pLEASE NEED HELP TO GET RID OF tROGEN

Ok give it another shot with attaching the logs and see what happens. :slight_smile:

jeffce trying to send files
Tiggie

Good job…that worked just fine.

Do the same for the OTL logs (OTL.txt and Attach.txt)

jefffce from Tiggie

jeffce from Tiggie. otl

jeffce I do not see a log for Adwcleaner, and the one for malwarebytes is in the programme can click on "Logs " and read it but do not know how I can attach it
To send.
Hope you can sort out what I have sent and its alright.
Learnt something new (Smile )
Tiggie

Don’t worry about AdwCleaner for now…let’s get that Malwarebytes log. It can be found in the following folder…

C:\Documents and Settings<USERNAME>\Application Data\Malwarebytes\Malwarebytes’ Anti-Malware\Logs

Trying now to attach mwb log and have found Adwcleaner will send that too hopefully.
When I type the C:\Documents and setting etc ending with logs in the choose file to update box, another box comes up saying"The above file name is invalid."
I did a full scan with Malwarebytes last night and have what looks like a text file in notepad on the desktop tried to attach that, but a box came up saying it was not a text and cannot upload it. What to do? I will keep trying .
Tiggie

The last message jeffce shot off before I was ready was just investigating things marked MWB

Sending you this jeffce, it should be a little imformation written in notepad. still working on finding the log and sending it to you. Sorry it will not let me send, it tells me its a data file and cannot upload it , it was mbr in note pad telling me i have a missing operation system…!!!but not the log as such.
Here is Adwcleaner for now.
Tiggie

Please download and run ERUNT (Emergency Recovery Utility NT). This program allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed. **Remember if you are using Windows Vista as your operating system right-click the executable and Run as Administrator.

Run OTL.exe

[*]Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL


:Services

:OTL
IE - HKLM\..\SearchScopes\{BE28C22E-F666-424d-B5FD-125C4AFEE34E}: "URL" = http://search.myheritage.com?orig=ds&q={searchTerms}
IE - HKU\S-1-5-21-192252866-2205986208-601751812-1008\..\SearchScopes\{BE28C22E-F666-424d-B5FD-125C4AFEE34E}: "URL" = http://search.myheritage.com?orig=ds&q={searchTerms}
O3 - HKLM\..\Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {90222687-F593-4738-B738-FBEE9C7B26DF} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKU\S-1-5-21-192252866-2205986208-601751812-1008\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKU\S-1-5-21-192252866-2205986208-601751812-1008\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O33 - MountPoints2\{6b699fc0-20d6-11e1-a890-001731aaab15}\Shell - "" = AutoRun
O33 - MountPoints2\{6b699fc0-20d6-11e1-a890-001731aaab15}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{6b699fc0-20d6-11e1-a890-001731aaab15}\Shell\AutoRun\command - "" = J:\Setup.exe
O33 - MountPoints2\{6b699fc1-20d6-11e1-a890-001731aaab15}\Shell - "" = Autorun
O33 - MountPoints2\{6b699fc1-20d6-11e1-a890-001731aaab15}\Shell\downloadsb\command - "" = C:\WINDOWS\explorer.exe -- [2008/04/14 01:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation)
O33 - MountPoints2\{e74674a0-cbad-11df-adf8-001731aaab15}\Shell\AutoRun\command - "" = J:\InstallTomTomHOME.exe
O33 - MountPoints2\J\Shell - "" = AutoRun
O33 - MountPoints2\J\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\J\Shell\AutoRun\command - "" = J:\Setup.exe
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

:Files
ipconfig /flushdns /c

:Commands
[emptytemp]
[resethosts]
[start explorer]
[Reboot]

[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot when it is done
[*]Then run a new scan and post a new OTL log ( don’t check the boxes beside LOP Check or Purity this time )

Post the new OTL log and let me know how your system is running now. :slight_smile:

This may be the log for when I did a full scan with malwarebytes
Will do the Arunt and other orocedure you need. Tiggie

I have Done it at last. this is the Malwarebytes log for the first quick scan. Its all in the where one saves it to it seems.Will now do what you instructed Erunt etc Tiggie

Ok sounds good. :slight_smile:

jeffce here is the Erunt log .I am now going to do OTL.exe
Tiggie

Ok…when you get OTL.txt please attach that. :slight_smile:

jeffce here is the OTL.exe file created last night.(Fix )
I am now running a new scan and will post it as soon as its finished.
Tiggie

jeffce this is the new OTL log done this morning. hope all is well now.
Will let you know how my system is running later today
I appreciate very much your patience with me
Tiggie

Hi,

Please run the set of instructions from Reply 30 once again exactly as I wrote them. For some reason the fix did not take.

Once complete please post the logs that are created. :slight_smile:

Hi jeffce, I ran the OTL.exe again yesterday.When it started it said "killing processes, DO NOT INTERUPT. " but unlike a scan those words did,nt move .when I went to bed last night everything was the same.This morning the programme said not responding. Wish it had said that last night. Hence you getting no mail from me.
I can try it again.
My ststem was running well yesterday happy to say.
Tiggie