malwarebytes not finding malware, issues with running scan and bluescreen

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
okay, I ran the scan w frst64 and will post the log, but i did notice w the last scan u had me to also run a sevices.exe log.. not sure if that was needed this time or not so i only did as u asked per this request.. log is attached:
 

Attachments

  • FRST.txt
    30.4 KB · Views: 127

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
thought while i was waiting i would post the info of the trojan dropper found a few days ago:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 05/27/2013 at 02:55 PM

Application Version : 5.6.1014

Core Rules Database Version : 10203
Trace Rules Database Version: 8015

Scan type : Custom Scan
Total Scan Time : 00:18:36

Operating System Information
Windows Vista Home Premium 64-bit, Service Pack 2 (Build 6.00.6002)
UAC Off - Administrator

Memory items scanned : 345
Memory threats detected : 0
Registry items scanned : 67948
Registry threats detected : 0
File items scanned : 28661
File threats detected : 1

Trojan.Unclassified/Dropper
C:\WINDOWS\SYSWOW64\ADOBE\SHOCKWAVE 12\LAUNCHGOOGLECHROME.EXE
 

Fiery

Level 1
Jan 11, 2011
2,007
You log is clean, I'm not sure if the dropper detected by Superantispyware is actually bad or not. Did you delete LAUNCHGOOGLECHROME.EXE or quarantined it?

What did your son do to get rid of the fake alerts? Was the PC actually infected because clicking those fake alerts doesn't necessarily result in malware on your PC.

Not sure what is causing the current symptoms, try tweaking tool again.

Download and Run Windows Repair (all in one)

Download Windows Repair (all in one)

  • Install the program then run it.
  • Go to step 2 and allow it to run Disc check by clicking Do It
  • Go to step 3 and allow it to run SFC
  • Go to start repairs tab and click start.
  • Allow the program to create a system restore and backup registries when prompted.
  • Check the box next to "Restart/Shutdown system when finished" and ensure all the boxes are checked along with the default checks
  • Then click Start.
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
My son clicked on something called pc optimizer pro, and supposedly it deleted on reboot after i used the adwcleaner prog, but now, i cant get anything to work, not the OTL, not the malwarebytes antimalware, and i even have the prog u just said to dl..the all in one but everytime i try to load a prog it gives me runtime errors, the ones are runtime error 440 and runtime error 9, i have snipped a cpl pix of what i see.. i seem to be missing some sort of microsoft files... for runtime??? c+++ i may have a few more if these dont give u an idea of what is happening... i posted the log on the 1st post for u from the adwcleaner log..
 

Attachments

  • eventlog.JPG
    eventlog.JPG
    116.2 KB · Views: 139
  • issue01.JPG
    issue01.JPG
    116.8 KB · Views: 146
  • issue2.52713.JPG
    issue2.52713.JPG
    39 KB · Views: 130
  • issue02.JPG
    issue02.JPG
    126.3 KB · Views: 139
  • issue03.JPG
    issue03.JPG
    153.6 KB · Views: 144

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
oh and i am running a scan right now and just found the trojan dropper again.... will snip a pic of it... running scan still will let u know if anymore pop up but again it is the chrome file..
 

Attachments

  • trodrop.JPG
    trodrop.JPG
    95.2 KB · Views: 149

Fiery

Level 1
Jan 11, 2011
2,007
Try this.

Open notepad and copy & paste the following:

2013-05-14 15:07 - 2013-05-28 15:39 - 00000420 ____A C:\Windows\Tasks\PC Optimizer Pro64 startups.job
2013-05-14 15:07 - 2013-05-14 15:07 - 00000000 ____D C:\ProgramData\PC Optimizer Pro
2013-05-14 15:07 - 2013-05-14 15:07 - 00000000 ____D C:\ProgramData\Application Data\PC Optimizer Pro
C:\WINDOWS\SYSWOW64\ADOBE\SHOCKWAVE 12\LAUNCHGOOGLECHROME.EXE

and save it as fixlist.txt onto your flash drive.

Then, boot to system recovery, plug in your flash drive, open FRST and click fix. Post the generated log.
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
i just tried to re dl the all in one and it said it couldnt create uninstall shortcut??? i just dunno what to do anymore.. if i try to add remove progs it doesnt let me.. is there another way to see what microsoft files im missing that isnt letting me do this? i tried system restores but i didnt try the last known good configuration yet...should i?
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
Fiery said:
Try this.

Open notepad and copy & paste the following:

2013-05-14 15:07 - 2013-05-28 15:39 - 00000420 ____A C:\Windows\Tasks\PC Optimizer Pro64 startups.job
2013-05-14 15:07 - 2013-05-14 15:07 - 00000000 ____D C:\ProgramData\PC Optimizer Pro
2013-05-14 15:07 - 2013-05-14 15:07 - 00000000 ____D C:\ProgramData\Application Data\PC Optimizer Pro
C:\WINDOWS\SYSWOW64\ADOBE\SHOCKWAVE 12\LAUNCHGOOGLECHROME.EXE

and save it as fixlist.txt onto your flash drive.

Then, boot to system recovery, plug in your flash drive, open FRST and click fix. Post the generated log.

ok, doing this now...
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
Gbaby614 said:
Fiery said:
Try this.

Open notepad and copy & paste the following:

2013-05-14 15:07 - 2013-05-28 15:39 - 00000420 ____A C:\Windows\Tasks\PC Optimizer Pro64 startups.job
2013-05-14 15:07 - 2013-05-14 15:07 - 00000000 ____D C:\ProgramData\PC Optimizer Pro
2013-05-14 15:07 - 2013-05-14 15:07 - 00000000 ____D C:\ProgramData\Application Data\PC Optimizer Pro
C:\WINDOWS\SYSWOW64\ADOBE\SHOCKWAVE 12\LAUNCHGOOGLECHROME.EXE

and save it as fixlist.txt onto your flash drive.

Then, boot to system recovery, plug in your flash drive, open FRST and click fix. Post the generated log.

ok, doing this now...

please forgive me, but I just lost ya somewhere on this, I did exactly as u said and copied the file to the flash drive and when i tried to go into recovery mode, and it asked for command prompt, i then opened frst, and it opened it in notebook everytime that i tried in a ascii type text... i did something wrong somewhere, so pls, for my sake, type step by step what i need to do so i can see where i went wrong... i am losong my mind at this point bc i feel horrible today, but i refuse to give up until this is cleared up... i just cant afford to be w/o this pc... thx again
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
i really hope i get back to u before u respond to the last msg, i did it over n over til i figured out what was wrong.. and here is the log: FINALLY LOL:
 

Attachments

  • Fixlog.txt
    318 bytes · Views: 108

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
i also think this is the page that has the missing frameworks i need... but not sure what ones.. http://msdn.microsoft.com/en-us/library/vstudio/w0x726c2.aspx
 

Fiery

Level 1
Jan 11, 2011
2,007
Gbaby614 said:
i really hope i get back to u before u respond to the last msg, i did it over n over til i figured out what was wrong.. and here is the log: FINALLY LOL:

Did you copy and paste the entire script? The fix log only fixed the first entry :s

When you have made fixlist.txt, put it on the USB. Don't open that txt file again. Go into system recovery, command prompt, start FRST and just press fix

The entire script is

start
2013-05-14 15:07 - 2013-05-28 15:39 - 00000420 ____A C:\Windows\Tasks\PC Optimizer Pro64 startups.job
2013-05-14 15:07 - 2013-05-14 15:07 - 00000000 ____D C:\ProgramData\PC Optimizer Pro
2013-05-14 15:07 - 2013-05-14 15:07 - 00000000 ____D C:\ProgramData\Application Data\PC Optimizer Pro
C:\WINDOWS\SYSWOW64\ADOBE\SHOCKWAVE 12\LAUNCHGOOGLECHROME.EXE
end
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
this is the log it produced after the second try..
 

Attachments

  • Fixlog.txt
    245 bytes · Views: 85

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
I'm hoping that u were able to see what was going on with my pc from that log, I still have the trojan droper in quarantine w antispyware bc I wanted to be able to give u the location if needed, I do know it has something to do w the chrome app, which dl'ed when my son allowed an arcade game on here, it also dl'ed a phone app called kinect or something of that nature, along with the pc optimizer pro, and i found many things that i tried to remove manually, and just havent been able to load windows security essitials since.. i know something is on here, its just hiding really well.. and i cant even dl anything at this point that might help in finding it.. but I will be checking back periodically to see if u have responded..
 

Fiery

Level 1
Jan 11, 2011
2,007
Odd, can you go manually delete the following file and folders:

C:\Windows\Tasks\PC Optimizer Pro64 startups.job
C:\ProgramData\PC Optimizer Pro
C:\ProgramData\Application Data\PC Optimizer Pro

You may have to enable hidden files and folders. (here is how: http://windows.microsoft.com/en-ca/windows-vista/show-hidden-files).

Also, you know the location of the trojan dropper right? Upload it to virustotal for a scan.

Please visit www.virustotal.com
  • Click the Choose file... button
  • Navigate to the file
  • Click the Open button
  • Click the Scan It button
  • Copy and paste the results back here.

Download Malwarebytes Anti-Rootkit from here to your Desktop
  • Unzip the contents to a folder on your Desktop.
  • Open the folder where the contents were unzipped and run mbar.exe
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • Make sure there is a check next to Create Restore Point and click the Cleanup button to remove any threats. Reboot if prompted to do so.
  • After the reboot, perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If there are threats, click Cleanup once more and reboot.
  • When done, please post the two logs in the MBAR folder(mbar-log.txt and system-log.txt)
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
so far I have tried to delete those folders manually, I wasnt able to even find them all but i did delete 1 of them, it was the 2nd one you listed, I havent been able to dl anything lately but Im going to try to dl the anti rootkit again, i know i tried to dl antimalware a few times and it kept giving runtime errors, i get a runtime error upon reboot too still, i think i tried to msg u about it and the pc shut off in mid sentence, so i will go try again now, brb
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
Im not able to save pics and certain progs to my pc.. its saying im having errors, and runtime errors, something about the .NET Framework Data Providers require Microsoft Data Access Components (MDAC) Please install Microsoft Data Access Components (MDAC) version 2.6 or later
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top