1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

[Solved] Malware check plz

Discussion in 'Malware Removal Help' started by Just-Me, Feb 26, 2015.

  1. allheart55 (Cindy E)

    allheart55 (Cindy E) Administrator Administrator

    Joined:
    Jun 11, 2009
    Messages:
    10,495
    Location:
    Pennsylvania
    Operating System:
    Windows 10
    Computer Brand or Motherboard:
    ASUS M4A77TD AM3 AMD 770 ATX AMD
    CPU:
    AMD Phenom II X6 1090T-Thuban 3.2GHz
    Memory:
    Crucial-DDR3 SDRAM 1333-8GB
    Hard Drive:
    WD Caviar Black SE HDD 640 GB - WD Caviar Black SE HDD 500 GB
    Graphics Card:
    Sapphire Radeon HD-7870 2GB
    Power Supply:
    CORSAIR CMPSU-750W
    I'm sorry, Just-Me, that was someone not trained in malware removal that should not have replied here.
     
  2. Just-Me

    Just-Me Registered Members

    Joined:
    Mar 2, 2014
    Messages:
    117
    Operating System:
    Windows 7
    oh ic...well I did reinstall it anyhow. was wondering what could be wrong since I paid for the program.
    thanks anyhow
     
  3. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    Hi, sorry for the delay...I thought I had an alert set up but didn't. Every day when I looked manually, I never saw your name listed on the response when I scanned due to other's replies.

    That error image you posted is for a Sony program that came with your computer. No need to worry about it if you are planning on restoring to factory settings...is that still your plan?

    Sometimes it can get corrupted, but that's not the root cause here for anything...lots of different scans coming up clean. Updating SAS is a moot point if you were still going to restore to factory settings. Let me know how you want to proceed!

    -etavares
     
  4. Just-Me

    Just-Me Registered Members

    Joined:
    Mar 2, 2014
    Messages:
    117
    Operating System:
    Windows 7
    yes my plans are still to put back to factory settings. I can't do it at this time due to my back. I have a long way to go yet before I can sit at the desk to be able to do it. its only been 2 wks since the surgery and get very sore sitting over 10 minutes. so as soon as I am ready I will come back to this topic and let you know.
    until then I would like to thank you once again for you help. talk to you soon as all is well at this end.
    have a wonderful weekend
     
  5. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    Hi, I hope you heal pretty quick from surgery; that does not sound fun, but hopefully you'll end up at a better end state. Just keep me posted if you have any questions. We can disable that error if you'd like in the interim so it's less annoying. That program doesn't need to start up.

    To do that, save the attached fixlist.txt to the same folder you have FRST saved to. Then, launch FRST, click Fix just once and it will remove that task.

    If you do that, please do post the fixlog.txt that will appear.

    -etavares
     

    Attached Files:

  6. Just-Me

    Just-Me Registered Members

    Joined:
    Mar 2, 2014
    Messages:
    117
    Operating System:
    Windows 7
    hi I am back to ask a question. in the scans that we ran...did you find the ask toobar? I was just online with Avast Virus Protector and he did a search in my machine and said that its its in my computer. he also told me that if he was to fix it up for me it was going to cost me $175.00. forget that I am not paying that kind of money. I asked him why doesn't my virus protector pick it up and send it to the vault and he didn't know what to say.
    is there any scan we can run to see if the toolbar is in my comp?
    all the programs that you had me install I deleted so we would have to start from the beginning again. sorry about this. I just read your message above.
    tyvm
     
  7. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    Hi,

    Those scans (and several of the scans we ran) would have shown the Ask toolbar, but it was not present. It's considered a potentially unwanted program since it often installs itself without asking. It wouldn't have caused the issues earlier however. It's quite possible it was installed since we last ran scans. Did you restore to factory settings at some point before this? Or update any software? Are you stil having the same issues as before?

    If you'd like, please answer those questions and follow these instructions and we can see if anything has changed.
    http://computerhelpforums.net/threa...-help-winxp-vista-win7-win8-and-win8-1.41927/

    -etavares
     
  8. Just-Me

    Just-Me Registered Members

    Joined:
    Mar 2, 2014
    Messages:
    117
    Operating System:
    Windows 7
    just installed and ran malware bytes and found nothing. I am still getting the pop up pages now and then. I have noticed that my paint shop pro freezes up on me and doesn't co-operate at times. I am attaching a screen shot of one of the pages that avast rep had brought up while he was in my pc and you will see just below the scale or whatever it is that the WD Drive Service and Paint Shop Pro are not responding.
    I have not even thought of starting to set back to factory settings yet. so much to back up with my psp and that is alot of work to set it all back up with all the plug ins etc.
    ty
     

    Attached Files:

  9. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    OK, helpful. Please follow the prep guide and we'll take another look. There's obviously something wrong that's well hidden.

    -etavares
     
  10. Just-Me

    Just-Me Registered Members

    Joined:
    Mar 2, 2014
    Messages:
    117
    Operating System:
    Windows 7
  11. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    Hi,

    adwCleaner found a bad add-on for Chrome. Since your popups were in more than just Chrome, that's not the root cause, but it's good it was found and removed.

    Based on your previous posting, those exceptions are unfortunately common.

    Please do follow the prep guide, we can take another look. The system is clearly unstable.

    -etavares
     
  12. Just-Me

    Just-Me Registered Members

    Joined:
    Mar 2, 2014
    Messages:
    117
    Operating System:
    Windows 7
    here is the Malwarebytes scan results
    now on to the next
     

    Attached Files:

  13. Just-Me

    Just-Me Registered Members

    Joined:
    Mar 2, 2014
    Messages:
    117
    Operating System:
    Windows 7
    the FRST results are attached
    now I will run the AdwCleaner
     

    Attached Files:

  14. Just-Me

    Just-Me Registered Members

    Joined:
    Mar 2, 2014
    Messages:
    117
    Operating System:
    Windows 7
    results from the AdwCleaner


    # AdwCleaner v4.203 - Logfile created 07/05/2015 at 20:12:14
    # Updated 30/04/2015 by Xplode
    # Database : 2015-05-05.1 [Server]
    # Operating system : Windows 7 Home Premium Service Pack 1 (x64)
    # Username : Lila - LILA-VAIO
    # Running from : C:\Users\Lila\Desktop\adwcleaner_4.203.exe
    # Option : Scan

    ***** [ Services ] *****


    ***** [ Files / Folders ] *****


    ***** [ Scheduled tasks ] *****


    ***** [ Shortcuts ] *****


    ***** [ Registry ] *****

    Data Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local

    ***** [ Web browsers ] *****

    -\\ Internet Explorer v11.0.9600.17728


    -\\ Mozilla Firefox v37.0.1 (x86 en-US)


    -\\ Google Chrome v42.0.2311.135


    *************************

    AdwCleaner[R0].txt - [1038 bytes] - [07/05/2015 19:13:39]
    AdwCleaner[R1].txt - [824 bytes] - [07/05/2015 20:12:14]
    AdwCleaner[S0].txt - [1100 bytes] - [07/05/2015 19:15:28]

    ########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [941 bytes] ##########
     
  15. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    Nothing in the log looks like malware, at least one that would explain those issues (popups in multiple browsers, system instability). So, there are two things we will do. First, we'll rule out viruses/malware with a second opinion from an antivirus (Malwarebytes' and adwCleaner are antimalware, slight difference).

    • Click here to download Emsisoft Emergency Kit. The download will automatically start after a moment.
    • Save EmsisoftEmergencyKit.exe to your Desktop.
    • Double click on EmsisoftEmergencyKit.exe (Windows Vista/7/8 users: Accept UAC warning if it is enabled). A screen like this will appear:
      20abd6a44c4b5f5aceca44e4e1050eb6.png
    • Leave everything as it is, then click Extract. This will unpack Emsisoft Emergency Kit to the EEK folder located in the root drive (usually C:\).
    • Once the extraction is done, an icon c2c5179c40dc9a09b986a58752fec1c8.png will appear on your Desktop. Double click it to start Emsisoft Emergency Kit.
    • Wait for Emsisoft Emergency Kit to finish loading signatures. A screen like this should appear:
      45616a1b216e4ab93420a1a64625e97f.png
    • Choose Yes, then wait for EEK to finish updating.
    • Choose Smart Scan under the Scan button. When EEK asks to activate PUP detection, choose Yes.
    • Wait for the scan to finish.
      9cc60e91f862982c3cf7721cf6be00dd.png
    • If EEK detects something, all detected items will be displayed. Place a checkmark before everything, then choose Quarantine Selected.
    • If Emsisoft Emergency Kit asks to reboot, please do so immediately.
    • The scan log is located in Logs -> Scan Logs. Click on the entry of the latest scan, choose Export and save the report on your Desktop.
      632134a9282cca5983bd91d6fb1cb26b.png
    • Please Copy and Paste the contents of the scan log in your next reply.

    Next, we'll run one other one after this that is a bit different. If both are clean, there are signs the hard drive is corrupted and it could be hardware. We'll dig into that later.

    -etavares
     
  16. Just-Me

    Just-Me Registered Members

    Joined:
    Mar 2, 2014
    Messages:
    117
    Operating System:
    Windows 7
    here is what came up with the scan. what it found I quarantined, but they are not showing on the scan report

    Emsisoft Emergency Kit - Version 9.0
    Scan log

    Date Scan Method Objects Scanned Objects Detected Duration Type
    05/11/2015 6:00:20 AM Smart 202631 4 0:46:41 Manual scan
     
  17. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    OK, one more scan, then let me know how it is running, please.

    Download RogueKiller and save it to your desktop.
    • Close all running processes (security programs etc )
    • Double click RogueKiller icon to run the program
      Vista/Win7/Win8 users should right click the icon and select Run as Administrator.
    • Wait for the Prescan to finish.
    • Now click the Scan button.
    • Please copy and paste the report in your next reply.

    -etavares
     
  18. Just-Me

    Just-Me Registered Members

    Joined:
    Mar 2, 2014
    Messages:
    117
    Operating System:
    Windows 7
    just a couple of questions here first. can I delete Emsisoft and the log files?

    now about this RogueKiller...which one do I download? there are two in there. I had downloaded the 54 bit and it ran for a couple of minutes and seems to me it froze up at 40% cause it stayed at 40% for well over an hour. I did as you said to save to desktop and run as admin. so does this scan take forever? lol
    I will wait to hear from you before I begin to scan again...tyvm
     
  19. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    Yes, you can delete EmiSoft and the los. As for RogueKiller, the 64 bit is the version you need. Did you disable all your antivirus/antimalware programs? They can block it.

    -etavares
     
  20. Just-Me

    Just-Me Registered Members

    Joined:
    Mar 2, 2014
    Messages:
    117
    Operating System:
    Windows 7
    yes I did disable my virus protector and superantispyware. will give it a go again. I will just let it run. I am too sore to sit at the pc and do anything else anyway LOL
    will get back to you as soon as its done...tyvm
     

Share This Page