PJC cleaned, but still some malware programs

Discussion in 'Malware Help (A Specialist Will Reply)' started by bricht, May 10, 2014.

  1. bricht

    bricht Private E-2

    I've run the malware programs and the PC seems to be working fine. However, if I go to Control Panel/Programs/Uninstall Program, the malware programs are still listed and won't uninstall. I haven't emptied any quarantined items.

    The original problem was adware and unwanted toolsbars.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Fix everything that Hitman found and then tell me what programs you are referring to.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    @TimW...

    Before the user fixes anything with Hitman the below should be uninstalled.
    • TelevisionFanatic Internet Explorer Toolbar
    • SavingsBull
    • Search Protect
    • PC Performer
    • KnowtheBible Internet Explorer Toolbar
    • FilmFanatic Internet Explorer Toolbar
    • Free Games 111


    If they will not uninstall via usual methods then try using Revo Uninstaller.
    If you get Hitman to fix those items you will break the program and definately have trouble uninstalling. Uninstalling should always be done first.
     
  4. bricht

    bricht Private E-2

    Too late. I read Tim's post first and hit Fix. There are still 3 unwanted programs left: Free games III, FilmFanatic IEToolbar, KnowtheBible IEToolbar.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then do this:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  6. bricht

    bricht Private E-2

    Here you go!
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    There are more left than you mentioned... you need to try using Revo Uninstaller. Let me know how you get on. Check against my list as you use Revo. Get all those uninstalled! ;)
     
  8. bricht

    bricht Private E-2

    Awesome program! How does it look now?
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What about SavingsBull? Did that come out? I still see it listed. Do you?
     
  10. bricht

    bricht Private E-2

    No I don't see SavingsBull.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode, if you haven't done so already.


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • R3 - URLSearchHook: (no name) - {3f2ae504-aa17-4805-90e8-56e48f98731c} - C:\Program Files (x86)\BibleTriviaTime_4l\bar\1.bin\4lSrcAs.dll (file missing)
    • O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    • O2 - BHO: Amazon 1Button App for IE - {26B19FA4-E8A1-4A1B-A163-1A1E46F830DD} - (no file)
    • O3 - Toolbar: KnowtheBible - {7abeab51-07be-42c5-89b4-c7f1a3a31816} - C:\Program Files (x86)\BibleTriviaTime_4l\bar\1.bin\4lbar.dll (file missing)
    • O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
    • O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
    • O20 - AppInit_DLLs: C:\PROGRA~2\Amazon\AMAZON~1\\AMAZON~3.DLL

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix exit HJT.




    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :files
    C:\ProgramData\PCSettings
    C:\ProgramData\pl6XD333
    C:\PROGRA~2\Amazon
    C:\Program Files (x86)\BibleTriviaTime_4l
    
    :reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6DDE8071-E4BA-461B-8A96-990DFAA0EBD1}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.




    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  12. bricht

    bricht Private E-2

    Here are the results. I've been away from this computer for a few days...hope it didn't change since then. Let me know.

    I followed your instructions. When I tried to paste OTM results into Notepad, the computer restarted on its own. Not sure why, maybe I clicked something accidentally?

    Mozilla firefox had a problem with cookies. I tried to fix it, but ended up having to delete it altogether.

    Other than that, it seems to be running fine.
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I don't understand.... cookies are useful for the most part and not problems...

    Also, it does not look like you put this machine back into NORMAL start up using MSCONFIG. Did you or not? Let me know.
     
  14. bricht

    bricht Private E-2

    Sorry. The problem with Firefox was only when I first turned on the PC and tried to access gmail. The message said I couldn't because something wasn't set to accept cookies. I checked the cookies setting in control panel/Security...Privacy and it was fine. It was probably just a glitch. I could access gmail from Chrome. After I uninstalled and re-installed Firefox it worked fine there too.

    I was away from the computer for several days and I'm worried someone might have used it (against my warning). Let me know if you see any evidence of new damage.

    I went into MSCONFIG before running HJT and it was already on Normal. I don't remember if I checked after the computer restarted, which was before I ran OTM. I thought I did.
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now run the below:

    Reset Mozilla Firefox to defaults.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  16. bricht

    bricht Private E-2

    I forgot to save the fixME.regit as "all files" before I ran it. So I saved it with that extension and ran it a second time. Also, I double clicked the C:\MGtools\GetLogs.bat file instead of 'Run as Administrator' for Windows 7. Hence the two MGlog attachments. Not sure if that created a problem. Sorry if it did-I got up too early and wasn't fully awake when I tried to do this step. :zzz

    As Firefox did not seem to have problems after I reloaded it, I decided to leave the settings alone, but thanks for the info. I may need it in the future.
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member


    Apparently there's a couple minor issues as seen in one of the logs.... Is your selected search engine conduit? Do you have a toolbar for Firefox called Mindspark?



     
  18. bricht

    bricht Private E-2

    I don't see any toolbars except google's. But I ended up resetting the Firefox defaults anyway after second thought. Do you want to see another MGlog? I'm not at the location, but can try to have someone run it for me.
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No, that's okay. The reset shoould have taken care of that.

    Any remaining issues relevant to this forum?
     
  20. bricht

    bricht Private E-2

    Not that I've seen. Thanks for all your help!:)
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds