help removing webroot secureanywhere

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by dkk, Dec 29, 2012.

  1. dkk

    dkk Private E-2

    i cannot remove webroot secureanywhere. it is being extremely resistant to removal, i have uninstalled via add remove programs, searched for webroot files on my computer found nothing, but it always starts up with windows 7,64x, and causes my keyboard to malfunction.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    This should be done in the software forum really, however... follow these instructions. Using MGtools Now attach the resulting MGlogs.zip.
     
  3. dkk

    dkk Private E-2

    i thought it was malware, but it isn't? i went through the whole malware removal guide
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No, it's not malware.


    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\Windows\SysWOW64\setup16.exe
    C:\Windows\SysWOW64\sho81DB.tmp
    C:\Windows\SysWOW64\shoB8FF.tmp
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Webroot SecureAnywhere
    C:\Program Files\Webroot
    
    :services
    WRSVC
    
    :reg
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\windows\currentVersion\Run]
    "WRSVC"=-
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{079E3917-A757-46AD-87F9-7B149C240B12}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Better now? :)
     
  5. dkk

    dkk Private E-2

    It worked after I ran OTM pasted and rebooted. V pleased thank you. Where do I post about an infection in my google chrome browser? Several random words on all webpages are turned into links which give rollover ads for winning an iphone 5. Doesnt happen in Internet Explorer. It was there before and after I ran the malware removal guide in full no steps skipped or disobeyed.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That'd be here. ;)

    Uninstall Google Chrome with Revo Uninstaller.

    Now reinstall and see if it's any better.
     
  7. dkk

    dkk Private E-2

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just go for a LESS thorough/aggressive uninstall. Should still remove enough. ;)
     
  9. dkk

    dkk Private E-2

    so what do i do with the screen i posted pics of?
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Nothing. Just rerun revo and uninstall in a less agressive way as suggested. :) If you do not feel comfortable with this, just uninstall it normally ;)
     
  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, dkk

    You should select each bold typed leftover item (those are Chrome related) by left-clicking in the box next to it, then clicking the Delete radio button... then the Next button when prompted.

    * You can also left-click any of those items that have a + in the box if you want to look at the expanded subkeys.

    dr.m
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds