Malware Removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by megaroer1, Sep 9, 2013.

  1. megaroer1

    megaroer1 Private E-2

    I was going through the Malware Removal for Delta-Search, and when it came to Hitman Pro, I forgot the step about changing all to ingore and hit next, after I did it there was no taking it back, I saw it after I hit it. Now I can't get into system restore or a couple things on my computer. Can someone please help me... :( Also the delta search virus is still on computer....
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. :)

    Can you ensure that you attach the log from Hitman showing what was deleted?
    Also, you need to be thorough and attach all of the other requested logs from running the R&R as referenced below.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. megaroer1

    megaroer1 Private E-2

    Will attach more logs in a sec
     

    Attached Files:

  4. megaroer1

    megaroer1 Private E-2

    Here are the last two logs! Thanks so much for your help!
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode, if you haven't done so already.


    VisualBee V.11 Toolbar <--- Uninstall this using Revo Uninstaller.



    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these 3 detections:

    • [RUN][SUSP PATH] HKCU\[...]\Run : SearchProtect (C:\Users\Dean\AppData\Roaming\SearchProtect\bin\cltmng.exe [7]) -> FOUND
    • [RUN][SUSP PATH] HKUS\S-1-5-21-3350826726-610725114-3020871678-1002\[...]\Run : SearchProtect (C:\Users\Dean\AppData\Roaming\SearchProtect\bin\cltmng.exe [7]) -> FOUND
    • [RUN][SUSP PATH] HKLM\[...]\RunOnce : Del22574155 (cmd.exe /Q /D /c del "C:\Users\Owner\AppData\Local\Temp\0.del" [x][x]) -> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Please rerun Hitman Pro and have it delete Malware remnants, & Potential Unwanted Programs.




    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\Users\Dean\AppData\Roaming\DSite
    C:\Users\Dean\AppData\Roaming\SearchProtect
    C:\ProgramData\-15009~1
    C:\ProgramData\-15069~1 
    C:\ProgramData\-19669~2
    C:\ProgramData\-1D269~2
    C:\ProgramData\-1D669~1
    C:\ProgramData\-1E669~1
    C:\ProgramData\D086~1 
    C:\Windows\Tasks\At1.job
    C:\Users\Owner\AppData\Local\Temp\0.del
    
    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "SearchProtect"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "SearchProtectAll"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\RunOnce]
    "Del22574155"=-
    [HKEY_USERS\S-1-5-21-3350826726-610725114-3020871678-1002\Software\Microsoft\Windows\CurrentVersion\run]
    "SearchProtect"=-
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.





    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  6. megaroer1

    megaroer1 Private E-2

    When I open another tab, Delta-search is still there....
     

    Attached Files:

  7. megaroer1

    megaroer1 Private E-2

    for some reason the RKreport(2) didn't save??? Trying to get the Jrt attached.
     
  8. megaroer1

    megaroer1 Private E-2

    jrt shows up, but then my computer locks and can't do anything so I restart computer and the log disappears... Also Delta-Search is still under Mozilla Firefox when i click on the plus to add another tab. Thanks for your help!!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this >> Reset Firefox to Defaults

    And then finish the rest of Kestrel13!'s instructions for getting the new MGlogs.zip file and attach it.
     
  10. megaroer1

    megaroer1 Private E-2

    Here is MGlogs. Sorry I forgot this one...
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below very old versions of software:
    Java(TM) 6 Update 2
    Now install the current version of Sun Java from: Sun Java Runtime Environment Make sure that when you see the form asking about installing Ask Toolbar that you uncheck this.

    Shutdown AVG before doing the below.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
    O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)

    After clicking Fix, exit HJT.


    Run OTM.exe that you previously downloaded by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Users\Owner\AppData\Roaming\0D0S1L2Z1P1B0T1P1B2Z
    C:\Windows\Tasks\Happy Lyrics Update.job
    :Reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "RunSpySweeperScheduleAtStartup"=-
    [HKEY_USERS\S-1-5-21-3350826726-610725114-3020871678-1000\Software\Microsoft\Windows\CurrentVersion\run]
    "RunSpySweeperScheduleAtStartup"=-
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXTlog
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  12. megaroer1

    megaroer1 Private E-2

    Will not let me do the Java update, says the version if this software is not compatible with the Windows system I am running. I think it's because it's trying to run for a 64 bit and she has a 32 bit.. Speaking of windows it will also not let me do the important updates that need to be done. I get code error 800b0100.

    Requested logs are attached.

    Still won't let me search/find the JRT.Textlog
     

    Attached Files:

  13. megaroer1

    megaroer1 Private E-2

    Was able to find the correct java update.
     
  14. megaroer1

    megaroer1 Private E-2

    finally got JRT to let me save log... I think other then the windows update everything is taken care of.. Thanks so much for both of your help. Do you think there is anything else I need to do???
     

    Attached Files:

    • JRT.txt
      File size:
      1.2 KB
      Views:
      1
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.
    Try running the below. Sometimes this helps. If it does not help, you will have to post in the Software Forum. Windows Update has always had many problems for many years. Many, if not most, are unrelated to malware.


    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.
    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
     
  16. megaroer1

    megaroer1 Private E-2

    Thanks so much for all your help!! Everything is working great!!!! YOU GUYS ARE THE BEST!!!
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  18. megaroer1

    megaroer1 Private E-2

    I do have one last thing I forgot to ask when I first log on to the computer i get an error that says Live Global Bid Application center Jpeg error number 3??
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not a malware problem. This is software you installed on your PC almost 6 yrs ago per your logs. The only thing I see from it is the below:

    Code:
    "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\
    LIVEGL~1      Feb 21 2008              "LiveGlobalBid Client Software"
    
    If this is not installed anymore or you do not use it then delete that folder and perhaps that startup warning will go away.
     
  20. megaroer1

    megaroer1 Private E-2

    I found the folder and deleted it and restarted the computer and the error still comes up?? Any other ideas how to get rid of it??
     
  21. megaroer1

    megaroer1 Private E-2

    Got it all taken care of, and went through your last post.. Thanks again!!
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds