addaware problems.

Discussion in 'Windows - Virus and spyware problems' started by Heaseba, Oct 5, 2013.

  Heaseba

    Heaseba Newbie

    Oct 5, 2013
    You said
    "Also after we finish you can have your hubby come on with his puter and I fix him up...."

    He says "Thank you."
    File below.

    Are those blue highlighted items virus?Because I have no idea what the battlefield heroes is from and don't want it,or that 'bing' crap.
    Last edited: Oct 9, 2013
  2oldGeek

    2oldGeek Active member

    Hi Heather,

    Well, you were clean enough but, I’m fussy about sweeping up after. This will clean up the leftover remnants and clean behind the refrigerator, so to speak :)

    Run OTL Script

    I would like you to run this custom script for me now and when it is complete please give me the report and a status update for the computer.

    Double-click OTL.exe to start the program.

    Copy and Paste the following code into the [​IMG]text box.

    DRV:64bit: - [2013/09/09 19:25:55 | 000,046,368 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtpx64.sys -- (avgtp)
    IE - HKCU\..\URLSearchHook: {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - C:\Program Files (x86)\Family Toolbar\tbhelper.dll ()
    FF - prefs.js..extensions.enabledItems: avg@toolbar:
    O2 - BHO: (MHTBPos00 Class) - {0C37B053-FD68-456a-82E1-D788EE342E6F} - C:\Program Files (x86)\Family Toolbar\tbcore3.dll ()
    O2:64bit: - BHO: (no name) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - No CLSID value found.
    O9:64bit: - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - Reg Error: Key error. File not found
    O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - Reg Error: Key error. File not found
    O13 - gopher Prefix: missing
    [2013/09/09 19:27:10 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Local\AVG SafeGuard toolbar
    [2013/09/09 19:26:54 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG SafeGuard toolbar
    [2013/09/09 19:26:20 | 000,046,368 | ---- | C] (AVG Technologies) -- C:\Windows\SysNative\drivers\avgtpx64.sys
    [2013/09/09 19:26:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG SafeGuard toolbar
    [2013/09/09 19:25:55 | 000,046,368 | ---- | M] (AVG Technologies) -- C:\Windows\SysNative\drivers\avgtpx64.sys
    [2011/12/13 10:50:49 | 000,000,101 | ---- | C] () -- C:\Users\Administrator\AppData\Local\fusioncache.dat
    [2010/02/20 16:10:59 | 000,032,256 | ---- | C] () -- C:\Users\Administrator\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    @Alternate Data Stream - 151 bytes -> C:\ProgramData\TEMP:0B4227B4
    ipconfig /flushdns /c
    C:\Program Files (x86)\Family Toolbar
    Then click the Run Fix button at the top.
    Click OK.

    OTL may ask to reboot the machine. Please do so if asked.

    The report should appear in Notepad after the reboot. Copy and Paste that report in your next reply.

    Note** if the report does not popup after the computer reboots you can find it here in this folder:
    C:\_OTL\MovedFiles - It will be named – mmddyyyy_hhmmss.log
    Where mmddyyyy_hhmmss - are numbers representing the date and time the fix was run.

    On the malware front, you're clean! [​IMG]

    We have a couple last things to take care of and then you're good to go.

    Uninstall ComboFix from your computer:
    • Click on Start > Run
    • Type Combofix /u in the run box and click Ok. Note the space between the x and the /u, it needs to be there.


    Over the course of the fix you've used a variety of special tools to help with the cleaning process - none of these are of any use to you now that you're clean, and it's best not to have them hanging around on your computer. OTC is a small program that removes all the leftover tools and logs from cleanup of malware.

    Please download OTC to your desktop.
    • Double-click OTC to run it. (Win7 right click on OTC and select "Run as an Administrator")
    • Click on the CleanUp! button and follow the prompts.
    • You will be asked to reboot the machine to finish the Cleanup process, choose Yes.
    • After the reboot all the tools we used should be gone.
    Note: Some more recently created tools may not yet be removed by OTC. Feel free to manually delete any tools it leaves behind.

    I had you remove SuperAntiSpyware because it is just not as good as MalwareBytes AntiMalware. So I suggest you download -> MBAM and use it once a week or so…

    That about does it so, let me know how things are doing.

  Heaseba

    Heaseba Newbie

    Oct 5, 2013
    Likes Received:
    Trophy Points:
  2oldGeek

    2oldGeek Active member

    Hi Heather,
    Let's not worry about it, you're clean. How is your computer doing now?
    You shouldn't have any problems and should be running faster...

    Avast! is very good and should keep you well protected. Run MalwareBytes ever so often and you will be able to keep the bad guys out.:)

    Have your Hubby come on to this thread and we will get him cleaned up also.

    Nice working with you. You did an excellent job and I thank you for not making it rough on me. LOL

    Til we meet again, have a "happy and safe surfing".

    2old Geek, The number "2" not Too, old with a small "o" and Geek with a Capital "G"

    I get the Bugs Out!

  Heaseba

    Heaseba Newbie

    Oct 5, 2013
    Likes Received:
    Trophy Points:
    you are too funny... love the 'bug'.
    My comp is running better than I can ever remember it running, so you did an awesome job of helping this OLD (with a capital O) lady get sorted out.
  2oldGeek

    2oldGeek Active member

    Oh, I did miss a bug.... I missed that note at the bottom of one of your posts.

    If you will run a Hijackthis Log and post it I think we can remove those with it..

    I just know you're not Old, I probably got socks older than you. LOL

  Alryss

    Alryss Member

    This is Heaseba's hubby. I have a few issues with my comp as well. She told me you may be able to assist me with them. One is a Malwarebyte notification of a pmb.exe virus. Thank you.
  2oldGeek

    2oldGeek Active member

    Jun 16, 2005
    Hello Alryss,

    I will be more than glad to assist you..

    First I need for you to run a few programs and post the Logs so I can see into your computer and determine what we will need to do in order to fix it...

    -Security Check-

    Download Security Check by screen317.
    Save it to your Desktop.

    Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
    A Notepad document should open automatically called checkup.txt; please post the contents of that document.


    Please download AdwCleaner by Xplode to your Desktop.

    • Close all open programs and internet browsers.
    • Double click on AdwCleaner.exe to run the tool.
    • Click on Delete tab follow the prompts.
    • A log file will automatically open after the scan has finished.
    • Please post the content of that log file with your next answer.
    • You can find the log file at C:\AdwCleaner[Rn].txt (n is a number).

    [​IMG] —Junkware Removal Tool--

    Please download Junkware Removal Tool to your Desktop.
    Please close your security software to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or 7, right-mouse click it and select Run as administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete, depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your Desktop and will automatically open.
    • Please post the contents of JRT.txt into your reply.


    • Download & SAVE to your Desktop RogueKiller for 32bit or Roguekiller for 64bit
    • Quit all programs that you may have started.
    • Please disconnect any USB or external drives from the computer before you run this scan!
    • For Vista or Windows 7, right-click and select "Run as Administrator to start"
    • For Windows XP, double-click to start.
    • Wait until pre-scan has finished ...
    • Then Click on "Scan" button
    • Wait until the Status box shows "Scan Finished"
    • click on "delete"
    • Wait until the Status box shows "Deleting Finished"
    • Click on "Report" and copy/paste the content of the Notepad into your next reply.
    • The log should be found in RKreport[1].txt on your Desktop
    • Exit/Close RogueKiller+

    Please paste the logs in your next reply.
    Let me know what problem persists.

  Heather59

    Heather59 Member

    Lost my password so had to remake the account. For the last 2 days, my computer has been freezing and stalling and driving me nuts...
  Heather59

    Heather59 Member

    Oct 28, 2013
    Last edited: Oct 28, 2013
  Heather59

    Heather59 Member

    He asked me to apologize for him. He didn't notice there was a 2nd page so thought you had not replied. He actually thought his post hadn't posted.
  Alryss

    Alryss Member

  2oldGeek

    2oldGeek Active member

    1.)Update your Win 7 and install SP1.

    2.)Uninstall Ad-Aware and install Avast 9 - it's much better!

    3.)Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.

    Uninstall Java(TM) 6 Update 24

    4.)Upgrading Java:
    • Download the latest version of JRE 7 Update 45.
    • Click the "Free Java Download" button.
    • Click the “Agree and Start Free Download” button.
    • Click on the download link for your system and save it to your desktop.
    Close any programs you may have running - especially your web browser.
    • Then from your desktop double-click on the download to install the newest version.(Vista/7 users, right click on the JRE download and select "Run as an Administrator.")


    Please download OTL by OldTimer to your Desktop.

    If you already have a copy of OTL, delete it and use this version.

    Double click OTL.exe to launch the program.

    Check the following.
    Scan all users.
    Standard Output.
    Lop check.
    Purity check.
    Under Extra Registry section, select Use SafeList
    Click the Run Scan button and wait for the scan to finish (usually about 10-15 mins).

    When finished it will produce two logs.
    OTL.txt (open on your desktop).
    Extras.txt (minimized in your taskbar)

    Please post me both logs


    P.S. please have Heather59 start a new thread so I may help her. At 71 it's very difficult to multi-task in the same thread. Very confusing..[​IMG]
  Heather59

    Trophy Points:
    NVM I downloaded and ran malwarebytes. found 66 issues and cleaned those. I think I may be ok for now. I will scream for help, if I find I still need it. Thanks :D
  2oldGeek

    2oldGeek Active member

    Gee Heather, I can't understand how you came up with that many issues. The last Log I have for you was clean. I sure would like to see that Log. You sure you have your AV running?

    The log can be found in MBAM under the Logs Tab.

  Heather59

    Heather59 Member

    No.. I'm not sure. The icon is in the toolbar, but I can't find a way to scan. Does it run automatically, or do you have to set something on it?
  2oldGeek

    2oldGeek Active member

    Are we talking about the MBAM icon or the AV icon.. Which program are we looking at to scan with? Sorry, confused:(
  Heather59

    avast..actually. This is my latest malwarebytes log..
    Last edited: Nov 10, 2013
  ddp

    you sure did have a bunch of nasties there.
  2oldGeek

    You should be able to click the AVAST icon and then click Scan or Quick Scan for it to run..

    Please DO NOT use the "Reply button" when posting. With these Big Logs it gets too hard to keep up with everything.

    You were clean what happened? [​IMG]

    These guys get bundled with other downloads and you really have to watch out when downloading so as not to include them in your install:

    Optimizer Pro

    With everything I can see from that Log, let's just start Fresh...

    -Security Check-

    Download Security Check by screen317.
    Save it to your Desktop.

    Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
    A Notepad document should open automatically called checkup.txt; please post the contents of that document.


    Please download AdwCleaner by Xplode to your Desktop.

    • Close all open programs and internet browsers.
    • Double click on AdwCleaner.exe to run the tool.
    • Click on Delete tab follow the prompts.
    • A log file will automatically open after the scan has finished.
    • Please post the content of that log file with your next answer.
    • You can find the log file at C:\AdwCleaner[Rn].txt (n is a number).

    [​IMG] —Junkware Removal Tool--

    Please download Junkware Removal Tool to your Desktop.
    Please close your security software to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or 7, right-mouse click it and select Run as administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete, depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your Desktop and will automatically open.
    • Please post the contents of JRT.txt into your reply.


    • Download & SAVE to your Desktop RogueKiller for 32bit or Roguekiller for 64bit
    • Quit all programs that you may have started.
    • Please disconnect any USB or external drives from the computer before you run this scan!
    • For Vista or Windows 7, right-click and select "Run as Administrator to start"
    • For Windows XP, double-click to start.
    • Wait until pre-scan has finished ...
    • Then Click on "Scan" button
    • Wait until the Status box shows "Scan Finished"
    • click on "delete"
    • Wait until the Status box shows "Deleting Finished"
    • Click on "Report" and copy/paste the content of the Notepad into your next reply.
    • The log should be found in RKreport[1].txt on your Desktop
    • Exit/Close RogueKiller+

    Please paste the logs in your next reply. DO NOT use the "reply" button. :)
    Let me know what problems you are having and we can go from there.

Share This Page