Yontoo 1.10.02

Discussion in 'Malware Help (A Specialist Will Reply)' started by jlachey, Jul 1, 2013.

  1. jlachey

    jlachey Private First Class

    I have Yontoo 1.10.02 in my add/remove programs list. When I try to remove it, I receive an error message stating 'setup initialization error.' Is this malware? How do I remove it?
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. jlachey

    jlachey Private First Class

    I wasn't able to remove it with Revo Uninstaller, so I ran the requested scans. I am not sure if MGtools worked because I had Sandboxie enabled. Please let me know if it didn't work and you would like me to run it again.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue, you need to use MSCONFIG to put the machine into normal start up mode.

    Uninstall Viewpoint Media Player


    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate this detection:
    • [APPINIT][SUSP PATH] HKLM\[...]\Windows : AppInit_DLLs (c:\docume~1\alluse~1\applic~1\browse~1\25976~1.107\{c16c1~1\mngr.dll [x]) -> FOUND

    Place a checkmark next to this item, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Re scan with Hitman and have it delete Potential Unwanted Programs


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Give ccleaner a run, not the reg scanner just the cleaner itself to be rid of some temp files.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. jlachey

    jlachey Private First Class

    How do I know which threats are potential unwanted programs? None of the threats detected by Hitman are listed in this category.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let me put it more simply, when you scan with Hitman, what does it find exactly? :)
     
  7. jlachey

    jlachey Private First Class

    It finds unwanted/malicious files and programs. So does that mean I should delete everything? Since there are files called PUPs, I thought that's what you meant.
     
  8. jlachey

    jlachey Private First Class

    I'm hoping Rogue Killer worked properly. I was asked to update it before running it this time, so the new report will be listed as rkreport[0] again. The registry merge was successful. Everything seems to be running fairly well. :)
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    PUP's = Potentially unwanted programs. Yes... this is what I want you to have Hitman delete. :) Please do so and then attach the new log after rescanning again.
     
  10. jlachey

    jlachey Private First Class

    The scan was clean this time. What should I do next?
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  12. jlachey

    jlachey Private First Class

    How does everything look now? Do you still detect any malware/spyware?
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    A little bit remains yes...


    We need to run an OTL Fix

    • Right-click OTL.exe And select " Run as administrator " to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the Image textbox. Do not include the word Code

    Code:
    :otl
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.claro-search.com/?affID=116695&tt=4812_7&babsrc=HP_ss&mntrId=d8a20fcc00000000000000c0a8814561
    CHR - default_search_provider: Claro Search (Enabled)
    CHR - default_search_provider: search_url = http://www.claro-search.com/?q={searchTerms}&affID=116695&tt=4812_7&babsrc=SP_ss&mntrId=d8a20fcc00000000000000c0a8814561
    
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.

    Everything running nicely? Ready for final steps?
     
  14. jlachey

    jlachey Private First Class

    I don't think it worked. The first time I tried it, my computer froze so I had to restart it. The second time, it did seem to work, but I then had to manually restart and I cannot find the report in notepad. What did I do wrong?
     
  15. jlachey

    jlachey Private First Class

    The only file I found on my computer that was modified today is OTL.EXE-1D6E14F0.pf. Could this be the report?
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try running the instructions in safe mode then please if normal mode is problematic.
     
  17. jlachey

    jlachey Private First Class

    It seemed to work and rebooted on its own in safe mode. However, I am still not finding a report in notepad. I'm also not sure what you mean when you say 'click image.' Is there an image on the screen that I am supposed to click on or is the word 'image' listed somewhere on the screen?
     
  18. jlachey

    jlachey Private First Class

    I did find a folder of OTL moved files in notepad- I don't know if this is what you are looking for.
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes then attach that please. Also rescan with OTL (just a scan) and attach that too please.
     
  20. jlachey

    jlachey Private First Class

    I have attached the 'moved files' file. This is the most recent one- there are previous files if you would like to see them. Now when I try to scan with OTL, the scan runs, but then Notepad opens with an error message saying 'access denied.' What could have caused this problem?
     

    Attached Files:

  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK I do not know why OTL gives access denied now. What I need to ask you though, is what malware problems actually remain now? Yontoo is uninstalled, how is everything behaving in that regard?
     
  22. jlachey

    jlachey Private First Class

    It mostly seems to be back to normal. The only problem I'm noticing is a script error when I try to visit certain sites in IE (it is mostly on this site).
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can always ask about that in the software forum. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  24. jlachey

    jlachey Private First Class

    Ok- thank you for your help! :)
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Most welcome. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds