Winzip Registry Optimizer seems to have broken my computer

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by robboemma, Jun 21, 2013.

  1. robboemma

    robboemma Private E-2

    Hi there

    I seem to have somehow accidentally downloaded a thing called "Winzip Registry Optimizer" that seemed to be popping up every time I switched on my computer.

    It seemed to get very slow very quickly until the thing kept freezing and then wouldn't shut down or reboot.

    I ran my McAfee virus scan but that won't go above 0%. I tried to download AVG free (on a different computer and transferred it via memory stick) in case there was a problem with McAfee but it freezes halfway through the install process. It seems to be getting upset whenever it tries to connect to the internet. My other computer is working fine on the same wifi.

    I googled the problem and saw it may be malware so I have ran all of the majorgeeks recommended scans and attach the log files although they don't seem to have detected anything suspicious.

    Please help :) Hugely grateful!

    Emma
     

    Attached Files:

  2. robboemma

    robboemma Private E-2

    ..... additional log files.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are from safe boot mode. To properly check your PC we require logs from normal boot mode. You did not say that you could not run your PC in normal boot mode. Let's do the below to get new logs. Complete all of the below in normal boot mode.

    Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Now run a new scan with Hitman Pro and attach the new log.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the newHitman Prolog
    • the JRT.TXTlog
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. robboemma

    robboemma Private E-2

    I tried to run the Junkware Removal Tool in normal boot, waited an hour but it got stuck at "Checking Modules".

    Anything I try and do in normal mode causes it to freeze. That's why I ran the scans in safe mode. It gets not very far and then gets stuck.

    I have left it sat trying to run JRT for now.... could it take hours??
     

    Attached Files:

    Last edited: Jun 23, 2013
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it should not take JRT that long to run. Kill it if you have not done so already.

    Okay then let me ask a few questions first before continuing.

    If I ask you to uninstall ALL of McAfee, will you be able to reinstall it later? That is do you have the necessary installation program?

    Also is this a personal computer or a company owned computer?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In addition to answering my questions from my previous message, also do the below.

    Uninstall the below very software:
    Browse22Save
    BrowseToSave 1.74


    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
     
    :Files
    C:\ProgramData\Browse22Save\514cae08726cb.dll
    C:\ProgramData\Browse22Save
    C:\ProgramData\Babylon
    C:\ProgramData\Tarma Installer
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Browse22Save
    C:\Program Files (x86)\AVG
    C:\Windows\TEMP\*.*
    C:\Users\The Robinsons\AppData\Local\Temp\*.*
    
    
    :Reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "Google Update"=-
    [HKEY_USERS\S-1-5-21-1255949861-2777176875-3314495166-1001\Software\Microsoft\Windows\CurrentVersion\run]
    "Google Update"=-
    
    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1255949861-2777176875-3314495166-1001Core.job
    C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1255949861-2777176875-3314495166-1001UA.job
    C:\Windows\tasks\Norton Security Scan for The Robinsons.job
    C:\Windows\tasks\Registry Optimizer_DEFAULT.job
    C:\Windows\tasks\Registry Optimizer_UPDATES.job
    
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
    
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{AD0E55E0-C8FA-46D1-80CE-27AA15E6B526}"
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{EFE95298-A483-4FF6-BF52-6E59F4C4B946}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D1961713-DCFD-6662-F4CB-4469D5483777}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXTlog
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. robboemma

    robboemma Private E-2

    I have uninstalled McAfee, Browse22Save & BrowseToSave 1.74.

    It is a personal computer.

    I downloaded OTM and ran it. It seemed to do quite a bit but then went to 'not responding' and seemed to be stuck.

    Then I wasn't sure if you had meant for me to run it in safe mode so I rebooted it in safe mode. It opened with an OTM log file (attached). I then re-ran OTM in safe mode which seemed to work ok.

    I rebooted again in normal mode and got another log file (attached).

    Then I tried to run JRT which got stuck at "Checking Modules" again.

    Then (perhaps stupidly) I re-ran OTM in normal mode in case it had done anything clever in safe mode and it went to 'not responding' again. I remembered to take a photo this time if it's of any use (attached) and i also attach this third log file.

    I then had a last-ditch attempt at JRT which worked!! Hurrah!

    MGtools also ran fine, logs attached.

    Have just had a surf on it on tinternet!!! And she seems to be working a beaut! I was also having problems whenever I tried to open explorer with 'windows key' E as it would just crash but that seems to be working as it should too!!!

    I am aware that there is more stuff I have to do - I've done major geeks before - but a great big thank you for getting me this far! Amazingness!!!!!
     

    Attached Files:

  8. robboemma

    robboemma Private E-2

    Photo attached, in case it's of any use :)
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs look good now.

    Are you having anymore malware issues?
     
  10. robboemma

    robboemma Private E-2

    I have used it for an hour this evening and it all seems to be working fine.

    Other than reinstalling McAfee, is there anything else i need to do? Shall i remove all of the programmes i downloaded from majorgeeks?

    Another quick question - have a hard drive which has been damaged by manhandling (by the kids!) containing thousands of photos and home movies. I have contacted the leading data recovery company and they have quoted £700 to fix it!!! So i've put it somewhere safe until I can afford it. I don't want to risk giving it to a less reputable data recovery company and losing all of my pictures and movies. Is this a problem that majorgeeks could help with or are there any pearls of wisdom you have to offer??

    Thanks again :) you are amazingly kind!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below final instructions!


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:


    No we do not offer any services like this. Recovery data from drives requires special equipment. Sometimes if really lucky, it is only the circuit board that has gone bad and a company like below can help with this

    http://www.onepcbsolution.com/

    It is a less costly solution but it is not always so simple especially if the drive was mishandled. Mishandling could have already trashed much of the data.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds