scan, and after a day and an half, it scanned a 1,658,000 files, I finally cancelled it and rebooted the computer. Upon reboot, I tried to run Malwarebyte from the system try. It ran in the background and said I had malware that need to be cleaned. It said to open the Malwarebyte app to take action. When I tried it wouldn't open at all. I uninstalled and reinstalled (ran as administrator) and it still wouldn't open. I rebooted and began the Malware removal process in this forum. I tried to run adware and although it showed the home screen it would close immediately. I checked to see if it were running in the background and there was nothing in Processes of the Task Manager and no log files in C:/Adware.

    I'm a bit perplexed. Any suggestions would help.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's see if we can figure out what is going on with this. We need this to run and create a log. If it is stopping at about 80%, it is a sign of a new MBR infection going around. So let's make sure you are doing it right. ;)
    • Download TDSSKiller from Kaspersky directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7,8 and 10, do not double click on it but rather, right click and select Run As Administrartor. )
    • If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123tdk.com).
    http://forums.majorgeeks.com/chaslang/images/TDSSkiller/tds1.jpg
    • Click on Run to allow the application to run properly.
    • If you see any popup warnings from your antivirus or firewall about it trying to access the nework or similar, make sure that you allow it to run/have access.
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    You will then see the below window
    http://forums.majorgeeks.com/chaslang/images/TDSSkiller/tds2.jpg
    • Click on the Start scan button to begin the scan and wait for it to finish. When it finishes, you will see a window similar to below accept you may have one indicating infections were found.
    http://forums.majorgeeks.com/chaslang/images/TDSSkiller/tds3.jpg
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should already be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
    • Reboot and the infection should hopefully be removed.
    TDSSkiller - How to run
     
  3. keeferj2

    keeferj2 Private First Class

    It reported no threats found. Here is the log.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  5. keeferj2

    keeferj2 Private First Class

    Do I need to rename this one as well?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Shouldn't be necessary.
     
  7. keeferj2

    keeferj2 Private First Class

    After Extracting the file and worming my way through the folders I have several files that are executable. Which one should I use? Mbam-Chameleon.com, MBam-Chameleon.exe, Mbam-Killer.exe. There are several firefox executables as well.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That one.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry....once extracted. the application one. It should open a command prompt. Follow the instructions.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Screen shot:

    MBAM .jpg
     
  11. keeferj2

    keeferj2 Private First Class

    So I initially started it and when the DOS box opened it also gave a pop up saying a new version of Malwarebtyes Anti Malware is ready to be installed. Install now? I clicked yes. Afterwards I was getting the same result. I went to the windows menu and opened the chameleon again. It started and after reading the instruction. I choice choice 1. The same box opened. As I was trying to decide to click yes or no on the install now, the text scrolled. It said a reboot is recommended to remove temporary directory (path name) then done. It updated Mban then started a scan. It finished a scan opened malware bytes and said press any key to close the dos box. When I did the malwarebyte app closed too. Tried to reopen it and it still won’t open.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download and run Emsisoft Emergency Kit.
    Double click EmergencyKitScanner.exe to install EEK
    When the installation of EEK is complete the Emergency Kit scanner will run.
    NOTE: Make sure to enable PUPs detection.
    Click "Yes" to Update Emsisoft Emergency Kit
    Under "Scan" click-on "Malware Scan".
    IMPORTANT: Do not quarantine or delete anything. We just want the scan log without anything being quarantined or deleted.
    Save the scan log somewhere that you can find it (desktop).
    Exit Emsisoft Emergency Kit.
    Attach the log.
     
  13. keeferj2

    keeferj2 Private First Class

    I'm uploading eek log and I was able to get Rogue Killer to run, I'm uploading that log as well. No action was taken on either.
     

    Attached Files:

    • eek.txt
      File size:
      1.7 KB
      Views:
      1
    • RK.txt
      File size:
      5.7 KB
      Views:
      1
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Okay....some progress. Rerun RogueKiller and have it remove these items;
    ¤¤¤ Processes : 2 ¤¤¤
    [Proc.Injected|Proc.RunPE] regsvr32.exe(11048) -- C:\Windows\SysWOW64\regsvr32.exe[-] -> Found
    [Proc.Injected|Proc.RunPE] regsvr32.exe(10180) -- C:\Windows\SysWOW64\regsvr32.exe[-] -> Found

    ¤¤¤ Tasks : 1 ¤¤¤
    [Hj.Shortcut] \{3946AFE1-4DB0-4D85-990E-A30C1A50ED38} -- "c:\program files (x86)\google\chrome\application\chrome.exe" (http://ui.skype.com/ui/0/7.2.0.103/en/abandoninstall?page=tsProgressBar) -> Found
    ¤¤¤ Files : 1 ¤¤¤
    [VT.Unknown][File] C:\Users\jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\klodbo.lnk [LNK@] C:\Users\jon\AppData\Local\Egsazlo\EGSYGI~1.BJY -> Found

    Reboot and rescan with RogueKiller, and try to also run ADWCleaner, MBAM and Hitman.
     
  15. keeferj2

    keeferj2 Private First Class

    When I ran the scan the [VT.Unknown][File] C:\Users\jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\klodbo.lnk [LNK@] C:\Users\jon\AppData\Local\Egsazlo\EGSYGI~1.BJY wasn't listed. I removed the first three. I rebooted the computer and ran the scan again. This morning I saw that the scan from RK had the two processes still listed. I removed them and rebooted. Then realized I should have reported it to you first and then remove them when told. Sorry. I'm just waking up.

    I tried to run AdwClean but after a long wait, a pop up said I didn't have permissions. (I ran it as an administrator). I was able to open Hitman. MBAM still didn't run.
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download the latest version of FRST the below link.
    Farbar Recovery Scan Tool and save it to your Desktop.
    Note: Make sure you download the proper version ( 32 bit or 64 bit ) for your PC. Only one will run, the correct one. So it you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  17. keeferj2

    keeferj2 Private First Class

    When I click on the link, it closes the browser. I reopen Edge and it closes immediately. I do it three time and a new window open with the Start Fresh screen option. I can open this tab but when I click on the tab for the FRST, it forces Edge to close. I can see the download page for FRST for just a second.
     
  18. keeferj2

    keeferj2 Private First Class

    Same thing with CHROME
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please do the below so that we can boot to System Recovery Options to run a scan. There will be two options to choose from.
    For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive. You must download to a clean computer!!

    Plug the flashdrive into the infected PC before you boot up!!

    Option1: Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    Option2: Enter System Recovery Options by using Windows installation disc:
    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  20. keeferj2

    keeferj2 Private First Class

    Whew!! Finally got it to boot to the options.
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)
    Now boot into normal Windows can continue with the below.

    Please download Zemana Malware Removal to your desktop and run it please.
    It auto updates, and you click scan. After it's finished, click on the icon that looks like Cell phone strength bars. High-light the report (by date log was produced) and click on the "Open Report" icon. (looks like a folder). That notepad.txt can then be copied/pasted into another .txt doc and saved. Upload that, please.
     

    Attached Files:

  22. keeferj2

    keeferj2 Private First Class

    I was able to run the FRST and have attached the Fixlog.txt. The ZAM finally finished.
     

    Attached Files:

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download ZHPCleanerto your desktop.
    Close all applications (including your web browsers and antivirus)
    Double-click on ZHPCleaner to run the tool.
    If you are using Windows Vista, 7/8/10; instead of double-clicking, right-mouse click ZHPCleaner and select "Run as Administrator".
    Please click the "J'accepte/I agree" button.
    First press the "Scanner" button. Be patient, the scan may take some time.
    Do NOT fix/repair anything yet! Please upload that logfile also with your next reply.

    Then please run MGTools.exe and attach the MGLogs.zip.
     
  24. keeferj2

    keeferj2 Private First Class

    While running ZHP an error popped up. “Line 100167 (file ‘c:/users/jon/desktop/zhpcleaner.exe’)

    Error: array variable gas incorrect number of subscriptions or subscript dimensions range exceeded “

    Only option is OK which closes the app
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Hummmm ......right click start/run and type in msconfig. When it opens, click on the startup tab and give me a screen shot, please.
     
  26. keeferj2

    keeferj2 Private First Class

    Reinstalled the ZHP by accident (clicked the wrong file to restart the scan) and it worked fine. Here are the logs.
     

    Attached Files:

  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Where did you download QuickTime from?
     
  28. keeferj2

    keeferj2 Private First Class

    Don't know. It was years ago. Most of the time I down load from the vendor or CNET Download.
     
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, I am not sure if it maybe corrupt, but please use Revo to uninstall it, reboot and rerun ZHP again. I am not finding any thing in your MGLogs.

    But these are suspect in ZHP ( so remove them first):
    FOUND folder: C:\Users\jon\AppData\Roaming\HMYGSetting =>Adware.Suspect
    FOUND file: C:\Users\jon\AppData\Roaming\HMYGSetting\SEIgnore.db =>Adware.Suspect
    FOUND key: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\adobe-reader.en.softonic.com [] =>.SUP.Softonic
    FOUND key: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\akamaihd.net [] =>.SUP.AkamaiHD
    FOUND key: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\en.softonic.com [] =>.SUP.Softonic
    FOUND key: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\softonic.com [] =>.SUP.Softonic
    FOUND key: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\uhytajrtpo-a.akamaihd.net [] =>.SUP.AkamaiHD
    FOUND key: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\adobe-reader.en.softonic.com [386] =>.SUP.Softonic
    FOUND key: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\akamaihd.net [] =>.SUP.AkamaiHD
    FOUND key: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\en.softonic.com [474] =>.SUP.Softonic
    FOUND key: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\slimware.com [847] =>.SUP.SlimWareUtilities
    FOUND key: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\softonic.com [] =>.SUP.Softonic
    FOUND key: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\uhytajrtpo-a.akamaihd.net [] =>.SUP.AkamaiHD
    FOUND key: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\ask.com [] =>Toolbar.Ask
     
  30. keeferj2

    keeferj2 Private First Class

    What is Revo?
     
  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  32. keeferj2

    keeferj2 Private First Class

    I may have screwed up here. I ran the ZHP scan and tried to remove the items listed. The folder had three check but only 1 was on the list. I unchecked the other two. I clicked on the Key button to look for all the keys. I looked for the file listed in your response but couldn't find it. I noticed that the unchecked boxes were rechecked when I went back to the Folder section. I assumed the Repair had to be run for key section. I unchecked the Two files that were not listed and hit repair. It reran the scan and reported no issues. I rebooted and reran the scan and it still said no issues. Hopefully it didn't cause too many issues for diagnosing this.
     

    Attached Files:

  33. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem. Tell me how things are running now. What issues remain, if any?
     
  34. keeferj2

    keeferj2 Private First Class

    Well, I can no longer do a search in Outlook. My Microphone has stopped working. I disabled it and reenabled it with no change. They were both working before this started. The AntiMalware software is able to run now. I can start to do the process Malware removal process if you wish.
     
  35. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please do. Your other issues may just be with Windows. We shall see.
     
  36. keeferj2

    keeferj2 Private First Class

    MGTools to follow
     

    Attached Files:

  37. keeferj2

    keeferj2 Private First Class

    All Files have been run. I still see a few issues listed but only added the reports when told to in the instructions.
     

    Attached Files:

  38. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just remove what ADW found. Otherwise your logs are clean. Any issues remaining should be addressed in the software forum. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Re-enable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8 or 10, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 or 10 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     
  39. keeferj2

    keeferj2 Private First Class

    Super!! I truly appreciate the tenacious effort on your part. That's a lot of hours working with me. Thank you so much. I'm still having the Outlook issues but everything else appears to be running fine. I'll take this to the software forum. Again, Thank you .
     
  40. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are very welcome. Good luck. :)
     
    keeferj2 likes this.
  41. keeferj2

    keeferj2 Private First Class

    As a follow up note. The search problem from Outlook turned out to be a known issue with their last update. There was a workaround and it now functions.

    The microphone had a spontaneous healing late last night. I'd like to say I did something but nope, it just started to work again. Got to love the logic of computer at times. Thank again.
     
  42. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    LOL.....you're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds