Freerides still standing firmly on my PC

Discussion in 'Malware Help (A Specialist Will Reply)' started by Wendy22, Mar 7, 2013.

  1. Wendy22

    Wendy22 Private E-2

    Ok I have finished all of the instructions here:




    Let me know if I messed up on the reports. Any help would be greatly appreciated. And if I can go ahead and run scans and "fix", let me know, ready to go over here to get Freerides out of my PC! :)

    Wendy
     
    Last edited by a moderator: Mar 8, 2013
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yea. Little bit... I'm going to need to delete all that as you posted it inline ;)
    You need to take a look at this.

    HOW TO: Attach Items To Your Post

    I need to be seeing attached logs from:

    • Malware Bytes
    • RogueKiller
    • Hitman Pro
    • MGTools
     
  3. Wendy22

    Wendy22 Private E-2

    Hello,

    Sorry about my incorrect huge log post last night! I have attached three of my logs, the third one said it was too big so I will try that one in a separate post.

    Thank you again :) and let me know if I have done anything incorrectly.
     

    Attached Files:

  4. Wendy22

    Wendy22 Private E-2

    This is the attachment I had trouble with. It may not open. If it does not, please let me know of a better way to save it so you can see it. Thanks again.

    Wendy
     

    Attached Files:

  5. Wendy22

    Wendy22 Private E-2

    Hi,

    Did I do my log attachments OK?

    Wendy
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes the attatchments are fine. If you were wondering why I hadn't replied until now, that's because i'm running on after having only 3 hours sleep last night, so catching up now.... ;)
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall the below:

    • Wajam
    • SpeedyPC Pro
    • ParetoLogic Privacy Controls
    • Coupon Companion Plugin

    Re run Hitman and have it delete Malware remnants and Potential Unwanted Programs.


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.searchcompletion.com/?si=10182&home=1
    • R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=fm...yByB0AtAtN0D0TzutBtDtCtBtDyCtCzz&cr=702692766
    • R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.searchcompletion.com/?si=10182&home=1
    • O2 - BHO: CrossriderApp0021804 - {11111111-1111-1111-1111-110211181104} - C:\Program Files (x86)\Coupon Companion Plugin\Coupon Companion Plugin.dll
    • O2 - BHO: Wajam IE BHO - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files (x86)\Wajam\IE\priam_bho.dll
    • O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    • O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    • O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
    • O23 - Service: WajamUpdater - Wajam - C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe

    After clicking Fix exit HJT.


    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    After reboot, check to see if your firewall is working.

    Delete these folders if they show:
    • C:\ProgramData\Free Ride Games
    • C:\ProgramData\AMMYY
    • C:\Program Files (x86)\Free Ride Games

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  8. Wendy22

    Wendy22 Private E-2

    Hey Kestrel13, glad the attachments were OK. Sorry you have only had a few hours of sleep (please do not extend yourself on my account btw, I'm not going anywhere and can wait until you are good to go - eat a burger, take a nap, watch a movie in your underwear, etc. LOL) I'll be in that same position this coming week, as I work in a busy IP law firm, and will have to file a ton of things by Friday, as the USPTO is raising their fees after that. So my life next week will be sitting at my work PC, with lots of Energy Drinks, Coffee, and perhaps the occasional 5 Hour Energy. :)

    Anyway, thank you ahead of time for reviewing my logs. Let me know if it is OK for me to go ahead and do fixes (Roguekiller and Hitman - Malwarebytes cannot find Freerides - even though it actually did, on a 2 hour Full Scan, land on it, and paused, but then moved on without detecting it). I really want to get rid of this Freerides as I am worried it eventually may steal my personal information.

    Many thanks ahead of time, and a virtual Latte :)

    Wendy
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, continue on and do follow my instructions. :)
     
  10. Wendy22

    Wendy22 Private E-2

    Done all of your instructions. Still it remains. I am a big unable to figure out how to do the last part of your instructions re MGtools, could not find that link.

    Here is what I just did:
    Deleted Wajam
    Deleted Speedy PC Pro
    Deleted Parent to Logic Privacy Controls (think I just deleted the whole thing)
    Deleted Coupon Companion plugin

    Ran Hitman under your instructions.

    Firewall I turned off but was up and running once I rebooted, and still it could not see Freerides, which still is on my desktop..
    Ran MGtools and restarted my PC.

    Effin thing is still there.

    PS- I will pay to have anyone here remotely try to get rid of this. Just sayin. It's like Christmas time and there is an evil mini elf in your stocking, and even when Christmas is over, it is still there, crawling around and scaring you.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Don't worry, we'll sort it, you need not pay for anything. ;)

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  12. Wendy22

    Wendy22 Private E-2

    Kestrel13! - Sorry I have taken so long to reply. This week is like a hell week at work with lots of OT. Anyway, I ran the Junkware Removal Tool and attached is the text log. After I ran it, I still noticed the freerides icon. Tried once again to uninstall it, but when I try my PC says it cannot find it. :(

    What should I do now at this point? This thing is determined to thwart everything that tries to get rid of it.
     

    Attached Files:

    • JRT.txt
      File size:
      5.7 KB
      Views:
      2
  13. Wendy22

    Wendy22 Private E-2

    Hmm, not sure if my quoted reply posted. So am re-posting as a regular reply!
     

    Attached Files:

    • JRT.txt
      File size:
      5.7 KB
      Views:
      0
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    My bad, i should have told you to do this a few posts back. Please try using Revo Uninstaller to unsinstall Free Ride Games Player. Let me know how you get on.
     
  15. Wendy22

    Wendy22 Private E-2

    Heya Kestrel13!

    OK, so, I downloaded Revo, it actually found Freerides Game Player (Yay), and I THINK it uninstalled it. But I still see the icon on my desktop, and a few games still remain on my desktop that may have come with it, like 7 Wonders, Cradle of Rome, etc.

    So do you think it is gone? When I rerun Revo only the above games are there, but Freerides is not there (I also rebooted). Mainly, the fact the icon is still there makes me wonder if it is truly gone or not. Let me know when you get a chance. No big hurries because I probably won't be able to check back in until tomorrow evening, maybe, depends. My work is very busy trying to make deadlines by Friday and I've been doing a lot of OT, and I get a whopping 2 hours once I get home before I have to go to bed. Be glad when this week is over! Be even happier when I am no longer free riding!

    Anyway, thanks again so much for all of your help! :)
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  17. Wendy22

    Wendy22 Private E-2

    Heya K,

    I am back and survived hell week at work, yay. I re-ran MG, check it out. I did get some error box in the middle of the scan, but it did not stop it, so I hope my scan is accurate. I hope this helps. And again, thank you very much for your help. :)
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Most welcome! :)

    Cradle of Rome and 7 wonders are still installed. ;) Rerun Revo and be rid of them.
     
  19. Wendy22

    Wendy22 Private E-2

    OK, I think I deleted all of the games that were attached to Freerides (3), BUT Freerides icon is still there. I'd like to take screenshot to show you, but no idea where it was saved. No more Accessories option that I used to use to use years ago to post screenshots. Anyway, really do not think Freerides is gone.

    And, when I was using Revo to uninstall, I got an error message in the middle of the scan that said "Missing Required Resource. Try to re-install EXE.extender.exe from your service provider's website". I got this error message every single time I tried to uninstall everything.

    I have never had to contact Cox for whatever it is talking about re that error popup box. Good golly I'm just tired of trying to get this off of my PC. It just seems all of mine (and your) efforts are not working completely. I cannot really afford to get a new PC right now (and my PC was bought in 2009, so not really that old. But I am contemplateing throwing in the towel and tossing it at this point. :(
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Don't give up, i'm compiling another fix.
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O4 - HKCU\..\Run: [Exetender] "C:\Program Files (x86)\Free Ride Games\GPlayer.exe" /runonstartup
    • O4 - HKUS\S-1-5-19\..\Run: [Exetender] "C:\Program Files (x86)\Free Ride Games\GPlayer.exe" /runonstartup (User 'LOCAL SERVICE')
    • O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    • O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    • O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
    After clicking Fix exit HJT.


    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    
    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "Exetender"=-
    [HKEY_USERS\S-1-5-21-480849465-2962989364-145090117-1000\Software\Microsoft\Windows\CurrentVersion\run]
    "Exetender"=-
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{110a9ea2-8810-4c04-b916-cfd4e9427fec}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{7FBFB352-70AB-4A70-8332-47369F2E0785}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9C80D49E-3699-45DC-A1B7-C2BFF1322162}]
    
    :files
    C:\ProgramData\Free Ride Games
    C:\Program Files (x86)\Free Ride Games
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  22. Wendy22

    Wendy22 Private E-2

    ok, Tried to do all here. I may be postintg tmi, but I hope this helps.:
     

    Attached Files:

  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Use MSCONFIG to be in NORMAL start up mode.


    We need to run an OTL Fix

    • Right-click OTL.exe And select " Run as administrator " to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code

    Code:
    :otl
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://search.searchcompletion.com/?si=10182&home=1
    FF - HKLM\Software\MozillaPlugins\@exent.com/npExentCtl,version=7.0.0.0: C:\Program Files (x86)\Free Ride Games\npExentCtl.dll (Exent Technologies Ltd.)
    FF - HKLM\Software\MozillaPlugins\www.exent.com/GameTreatWidget: C:\Program Files (x86)\Free Ride Games\NPGameTreatPlugin.dll File not found
    DRV - (X5XSEx_Pr143) -- C:\Program Files (x86)\Free Ride Games\X5XSEx_Pr143.sys (Exent Technologies Ltd.)
    @Alternate Data Stream - 5632 bytes -> C:\ProgramData:gs5sys
    @Alternate Data Stream - 4096 bytes -> C:\Users\Wendy\Desktop\desktop.ini:gs5sys
    @Alternate Data Stream - 3584 bytes -> C:\Users\Public\Documents\desktop.ini:gs5sys
    @Alternate Data Stream - 1536 bytes -> C:\Users\Wendy\Documents\desktop.ini:gs5sys
    @Alternate Data Stream - 1536 bytes -> C:\Users\Wendy\desktop.ini:gs5sys
    
    :files
    C:\ProgramData\Free Ride Games
    C:\Program Files (x86)\Free Ride Games
      
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.


    Run OTL normally now, just a scan like you did the first time and attach the new log.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
    Last edited: Mar 18, 2013
  24. Wendy22

    Wendy22 Private E-2

    I hope this helps
     
  25. Wendy22

    Wendy22 Private E-2

    Ok I tried to do what you said, but every time I tried to load the log, it said I already had dont it.. so would not let me re-upload it here.
     
  26. Wendy22

    Wendy22 Private E-2

    This website will not let me re-load new logs. :)
     
  27. Wendy22

    Wendy22 Private E-2

    And I cannot find All Programs - Accessories, on my pc (Windows Ultimate 7,which was put on my PC by another, no instructions given either.) I'd love to do a screenshot. I rebooted, and the icon i Still there.
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sigh.. this is stubborn. Re run OTL normally, just a scan and attach log.
     
  29. Wendy22

    Wendy22 Private E-2

    Yah, don't know, did all you said to do. Took hours. Had a few error messages:

    "SteelWerx WhoAmI application has stopped working"
    and
    "A problem caused the proram to stop wrking correctly. Windows wil close this proram and notifiy you of a soluton is available"4
    and
    Application ahs generated an exception that could not be handled = process id=013e8 (5096)thread ID- oxddo (3536)

    I will say Freerides is no longer an icon on my PC, which is so great, but it is still in my "All programs" program files.

    I feel progress is being made, but it is still not finished.

    Let me know if I am doing anything wrong,. I will say whan you said "do not copy the word" files what that exactly meant. I just copied and pasted all in your box. Perhaps that may have been en error on my part?
     

    Attached Files:

  30. Wendy22

    Wendy22 Private E-2

    This may be a repeat..
     

    Attached Files:

  31. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just delete them then.

    Still some signs of it, only a bit but let's do this:

    We are going to be uninstalling your old version of FireFox and installing the new version. So do the below to save bookmarks:

    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.
    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:
    • C:\Program Files (x86)\Mozilla Firefox
    • C:\users\UserAccount\AppData\Roaming\Mozilla\Firefox

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).

    Everything ok still?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds