Author Topic: HitmanPro Unwanted Programs and Emsisoft  (Read 2478 times)

Offline UncleDoug

  • Comodo's Hero
  • *****
  • Posts: 651
Re: HitmanPro Unwanted Programs and Emsisoft
« Reply #15 on: August 12, 2015, 04:06:14 PM »
You should not run Zoek with custom scripts,it may cause serious damage.

Sorry but I thought you requested I do ?

" Run tool as Administrator and input following script :

Code: [Select]

createsrpoint;
emptyalltemp;
emptyclsid;
chrdefaults;
FFdefaults;


Push Run script button once and wait when it's done, if requires a reboot allow it to do so. "

Offline UncleDoug

  • Comodo's Hero
  • *****
  • Posts: 651
Re: HitmanPro Unwanted Programs and Emsisoft
« Reply #16 on: August 12, 2015, 04:17:12 PM »
Re-run FRST so i can see better look at your system.

I will but wondered if under Advanced I should check none are all of the boxes ?  It seems it can you show you more than a deep scan (If the box is checked ?) 

But I cannot tell IF any of the boxes might show you registry keys that are remnants / traces of Yahoo Toolbar and Default Tab that are shown by HitmanPro  ?

Oops   You said FRST and not ZOEK  will run it and attach it here in a minute

I noticed that FRST also had a Scan File and a Scan Registry Options ?




[attachment deleted by admin]
« Last Edit: August 12, 2015, 04:45:56 PM by UncleDoug »

Offline Silwncer

  • Board moderator
  • Comodo Family Member
  • ***
  • Posts: 92
  • Malware Removal Expert
    • TechForums
Re: HitmanPro Unwanted Programs and Emsisoft
« Reply #17 on: August 14, 2015, 08:21:17 AM »
Sorry for late reply, i was busy. I was meant that you should use my scripts only, not others because they may break your computer. zoek is very powerful tool .

Offline Silwncer

  • Board moderator
  • Comodo Family Member
  • ***
  • Posts: 92
  • Malware Removal Expert
    • TechForums
Re: HitmanPro Unwanted Programs and Emsisoft
« Reply #18 on: August 14, 2015, 08:25:14 AM »
I don't see anything suspicious in logs.

Offline UncleDoug

  • Comodo's Hero
  • *****
  • Posts: 651
Re: HitmanPro Unwanted Programs and Emsisoft
« Reply #19 on: August 14, 2015, 10:50:12 PM »
I was not sure but thought so !

But I would like to remove those traces / remnants of Yahoo Tool Bar and Default Tab that were found by HitmanPro in the Registry !

Hoped you might be able to help me easily do it ?

Also uninstall the Bing Rewards Client Installer that you requested I do at the beginning, BUT I could not find it ?

Thanks
UncleDoug


Offline Silwncer

  • Board moderator
  • Comodo Family Member
  • ***
  • Posts: 92
  • Malware Removal Expert
    • TechForums
Re: HitmanPro Unwanted Programs and Emsisoft
« Reply #20 on: August 15, 2015, 05:27:13 AM »
Scan with Malwarebytes AntiMalware

Download Malwarebytes and install it on your system (Run setup as Administrator).

At the end of installation, uncheck "Enable free trial of Malwarebytes Premium", then click Finish.

Make sure you have latest definitions by clicking on Update Now,then under Scan choose Threat Scan.

After scanning is done, click on Remove if malware is found,tool will ask for restart , allow it to do so.

Attach MBAM log here (you can find it in History > Application Logs).

https://www.malwarebytes.org/

Scan with Zemana Antimalware
 
Download Zemana Antimalware and install it on your system.
 
Under Scan type choose Full Scan and let the tool scan system.
 
If malware is found click Next to remove it, if tool asks for restart, allow it .
 
If no malware is found , just exit program.
 
NOTE: Leave actions at default.

https://zemana.com/

Scan with Norton Power Eraser

CAUTION: NPE uses aggressive methods to detect and remove malware,so do not touch any of settings !

Download NPE by Symantec and save it to your desktop.

Run the tool as Administrator,accept license agreement,and click  Scan button.

Program will ask you to reboot to continue scanning (includes rootkit scan),so allow it to restart.

After restart program will automatically launch itself and start scanning. Scanning takes 5-10 minutes,so be patient !

If malware is detected,make sure that Create restore point option is checked,then click Fix button. After that,click on Restart now to complete removal.

https://security.symantec.com/nbrt/npe.aspx

Offline UncleDoug

  • Comodo's Hero
  • *****
  • Posts: 651
Re: HitmanPro Unwanted Programs and Emsisoft
« Reply #21 on: August 20, 2015, 01:25:41 PM »
Sorry for taking so long on replying.

Quote
Scan with Malwarebytes AntiMalware

Download Malwarebytes and install it on your system (Run setup as Administrator).

At the end of installation, uncheck "Enable free trial of Malwarebytes Premium", then click Finish.

Not sure what I am doing wrong, tried 7 times to download the FREE Trial, E nable Free Trial is checked, and clicked Finish.
Each time the Free Version shows up in the Dashboard.  The only option was to pay for the Premium not the Free Trial ?

Attached is the log and nothing was found.

Quote
Scan with Zemana Antimalware
Found nothing

Quote
Scan with Norton Power Eraser
The Only thing it found was my fault.  Tried to install AdBlock Plus into IE.   When I browsed to the AdBlock Plus site it recognized it was IE but would not install.  In reading the author stated that it does not support IE.

SuperAntispyware found 2 pups and 24 cookies
AdwCleaner found nothing
JRT found nothing
Spybot found around 20 registry key pups but none were those that I listed in the original post.

Tried a few cleanup utilities and again nothing.
Even ran the Kapersky Free scan and Bitdefender Adware Removal Tool, with the same results.

These PuP traces are buried in the registry and until one of the above programs searches for them I will have to wait !

Thanks for trying,
UncleDoug

Offline Silwncer

  • Board moderator
  • Comodo Family Member
  • ***
  • Posts: 92
  • Malware Removal Expert
    • TechForums
Re: HitmanPro Unwanted Programs and Emsisoft
« Reply #22 on: August 20, 2015, 01:50:52 PM »
Free version is enough for scanning and removal. Re-run FRST and attach fresh logs.

Offline UncleDoug

  • Comodo's Hero
  • *****
  • Posts: 651
Re: HitmanPro Unwanted Programs and Emsisoft
« Reply #23 on: August 21, 2015, 12:01:46 AM »
Here are the logs, but I doubt it will show the traces or remnant keys of the PuPs for YahooToolbar or Default Tab from the Original Post.
 
Wondered but doubted that the Registry Scan in Frst would show leftover traces ?

[attachment deleted by admin]

Offline Silwncer

  • Board moderator
  • Comodo Family Member
  • ***
  • Posts: 92
  • Malware Removal Expert
    • TechForums
Re: HitmanPro Unwanted Programs and Emsisoft
« Reply #24 on: August 21, 2015, 03:19:53 AM »
Nothing suspicious found except sites with adult content in hosts.

Offline UncleDoug

  • Comodo's Hero
  • *****
  • Posts: 651
Re: HitmanPro Unwanted Programs and Emsisoft
« Reply #25 on: August 22, 2015, 07:33:54 PM »
As I wondered about earlier, I have not found a program that will scan the registry for traces/remnants of deleted PuPs and allow you to choose what to delete.  At least all the programs I have tried do not find these registry keys.

I think my Host file is being locked by one or more of my security programs.
Any recommendation on how to Clean it and keep it updated ?

 

Offline Silwncer

  • Board moderator
  • Comodo Family Member
  • ***
  • Posts: 92
  • Malware Removal Expert
    • TechForums
Re: HitmanPro Unwanted Programs and Emsisoft
« Reply #26 on: August 23, 2015, 04:04:40 AM »
Fix with Farbar Recovery Scan Tool

 :-La This fix is made for use on that particular machine. Running it on another one may break your system.

Download attached fixlist.txt and save it on same location as FRST, they must be in same location otherwise fix will not work !

Re-run FRST as Administrator, click Fix button once and wait while it's fixing.

It will ask for restart, click OK to do so.

fixlog.txt attach to your reply.



[attachment deleted by admin]

Offline UncleDoug

  • Comodo's Hero
  • *****
  • Posts: 651
Re: HitmanPro Unwanted Programs and Emsisoft
« Reply #27 on: August 23, 2015, 07:32:51 PM »
I have a question before I run the fix

These are 2 photos of my daughter who just moved to Hawaii.  I wonder what kind of problem you saw ? 
Will I lose those photos ?

AlternateDataStreams: C:\Users\Martha\Desktop\Sara in Hawaii  3-22-15.jpg:$CmdZnID
AlternateDataStreams: C:\Users\Martha\Desktop\Sara in White.jpg:$CmdZnID


Thanks
« Last Edit: August 23, 2015, 07:34:40 PM by UncleDoug »

Offline Silwncer

  • Board moderator
  • Comodo Family Member
  • ***
  • Posts: 92
  • Malware Removal Expert
    • TechForums
Re: HitmanPro Unwanted Programs and Emsisoft
« Reply #28 on: August 24, 2015, 12:56:15 AM »
You can back them up if something goes wrong.

 

Seo4Smf 2.0 © SmfMod.Com Smf Destek