SuperAntiSpyware and Malwarebytes having problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by jimpeel, Nov 18, 2009.

  1. jimpeel

    jimpeel Sergeant

    I've been through the Read This First as far as I can go.

    The unit which I am working on has ~300 infected files of various types. There are adware, trojans, bots, you name it.

    SAS hangs in the middle of the scan and sends a report to the authors. It locks up if I try to get the updates. In have to <ctrl-alt-del> to kill it and start over. A couple of times I was able to get to the quarantine and removal stage but after about six bars on the activity scale it stops. Waited over an hour with no movement.

    MalwareBytes goes through the routine but freezes during the quarantine procedure.

    The strange thing is that the programs run flawlessly on the Guest account but not on the Administrator account. The problem is that they do not seem to remove anything even though they say they are.

    I was able to get a report on some of the problems which all have to do with something called FunWebProducts.

    There seemed to be remnants left in the registry so I removed them manually -- after backing up the registry -- but still see no improvement. The program is not in the Program Files folder even though the registry entry says it should be there.

    Here is the result that I used to remove the registry entries:

    How do I get SAS and MB to run in the Administrator account?

    Thanks,

    J
     
    Last edited: Nov 18, 2009
  2. jimpeel

    jimpeel Sergeant

    The unit I am attempting to repair has Windows XP Media Center Edition sp3 installed. Could that have anything to do with my issues? I have never heard of this platform before a few minutes ago.

    Thanks,

    J
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What exactly does this mean? You did not even mention trying to run ComboFix, RootRepeal, nor MGtools.

    FunWebProducts is just trivial junk.
     
  4. jimpeel

    jimpeel Sergeant

    The readme first specifically says that we should follow the instructions exactly.

    I did run Combofix, which ran just fine, but I was unsure what to do with RootRepeal. It says do not run on 64 bit systems in big bold red letters. I wasn't sure so I didn't.

    MGtools was still one more program that would have been run out of order.

    What has that to do with the fact that SuperAntiSpyware and MalwareBytes freeze up, refuse to update, and have to be forced to terminate using Windows Task Manager?

    What has that to do with the fact that Malwarebytes and SuperAntiSpyware would run in the guest account but not on the administrator account and would leave files undeleted on the administrator account?

    The reason that I did not run RootRepeal and MGtools is because I did not know whether the Windows XP Media Center Edition sp3 is a 64 bit platform. All I could find about it was that it is an extension of Windows XP Pro which was not offered except as a bundled platform on computers which were designed for displaying media.

    The vast majority of the files which were returned as infected with adware, spyware, and backdoor bots by Malwarebytes -- which would then refuse to quarantine and delete those same files prior to locking up and having to be terminated manually -- were associated with the "trivial junk" program FunWebProducts.

    I finally went into the registry and removed all of the files manually and that seemed to take care of the problems. That still did not explain why Malwarebytes and SAS did not run or whether the problems were platform specific to Windows XP Media Center Edition.

    If you wish to address the issue of why the two programs did not run, and still do not run, on that platform I would be happy to hear any input to that issue. Everything else is no longer a problem and can be set aside as solved.

    Thanks,

    J
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it does not. It says not to skip steps but skipping is not the same thing as trying to run a step and being blocked which is why the very beginning ot the READ & RUN ME begins with the below notes
    So basically if you could not run a particular step, you are supposed to keep on going.

    The ComboFix step tells you the same thing and you already ran ComboFix. Thus you obviously don't have a 64 bit system. ;)

    What has what to do with it?

    As stated above you don't have a 64 bit platform since you ran ComboFix and MGtools does not tell you it cannot be run on a 64 bit system. It full supports both 32 bit and 64 bit systems.


    In the registry, you are removing registry keys and values. You are not removing files.

    Without seeing all of the logs we have no idea if you are still having malware problems nor whether there was anything related to malware causing this problem. For all we know you may have hard disk or file system problems or you could have a permissions issues with registry keys and files (which is most likely the problem). We also don't even know if you are running the correct versions of any of the tools.

    You need to try to run ALL steps on the problem user account not the Guest account which should not even be active. The Guest account should be disabled since it is a major security risk.
     
  6. jimpeel

    jimpeel Sergeant

    Thanks for the replies. The unit has been returned to the owner but I could get it again and try the scans again.

    I tried to kill the Guest account but there was nothing in the procedure for removing it. I was able to turn it off. How does one go about killing an account completely?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You cannot. It is required by Windows just like the Administrator account. You just need to Disable it which does not mean just hide it from appearing on the welcome screen because it could then still be used.
     
  8. jimpeel

    jimpeel Sergeant

    I did that. Thanks.

    j
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. If you ever get the PC back. You will have to download new versions of tools and run new scans since by then you will be out of date. Attach logs next time too.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds