Downloader.AUO

Discussion in 'Malware Help (A Specialist Will Reply)' started by gettinold, May 8, 2014.

  1. gettinold

    gettinold Private E-2

    Post continued from here

    I have Windows 7 Pro
    Service pac 1

    Acer Veriton L4806
    Intel (R) Core (TM)2 Duo CPU
    Ram 4 GB 64 Bit

    What else do I need to put here??

    followed instructions as stated in previous post Attaching log files

    TdsKiller Nothing found

    anything else I need to do here??

    Wendy
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did you mean here? ;)

    http://forums.majorgeeks.com/showthread.php?t=285645


    Uninstall the below softwares:




    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate this detection:

    • [RUN][SUSP PATH] HKUS\S-1-5-21-2043433075-1788664187-1490434350-500\[...]\Run : Updater (C:\ProgramData\Updater\updater.exe [x]) -> FOUND

    Place a checkmark next to this item, leave the others unchecked.
    Now press the Delete button.

    Now try and locate this entry too and have it removed:

    • ¤¤¤ Browser Addons : 2 ¤¤¤
    • [CHR][PUP] Default : Tube Dimmer

    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.








    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\ProgramData\ParetoLogic
    C:\ProgramData\cleanpc365
    C:\Program Files (x86)\Conduit
    C:\Program Files (x86)\sweetpacks bundle uninstaller
    C:\Users\Administrator\AppData\LocalLow\AskToolbar
    C:\Users\User\AppData\Local\Conduit
    C:\Users\User\AppData\LocalLow\Conduit
    C:\Users\User\Documents\Optimizer Pro
    
    :reg
    [-HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}]   
    [-HKLM\SOFTWARE\Classes\s]
    [-HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}]
    [-HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{3c471948-f874-49f5-b338-4f214a2ee0b1}]
    [-HKLM\SOFTWARE\Wow6432Node\Conduit]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\advisorletters_RASAPI32]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\advisorletters_RASMANCS]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AskPartnerCobrandingTool_RASAPI32]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AskPartnerCobrandingTool_RASMANCS]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\RegistryHelper_RASAPI32]
    [-HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\RegistryHelper_RASMANCS]
    [-HKLM\SOFTWARE\Wow6432Node\SweetIM]
    [-HKLM\SOFTWARE\Wow6432Node\{1146AC44-2F03-4431-B4FD-889BC837521F}]
    [-HKLM\SOFTWARE\Wow6432Node\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}]
    [-HKLM\SOFTWARE\Wow6432Node\{6791A2F3-FC80-475C-A002-C014AF797E9C}]
    [-HKLM\SYSTEM\ControlSet001\services\eventlog\Application\Registry Helper Service]
    [-HKLM\SYSTEM\ControlSet002\services\eventlog\Application\Registry Helper Service]
    [-HKLM\SYSTEM\CurrentControlSet\services\eventlog\Application\Registry Helper Service]
    [-HKU\.DEFAULT\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}]
    [-HKU\S-1-5-18\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}]
    [-HKU\S-1-5-21-2043433075-1788664187-1490434350-1000\Software\AppDataLow\Software\Conduit]
    [-HKU\S-1-5-21-2043433075-1788664187-1490434350-1000\Software\AppDataLow\Software\Smartbar]
    [-HKU\S-1-5-21-2043433075-1788664187-1490434350-1000\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}]
    [-HKU\S-1-5-21-2043433075-1788664187-1490434350-1000\Software\Conduit]
    [-HKU\S-1-5-21-2043433075-1788664187-1490434350-1000\Software\Condut]
    [-HKU\S-1-5-21-2043433075-1788664187-1490434350-1000\Software\IM]
    [-HKU\S-1-5-21-2043433075-1788664187-1490434350-1000\Software\Microsoft\Internet Explorer\SearchScopes\{1B4C5D4D-385C-4DEE-90F2-6D6FECDA94DA}]
    [-HKU\S-1-5-21-2043433075-1788664187-1490434350-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6E189067-2672-4C86-8FCE-7A4F5605AA8A}]
    [-HKU\S-1-5-21-2043433075-1788664187-1490434350-1000\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}]
    [-HKU\S-1-5-21-2043433075-1788664187-1490434350-1000\Software\SweetIM]
    [-HKU\S-1-5-21-2043433075-1788664187-1490434350-1000\Software\Tbccint_HKLM]
    [-HKU\S-1-5-21-2043433075-1788664187-1490434350-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "SpeedItupFree"=-
    "BackgroundContainerV2"=-
    "Updater"=-
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{1B4C5D4D-385C-4DEE-90F2-6D6FECDA94DA}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{6E189067-2672-4C86-8FCE-7A4F5605AA8A}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{6FA16628-8EEB-419C-A3CD-17843A1A3D7E}]
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    • Rerun Hitman Pro and attach the new log.
    • Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    • Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. gettinold

    gettinold Private E-2

    Kestrel

    I must be obtuse or losing I ran Rogue Killer as admin but can't locate any file or words that even come close to what you have listed

    Have Susp PAth Task %windir%\tasks AVG secure search -update_june 2013 etc

    Help
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just skip that step then. ;)
     
  5. gettinold

    gettinold Private E-2

    Attempted to download OTM AVG stopped it Said it was a virus

    Should shut down AVG

    Wendy
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, shut avg down please! :)
     
  7. gettinold

    gettinold Private E-2

    Ok Log file (me thinks) for OTM attached

    Moving to the next step
     

    Attached Files:

  8. gettinold

    gettinold Private E-2

    Attaching RTM log and Hitman

    What next ??

    Wendy
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You missed this step:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  10. gettinold

    gettinold Private E-2

    Attaching MGlogs

    Also would like to know if I can assistance with cleaning up my start up files
    Not sure about the right word When I turn my pc back on Notsure how to stop some files from loading

    How can I get programs to save where I want them. They always seem to go to user.

    Would like to get rid of the user altogether as I am the only one on this thing

    Wendy
     

    Attached Files:

    Last edited: May 9, 2014
  11. gettinold

    gettinold Private E-2

    Restarted and seems to running Ok now

    Wendy
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there Wendy.

    WiseConvert Toolbar
    <--- Uninstall this.
    Updater <--- I already asked you to uninstall this, it's still installed, did you have troubles? :confused
     
  13. gettinold

    gettinold Private E-2

    Not sure what kind of troubles I would run across or even what to look for. Deleted via Program removal

    done same way

    Can I remove all the log files from desktop?? Also have 2 desktop.ini files?? What are they Can I delete them as well



    Wendy
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did you uninstall them BEFORE I had you run the GetLogs.bat? Or just now after reading my post?

    Not yet!
    They are fine. they are showing because we have hidden files and folders set to show. ;)
     
  15. gettinold

    gettinold Private E-2

    No I ran everything first then deleted them Hope that was OK

    I still have the last log from Rogue killeer on my desktop The others are still in the Recycle bin

    This am I was printing diagrams and Windows Photo viewer locked up on me. Tried CTRL ALT DEL and ended up with this message

    Failure to display security & shut down options

    Clicked for more information

    Got this

    Logon process unable to display security and logon options When CTRL ALT DEL was pressed If operation system does not respond hit
    ESC or restart pc by using power switch.

    Had to use Esc Not problem with it after that

    As my grandson would say What happened??

    Wendy
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do this so I can get a fresh take on things:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  17. gettinold

    gettinold Private E-2

    Attached the file as requested
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I would like for you to use MSConfig to put this machine back into normal start up mode.

    Tell me what malware issues remain.
     
  19. gettinold

    gettinold Private E-2

    Thought I was Checking now Guess I was wrong Rebooting now then will continue

    Thanks wasn't even aware I was in selective mode

    Wendy
     
  20. gettinold

    gettinold Private E-2

    Ok log file for Malware

    Scanned in Normal start up

    Wendy
     

    Attached Files:

  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Shows no action taken. Did you let MBAM fix what it found?
     
  22. gettinold

    gettinold Private E-2

    No I did not delete anything

    Had loads of Pup extensions or files in it with lots of red WRong file I guess

    Will redo the scan again as I can't locate the one I did

    Wendy
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK. Have it fix what it found and then please explain what malware issues remain.
     
  24. gettinold

    gettinold Private E-2

    Try this again file attached

    Me thinks it is the same as before

    Although It has alot of Red highlites all starting with pup optional

    Wendy
     

    Attached Files:

  25. gettinold

    gettinold Private E-2

    did that so rebooting Will back on line later this afternoon Maybe

    Long weekend and am packing to go away

    Wendy
     
  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK so I'll hear back from you after the weekend?
     
  27. gettinold

    gettinold Private E-2

    Back for now

    MBAM log file attached

    Also attached MGlog

    I had a hotmail account at one time How do I prevent that from loading Have Corel Central as well but never use it How do I prevent it from loading when I reboot

    No idea what is needed in msconfig and what I can prevent from loading

    Wendy
     

    Attached Files:

  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to let Malware Bytes fix what it finds. (It's saying no action taken)

    Now please explain what issues remain that we can deal with here in the malware removal forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds