Why doesn’t Avast boot scan get rid of it, and how do you?
Attach your basic logs. (MBAM, FRST and aswMBR…!!)
Instructions: https://forum.avast.com/index.php?topic=53253.0
You’ve gotta be kidding me…I have to use I’m not even sure how many other companies’ product and pretend I’m a computer programmer; saving and attaching files and logs to who knows what and to do who knows what with?
Every one of you guys act like YOUR individual product is the shit, and nothing can get by it, but when something does, you tell me to go not just elsewhere and fix it myself, but to go to SEVERAL elsewheres and jump through 1000 hoops in hope of fixing it?
Like THAT’S gonna work…I have a better idea…you’re the virus company, how about YOU create a fix for it that we can click on? You know…kind of like how it’s SUPPOSSED to work?
Tone down your language, The solution if you are not happy is change your AV solution. It will not do any good as no mainstream av totally removes PUP’s even MBAM misses portions
This was installed with another programme you downloaded so you allowed it to be installed. We can help or not your choice.
I ALLOWED it to be installed? That’s rich…I could have sworn that was the job of the virus protection programs - you didn’t catch it, and that is your job, and you’re telling me it’s MY fault for not catching it myself?
Please…and I have no idea what you just said…change my av solution? I have no idea what that means, and if that is your idea of “helping”…
if you want help … attach the requested logs and it will be solved Malwarebytes and Farbar Recovery Scan Tool logs
Potentially Unwanted Program) An application that is installed along with the desired application the user actually asked for. Also called a “barnacle,” in most cases, the PUP is spyware, adware or some other unwanted software. However, what makes spyware or adware a PUP rather than pure malware is the fact that the end user license agreement (EULA) does inform the user that this additional program is being installed. Considering hardly anyone ever reads the license agreement, the distinction is a subtle one. See spyware, adware and malware.
Listen closely.
- You’ve spoken with such attitude to Essex, I would actually say I wouldn’t help you out here.
- Avast! Anti-VIRUS. Mobogenie isn’t self replicating to my knowledge?
- If you google how to add PUP’s to the Avast! detection scanners, you wouldn’t be here
- It’s kind of your fault, you did install it.
- The logs posted, contain no private information, short of Username, computer name, and maybe country, also any file paths… The very fact you POSTED on this forum, to some, is more invasive of your privacy then those logs will ever be. Don’t believe me? Run FRST, see if you can find any information that isn’t 1) Username, 2) Computer name and 3) Isn’t your country.
If you wish, I will gladly run FRST, aswMBR and MBAM and publicly post my logs. I have absolutely no issue with it.
Last I checked, clicking a few buttons doesn’t count as being a programmer. Or attaching a few log files.
Find Essexboy in there. He is probably one of the most qualified people I know who can help you. If you don’t believe his expertise, or my recommendation, search Thanks Essex in Avast!.
(Or just go here: https://forum.avast.com/index.php?topic=86949.15)
Note: If you want Avast! to find MoboGenie, using Avast! 2014 - Click on Avast! > Scan > Quick Scan > Settings > Check the PUP option, if not already checked.
It gets harder and harder to avoid bundled PUP-adware and PUP-crap with downloads. It means "easy money’ for the developer of the software and the marketeers that earn on the bundling, unaware or not interested in the nuisance of their persistent added crap that delivers them “easy money” for average end-users. Nowadays everyone that downloads software from the internet should be wary not to include possibly unwanted additional “goodies” of persistent adware-crap, and some really can be “a pain in the proverbial parts”. So avoid software bundlers and do custom installs while opting out of bundled stuff.
There are five ways to get rid of it: http://www.wikihow.com/Remove-Mobogenie-Virus
I’d prefer and advise you to use the guidance of a qualified removal expert like essexboy here.
He and his colleagues are some of the best to be found on this small digital globe.
In the mean time while you wait for your log files to be examined, read the above link I have posted.
I shall get Essex again.
attachments pretty sure I did them all but don’t think I found and attached all
No, you’re fine. Tis what Essexboy requires. Please keep in mind, Essex lives in the UK, and probably won’t be online for 6-7 hours still.
Gotcha…also, since a lot of things were removed during the various scans, I did another avast boot scan, and a few more variations on the virus have appeared, if it matters.
Also, Unchecky will keep out the Adware. Although, again, won’t see it 100% of the time, but gets most cases.
(Not related to Avast!!!)
Just wait until Essexboy comes online. I re-PM’d him the link for this thread.
Looks like most are gone now, once we have completed I will remove all the tools downloaded
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION CHR HKU\S-1-5-21-2663191845-3344070212-2114054786-1002\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION URLSearchHook: HKU\S-1-5-21-2663191845-3344070212-2114054786-1002 - Default Value = {CFBFAE00-17A6-11D0-99CB-00C04FD64497} URLSearchHook: HKU\S-1-5-21-2663191845-3344070212-2114054786-1002 - (No Name) - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No File 2014-11-23 21:20 - 2014-11-23 21:20 - 00003192 _____ () C:\Windows\System32\Tasks\{A358CB3C-3256-422B-B3DE-E28DC63DC2FE} Task: {B5F2169B-5DB0-4CBD-A305-055F67927B80} - System32\Tasks\0 => Iexplore.exe <==== ATTENTION Task: {F9439B13-BA50-4578-AA30-A2EDAD5EDB40} - System32\Tasks\4469 => Wscript.exe C:\Users\Jim\AppData\Local\Temp\launchie.vbs //B <==== ATTENTION C:\Users\Jim\AppData\Roaming\Movdap EmptyTemp: CMD: bitsadmin /reset /allusers
Save this as fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that
Please download AdwCleaner by Xplode onto your desktop.
[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S1].txt as well.
AdwCleaner v4.102 - Report created 30/11/2014 at 12:18:57
Updated 23/11/2014 by Xplode
Database : 2014-11-27.1 [Live]
Operating System : Windows 8 (64 bits)
Username : Jim - EXECUTIVEPCH
Running from : C:\Users\Jim\Desktop\AdwCleaner.exe
Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
***** [ Browsers ] *****
-\ Internet Explorer v10.0.9200.17148
AdwCleaner[R0].txt - [14112 octets] - [29/11/2014 15:13:31]
AdwCleaner[R1].txt - [802 octets] - [30/11/2014 12:11:14]
AdwCleaner[S0].txt - [12394 octets] - [29/11/2014 15:25:23]
AdwCleaner[S1].txt - [724 octets] - [30/11/2014 12:18:57]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [783 octets] ##########
Post fixlog too please.
How is the computer behaving at the moment, any problems at all ?