This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Malawarebytes Will Not Load, Some Streaming Too [Closed]

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am unable to run my premium Malawarebytes program. 

I have attempted to run the exe. again but, it will not run after I am given the option to run the program.

About the same time this happened, a radio station I listen to online with their Triton Digital player will not load all the way.

This is what I get for letting my daughter use my computer and for me not being careful in making sure my real time defense is turned on.

She apparently had turned it off and I downloaded something from a "legacy" site claiming to have the program Handbrake for my machine type.

I am running Mozilla Firefox as a browser as well as Chrome.

Thanks so much for the help in advance. This is a bit beyond what I can normally handle.

Hmmmm…this is interesting. After posting my troubles, I left my computer on for an hour or so only to return and find a message saying something "catastrophic has happened" and I should report.

Found that I did not have an internet connection….thought a bit, tried a set point restore (no luck)….the finally physically removed my wireless antenna and got things to work again.

Guess this bug developer has thought a lot of things out.

Please help me before I can't post here again!

Hello fodera13606 and welcome to the WTT forum.

Apologies for the delay. My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Run RogueKiller

IMPORTANT: Please remove any usb or external drives from the computer before you run this scan!

Close all running programs.


Download RogueKiller to your desktop


  • close all running programs
  • for Windows Vista/Seven, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
  • when the pre-scan is finished, click on Scan
  • click on Report and copy/paste the content in your next post
  • NOTE: DO NOT attempt to remove anything that the scan detects –everything that is reported is not necessarily bad

If the program is blocked, continue to try it several times. If it still doesn’t work, (it could happen), rename it to winlogon.exe.

Please post the contents of the RKreport.txt in your next reply.

===================================================

Run Farbar Recovery Scan Tool

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • press Scan button
  • it will produce a log called Frst.txt in the same directory the tool is run from
  • please copy and paste log back here.
  • the first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the Frst.txt into your reply.

Logs to include with next post:

RKreport.txt
Frst.txt
Addition.txt


Thanks

Satchfan

 

📎FRST.txt📎Addition.txtHaving difficulty downloading the first program.

Used a different browser to download as I over rid the safety protocol.

Could not open Rogue Killer exe. file.

 

Was able to download the second program and installed it to my desktop.

 

Ran that and posted log(s)

 

Awaiting instructions.

Thanks Satchfan!!!

Thanks for the logs but in future please copy/paste them, not attach them.

 

I’d still like to see a RogueKiller log: please try it again and if it still won’t run, try running it in Safe mode.

 

OK, tried Safe Mode for Rogue Killer and still no luck.

I get a window, click run, the hour glass flashes briefly and then nothing.

Much like when I try to run Malwarebytes only then, no window just a brief flash of the hour glass..

 

Sorry….makes sense to copy and paste in this business. Will do!

Thanks!

OK let’s try it another way. Run these in safe mode also if necessary.


Download zoek.exe to your Desktop:

Important: Disable your AntiVirus and AntiSpyware programs, so they do not interfere with the running of Zoek.exe. You can find instructions how to disable your security applications here.

  • on Windows Vista, 7/8, right-click Zoek.exe and select: Run as Administrator
  • give it a few seconds to appear
  • copy/paste the entire script inside the codebox below into the input field of Zoek:
    createsrpoint;
    autoclean;
    emptyalltemp;
    ipconfig /flushdns;b
    
    
  • close any open programs.
  • click the Run script button, and wait. It takes a few minutes to run.
  • when the tool finishes, the zoek-results.log is opened in Notepad: the log can also be found on the systemdrive, normally C:\
  • if a reboot is needed, the log will be opened after the reboot.

===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.

  • run AdwCleaner
  • when it has finished, select Clean
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

===================================================

Download and run Junkware Removal Tool

[external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.

  • shut down your protection software now to avoid potential conflicts.
  • run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator"
  • the tool will open and start scanning your system
  • please be patient as this can take a while to complete depending on your system's specifications
  • on completion, a log (JRT.txt) is saved to your desktop and will automatically open
  • post the contents of JRT.txt into your next message.

Logs to include with next post:

zoek-results.log
AdwCleaner log
JRT.txt


It's late here now, (UK), so I won't reply again tonight but will get back as soon as other obligations permit.

Thanks

Satchfan

 

Over an hour and this is all I have…safe mode would not open too.

Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by Dad on Tue 07/14/2015 at 21:26:25.25.
Microsoft Windows XP Professional 5.1.2600 Service Pack 3 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Documents and Settings\Dad\Desktop\zoek.exe [Scan all users] [Script inserted] 
 
===== Runcheck 21:28:49.71 =====
 
— Create Environment Variables 21:28:56.06 

Download/run RKill:

Please download RKill from one of the following links and save to your Desktop:

 

Link One
Link Two
Link Three
Link Four

  • double-click on the RKill desktop icon to run the tool
  • a black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully
  • if not, delete the file, then download and use the one provided in Link 2
  • if it does not work, repeat the process and attempt to use one of the remaining links until the tool runs
  • if the tool does not run from any of the links provided, please let me know
  • do not reboot the computer, you will need to run the application again
  • please leave RKill on the Desktop until otherwise advised.

Note: If your security software warns about RKill, please ignore and allow the download to continue.

At this point, you should now be able to run the scans.

Once RKill has run, do NOT reboot the machine before trying to run the scans.

If for some reason the machine reboots, repeat the process. Again, try not to restart the machine before running the scans.
 

 

Satchfan

Tool would not run from any of the links provided. 

The 4th link was a "404 not found"

Tried it in safe mode also. Did not work.

Ran 'Adwcleaner', have a log file but, Chrome will not let me cut and paste here.

'JRT' would not run in any mode.

Chrome will not let me cut and paste here.

 

I have that problem with Firefox here. Try using Ctrl+V to paste the AdwCleaner log. If not, use Internet Explorer.

 

Apologies for the bad links, Try this link for RKill.

Will try the new link.

Still can't copy and paste that adwcleaner log.

This is probably just a mess but, copied and pasted to word……then copy and pasted it here.

If you have and other ideas, I will try. LOL!

 

# AdwCleaner v4.208 - Logfile created 15/07/2015 at 05:50:26

# Updated 09/07/2015 by Xplode

# Database : 2015-07-09.2 [Local]

# Operating system : Microsoft Windows XP Service Pack 3 (x86)

# Username : Dad - PETE-05F6D62355

# Running from : C:\Documents and Settings\Dad\Desktop\adwcleaner_4.208.exe

# Option : Scan

 

***** [ Services ] *****

 

Service Found : mcaudrv_simple

Service Found : ManyCam

 

***** [ Files / Folders ] *****

 

File Found : C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\ndwc8g77.default-1413647459921\searchplugins\search-provided-by-yahoo.xml

File Found : C:\WINDOWS\system32\drivers\mcvidrv.sys

Folder Found : C:\Documents and Settings\All Users\Application Data\EmailNotifier

Folder Found : C:\Documents and Settings\All Users\Start Menu\Programs\Coupons

Folder Found : C:\Documents and Settings\cheryl\Desktop\Snow

Folder Found : C:\Documents and Settings\Dad\Application Data\DriverFinder

Folder Found : C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\ndwc8g77.default-1413647459921\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}

 

***** [ Scheduled tasks ] *****

 

 

***** [ Shortcuts ] *****

 

 

***** [ Registry ] *****

 

Data Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local

Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}

Key Found : HKCU\Software\PRODUCTSETUP

Key Found : HKLM\SOFTWARE\Classes\CLSID\{A07E5BFF-B16C-4ABA-A30F-514213A945E6}

Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}

Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{BC0BF363-63AB-4FF7-8EF1-AE0D7F711B24}

Key Found : HKU\.DEFAULT\Software\AskPartnerNetwork

 

***** [ Web browsers ] *****

 

-\\ Internet Explorer v8.0.6001.18702

 

Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ggbg_15_28¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0EyE0FyE0CyCyDyEyB0BtD0A0C0B0DzytN0D0Tzu0StCtBzzyCtN1L2XzutAtFtCtDtFtCtDtFtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyEtC0Bzz0CyD0B0DtGyDyDyBtAtG0EyBtC0DtGtA0ByByBtG0EtBzy0FtD0BtB0D0A0BtC0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDyDtB0B0B0FtA0BtG0FzytB0BtGyE0ByDtAtG0A0ByDzztGyD0E0FtD0DtDtAtAzytBzyzz2QtN0A0LzuyE%26cr%3D1598730719%26a%3Dwncy_ggbg_15_28%26os%3DWindows XP

 

-\\ Mozilla Firefox v39.0 (x86 en-US)

 

[nw4irwot.default] - Line Found : user_pref("browser.startup.homepage", "hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ggbg_15_28¶m1=1¶m2=f%3D1%26b%3DFirefox%26cc%3Dus%26pa%3DWincy%26cd[…]

 

-\\ Google Chrome v43.0.2357.134

 

[C:\Documents and Settings\Caitlin.PETE-05F6D62355\Local Settings\Application Data\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://websearch.ask.com/redirect?client=cr&src=kw&tb=FWV5&o=14193&locale=en_US&apn_uid=984a32c3-08b0-40c5-a2fe-adb376543ae1&apn_ptnrs=%5EFM&apn_sauid=1B93B4D7-3206-4FF0-BE79-F9985F1A4A92&apn_dtid=%5Epfm013%5EYY%5EUS&q={searchTerms}

[C:\Documents and Settings\Caitlin.PETE-05F6D62355\Local Settings\Application Data\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=w3i&hsimp=yhs-geneiotransfer&type=W3i_IA,206,0_0,StartPage,20120520,18047,0,0,6434&p={searchTerms}

[C:\Documents and Settings\Caitlin.PETE-05F6D62355\Local Settings\Application Data\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://asksearch.ask.com/redirect?client=cr&src=kw&tb=FWV6&o=APN10756&itbv=11.8.1.345&doi=2013-04-13&locale=en_US&apn_uid=567E1225-AB14-40EB-BF4F-958C41C2ECEC&apn_ptnrs=^AUM&apn_dtid=^FRW002^YY^US&apn_dbr=cr_26.0.1410.64&&q={searchTerms}

[C:\Documents and Settings\Caitlin.PETE-05F6D62355\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences] - Found [Extension] : dlnembnfbcpjnepmfjmngjenhhajpdfd

[C:\Documents and Settings\Dad\Local Settings\Application Data\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}

[C:\Documents and Settings\Dad\Local Settings\Application Data\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}

[C:\Documents and Settings\Dad\Local Settings\Application Data\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ggbg_15_28¶m1=1¶m2=f%3D4%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0EyE0FyE0CyCyDyEyB0BtD0A0C0B0DzytN0D0Tzu0StCtBzzyCtN1L2XzutAtFtCtDtFtCtDtFtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyEtC0Bzz0CyD0B0DtGyDyDyBtAtG0EyBtC0DtGtA0ByByBtG0EtBzy0FtD0BtB0D0A0BtC0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDyDtB0B0B0FtA0BtG0FzytB0BtGyE0ByDtAtG0A0ByDzztGyD0E0FtD0DtDtAtAzytBzyzz2QtN0A0LzuyE%26cr%3D1598730719%26a%3Dwncy_ggbg_15_28%26os%3DWindows XP&p={searchTerms}

[C:\Documents and Settings\Dad\Local Settings\Application Data\Google\Chrome\User Data\Default\Secure Preferences] - Found [Homepage] : hxxp://www.facebook.com/","homepage_is_newtabpage":true,"pinned_tabs":[],"prefs":{"preference_reset_time":"13075210944515125"},"profile":{},"protection":{"macs":{"browser":{"show_home_button":"5B69D7F7554BA74BF96D29CD4EF71D73A69634081409B7E8691CD35F2A297482"},"default_search_provider":{"keyword":"A0271C9CA55DD00D1BC4B6BD26313EF6FC6396F40E1922454F53A841D0854FE1","name":"826D898BF1923BA5AFE8CAB366D5F703A79ED112E56B42D708F663AB5D5861CD","search_url":"BC37953A84FDA6AD4A4DF30B6CB09B7627A3D7E187678BBE6990A40A6A5609ED"},"default_search_provider_data":{"template_url_data":"A11FDA19ACD3AF7CC1484F30F8F544EC4C2E7159B0831A62373006AB83844E38"},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":"33EBEEF6D460B25D591D80040F30FB23E60C535E9C64DDDDEAEA503E24F8179D","amfclgbdpgndipgoegfpkkgobahigbcl":"1CF5276CC7EAC6D02A6CAD9E0F75B3AC9608094FC44D1C6472B5A3879E863E72","bepbmhgboaologfdajaanbcjmnhjmhfn":"81A94BB1B1D18D27320D0A3E34C89BEED2C628C4DAB7200057A8BAB3E9DA9B10","bojhhinnlgdmcajekighmiiehpofkodp":"D229F6C833D78F164B96F0E67B986AAB5D53DAFB62D9A00CDB926285E8B406B6","bopakagnckmlgajfccecajhnimjiiedh":"35E3CD88A89BB3C58C7A7531765891A4405B2FB77FEEA1C1C3EEF28C6A035A2D","dnhpdliibojhegemfjheidglijccjfmc":"F6F5CAA445C4E5B2118035B1821FDDF80854A81CDEC145BE0DD935CB0CE45ED4","eemcgdkfndhakfknompkggombfjjjeno":"6AFD4F90AD939C69355B47D8F045B6A2EA6CAFD65B13F9F5ECF19085C3C9F46E","ennkphjdgehloodpbhlhldgbnhmacadg":"FADC08282A52307B2D203CEE5BA56D6ABF8FE4252AF1C9468B5017A16AA408C7","gfdkimpbcpahaombhbimeihdjnejgicl":"9479C987C1FC609FB84E977AEDFDF3188931B6C6976F266CAE51C16BF7AF7CAC","idhngdhcfkoamngbedgpaokgjbnpdiji":"5C3B54282E4E5C5ADD83F50F95DF9CDE32C9D63413005F47F0554944CF03D7A2","jfmjfhklogoienhpfnppmbcbjfjnkonk":"9FB416FE73446D2B65191920D114F5127C7C0AC59D69C8F22454322CFF2A0E9B","kmendfapggjehodndflmmgagdbamhnfd":"A910CA9E1892F40AD075980B62F4E490D0F96175B9CAD34C2DA477997914EE13","knipolnnllmklapflnccelgolnpehhpl":"3F88EE913FFC0CD1C89107436513A8DDD5ACFCB252B6655C56712A3C5E2A9710","lccekmodgklaepjeofjdjpbminllajkg":"554433AF9605A4E8CA34DBE0B855D0B4EFA0EBF763020E825E45DCCDD06CFF8B","mfehgcgbbipciphmccgaenjidiccnmng":"0581B0BF2F63515A1F103FBEF55A12D5451D7AD290E327E0AB9504C8CC9591F0","mgndgikekgjfcpckkfioiadnlibdjbkf":"7C3C83981E19375237344300F3F473F180AF8FCE5B3E699F54F32BC4DA8CF7D2","mhjfbmdgcfjbbpaeojofohoefgiehjai":"AD30DADF6006A053B42A9A000AB406BC3EF9F0E84584D572196127FF58A3E141","nbpagnldghgfoolbancepceaanlmhfmd":"8F9D33A3644BF3DDA0C50C9B94417EBAB18153796009A81A483E9AB924266767","neajdppkdcdipfabeoofebfddakdcjhd":"EDB0757096059D696226E3C0022AB73F151944BD5D591AB5FEE54FE48B2B9A40","nkeimhogjdpnpccoofpliimaahmaaome":"71700DF94F2B48567C64ACB5DB5A550B93804A79ADB124FB0F7C795857861C32","nmmhkkegccagdldgiimedpiccmgmieda":"5DE0E41CB1F9115AEB37D494B157CAC0F00DE1C5268ECCAC72209BB7AC655030","pafkbggdmjlpgkdkcbjmhmfcdpncadgh":"905FAA1356088F0000755E1D5AEA94CD2842D2808CAA5D286D298283EBD8B5DB"}},"google":{"services":{"last_username":"A7DBAD28CE157B90C29AB574FD2871747F65780B1D259CFA7CAE55DC7A1877D8","username":"96C83021AF8B5B3C9D0D8F3DD6CD6D82351AD01F5DE92034298564EEEB8B63EC"}},"homepage":"37E8BE3DE0467F5D15F53BA165AB0853ECADB1D719D1EE6B67D346D9E3E70A88","homepage_is_newtabpage":"488A2073EA1A775539F83985321B6C115F08674C1C4F7FB40A6411B1D8DE1A70","pinned_tabs":"594591AEC5B0BF19A8091CAA2E0D4D7699218C6DF41BCE7A7C5D135C916B28F4","prefs":{"preference_reset_time":"0CC2A58573DD4630C70FA937F813D0C1AC044D97895C618E8E008A30B6DE5631"},"profile":{"reset_prompt_memento":"DBF8556779CAB29FCF58D192E68A7629F75E14B605685E106A3309CB2486A430"},"safebrowsing":{"incidents_sent":"0F9001D53E70AC6863FE9F01BF97388C3CBCC6D38D5749221BC3CE196E1AF758"},"search_provider_overrides":"EAAF6EDF3E07776A16EB5CB3A909BA10AF019E3C18F53C6CD815EB7CFEFF67B2","session":{"restore_on_startup":"65F16225C0E642DEDF2B9F544E924B4ACE07267118A89E771A97EAF8A2BB390D","startup_urls":"E0802A2FAD019D425203BFFF79C0908356B91CDFFD2D92EE04E0EC10D5071B15"},"software_reporter":{"prompt_reason":"40C30C3DE4D767EFC3C66FAF317948A88CFCDA87B51359B8E26528FC6ACD9717","prompt_seed":"CE5679A05AEA3C35995C726DB537A22B9555F294ABC08D1CDE0149545E46FAC5","prompt_version":"FB32623349008D3B28C06C18470ECFBB7D157AD8767A4B21AE030B3AB02839FF"},"sync":{"remaining_rollback_tries":"66DC598B611DCCCF413774880DB3BA36D6C14BF286B18EBF97D28825C59BF3CC"}},"super_mac":"B38C541EEB7266EC3C6E309CB4E86B680274BB4425A007AFFCD1B8D6B045FFEE"},"session":{"restore_on_startup":5,"startup_urls":["hxxps://www.facebook.com/","hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ggbg_15_28¶m1=1¶m2=f%3D7%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0EyE0FyE0CyCyDyEyB0BtD0A0C0B0DzytN0D0Tzu0StCtBzzyCtN1L2XzutAtFtCtDtFtCtDtFtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyEtC0Bzz0CyD0B0DtGyDyDyBtAtG0EyBtC0DtGtA0ByByBtG0EtBzy0FtD0BtB0D0A0BtC0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDyDtB0B0B0FtA0BtG0FzytB0BtGyE0ByDtAtG0A0ByDzztGyD0E0FtD0DtDtAtAzytBzyzz2QtN0A0LzuyE%26cr%3D1598730719%26a%3Dwncy_ggbg_15_28%26os%3DWindows XP

[C:\Documents and Settings\Dad\Local Settings\Application Data\Google\Chrome\User Data\Default\Secure Preferences] - Found [Startup_URLs] : E0802A2FAD019D425203BFFF79C0908356B91CDFFD2D92EE04E0EC10D5071B15"},"software_reporter":{"prompt_reason":"40C30C3DE4D767EFC3C66FAF317948A88CFCDA87B51359B8E26528FC6ACD9717","prompt_seed":"CE5679A05AEA3C35995C726DB537A22B9555F294ABC08D1CDE0149545E46FAC5","prompt_version":"FB32623349008D3B28C06C18470ECFBB7D157AD8767A4B21AE030B3AB02839FF"},"sync":{"remaining_rollback_tries":"66DC598B611DCCCF413774880DB3BA36D6C14BF286B18EBF97D28825C59BF3CC"}},"super_mac":"B38C541EEB7266EC3C6E309CB4E86B680274BB4425A007AFFCD1B8D6B045FFEE"},"session":{"restore_on_startup":5,"startup_urls":["hxxps://www.facebook.com/","hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ggbg_15_28¶m1=1¶m2=f%3D7%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0EyE0FyE0CyCyDyEyB0BtD0A0C0B0DzytN0D0Tzu0StCtBzzyCtN1L2XzutAtFtCtDtFtCtDtFtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyEtC0Bzz0CyD0B0DtGyDyDyBtAtG0EyBtC0DtGtA0ByByBtG0EtBzy0FtD0BtB0D0A0BtC0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDyDtB0B0B0FtA0BtG0FzytB0BtGyE0ByDtAtG0A0ByDzztGyD0E0FtD0DtDtAtAzytBzyzz2QtN0A0LzuyE%26cr%3D1598730719%26a%3Dwncy_ggbg_15_28%26os%3DWindows XP

 

*************************

 

AdwCleaner[R0].txt - [8700 bytes] - [14/10/2014 20:08:02]

AdwCleaner[R1].txt - [1394 bytes] - [15/10/2014 18:31:25]

AdwCleaner[R2].txt - [1454 bytes] - [15/10/2014 18:39:10]

AdwCleaner[R3].txt - [1568 bytes] - [16/10/2014 07:29:55]

AdwCleaner[R4].txt - [11809 bytes] - [15/07/2015 05:50:26]

AdwCleaner[S0].txt - [8598 bytes] - [14/10/2014 20:14:30]

AdwCleaner[S1].txt - [1184 bytes] - [15/10/2014 18:45:49]

AdwCleaner[S2].txt - [1298 bytes] - [16/10/2014 07:37:03]

 

########## EOF - C:\AdwCleaner\AdwCleaner[R4].txt - [12046 bytes] ##########

Sorry, I am not having any luck getting RKill to run on my computer.

I can download the files fine but, when I go to open them I cannot.

Just like my Malwarebytes program.

Looks as though someone knows what programs are used to combat the malware and has prevented them from running.

You did well to get AdwCleaner to work but didn't follow the instructions.

 

  • run AdwCleaner
  • when it has finished, select Clean
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

Satchfan

 

# AdwCleaner v4.208 - Logfile created 15/07/2015 at 18:13:30

# Updated 09/07/2015 by Xplode

# Database : 2015-07-15.1 [Server]

# Operating system : Microsoft Windows XP Service Pack 3 (x86)

# Username : Dad - PETE-05F6D62355

# Running from : C:\Documents and Settings\Dad\Desktop\adwcleaner_4.208.exe

# Option : Cleaning

 

***** [ Services ] *****

 

[#] Service Deleted : mcaudrv_simple

[#] Service Deleted : ManyCam

 

***** [ Files / Folders ] *****

 

Folder Deleted : C:\Documents and Settings\All Users\Application Data\EmailNotifier

Folder Deleted : C:\Documents and Settings\All Users\Start Menu\Programs\Coupons

[!] Folder Deleted : C:\Documents and Settings\cheryl\Desktop\Snow

Folder Deleted : C:\Documents and Settings\Dad\Application Data\DriverFinder

Folder Deleted : C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\ndwc8g77.default-1413647459921\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}

File Deleted : C:\WINDOWS\system32\drivers\mcvidrv.sys

File Deleted : C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\ndwc8g77.default-1413647459921\searchplugins\search-provided-by-yahoo.xml

 

***** [ Scheduled tasks ] *****

 

 

***** [ Shortcuts ] *****

 

 

***** [ Registry ] *****

 

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A07E5BFF-B16C-4ABA-A30F-514213A945E6}

Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}

Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}

Key Deleted : HKCU\Software\PRODUCTSETUP

Key Deleted : HKU\.DEFAULT\Software\AskPartnerNetwork

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{BC0BF363-63AB-4FF7-8EF1-AE0D7F711B24}

Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local

 

***** [ Web browsers ] *****

 

-\\ Internet Explorer v8.0.6001.18702

 

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]

 

-\\ Mozilla Firefox v39.0 (x86 en-US)

 

[nw4irwot.default\prefs.js] - Line Deleted : user_pref("browser.startup.homepage", "hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ggbg_15_28¶m1=1¶m2=f%3D1%26b%3DFirefox%26cc%3Dus%26pa%3DWincy%26cd[…]

 

-\\ Google Chrome v43.0.2357.134

 

[C:\Documents and Settings\Caitlin.PETE-05F6D62355\Local Settings\Application Data\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://websearch.ask.com/redirect?client=cr&src=kw&tb=FWV5&o=14193&locale=en_US&apn_uid=984a32c3-08b0-40c5-a2fe-adb376543ae1&apn_ptnrs=%5EFM&apn_sauid=1B93B4D7-3206-4FF0-BE79-F9985F1A4A92&apn_dtid=%5Epfm013%5EYY%5EUS&q={searchTerms}

[C:\Documents and Settings\Caitlin.PETE-05F6D62355\Local Settings\Application Data\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=w3i&hsimp=yhs-geneiotransfer&type=W3i_IA,206,0_0,StartPage,20120520,18047,0,0,6434&p={searchTerms}

[C:\Documents and Settings\Caitlin.PETE-05F6D62355\Local Settings\Application Data\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://asksearch.ask.com/redirect?client=cr&src=kw&tb=FWV6&o=APN10756&itbv=11.8.1.345&doi=2013-04-13&locale=en_US&apn_uid=567E1225-AB14-40EB-BF4F-958C41C2ECEC&apn_ptnrs=^AUM&apn_dtid=^FRW002^YY^US&apn_dbr=cr_26.0.1410.64&&q={searchTerms}

[C:\Documents and Settings\Caitlin.PETE-05F6D62355\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences] - Deleted [Extension] : dlnembnfbcpjnepmfjmngjenhhajpdfd

[C:\Documents and Settings\Dad\Local Settings\Application Data\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}

[C:\Documents and Settings\Dad\Local Settings\Application Data\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}

[C:\Documents and Settings\Dad\Local Settings\Application Data\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ggbg_15_28¶m1=1¶m2=f%3D4%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0EyE0FyE0CyCyDyEyB0BtD0A0C0B0DzytN0D0Tzu0StCtBzzyCtN1L2XzutAtFtCtDtFtCtDtFtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyEtC0Bzz0CyD0B0DtGyDyDyBtAtG0EyBtC0DtGtA0ByByBtG0EtBzy0FtD0BtB0D0A0BtC0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDyDtB0B0B0FtA0BtG0FzytB0BtGyE0ByDtAtG0A0ByDzztGyD0E0FtD0DtDtAtAzytBzyzz2QtN0A0LzuyE%26cr%3D1598730719%26a%3Dwncy_ggbg_15_28%26os%3DWindows XP&p={searchTerms}

[C:\Documents and Settings\Dad\Local Settings\Application Data\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Homepage] :

[C:\Documents and Settings\Dad\Local Settings\Application Data\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Startup_URLs] : E0802A2FAD019D425203BFFF79C0908356B91CDFFD2D92EE04E0EC10D5071B15"},"software_reporter":{"prompt_reason":"40C30C3DE4D767EFC3C66FAF317948A88CFCDA87B51359B8E26528FC6ACD9717","prompt_seed":"CE5679A05AEA3C35995C726DB537A22B9555F294ABC08D1CDE0149545E46FAC5","prompt_version":"FB32623349008D3B28C06C18470ECFBB7D157AD8767A4B21AE030B3AB02839FF"},"sync":{"remaining_rollback_tries":"66DC598B611DCCCF413774880DB3BA36D6C14BF286B18EBF97D28825C59BF3CC"}},"super_mac":"B38C541EEB7266EC3C6E309CB4E86B680274BB4425A007AFFCD1B8D6B045FFEE"},"session":{"restore_on_startup":5,"startup_urls":["hxxps://www.facebook.com/","hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ggbg_15_28¶m1=1¶m2=f%3D7%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0EyE0FyE0CyCyDyEyB0BtD0A0C0B0DzytN0D0Tzu0StCtBzzyCtN1L2XzutAtFtCtDtFtCtDtFtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyEtC0Bzz0CyD0B0DtGyDyDyBtAtG0EyBtC0DtGtA0ByByBtG0EtBzy0FtD0BtB0D0A0BtC0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDyDtB0B0B0FtA0BtG0FzytB0BtGyE0ByDtAtG0A0ByDzztGyD0E0FtD0DtDtAtAzytBzyzz2QtN0A0LzuyE%26cr%3D1598730719%26a%3Dwncy_ggbg_15_28%26os%3DWindows XP

 

*************************

 

AdwCleaner[R0].txt - [8700 bytes] - [14/10/2014 20:08:02]

AdwCleaner[R1].txt - [1394 bytes] - [15/10/2014 18:31:25]

AdwCleaner[R2].txt - [1454 bytes] - [15/10/2014 18:39:10]

AdwCleaner[R3].txt - [1568 bytes] - [16/10/2014 07:29:55]

AdwCleaner[R4].txt - [12126 bytes] - [15/07/2015 05:50:26]

AdwCleaner[R5].txt - [12187 bytes] - [15/07/2015 18:07:11]

AdwCleaner[S0].txt - [8598 bytes] - [14/10/2014 20:14:30]

AdwCleaner[S1].txt - [1184 bytes] - [15/10/2014 18:45:49]

AdwCleaner[S2].txt - [1298 bytes] - [16/10/2014 07:37:03]

AdwCleaner[S3].txt - [6673 bytes] - [15/07/2015 18:13:30]

 

########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [6732  bytes] ##########

 

Google Chrome browser now inoperative. Will wait for instruction.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI