Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Logs from malware removal guide  (Read 5310 times)

0 Members and 1 Guest are viewing this topic.

jpb759

  • Guest
Logs from malware removal guide
« on: April 29, 2010, 09:38:41 PM »
i reported a malware problem earlier, as a guest, but have since become a registered user. i'm being prompted to allow the installation of an ask toolbar. i removed everything "ask" related using revo uninstaller, but continued to receive the prompt. i followed the steps in the "malware removal guide" and am submitting the requested logs for review. also, i'm confused regarding step 6. i ran HJT, but took no action when i received the results of the scan. how do i proceed in regards to the scan results? thanks for all your help, you guys are doing a great job!       

[recovering disk space - old attachment deleted by admin]

evilfantasy

  • Malware Removal Specialist


  • Genius
  • Calm like a bomb
  • Thanked: 493
  • Experience: Experienced
  • OS: Windows 11
Re: Logs from malware removal guide
« Reply #1 on: May 04, 2010, 07:34:47 PM »
Hello jpb759.

You have way too much real-time antispyware running. This actually giving you less protection rather than more.

Winpatrol
SpySweeper
Malwarebytes


Disable either SpySweeper or Malwarebytes and just use it as an on-demand scanner. Winpatrol should be fine as it does not interfere with anything like the others do.

----------

Disable SpySweeper so it does not block any fixes.

You can re-enable it after we're done.

To disable SpySweeper:
  • Open Spysweeper and click Options over to the left thenProgram Options and uncheck Load at windows startup
  • Over to the left click Shields and uncheckeverything.
  • UncheckHome page shield
  • UncheckAutomatically restore default without notification
.
----------

Disable Winpatrol so it does not block any fixes.

You can re-enable it after we're done.

Right-click the running icon of Winpatrol in the sytem tray and choose exit.

----------

Malwarebytes is a version behind so you need to update and run it again.

Open Malwarebytes' Anti-Malware.

* Click the Update tab.
* Click Check for Updates
* If an update is found, it will download and install.
* Click the Scanner tab.
* Select Perform Quick Scan, then click Scan.
* The scan may take some time to finish,so please be patient.
* When the scan is complete, click OK, then Show Results to view the results.
* Make sure that everything is checked, and click Remove Selected.
* When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
* Copy & Paste the entire report in your next reply.

Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

----------

Right click HijackThis and choose Run as Administrator

Next select Do a system scan only

Place a check mark next to the following entries: (if there)

- O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

Important: Close all open windows except for HijackThis and then click Fix checked.

Once completed, exit HijackThis.

----------

I am not seeing where the Ask installer is running from so we need to go in and find it. The 64 bit OS also limits us as to the tools we can use. But we will get it.

First let's try the easy way and hope it finds and removes the leftovers.

Ask Toolbar Remover 1.3:

A program that is able to remove the Ask toolbar (plus all the debris) and set the homepage back to the one the user wants to.
More info here. http://fred-de-vries.blogspot.com/2009/12/autoclean-ask-toolbar-remover.html
Download here. http://autoclean.computersitter.com/downloads/ASKRemover.zip?attredirects=0&d=1

Just download and open the zip file then run the tool. A window swill open with more information and that is normal. The tool runs/completes very fast.

Restart the computer and let me know if it worked.