SoftwareUpdater.ui.exe CANNOT BE UNINSTALLED!

I need help. I have an unwanted program called SoftwareUpdater. Avast has quarantined SoftwareUpdater.Ui.exe as well as something called bootstrapper that seems to be from the same folder, yet the program persists! Half the time I boot up my computer, an orange splash window with a mammoth on it asking me to install an update for something called ‘TubeBox’ pops up, with softwareupdater.ui.exe in the start menu. When I end the task, the splash popup closes, and I know where softwareupdater.ui.exe is located on my C drive.

However, I’m also having a problem where only 9 programs that aren’t published by Microsoft show up in my “Programs and Features” list (accessed from the Control Panel), and in addition to dozens of programs and games, SoftwareUpdater is missing from the list. It is also missing in IObit uninstaller and CCleaner’s uninstaller (which I obtained as a recommendation for removing programs that don’t show up in “Programs and Features”), there’s no uninstall file for it on my C drive, nor is it listed in the start menu. I’ve even tried loading “Installer” via “run” in the start menu, and there are no subjects describing this program among the msi files.

Is there ANY way to remove this without reformatting my computer?! I fear it may actually be responsible for my Programs List failing to populate in full as some sort of defense mechanism to prevent me from uninstalling it… And every time I Google how to uninstall it, I’m told to do so through the Control Panel, which doesn’t work; every time I Google the issue with my Control Panel programs list not populating, I’m told to use CCleaner’s uninstaller, which ALSO cannot be done. Please help!

Lots of adware by the sound of it

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

[*]Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
[*]Select additions at the bottom
[*]Press Scan button.

https://dl.dropboxusercontent.com/u/73555776/frst.JPG

[*]It will produce a log called FRST.txt in the same directory the tool is run from.
[*]Please attach both logs generated.

I’m a bit nervous about programs I’m not familiar with (for obvious reasons), but I will try this…

Okay, here is the first log…

And the second. Sorry it doesn’t seem to allow more than one attachment per message…

Rest assured, any programme I ask you to use will be safe

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:

HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] ATTENTION! ====> ZeroAccess? HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.dosearches.com/web/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=ds&from=cor&uid=SAMSUNGXHM321HI_S25WJ9FB602642&ts=1384208066&type=default&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.dosearches.com/web/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=ds&from=cor&uid=SAMSUNGXHM321HI_S25WJ9FB602642&ts=1384208066&type=default&q={searchTerms} SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.dosearches.com/web/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=ds&from=cor&uid=SAMSUNGXHM321HI_S25WJ9FB602642&ts=1384208066&type=default&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.dosearches.com/web/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=ds&from=cor&uid=SAMSUNGXHM321HI_S25WJ9FB602642&ts=1384208066&type=default&q={searchTerms} SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snap.do/?publisher=VertiTechnologyYB&dpid=VertiTechnologyYB&co=US&userid=7dc4a3d5-4bc1-4d46-ad13-d5b58b84865f&searchtype=ds&q={searchTerms}&installDate=30/04/2013 SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.dosearches.com/web/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=ds&from=cor&uid=SAMSUNGXHM321HI_S25WJ9FB602642&ts=1384208066&type=default&q={searchTerms} SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snap.do/?publisher=VertiTechnologyYB&dpid=VertiTechnologyYB&co=US&userid=7dc4a3d5-4bc1-4d46-ad13-d5b58b84865f&searchtype=ds&q={searchTerms}&installDate=30/04/2013 SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = https://mysearch.avg.com/search?cid={49FF7406-2FA5-4436-B0EC-9A3F18BDF37C}&mid=7bfdd7e81d0b47d2968bfd6e9139a20c-71363fd66fe193ea3ba7c323cf37244d306fed0b&lang=en&ds=oc011&coid=avgtbdisoc&cmpid=&pr=sa&d=2014-08-23 14:11:17&v=18.1.9.799&pid=safeguard&sg=&sap=dsp&q={searchTerms} SearchScopes: HKCU - {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = https://search.yahoo.com/yhs/search?type=odc228&hspart=avast&hsimp=yhs-001&p={searchTerms} SearchScopes: HKCU - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = BHO-x32: No Name -> {19FD4AD0-7536-3999-86D9-4FA3792C82D0} -> No File Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Toolbar: HKLM-x32 - No Name - {95B7759C-8C7F-4BF1-B163-73684A933233} - No File FF user.js: detected! => C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\nwd8yujj.default\user.js FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\safeguard-secure-search.xml FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe http://www.dosearches.com/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=sc&from=cor&uid=SAMSUNGXHM321HI_S25WJ9FB602642&ts=1384208066 CHR HKLM\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\Web Assistant\source.crx [] CHR HKLM-x32\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\Web Assistant\source.crx [] CHR HKLM-x32\...\Chrome\Extension: [jplinpmadfkdgipabgcdchbdikologlh] - C:\Program Files (x86)\1ClickDownload\1click12.crx [2014-08-22] CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION S4 vToolbarUpdater18.1.9; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe [1820184 2014-08-23] (AVG Secure Search) S3 AVP; "C:\Users\Owner\AppData\Local\Temp\MRI_TEMP\Kaspersky Antivirus\AVP\Scanner\AVP.exe" -r [X] 2014-08-27 17:19 - 2014-08-27 17:21 - 00004208 _____ () C:\Windows\System32\Tasks\Software Updater 2014-08-23 14:11 - 2014-08-23 14:12 - 00000366 _____ () C:\Windows\Tasks\Open Chrome.job 2014-08-23 14:11 - 2014-08-23 14:11 - 00002608 _____ () C:\Windows\System32\Tasks\Open Chrome Task: {43269057-81D2-4BEE-B805-AB4BE4DF8EAC} - System32\Tasks\4704 => Wscript.exe C:\Users\Owner\AppData\Local\Temp\launchie.vbs //B Task: {4512B9B5-2D41-49EC-B114-5C9778286681} - System32\Tasks\Software Updater => C:\Program Files (x86)\SoftwareUpdater\SoftwareUpdater.Bootstrapper.exe [2014-08-27] () Task: {4FADC0AC-3F92-4F69-85C0-B0172BC178CB} - System32\Tasks\Software Updater Ui => C:\Program Files (x86)\SoftwareUpdater\SoftwareUpdater.Ui.exe [2014-02-17] () Task: {52ACA315-EFF9-4F1C-932D-168BB30FF6CF} - System32\Tasks\0 => Iexplore.exe Task: {BA51E29D-CCE3-41C8-AD5D-A0C2726DC0B2} - System32\Tasks\Open Chrome => Chrome.exe --new-window http://toolbar.avg.com/almost-done?pid=safeguard&lang=en Task: {D021AE2C-5C6F-40D8-AFCA-D33E66CDB01F} - System32\Tasks\Go for FilesUpdate => C:\Program Files (x86)\GoforFiles\GFFUpdater.exe <==== ATTENTION AlternateDataStreams: C:\Windows:92AB3E37263D73CE AlternateDataStreams: C:\ProgramData\Temp:6DDED7D9 AlternateDataStreams: C:\ProgramData\Temp:8E86D32B AlternateDataStreams: C:\ProgramData\Temp:AA199F0F AlternateDataStreams: C:\ProgramData\Temp:D6255023 HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\62164948.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\62164948.sys => ""="Driver" HKU\S-1-5-21-1556968313-95784786-1145212520-1001\Software\Classes\.exe: => <===== ATTENTION! EmptyTemp: CMD: bitsadmin /reset /allusers

Save this as fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.

[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S1].txt as well.

If I make any changes before I use this (for example, installing Nero so I can back up my most important files, as I’ve already done since I posted my log last night) will this fix still work (without causing any problems as it would a different machine), or should I start over?

No problem, this will run as it stands

I apologize for the wait, I hope you’re even still around. I’m in the process of moving, and, unfortunately, don’t have time for my computer despite how desperately it needs my attention. I’ll get to this as soon as possible though. Thanks in advance.

No problem, whenever you are ready :slight_smile: