Can't get rid of unwanted programme

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by paxo26, Jul 20, 2013.

  1. paxo26

    paxo26 Private E-2

    Can someone please help me! I have somehow acquired delta search, I also constantly get Mcafee popping up saying that a potentially unwanted programme has been blocked but it won't remove it, just constantly pops up. Mt PC is alot slower and I get a message from time to time saying that a programme tried to change my web browser. HELP!!!!!!!!!!!!
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to the Malware Removal Forum.

    Please read ALL of this message including the notes before doing anything.

    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. paxo26

    paxo26 Private E-2

    Hi Kestrel,
    I've attached the requested logs for you to look at, I have now somehow managed to acquire AVG search and can't get my web browser back to google chrome!
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you also attach the Mglogs.zip fromr running MGTools.exe please? Thanks. :)
     
  5. paxo26

    paxo26 Private E-2

    Sorry, I got a message on screen saying mglogs.zip failed to be created
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run the C:\MGtools\ReZip.batfile by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator), then look in the C:\MGtools folder for a slightly different zip file named MGlogsR.zip Attach it to your next message.
     
  7. paxo26

    paxo26 Private E-2

    Attached as requested
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall BrowserDefender

    Rerun Hitman and have it delete Potential Unwanted Programs.

    Delete this folder if it shows: C:\Users\Metin\AppData\Roaming\BABSOL~1 - Let me know!

    Re run RogueKiller and attach the new log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  9. paxo26

    paxo26 Private E-2

    Hi, it didn't appear to work. I went to the browser defender uninstall file and double clicked it which didn't seem to do anything, I also ran it as administrator which also did not appear to do anything.

    I re ran hitman which didn't give an option to delete any threats, I've re run RK and MG tools. The Mg tools report failed.

    The other file C:\Users\Metin\AppData\Roaming\BABSOL~1 wasn't present
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Use Revo to uninstall Browser Defender.


    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.

    Code:
    :Files
    C:\Users\Metin\AppData\Roaming\BABSOL~1
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document into a text file and attach it here in your next post.


    Now rescan with RogueKiller and attach the resulting log.

    Please run the C:\MGtools\ReZip.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator), then look in the C:\MGtools folder for a slightly different zip file named MGlogsR.zip Attach it to your next message.
     
  11. paxo26

    paxo26 Private E-2

    And here are the requested logs.....that was an effort!

    OTM log:

    All processes killed
    ========== FILES ==========
    C:\Users\Metin\AppData\Roaming\BabSolution\Shared folder moved successfully.
    C:\Users\Metin\AppData\Roaming\BabSolution\CR folder moved successfully.
    C:\Users\Metin\AppData\Roaming\BabSolution folder moved successfully.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Children
    ->Temp folder emptied: 439799 bytes
    ->Temporary Internet Files folder emptied: 178701374 bytes
    ->Java cache emptied: 0 bytes
    ->Google Chrome cache emptied: 350298869 bytes
    ->Flash cache emptied: 1290 bytes

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Metin
    ->Temp folder emptied: 57922280 bytes
    ->Temporary Internet Files folder emptied: 14754849 bytes
    ->Java cache emptied: 0 bytes
    ->Google Chrome cache emptied: 109862992 bytes
    ->Flash cache emptied: 843 bytes

    User: Public

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 5562188 bytes
    %systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 128 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 128 bytes
    RecycleBin emptied: 5702588 bytes

    Total Files Cleaned = 690.00 mb


    OTM by OldTimer - Version 3.1.21.0 log created on 07242013_180221

    Files moved on Reboot...
    C:\Users\Metin\AppData\Local\Temp\FireFly(201307241745265E4).log moved successfully.
    C:\Users\Metin\AppData\Local\Temp\integratedoffice.exe_c2ruidll(201307241745265E4).log moved successfully.
    C:\Users\Metin\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
    File move failed. C:\windows\temp\avg_secure_search.log scheduled to be moved on reboot.
    C:\windows\temp\FireFly(201307222130351288).log moved successfully.
    C:\windows\temp\integratedoffice.exe_c2ruidll(201307222130351288).log moved successfully.
    C:\windows\temp\integratedoffice.exe_streamserver(201307222130351288).log moved successfully.
    File move failed. C:\windows\temp\ood_stream.x86.en-us.dat scheduled to be moved on reboot.
    File move failed. C:\windows\temp\ood_stream.x86.x-none.dat scheduled to be moved on reboot.
    C:\windows\temp\winstore.log moved successfully.
    C:\windows\SysWow64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
    C:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.

    Registry entries deleted on Reboot...
     

    Attached Files:

    Last edited: Jul 24, 2013
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\OApps\SelectionLinks.dll (file missing)
    O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\OApps\SelectionLinks.dll (file missing)
    O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\OApps\SelectionLinks.dll (file missing)
    O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\OApps\SelectionLinks.dll (file missing)
    O20 - AppInit_DLLs: c:\progra~3\browse~1\261339~1.144\{c16c1~1\browse~1.dll
    O23 - Service: BrowserDefendert - Unknown owner - C:\ProgramData\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe
    O23 - Service: vToolbarUpdater15.3.0 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe


    After clicking Fix, exit HJT.


    Now uninstall the below programs:
    AVG SafeGuard toolbar
    BrowserDefender
    Delta Chrome Toolbar
    SparkTrust PC Cleaner Plus



    [*]Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    btdna.exe
    SUPERAntiSpyware.exe
    
    :Services
    ToolbarUpdater15.3.0
    BrowserDefendert
     
    :Files
    parkTrust PC Cleaner Plus.lnk
    C:\ProgramData\AVG SafeGuard toolbar
    C:\ProgramData\Babylon
    C:\ProgramData\BrowserDefender
    C:\ProgramData\SparkTrust
    C:\Program Files (x86)\AVG SafeGuard toolbar
    C:\Program Files (x86)\OApps
    C:\Program Files (x86)\SparkTrust
    C:\Program Files (x86)\Common Files\AVG Secure Search
    C:\Program Files (x86)\Common Files\SparkTrust
    C:\Users\Metin\Desktop\SparkTrust PC Cleaner Plus.lnk
    C:\Users\Metin\AppData\Roaming\BabSolution
    C:\Users\Metin\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data
    C:\Users\Metin\AppData\Local\Google\Chrome\User Data\Default\bProtectorPreferences
    C:\Users\Metin\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde
    C:\Users\Metin\AppData\LocalLow\Delta
    C:\Windows\System32\Tasks\EPUpdater
    C:\windows\tasks\SparkTrust PC Cleaner Plus.job
    C:\windows\tasks\SparkTrust Registration3.job
    C:\windows\tasks\SparkTrust Update Version3 Startup Task.job
    C:\windows\tasks\SparkTrust Update Version3.job
    C:\Users\Metin\AppData\Local\Temp\*.*
    
    
    :Reg
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\windows\currentVersion\Run]
    "QuickTime Task"=-
    "vProt"=-
    
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=""
    
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Prod.cap]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\s\ (Softonic)
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\DataMngr]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Delta Chrome Toolbar]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}]
    [-HKEY_USERS\S-1-5-21-2435600038-1866410919-1957774061-1001\Software\DataMngr]
    [-HKEY_USERS\S-1-5-21-2435600038-1866410919-1957774061-1001\Software\DataMngr_Toolbar]
    [-HKEY_USERS\S-1-5-21-2435600038-1866410919-1957774061-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975}]
    [-HKEY_USERS\S-1-5-21-2435600038-1866410919-1957774061-1001\Software\Microsoft\Internet Explorer\Main\bProtector Start Page]
    [-HKEY_USERS\S-1-5-21-2435600038-1866410919-1957774061-1001\Software\Microsoft\Internet Explorer\SearchScopes\bProtectorDefaultScope]
    [-HKEY_USERS\S-1-5-21-2435600038-1866410919-1957774061-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}]
    [-HKEY_USERS\S-1-5-21-2435600038-1866410919-1957774061-1001\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now please download Junkware Removal Tool to your desktop.

    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.txtlog
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  13. paxo26

    paxo26 Private E-2

    requested logs are attached, i'll use the laptop to check how it is operating.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds