I got a virus that turned off Microsoft Essentials and prevented me from starting it. I tried getting other programs to remove it but i believe that the virus also disabled Microsoft installer. My skype wont start properly along with other programs i use daily taking an extremely long time to start then starts to not respond. Any scans I perform come up empty and any attepmt to start microsoft defender says, file not found did you type it in correctly, or something like that despite me opening it from it's specific folder in program files. Renaming the application in a copy paste version of that folder will let me start it but cant do much from there. Thank you for your time anyone that reads this and thank you in advance for any help offered.

Recommended Answers

All 22 Replies

Have you tried Malwarebytes? If the installation is blocked you may also need to try Malwarebytes Chameleon.

"Windows could not find c:.....malwarebyte make sure it is typed in correctly"
And here is the RougeKiller log:

RogueKiller V8.7.13 x64 [Dec 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.adlice.com/forum/
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : 00000000000000000000 [Admin rights]
Mode : Scan -- Date : 12/19/2013 17:23:08
| ARK || FAK || MBR |

¤¤¤ Bad processes : 3 ¤¤¤
[SUSP PATH] msconfig.exe -- C:\ProgramData{$7187-6415-6885-1855$}\msconfig.exe [-] -> KILLED [TermProc]
[SUSP PATH] mseinstall.exe -- C:\Users\00000000000000000000\Desktop\mseinstall.exe [7] -> KILLED [TermProc]
[HIDDEN] msconfig.exe -- C:\ProgramData{$7187-6415-6885-1855$}\msconfig.exe [-] -> KILLED [TermProc]

¤¤¤ Registry Entries : 25 ¤¤¤
[RUN][SUSP PATH] HKCU[...]\Run : Browser Protect (C:\Users\00000000000000000000\AppData\Local\Temp\Browser Protect\Browser Protect.exe [-]) -> FOUND
[SHELL][SUSP PATH] HKCU[...]\Windows : load (C:\ProgramData{$7187-6415-6885-1855$}\msconfig.exe [-]) -> FOUND
[IFEO] HKLM[...]\avcenter.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\avguard.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\avp.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\bdagent.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\ccuac.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\ComboFix.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\egui.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\hijackthis.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\keyscrambler.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\mbam.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\MpCmdRun.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\MSASCui.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\MsMpEng.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\msseces.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\NisSrv.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\spybotsd.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\wireshark.exe : Debugger (nsjw.exe [x]) -> FOUND
[IFEO] HKLM[...]\zlclient.exe : Debugger (nsjw.exe [x]) -> FOUND
[HJ][PUM] HKLM[...]\Wow6432Node[...]\SystemRestore : DisableSR (1) -> FOUND
[HJ SMENU][PUM] HKCU[...]\Advanced : Start_ShowMyPics (0) -> FOUND
[HJ SMENU][PUM] HKCU[...]\Advanced : Start_ShowMyMusic (0) -> FOUND
[HJ DESK][PUM] HKLM[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK][PUM] HKLM[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Scheduled tasks : 0 ¤¤¤

¤¤¤ Startup Entries : 0 ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED 0x0] ¤¤¤

¤¤¤ External Hives: ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts

¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: (\.\PHYSICALDRIVE0 @ IDE) TOSHIBA DT01ACA100 ATA Device +++++
--- User ---
[MBR] 1d652e16b25a11d5522b2474eb0e1685
[BSP] 817ff837094291983d34add63df2087b : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 953767 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[0]_S_12192013_172308.txt >>

Re-scan with RogueKiller and have it remove everything except:

[HJ SMENU][PUM] HKCU[...]\Advanced : Start_ShowMyPics (0) -> FOUND
[HJ SMENU][PUM] HKCU[...]\Advanced : Start_ShowMyMusic (0) -> FOUND
[HJ DESK][PUM] HKLM[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK][PUM] HKLM[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

If you intentionally disabled System Restore, then uncheck:

[HJ][PUM] HKLM[...]\Wow6432Node[...]\SystemRestore : DisableSR (1) -> FOUND

Reboot - MSE + Malwarebytes should be able to run.

Between Rougekiller and malwarebytes I was able to get essentials to reinstal and launch. I am now doing a full scan with it but my skype still has issues starting. Once it is up it seems to run somewhat smoothly until someone calls me. Also, when logging into my League of Legends account I get "did not receive a response from server" and it tells me to make sure windows is up to date and I have no idea where to update it since I cant seem to from my computer.

it tells me to make sure windows is up to date and I have no idea where to update it since I cant seem to from my computer.

Do you mean that Windows Update will not run?

Run Junkware Removal Tool, reboot, then run DDS. Run another scan with RogueKiller, then post the logs from all scans.

Sorry if I was unclear but my skype runs awful and windows update does run but has not helped after I just updated it. Running services, microsoft management console stops responding. I feel like the virus took or shut down something that made these things run smoothly.

Have you run the scans with JRT and DDS?

Running services, microsoft management console stops responding.

I'll look at this once I see your logs.

JRT:
~~~ Services

~~~ Registry Values

Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\dw7
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\{ae07101b-46d4-4a98-af68-0333ea26e113

~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\nctaudiocdgrabber2.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID{3C471948-F874-49F5-B338-4F214A2EE0B1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID{FB684D26-01F4-4D9D-87CB-F486BEBA56DC
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\bi
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\smartbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\visualbee
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduitsearchscopes
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\crossrider
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\smartbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\installiq
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\visualbee
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\s
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\quickshare_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\quickshare_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\webcakedesktop_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\webcakedesktop_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3287806
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3291326
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_for_free-sound-recorder_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_for_free-sound-recorder_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\ApnSetup_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\ApnSetup_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_for_free-sound-recorder_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_for_free-sound-recorder_RASMANCS
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes{CACA0828-9262-4FDB-B3C9-E0B46C9CACDF

~~~ Files

Successfully deleted: [File] "C:\Users\00000000000000000000\appdata\local\google\chrome\user data\default\local storage\http_app.mam.conduit.com_0.localstorage"
Successfully deleted: [File] "C:\Users\00000000000000000000\appdata\local\google\chrome\user data\default\local storage\http_app.mam.conduit.com_0.localstorage-journal"
Successfully deleted: [File] "C:\end"

~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Folder] "C:\ProgramData\tarma installer"
Successfully deleted: [Folder] "C:\ProgramData\trymedia"
Successfully deleted: [Folder] "C:\Users\00000000000000000000\AppData\Roaming\drivercure"
Successfully deleted: [Folder] "C:\Users\00000000000000000000\appdata\local\conduit"
Successfully deleted: [Folder] "C:\Users\00000000000000000000\appdata\local\cre"
Successfully deleted: [Folder] "C:\Users\00000000000000000000\appdata\local\webplayer"
Successfully deleted: [Folder] "C:\Users\00000000000000000000\appdata\locallow\conduit"
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"

~~~ Chrome

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\bicnnkjibmphdeigoodpjlcklcnaobdj

~~~ Event Viewer Logs were cleared

Scan was completed on Thu 12/19/2013 at 22:10:19.03
End of JRT log

Could not post DDS because of code snippets formated incorrectly in this post.

Just click on the paperclip in the toolbar and attach the DDS logs.

DDS

There's a bit of junk to remove and outdated java to uninstall. Also Skype seems to be corrupted.
Download OTL and save it to your desktop. Click on Run Scan.
When it has finished, there'll be 2 logs created. Attach the logs to your post.

Otl

The latest Java JRE version is 7 Update 45, uninstall all older versions from Programs and Features.
Java 7 Update 25
Java 7 Update 40

Download the updated version (if needed) from http://www.oracle.com/technetwork/java/javase/downloads/jre7-downloads-1880261.html

Run OTL, paste the content of the following code box into the main window, then click Run Fix. (double click in the code box to select all, then right click copy)

:OTL
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O32 - AutoRun File - [2013/12/02 18:34:50 | 000,013,547 | ---- | M] () - C:\autoupdate.log -- [ NTFS ]

:Commands
[EMPTYFLASH]
[EMPTYJAVA]
[EMPTYTEMP]

Reboot your PC if it doesn't automatically do so. Post the log.
Go to start menu -> all programs -> accessories -> right click on command prompt and Run as administrator.
At the command prompt, type in SFC /SCANNOW press Enter. Let me know if it finds any errors that can't be fixed.

All processes killed
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\{ae07101b-46d4-4a98-af68-0333ea26e113} deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{ae07101b-46d4-4a98-af68-0333ea26e113}\ deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\Locked deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found.
C:\autoupdate.log moved successfully.
========== COMMANDS ==========

[EMPTYFLASH]

User: 00000000000000000000
->Flash cache emptied: 84412 bytes

User: All Users

User: Default
->Flash cache emptied: 57616 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Public

User: UpdatusUser

Total Flash Files Cleaned = 0.00 mb

[EMPTYJAVA]

User: 00000000000000000000
->Java cache emptied: 16634297 bytes

User: All Users

User: Default

User: Default User

User: Public

User: UpdatusUser

Total Java Files Cleaned = 16.00 mb

[EMPTYTEMP]

User: 00000000000000000000
->Temp folder emptied: 788861269 bytes
->Temporary Internet Files folder emptied: 464362049 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 525352960 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 200704 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 543700293 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 88915 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 42287446 bytes
%systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 630 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 2,255.00 mb

OTL by OldTimer - Version 3.2.69.0 log created on 12212013_003302

Files\Folders moved on Reboot...
C:\Users\00000000000000000000\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\00000000000000000000\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

And the command prompt said corrupt files found and fixed no errors.

And the command prompt said corrupt files found and fixed no errors.

Open an elevated command prompt as before and paste in the following:
findstr /c:"[SR] Cannot" %windir%\logs\cbs\cbs.log >"%userprofile%\Desktop\sfcdetails.txt"

If the sfcdetails.txt saved to your desktop isn't an empty file, attach it to your post. Hopefully this will show how much file corruption there is.

cmd said cannot open c:\windows...
and the file saved to desktop was blank

It's likely that MSE accessed the file, blocking you from reading it. Try temporarily disabling MSE protection, then open a new elevated cmd prompt and try again.

nope

Go to %windir%\logs\cbs\cbs.log and see if you can copy/paste the log to your desktop.
If successful try again with command:
findstr /c:"[SR] Cannot" "%userprofile%\Desktop\cbs.log" >"%userprofile%\Desktop\sfcdetails.txt"

Hi,

You can use Norton Anti Virus to get rig of the virus.

Regards,
JP

use avg antivirus free it will remove any malware or virus

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.