Jump to content

Remove Findgala from system


Recommended Posts

  • Replies 54
  • Created
  • Last Reply

Top Posters In This Topic

We need to run MBAR again......

Download Malwarebytes Anti-Rootkit from HERE

  • Unzip the contents to a folder in a convenient location.
  • Open the folder where the contents were unzipped and run mbar.exe
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
  • Wait while the system shuts down and the cleanup process is performed.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • When done, please post the two logs produced they will be in the MBAR folder..... mbar-log.txt and system-log.txt
To attach a log if needed:

Bottom right corner of this page.

more-reply-options.jpg

New window that comes up.

choose-files1.jpg

~~~~~~~~~~~~~~~~~~~~~~~

Note:

If no additional threats were found, verify that your system is now running normally, making sure that the following items are functional:

Internet access

Windows Update

Windows Firewall

If there are additional problems with your system, such as any of those listed above or other system issues, then run the fixdamage tool included with Malwarebytes Anti-Rootkit and reboot. It's located in the Plugins folder which is in the MBAR folder.

Just run fixdamage.exe.

Verify that they are now functioning normally.

MrC

Link to post
Share on other sites

Lets give ComboFix another try:

Please download and run ComboFix.

The most important things to remember when running it is to disable all your malware programs and run Combofix from your desktop.

Please visit this webpage for download links, and instructions for running ComboFix

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Information on disabling your malware programs can be found Here.

Make sure you run ComboFix from your desktop.

Give it at least 30-45 minutes to finish if needed.

Please include the C:\ComboFix.txt in your next reply for further review.

---------->NOTE<----------

If you get the message Illegal operation attempted on registry key that has been marked for deletion after you run ComboFix....please reboot the computer, this should resolve the problem. You may have to do this several times if needed.

MrC

Link to post
Share on other sites

Hi, I restored system to an earlier point and ran the MBAR . Please find the logs attached.

Please let me know what needs to be done next. However while running ComboFix i got one error message

like mabr.3exe has stopped working and needs to close. I am not sure about the name "mabr.3exe". And it gives me a message to send error report to Microsoft.

 

Thanks.

mbar-log-2013-08-27 (16-14-51).txt

Link to post
Share on other sites

OK, we're not going to run ComboFix any more, see if you can manually delete these files and folder:

c:\documents and settings\331251\Application Data\SearchProtect <---folder

c:\windows\system32\SET259.tmp <---all these .tmp files

c:\windows\system32\SET25A.tmp

c:\windows\system32\SET25B.tmp

c:\windows\system32\SET25C.tmp

c:\windows\system32\SET25D.tmp

c:\windows\system32\SET25E.tmp

c:\windows\system32\SET25F.tmp

c:\windows\system32\SET26.tmp

c:\windows\system32\SET260.tmp

c:\windows\system32\SET261.tmp

c:\windows\system32\SET262.tmp

c:\windows\system32\SET263.tmp

c:\windows\system32\SET264.tmp

c:\windows\system32\SET265.tmp

c:\windows\system32\SET266.tmp

c:\windows\system32\SET267.tmp

c:\windows\system32\SET268.tmp

c:\windows\system32\SET269.tmp

c:\windows\system32\SET26A.tmp

c:\windows\system32\SET26B.tmp

c:\windows\system32\SET26C.tmp

c:\windows\system32\SET26D.tmp

c:\windows\system32\SET26F.tmp

c:\windows\system32\SET27.tmp

c:\windows\system32\SET270.tmp

c:\windows\system32\SET271.tmp

c:\windows\system32\SET272.tmp

c:\windows\system32\SET273.tmp

c:\windows\system32\SET274.tmp

c:\windows\system32\SET275.tmp

c:\windows\system32\SET276.tmp

c:\windows\system32\SET277.tmp

c:\windows\system32\SET278.tmp

c:\windows\system32\SET279.tmp

c:\windows\system32\SET27A.tmp

c:\windows\system32\SET27B.tmp

c:\windows\system32\SET27C.tmp

c:\windows\system32\SET27D.tmp

c:\windows\system32\SET27E.tmp

c:\windows\system32\SET27F.tmp

c:\windows\system32\SET28.tmp

c:\windows\system32\SET280.tmp

c:\windows\system32\SET281.tmp

c:\windows\system32\SET282.tmp

c:\windows\system32\SET283.tmp

c:\windows\system32\SET284.tmp

c:\windows\system32\SET285.tmp

c:\windows\system32\SET286.tmp

c:\windows\system32\SET287.tmp

c:\windows\system32\SET288.tmp

c:\windows\system32\SET289.tmp

c:\windows\system32\SET28A.tmp

c:\windows\system32\SET28B.tmp

c:\windows\system32\SET28C.tmp

c:\windows\system32\SET28D.tmp

c:\windows\system32\SET28E.tmp

c:\windows\system32\SET28F.tmp

c:\windows\system32\SET29.tmp

c:\windows\system32\SET290.tmp

c:\windows\system32\SET291.tmp

c:\windows\system32\SET292.tmp

c:\windows\system32\SET293.tmp

c:\windows\system32\SET294.tmp

c:\windows\system32\SET295.tmp

c:\windows\system32\SET296.tmp

c:\windows\system32\SET297.tmp

c:\windows\system32\SET298.tmp

c:\windows\system32\SET299.tmp

c:\windows\system32\SET29A.tmp

c:\windows\system32\SET29C.tmp

c:\windows\system32\SET29D.tmp

c:\windows\system32\SET29E.tmp

c:\windows\system32\SET29F.tmp

c:\windows\system32\SET2A.tmp

c:\windows\system32\SET2A0.tmp

c:\windows\system32\SET2A1.tmp

c:\windows\system32\SET2A2.tmp

c:\windows\system32\SET2A3.tmp

c:\windows\system32\SET2A4.tmp

c:\windows\system32\SET2A5.tmp

c:\windows\system32\SET2A6.tmp

c:\windows\system32\SET2A7.tmp

c:\windows\system32\SET2A8.tmp

c:\windows\system32\SET2A9.tmp

c:\windows\system32\SET2AA.tmp

c:\windows\system32\SET2AB.tmp

c:\windows\system32\SET2AC.tmp

c:\windows\system32\SET2AD.tmp

c:\windows\system32\SET2AE.tmp

c:\windows\system32\SET2AF.tmp

c:\windows\system32\SET2B.tmp

c:\windows\system32\SET2B0.tmp

c:\windows\system32\SET2B1.tmp

c:\windows\system32\SET2B2.tmp

c:\windows\system32\SET2B3.tmp

c:\windows\system32\SET2B4.tmp

c:\windows\system32\SET2B5.tmp

c:\windows\system32\SET2B6.tmp

c:\windows\system32\SET2B7.tmp

c:\windows\system32\SET2B8.tmp

c:\windows\system32\SET2B9.tmp

c:\windows\system32\SET2BA.tmp

c:\windows\system32\SET2BB.tmp

c:\windows\system32\SET2BC.tmp

c:\windows\system32\SET2BD.tmp

c:\windows\system32\SET2BE.tmp

c:\windows\system32\SET2BF.tmp

c:\windows\system32\SET2C.tmp

c:\windows\system32\SET2C0.tmp

c:\windows\system32\SET2C1.tmp

c:\windows\system32\SET2C2.tmp

c:\windows\system32\SET2C3.tmp

c:\windows\system32\SET2C4.tmp

c:\windows\system32\SET2C5.tmp

c:\windows\system32\SET2C6.tmp

c:\windows\system32\SET2C7.tmp

c:\windows\system32\SET2C9.tmp

c:\windows\system32\SET2CA.tmp

c:\windows\system32\SET2CB.tmp

c:\windows\system32\SET2CC.tmp

c:\windows\system32\SET2CD.tmp

c:\windows\system32\SET2CE.tmp

c:\windows\system32\SET2CF.tmp

c:\windows\system32\SET2D.tmp

c:\windows\system32\SET2D0.tmp

c:\windows\system32\SET2D1.tmp

c:\windows\system32\SET2D2.tmp

c:\windows\system32\SET2D3.tmp

c:\windows\system32\SET2D4.tmp

c:\windows\system32\SET2D5.tmp

c:\windows\system32\SET2D6.tmp

c:\windows\system32\SET2D7.tmp

c:\windows\system32\SET2D8.tmp

c:\windows\system32\SET2D9.tmp

c:\windows\system32\SET2DA.tmp

c:\windows\system32\SET2DB.tmp

c:\windows\system32\SET2DC.tmp

c:\windows\system32\SET2DD.tmp

c:\windows\system32\SET2DE.tmp

c:\windows\system32\SET2DF.tmp

c:\windows\system32\SET2E.tmp

c:\windows\system32\SET2E0.tmp

c:\windows\system32\SET2E1.tmp

c:\windows\system32\SET2E2.tmp

c:\windows\system32\SET2F.tmp

c:\windows\system32\SET2F2E.tmp

c:\windows\system32\SET2F2F.tmp

c:\windows\system32\SET2F30.tmp

c:\windows\system32\SET2F31.tmp

c:\windows\system32\SET2F32.tmp

c:\windows\system32\SET2F33.tmp

c:\windows\system32\SET2F34.tmp

c:\windows\system32\SET2F35.tmp

c:\windows\system32\SET2F36.tmp

c:\windows\system32\SET2F37.tmp

c:\windows\system32\SET2F38.tmp

c:\windows\system32\SET2F39.tmp

c:\windows\system32\SET2F3A.tmp

c:\windows\system32\SET2F3B.tmp

c:\windows\system32\SET2F3C.tmp

c:\windows\system32\SET2F3D.tmp

c:\windows\system32\SET2F3E.tmp

c:\windows\system32\SET2F3F.tmp

c:\windows\system32\SET2F41.tmp

c:\windows\system32\SET2F42.tmp

c:\windows\system32\SET2F43.tmp

c:\windows\system32\SET2F44.tmp

c:\windows\system32\SET2F45.tmp

c:\windows\system32\SET2F46.tmp

c:\windows\system32\SET2F47.tmp

c:\windows\system32\SET2F48.tmp

c:\windows\system32\SET2F49.tmp

c:\windows\system32\SET2F4A.tmp

c:\windows\system32\SET2F4B.tmp

c:\windows\system32\SET2F4C.tmp

c:\windows\system32\SET2F4D.tmp

c:\windows\system32\SET2F4E.tmp

c:\windows\system32\SET2F4F.tmp

c:\windows\system32\SET2F50.tmp

c:\windows\system32\SET2F51.tmp

c:\windows\system32\SET2F52.tmp

c:\windows\system32\SET2F53.tmp

c:\windows\system32\SET2F54.tmp

c:\windows\system32\SET2F55.tmp

c:\windows\system32\SET2F56.tmp

c:\windows\system32\SET2F57.tmp

c:\windows\system32\SET2F58.tmp

c:\windows\system32\SET2F59.tmp

c:\windows\system32\SET2F5A.tmp

c:\windows\system32\SET30.tmp

c:\windows\system32\SET31.tmp

c:\windows\system32\SET32.tmp

c:\windows\system32\SET33.tmp

c:\windows\system32\SET34.tmp

c:\windows\system32\SET35.tmp

c:\windows\system32\SET36.tmp

c:\windows\system32\SET37.tmp

c:\windows\system32\SET38.tmp

c:\windows\system32\SET39.tmp

c:\windows\system32\SET3A.tmp

c:\windows\system32\SET3B.tmp

c:\windows\system32\SET3C.tmp

c:\windows\system32\SET3D.tmp

c:\windows\system32\SET3E.tmp

c:\windows\system32\SET3F.tmp

c:\windows\system32\SET40.tmp

c:\windows\system32\SET41.tmp

c:\windows\system32\SET42.tmp

c:\windows\system32\SET43.tmp

c:\windows\system32\SET44.tmp

c:\windows\system32\SET45.tmp

c:\windows\system32\SET46.tmp

c:\windows\system32\SET47.tmp

c:\windows\system32\SET48.tmp

c:\windows\system32\SET49.tmp

c:\windows\system32\SET4B.tmp

c:\windows\system32\SET4C.tmp

c:\windows\system32\SET4D.tmp

c:\windows\system32\SET4E.tmp

c:\windows\system32\SET4F.tmp

c:\windows\system32\SET50.tmp

c:\windows\system32\SET51.tmp

c:\windows\system32\SET52.tmp

c:\windows\system32\SET53.tmp

c:\windows\system32\SET54.tmp

c:\windows\system32\SET55.tmp

c:\windows\system32\SET56.tmp

c:\windows\system32\SET57.tmp

c:\windows\system32\SET58.tmp

c:\windows\system32\SET59.tmp

c:\windows\system32\SET5A.tmp

c:\windows\system32\SET5B.tmp

c:\windows\system32\SET5C.tmp

c:\windows\system32\SET5D.tmp

c:\windows\system32\SET5E.tmp

c:\windows\system32\SET5F.tmp

c:\windows\system32\SET60.tmp

c:\windows\system32\SET61.tmp

c:\windows\system32\SET62.tmp

c:\windows\system32\SET63.tmp

c:\windows\system32\SET64.tmp

c:\windows\system32\SET65.tmp

c:\windows\system32\SET66.tmp

c:\windows\system32\SET67.tmp

c:\windows\system32\SET68.tmp

c:\windows\system32\SET69.tmp

c:\windows\system32\SET6A.tmp

c:\windows\system32\SET6B.tmp

c:\windows\system32\SET6C.tmp

c:\windows\system32\SET6D.tmp

c:\windows\system32\SET6E.tmp

c:\windows\system32\SET6F.tmp

c:\windows\system32\SET70.tmp

c:\windows\system32\SET71.tmp

c:\windows\system32\SET72.tmp

c:\windows\system32\SET73.tmp

c:\windows\system32\SET74.tmp

c:\windows\system32\SET75.tmp

c:\windows\system32\SET76.tmp

c:\windows\system32\SET78.tmp

c:\windows\system32\SET79.tmp

c:\windows\system32\SET7A.tmp

c:\windows\system32\SET7B.tmp

c:\windows\system32\SET7C.tmp

c:\windows\system32\SET7D.tmp

c:\windows\system32\SET7E.tmp

c:\windows\system32\SET7F.tmp

c:\windows\system32\SET80.tmp

c:\windows\system32\SET81.tmp

c:\windows\system32\SET82.tmp

c:\windows\system32\SET83.tmp

c:\windows\system32\SET84.tmp

c:\windows\system32\SET85.tmp

c:\windows\system32\SET86.tmp

c:\windows\system32\SET87.tmp

c:\windows\system32\SET88.tmp

c:\windows\system32\SET89.tmp

c:\windows\system32\SET8A.tmp

c:\windows\system32\SET8B.tmp

c:\windows\system32\SET8C.tmp

c:\windows\system32\SET8D.tmp

c:\windows\system32\SET8E.tmp

c:\windows\system32\SET8F.tmp

c:\windows\system32\SET90.tmp

c:\windows\system32\SET91.tmp

c:\windows\system32\SET92.tmp

c:\windows\system32\SET93.tmp

c:\windows\system32\SET94.tmp

c:\windows\system32\SET95.tmp

c:\windows\system32\SET96.tmp

c:\windows\system32\SET97.tmp

c:\windows\system32\SET98.tmp

c:\windows\system32\SET99.tmp

c:\windows\system32\SET9A.tmp

c:\windows\system32\SET9B.tmp

c:\windows\system32\SET9C.tmp

c:\windows\system32\SET9D.tmp

c:\windows\system32\SET9E.tmp

c:\windows\system32\SET9F.tmp

c:\windows\system32\SETA0.tmp

c:\windows\system32\SETA1.tmp

c:\windows\system32\SETA2.tmp

c:\windows\system32\SETA3.tmp

c:\windows\system32\SETA5.tmp

c:\windows\system32\SETA6.tmp

c:\windows\system32\SETA7.tmp

c:\windows\system32\SETA8.tmp

c:\windows\system32\SETA9.tmp

c:\windows\system32\SETAA.tmp

c:\windows\system32\SETAB.tmp

c:\windows\system32\SETAC.tmp

c:\windows\system32\SETAD.tmp

c:\windows\system32\SETAE.tmp

c:\windows\system32\SETAF.tmp

c:\windows\system32\SETB.tmp

c:\windows\system32\SETB0.tmp

c:\windows\system32\SETB1.tmp

c:\windows\system32\SETB2.tmp

c:\windows\system32\SETB3.tmp

c:\windows\system32\SETB4.tmp

c:\windows\system32\SETB5.tmp

c:\windows\system32\SETB6.tmp

c:\windows\system32\SETB7.tmp

c:\windows\system32\SETB8.tmp

c:\windows\system32\SETB9.tmp

c:\windows\system32\SETBA.tmp

c:\windows\system32\SETBB.tmp

c:\windows\system32\SETBC.tmp

c:\windows\system32\SETBD.tmp

c:\windows\system32\SETBE.tmp

c:\windows\system32\SETBF.tmp

c:\windows\system32\SETC.tmp

c:\windows\system32\SETC0.tmp

c:\windows\system32\SETC1.tmp

c:\windows\system32\SETC2.tmp

c:\windows\system32\SETC3.tmp

c:\windows\system32\SETC4.tmp

c:\windows\system32\SETC5.tmp

c:\windows\system32\SETC6.tmp

c:\windows\system32\SETC7.tmp

c:\windows\system32\SETC8.tmp

c:\windows\system32\SETC9.tmp

c:\windows\system32\SETCA.tmp

c:\windows\system32\SETCB.tmp

c:\windows\system32\SETCC.tmp

c:\windows\system32\SETCD.tmp

c:\windows\system32\SETCE.tmp

c:\windows\system32\SETCF.tmp

c:\windows\system32\SETD.tmp

c:\windows\system32\SETD0.tmp

c:\windows\system32\SETD2.tmp

c:\windows\system32\SETD3.tmp

c:\windows\system32\SETD4.tmp

c:\windows\system32\SETD5.tmp

c:\windows\system32\SETD6.tmp

c:\windows\system32\SETD7.tmp

c:\windows\system32\SETD8.tmp

c:\windows\system32\SETD9.tmp

c:\windows\system32\SETDA.tmp

c:\windows\system32\SETDB.tmp

c:\windows\system32\SETDC.tmp

c:\windows\system32\SETDD.tmp

c:\windows\system32\SETDE.tmp

c:\windows\system32\SETDF.tmp

c:\windows\system32\SETE.tmp

c:\windows\system32\SETE0.tmp

c:\windows\system32\SETE1.tmp

c:\windows\system32\SETE2.tmp

c:\windows\system32\SETE3.tmp

c:\windows\system32\SETE4.tmp

c:\windows\system32\SETE5.tmp

c:\windows\system32\SETE6.tmp

c:\windows\system32\SETE7.tmp

c:\windows\system32\SETE8.tmp

c:\windows\system32\SETE9.tmp

c:\windows\system32\SETEA.tmp

c:\windows\system32\SETEB.tmp

c:\windows\system32\SETEC.tmp

c:\windows\system32\SETED.tmp

c:\windows\system32\SETEE.tmp

c:\windows\system32\SETEF.tmp

c:\windows\system32\SETF.tmp

c:\windows\system32\SETF0.tmp

c:\windows\system32\SETF1.tmp

c:\windows\system32\SETF2.tmp

c:\windows\system32\SETF3.tmp

c:\windows\system32\SETF4.tmp

c:\windows\system32\SETF5.tmp

c:\windows\system32\SETF6.tmp

c:\windows\system32\SETF7.tmp

c:\windows\system32\SETF8.tmp

c:\windows\system32\SETF9.tmp

c:\windows\system32\SETFA.tmp

c:\windows\system32\SETFB.tmp

c:\windows\system32\SETFC.tmp

c:\windows\system32\SETFD.tmp

c:\windows\system32\SETFE.tmp

.

---------------------------------------------------------------

Then............

Please download AdwCleaner by Xplode and save to your Desktop.

  • Double click on AdwCleaner.exe to run the tool.

    Vista/Windows 7/8 users right-click and select Run As Administrator

  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
If you agree with everything listed to be removed in the folders section...........

Double click on AdwCleaner.exe to run the tool again.

  • Click on the Scan button.
  • AdwCleaner will begin to scan your computer like it did before.
  • After the scan has finished...
  • This time click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[s0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
Then..................

Open up Malwarebytes > Settings Tab > Scanner Settings > Under action for PUP > Select Show in Results List and Check for removal.

Please Update and run a Quick Scan with Malwarebytes Anti-Malware, post the report.

Make sure that everything is checked, and click Remove Selected.

Please let me know how computer is running now, MrC

Link to post
Share on other sites

Please find attached the ADT cleaner log. I am not able to delete the "Search Protect" folder. Ans most of these files were not found under System32 folder. So I deleted the files I found there. And I think search Protect folder is deleted by ADT Cleaner. I will run MBAM now will post the logs for the same. Thanks.

AdwCleanerS0.txt

Link to post
Share on other sites

Please download on the Desktop the following application: Windows Repair

Next, extract and launch the Repair_Windows.exe

Click on Start repairs tab and then click on Start

Check mark following options alone

Repair Internet Explorer:

Checkmark Restart System When Finished option

click the Start button

System should restart after repair

Let me know.....MrC

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.