ilivid toolbar and other toolbars

Discussion in 'Malware Help (A Specialist Will Reply)' started by thai_american_42, Jul 27, 2013.

  1. thai_american_42

    thai_american_42 Corporal

    On July 21st, I downloaded some free software. Spybot search and destroy then found 4 to 5 malicious toolbars installed. I tried to delete them (not using Major Geek's procedure), including running AdwCleaner. I also deleted some start up items, thinking they were part of the problem. Spybot eventually ran and produced a clean search report.

    One of the toolbars was ilivid toolbar, but I don't recall the name of the others. My computer still is running odd, so I don't think I actually got all the malware. Also, my start up takes much longer, so I probably messed up my start up as well. I'm able to start up, but it is not as it was before the July 21st incident.

    I went through the READ & RUN ME FIRST Malware Removal Guide and attached the logs. Some note:

    TDSSKiller - when I began to run TDSSKiller it gave a warning "Can't initialize log" and a warning "can't load driver." TDSSKiller did not find anything and did not produce a log for me to attach.

    HitmanPro - HitmanPro did not enter its "Force Breach" mode and instead read "Trial license expired. Removal of viruses and other malicious software is disabled. Buy Now."

    MGTools - I could not locate a MGLogs.zip file. I found a MGlogsR.zip file and attached that.

    Please review the attachments and let me know what to do next.

    Thanks!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. You can rerun Hitman and have it remove those PUPs.

    Any other issues should probably be addressed in the software forum.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix
      (This uninstall will only work as written if you
      installed ComboFix on your Desktop like we requested.)

      • Click START then RUN and enter the below into the run box and then click OK.

        Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows
          defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and
      deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any
      others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the
      C:\MGtools\enableUAC.reg
      file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file
      to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush
        your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:



    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  3. thai_american_42

    thai_american_42 Corporal

    Thanks for the reply.

    I get the "Trial license expired. Removal of viruses and other malicious software is disabled" from HitmanPro_x64, so I'm unable to rerun Hitman and have it remove those PUPs. (Potentially Unwanted Programs)

    I removed the first of the two PUPs manually. I ran regedit and found

    HKU\S-1-5-21-330010271-3606213368-2544051051-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975} (Claro)

    under HKEYS_USERS, but when I tried to delete it I was told "Unable to delete all specified values" and the second of the two PUPs still remains.

    Do you have another way that I can delete the PUP (other than buying HitmanPro for this one task)?

    Thanks.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.

    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  5. thai_american_42

    thai_american_42 Corporal

    I ran JRT and attached the JRT.txt log.
     

    Attached Files:

    • JRT.txt
      File size:
      1.4 KB
      Views:
      7
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    How are things running now?
     
  7. thai_american_42

    thai_american_42 Corporal

    My computer seems to be running fine. I ran Hitman again and it still found
    2D3B0F-69BE-477A-90F5-FDDB05357975
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to attach the log so I can see what it is complaining about.
     
  9. thai_american_42

    thai_american_42 Corporal

    I re-ran and attached the Hitman Pro log. Please let me know how to handle/remove the item shown in the log from my computer. Thanks!
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just rerun Hitman and have it delete that PUP.

    Tell me how things are running.
     
  11. thai_american_42

    thai_american_42 Corporal

    PUP: HKU\S-1-5-21-2695133797-1182268270-630223487-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975} (Claro)

    When I reran Hitman, I received the message "Trial license expired. Removal of viruses and other malicious software is disabled". I'm unable to have Hitman delete the PUP listed in my prior attachment. My computer seems to run OK, but I would prefer to delete the PUP.
     
  12. thai_american_42

    thai_american_42 Corporal

    Here is the Hitmanpro attachment from my recent run of Hitmanpro.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.

    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  14. thai_american_42

    thai_american_42 Corporal

    Hi Tim,

    Attached is the JRT.txt log from the JRT scan I just ran.

    Take care!
     

    Attached Files:

    • JRT.txt
      File size:
      632 bytes
      Views:
      3
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It should have removed Claro, if it exists. So rerun Hitman and attach the new log.
     
  16. thai_american_42

    thai_american_42 Corporal

    I reran Hitmanpro and attached the new log.
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to run / and type in regedit. Once the registry opens, scroll to that key and delete the value.
     
  18. thai_american_42

    thai_american_42 Corporal

    I went to run / and type in regedit. The registry opened and I scrolled to the key:

    HKEYS_USERS\S-1-5-21-2695133797-1182268270-630223487-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975}

    I right clicked on 4D2D3B0F-69BE-477A-90F5-FDDB05357975 and selected "delete". I received the message "Unable to delete all specified values" and the value was not deleted.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try uninstalling Hitman, run CCleaner and reinstall. Then see if it will remove it. Let me know.
     
  20. thai_american_42

    thai_american_42 Corporal

    I uninstalled Hitman, ran CCleaner and reinstall Hitman. I attached the log of the recent Hitman run. When I reran Hitman, I received the message "Trial license expired. Removal of viruses and other malicious software is disabled". The Hitman expiration date is listed as 2012-11-03. The rerun of Hitman did not remove the PUP.
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.

    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup

    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.


    Now rerun Hitman.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds