Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Search Safer Inc keeps prompting me at startup to allow it to make changes


  • Please log in to reply
14 replies to this topic

#1 kellygirl924

kellygirl924

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:10:48 PM

Posted 03 July 2014 - 04:53 PM

I'm actually getting two prompt boxes at startup that I've never seen before. I will have to restart my computer to get what the other prompt is. This one has me concerned because it's an exe file and looks like it's in my registry. When I looked at the properties I found the file location. It's c:\program files\pc reg\service.exe

 

I'm not sure where this came from as my kids both use this computer as well. They usually watch YouTube videos and Facebook. I myself had gone to a free font site and accidentally clicked on something I thought was the font file. I thought I removed it but apparently not. It also seems like it had turned off my antivirus. I have Norton Security Suite from Comcast. 

 

Can you help from what I've given or should I get more information and if so what would you like? I'll gather it all in one response if you need more information. 

 

Thank you in advance for your help,

Kelly  :)

 

BC AdBot (Login to Remove)

 


#2 MalwareAbort

MalwareAbort

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:48 PM

Posted 03 July 2014 - 05:28 PM

Hi kellygirl924,

 

Please follow these instructions PLEASE feel free to let me know if you have any trouble!

 

  • Please download AdwCleaner by Xplode and save to your Desktop.
  • Double-click on AdwCleaner.exe to run the tool.
    Vista/Windows 7/8 users right-click and select Run As Administrator.
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • After reviewing the log, click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.

 

Next download and install Malwarebytes Anti-Malware from here (https://www.bleepingcomputer.com/download/malwarebytes-anti-malware/)

  • Click on run scan at the top right hand of the program and allow it to run.
  • If you can not run Malwarebytes please let me know!

Let me know how the following turns out.


"Imagine a world without malware"


#3 kellygirl924

kellygirl924
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:10:48 PM

Posted 04 July 2014 - 09:19 AM

Thank you. Sorry for the delay. We had a severe thunderstorm last night and high winds, almost like a tornado but we got lucky.

 

Here are my results:

 

# AdwCleaner v3.214 - Report created 04/07/2014 at 10:03:15
# Updated 29/06/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Kelly Boran - KELLYBORAN-PC
# Running from : C:\Users\Kelly Boran\Downloads\AdwCleaner.exe
# Option : Clean
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\ProgramData\374311380 
Folder Deleted : C:\ProgramData\apn
Folder Deleted : C:\ProgramData\Performancer
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\optimizer pro v3.2
Folder Deleted : C:\Program Files (x86)\Optimizer Pro
Folder Deleted : C:\Program Files (x86)\Speedial
Folder Deleted : C:\Program Files (x86)\webget
Folder Deleted : C:\Program Files (x86)\xfin_portal
Folder Deleted : C:\Program Files\pcreg
Folder Deleted : C:\Users\Kelly Boran\AppData\LocalLow\comcasttb
Folder Deleted : C:\Users\Kelly Boran\AppData\LocalLow\xfin_portal
Folder Deleted : C:\Users\Kelly Boran\AppData\Roaming\Optimizer Pro
Folder Deleted : C:\Users\Kelly Boran\AppData\Roaming\Speedial
Folder Deleted : C:\Users\Kelly Boran\AppData\Roaming\UpdaterEX
Folder Deleted : C:\Users\Kelly Boran\Documents\Optimizer Pro
Folder Deleted : C:\Users\Kelly Boran\AppData\Local\Google\Chrome\User Data\Default\Extensions\bopakagnckmlgajfccecajhnimjiiedh
File Deleted : C:\END
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Deleted : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{dfc86759}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{49BC4DD1-0E69-4611-9164-0009538C5E46}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{0214A12B-C5A3-437F-A6F3-068ABCD8C85E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{08635077-8829-49E2-B338-C968817EB460}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{20A3F109-F7C1-47B4-8098-8E654B264B1D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4B9BCCE8-A70B-402A-A7E1-DB96831EE26F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8C7478AB-3155-463E-936F-55F91F0F10D0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{96DD9437-5D20-4EFB-BF52-A4A605A4E0AA}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9E1B65EE-A131-42B4-94CA-847505E2F611}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0214A12B-C5A3-437F-A6F3-068ABCD8C85E}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{96DD9437-5D20-4EFB-BF52-A4A605A4E0AA}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4A11A6BD-7880-49BD-92D4-6F09D0BD3250}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{68DE31F7-43FF-4EE2-B88B-10665016970D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4B9BCCE8-A70B-402A-A7E1-DB96831EE26F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4B9BCCE8-A70B-402A-A7E1-DB96831EE26F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2318C2B1-4965-11D4-9B18-009027A5CD4F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4B9BCCE8-A70B-402A-A7E1-DB96831EE26F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1791C1B5-FFD0-4D4B-ABCD-7A7DF6EAA89C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{49BC4DD1-0E69-4611-9164-0009538C5E46}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4B9BCCE8-A70B-402A-A7E1-DB96831EE26F}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{2318C2B1-4965-11D4-9B18-009027A5CD4F}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{4B9BCCE8-A70B-402A-A7E1-DB96831EE26F}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{0214A12B-C5A3-437F-A6F3-068ABCD8C85E}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{96DD9437-5D20-4EFB-BF52-A4A605A4E0AA}
Value Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{2318C2B1-4965-11D4-9B18-009027A5CD4F}]
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{49BC4DD1-0E69-4611-9164-0009538C5E46}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\wecarereminder
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKCU\Software\AppDataLow\Software\xfin_portal
Key Deleted : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\Software\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Deleted : HKLM\Software\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Key Deleted : HKLM\Software\InstallIQ
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\xfin_portal
Data Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~3\PERFOR~1\PERFOR~2.DLL
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v0.0.0.0
 
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
 
-\\ Google Chrome v35.0.1916.114
 
[ File : C:\Users\AmandaLynn921\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
Deleted [Search Provider] : hxxp://search.aol.com/aol/search?query={searchTerms}
Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
 
[ File : C:\Users\justin\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
Deleted [Search Provider] : hxxp://search.aol.com/aol/search?query={searchTerms}
Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
Deleted [Search Provider] : hxxp://speedial.com/results.php?f=4&q={searchTerms}&a=spd_dnldstr_14_21_ch&cd=2XzuyEtN2Y1L1QzuzytDtB0BtAyE0AyBtByB0FyB0DyCtC0DtN0D0Tzu0SzzyByEtN1L2XzutBtFtBtDtFtCyDtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StDzyzytByE0C0ByDtGyCtBtBzytG0CtC0C0AtGtCyDyD0AtGyCyCtByEyC0ByC0A0F0A0E0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCyD0CyDtD0BzztBtG0E0D0BzztGtCyDtCyCtGyB0DyByBtGtCtC0D0B0C0D0Ezz0CyDyByD2Q&cr=1293096636&ir=
Deleted [Search Provider] : hxxp://search.gboxapp.com/?category=web&query={searchTerms}&x=0&y=0&language=en
Deleted [Startup_urls] : hxxp://speedial.com/?f=1&a=spd_dnldstr_14_21_ch&cd=2XzuyEtN2Y1L1QzuzytDtB0BtAyE0AyBtByB0FyB0DyCtC0DtN0D0Tzu0SzzyByEtN1L2XzutBtFtBtDtFtCyDtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StDzyzytByE0C0ByDtGyCtBtBzytG0CtC0C0AtGtCyDyD0AtGyCyCtByEyC0ByC0A0F0A0E0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCyD0CyDtD0BzztBtG0E0D0BzztGtCyDtCyCtGyB0DyByBtGtCtC0D0B0C0D0Ezz0CyDyByD2Q&cr=1293096636&ir=
Deleted [Startup_urls] : hxxp://search.gboxapp.com/
Deleted [Homepage] : hxxp://speedial.com/?f=1&a=spd_dnldstr_14_21_ch&cd=2XzuyEtN2Y1L1QzuzytDtB0BtAyE0AyBtByB0FyB0DyCtC0DtN0D0Tzu0SzzyByEtN1L2XzutBtFtBtDtFtCyDtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StDzyzytByE0C0ByDtGyCtBtBzytG0CtC0C0AtGtCyDyD0AtGyCyCtByEyC0ByC0A0F0A0E0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCyD0CyDtD0BzztBtG0E0D0BzztGtCyDtCyCtGyB0DyByBtGtCtC0D0B0C0D0Ezz0CyDyByD2Q&cr=1293096636&ir=
Deleted [Extension] : bakijjialdiiboeaknfpmflphhmljfkd
Deleted [Extension] : booedmolknjekdopkepjjeckmjkdpfgl
Deleted [Extension] : bopakagnckmlgajfccecajhnimjiiedh
Deleted [Extension] : flpcjncodpafbgdpnkljologafpionhb
 
[ File : C:\Users\Kelly Boran\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
Deleted [Search Provider] : hxxp://search.aol.com/aol/search?query={searchTerms}
Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
Deleted [Search Provider] : hxxp://speedial.com/results.php?f=4&q={searchTerms}&a=spd_dnldstr_14_21_ch&cd=2XzuyEtN2Y1L1QzuzytDtB0BtAyE0AyBtByB0FyB0DyCtC0DtN0D0Tzu0SzzyByEtN1L2XzutBtFtBtDtFtCyDtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StDzyzytByE0C0ByDtGyCtBtBzytG0CtC0C0AtGtCyDyD0AtGyCyCtByEyC0ByC0A0F0A0E0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCyD0CyDtD0BzztBtG0E0D0BzztGtCyDtCyCtGyB0DyByBtGtCtC0D0B0C0D0Ezz0CyDyByD2Q&cr=1293096636&ir=
Deleted [Startup_urls] : hxxp://speedial.com/?f=1&a=spd_dnldstr_14_21_ch&cd=2XzuyEtN2Y1L1QzuzytDtB0BtAyE0AyBtByB0FyB0DyCtC0DtN0D0Tzu0SzzyByEtN1L2XzutBtFtBtDtFtCyDtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StDzyzytByE0C0ByDtGyCtBtBzytG0CtC0C0AtGtCyDyD0AtGyCyCtByEyC0ByC0A0F0A0E0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCyD0CyDtD0BzztBtG0E0D0BzztGtCyDtCyCtGyB0DyByBtGtCtC0D0B0C0D0Ezz0CyDyByD2Q&cr=1293096636&ir=
Deleted [Startup_urls] : hxxp://search.gboxapp.com/
Deleted [Homepage] : hxxp://www.trovi.com/?gd=&ctid=CT3325291&octid=EB_ORIGINAL_CTID&ISID=MD248D32C-8E4D-42D9-BC22-EC9B62B3C22C&SearchSource=55&CUI=&UM=2&UP=&SSPV=
Deleted [Extension] : booedmolknjekdopkepjjeckmjkdpfgl
Deleted [Extension] : bopakagnckmlgajfccecajhnimjiiedh
Deleted [Extension] : flpcjncodpafbgdpnkljologafpionhb
 
*************************
 
AdwCleaner[R0].txt - [10223 octets] - [04/07/2014 09:46:25]
AdwCleaner[S0].txt - [10390 octets] - [04/07/2014 10:03:15]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [10451 octets] ##########


#4 kellygirl924

kellygirl924
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:10:48 PM

Posted 04 July 2014 - 09:45 AM

I'm getting an error message with the Malwarebytes software.

 

It won't let me copy and paste so I'll describe it as best as possible.

 

It's a window that comes up titled, Malwarebytes Anti-Malware. and it says in the box: Malwarebytes Anti-Malware has stopped working. Windows can check online for a solution to the problem.

When I click the, Check online for a solution and close the program it just closes the program and no online solution pops up. 

 

I didn't know how to disable my antivirus or firewall so I left that alone. Could that be the problem? 



#5 MalwareAbort

MalwareAbort

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:48 PM

Posted 04 July 2014 - 06:39 PM

I'm getting an error message with the Malwarebytes software.

 

It won't let me copy and paste so I'll describe it as best as possible.

 

It's a window that comes up titled, Malwarebytes Anti-Malware. and it says in the box: Malwarebytes Anti-Malware has stopped working. Windows can check online for a solution to the problem.

When I click the, Check online for a solution and close the program it just closes the program and no online solution pops up. 

 

I didn't know how to disable my antivirus or firewall so I left that alone. Could that be the problem? 

Have you installed malwarebytes before?

 

IF SO: Run this (https://www.bleepingcomputer.com/download/malwarebytes-anti-malware/_clean) then reinstall it

IF above fails or you havent installed before, try chameleon:

 

Chameleon (Downloaded from: http://downloads.malwarebytes.org/file/chameleon/)

You should save the .zip archive to an easy to access location.

 

Usage

  • Extract the file and its contents (Right click -> Extract All...)
  • In the newly created folder you should see two sub folders (Chameleon -> Windows)
  • In the Windows folder you should see a help file called chameleon.
  • Open the file (double click)
  • Follow the on screen instructions from malwarebytes

"Imagine a world without malware"


#6 kellygirl924

kellygirl924
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:10:48 PM

Posted 05 July 2014 - 09:21 AM

I never had malwarebytes installed before this. This is my first issue with this computer. I'm sure I should have more security systems in play (especially now) to protect me besides the Norton Security Suites.

So, my results of the try with Chameleon:  :(  :scratchhead: none of the 12 steps (button links they give you) worked from Chameleon.

 

I'm going to restart my computer and get you the other popup information. The first one (service.exe) is gone, as far as I know. That one doesn't popup anymore. 

 

I'll start a new reply with the other popup information. 



#7 kellygirl924

kellygirl924
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:10:48 PM

Posted 05 July 2014 - 09:35 AM

Here's the other popup window information:

 

User Account Control

 

Do you want to allow the following program to make changes to this computer?

 

Program name: fwupdate.exe

Verified publisher: LG Electronics Inc.

File origin: Hard drive on this computer

Program location: "C:\Program Files(x86)\lg_fwupdate\fwupdate.exe" blrun

 

I couldn't copy and paste so I wrote it all out. Hope that helps. 



#8 MalwareAbort

MalwareAbort

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:48 PM

Posted 05 July 2014 - 02:39 PM

Here's the other popup window information:

 

User Account Control

 

Do you want to allow the following program to make changes to this computer?

 

Program name: fwupdate.exe

Verified publisher: LG Electronics Inc.

File origin: Hard drive on this computer

Program location: "C:\Program Files(x86)\lg_fwupdate\fwupdate.exe" blrun

 

I couldn't copy and paste so I wrote it all out. Hope that helps. 

The executable looks safe! It appears to come from some form of LG's Drivers, Do you own any LG Products?

 

Next up run ESET  (takes a long time usually)

  • Hold down Control and click on this link to open ESET OnlineScan in a new window.
  • Click the esetonlinebtn.png button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the esetsmartinstaller_enu.png icon on your desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under scan settings, check "Scan Archives" and "Remove found threats"
  • Click Advanced settings and select the following:
  • Scan potentially unwanted applications
  • Scan for potentially unsafe applications
  • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.
  • NOTE:Sometimes if ESET finds no infections it will not create a log.

 

If you would like to remove the program (LG Updater) please run the following and I can assist you in removing it:

Download minitoolbox (http://www.bleepingcomputer.com/download/minitoolbox/) and run it with the following boxes checked:

  • List Installed Programs
Copy the resulting log and paste into a reply here.

 

Otherwise you should be allowed to let the program run.


Edited by MalwareAbort, 05 July 2014 - 02:42 PM.

"Imagine a world without malware"


#9 kellygirl924

kellygirl924
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:10:48 PM

Posted 05 July 2014 - 02:40 PM

Ok, since the above posts I had come accross the Malwarebytes website and found a way to get the software to work. What did you need after the scan was run? 

 

Here's a link to what I did that worked:

 

https://forums.malwarebytes.org/index.php?/topic/152044-malwarebytes-does-not-work/

 

:)  :)



#10 kellygirl924

kellygirl924
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:10:48 PM

Posted 05 July 2014 - 02:42 PM

Awesome! Thank you! I think I do have an LG product. I'll check to be sure. If not I'll follow the instructions above to remove. 



#11 kellygirl924

kellygirl924
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:10:48 PM

Posted 05 July 2014 - 02:46 PM

Yup! My CD drive is made by LG...going to restart my computer and allow it to run. 

 

Thank you so much again!!  :clapping:



#12 MalwareAbort

MalwareAbort

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:48 PM

Posted 05 July 2014 - 02:47 PM

Ok, since the above posts I had come accross the Malwarebytes website and found a way to get the software to work. What did you need after the scan was run? 

 

Here's a link to what I did that worked:

 

https://forums.malwarebytes.org/index.php?/topic/152044-malwarebytes-does-not-work/

 

:)  :)

Just the log please, If you have already closed malwarebytes a log will be available in the History Tab -> Application Logs :)

 

 

Yup! My CD drive is made by LG...going to restart my computer and allow it to run. 

 

Thank you so much again!!   :clapping:

 

No problem! Glad things are working again  :thumbsup:


Edited by MalwareAbort, 05 July 2014 - 02:48 PM.

"Imagine a world without malware"


#13 kellygirl924

kellygirl924
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:10:48 PM

Posted 05 July 2014 - 04:06 PM

Here's the log:
 
Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 7/5/2014
Scan Time: 3:01:49 PM
Logfile: Malwarebytes Log.txt
Administrator: Yes
 
Version: 2.00.2.1012
Malware Database: v2014.07.05.10
Rootkit Database: v2014.07.03.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
 
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Kelly Boran
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 346271
Time Elapsed: 4 min, 29 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 0
(No malicious items detected)
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 4
PUP.Optional.StormAlerts.A, C:\Users\Kelly Boran\AppData\Local\StormAlerts, , [fbf3ecaf1d5e52e4ab4cae295ca66c94], 
PUP.Optional.StormAlerts.A, C:\Users\Kelly Boran\AppData\Local\StormAlerts\0523165004, , [fbf3ecaf1d5e52e4ab4cae295ca66c94], 
PUP.Optional.StormAlerts.A, C:\Users\Kelly Boran\AppData\Local\Weather_Warnings_LLC\StormAlerts.exe_Url_jll2wrv0dzx1wljx4sdyw3erwcjxoqgf, , [efff38639edde84efe25b7e4b05229d7], 
PUP.Optional.StormAlerts.A, C:\Users\Kelly Boran\AppData\Local\Weather_Warnings_LLC\StormAlerts.exe_Url_jll2wrv0dzx1wljx4sdyw3erwcjxoqgf\1.6.0.0, , [efff38639edde84efe25b7e4b05229d7], 
 
Files: 37


#14 MalwareAbort

MalwareAbort

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:48 PM

Posted 05 July 2014 - 06:20 PM

Alright kelly,

It looks like you are all set!
Please let me know if you have any questions.

"Imagine a world without malware"


#15 kellygirl924

kellygirl924
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:10:48 PM

Posted 05 July 2014 - 06:40 PM

Thank you again for all your help!! This is the best site ever :)






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users