Jump to content

MBAM won't start - Chamelon didn't work. Need someone to help with process, please.


Recommended Posts

MBAM stopped working. Tried uninstalling it, that failed. Tried all 13 Chameleons, all failed. Need someone to take me through the process with the other removal tools. I posted in the wrong area of the forum earlier and was refered here. Here are my Farbar files. I have not tried to fix anything yet. Appreciate any help, thanks!

Addition.txt

FRST.txt

Link to post
Share on other sites

  • Replies 50
  • Created
  • Last Reply

Top Posters In This Topic

Hello and welcome to Malwarebytes,

Please be aware the following P2P/Piracy Warning is a standard opening reply made here at Malwarebytes, we make no accusations but do make you aware of Forum Protocol....
 

 

If you're using Peer 2 Peer software such as uTorrent, BitTorrent or similar you must either fully uninstall them or completely disable them from running while being assisted here.Failure to remove or disable such software will result in your topic being closed and no further assistance being provided.If you have illegal/cracked software, cracks, keygens etc. on the system, please remove or uninstall them now and read the policy on Piracy.

 

Next,

 

Please download MBAM-clean and save it to your desktop.

  •    Right-click on mbam-clean.exe icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  •    It will ask you to reboot the machine - please do so.
  •    Run the cleaner tool again, re-boot when complete.


Download & install the newset MBAM version.

Please download 51a46ae42d560-malwarebytes_anti_malware.Malwarebytes Anti-Malware
 

  •    Install the progam and select update.
  •    Once updated, click the Settings tab, in the left panel choose Detctions & protection and tick Scan for rootkits.
  •    In the same tab, under PUP and PUM detections make sure it is set to Treat detections as malware.
  •    Click the Scan tab, choose Threat Scan is checked and click Scan Now.
  •    If threats are detected, click the Apply Actions button. You will now be prompted to reboot. Click Yes.
  •    Upon completion of the scan (or after the reboot), click the History tab.
  •    Click Application Logs and double-click the Scan Log.
  •    At the bottom click Export and choose Text file.


Save the file to your desktop and include its content in your next reply.
 

 

Next,

 

Please download RogueKiller and save it to your desktop from the following link: http://www.bleepingcomputer.com/download/roguekiller/

  • Quit all running programs.
  • For Windows XP, double-click to start.
  • For Vista,Windows 7/8/8.1/10, Right-click on the program and select Run as Administrator to start and when prompted allow it to run.
  • Read and accept the EULA (End User Licene Agreement)
  • Click Scan to scan the system.
  • When the scan completes select "Report",in the next window select "Export txt" the log will open as a text file post that log... Also save to your Desktop for reference. log will open.
  • Close the program > Don't Fix anything!

 

 

Post those logs for me to see...

 

Thank you,

 

Kevin.

Link to post
Share on other sites

Double-click RogueKiller.exe to run again. (Vista/7/8/10 right-click and select Run as Administrator)

When "initializing/pre-scan” completes  press the Scan button, this may take a few minutes to complete.

When the scan completes open the Registry tab and locate the following detections:


[PUP] (X86) HKEY_LOCAL_MACHINE\Software\Conduit -> Found
[PUP|VT.not-a-virus:AdWare.Win32.Coupons.w] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\CouponPrinterService (C:\Program Files (x86)\Coupons\CouponPrinterService.exe) -> Found
[PUP|VT.not-a-virus:AdWare.Win32.Coupons.w] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CouponPrinterService (C:\Program Files (x86)\Coupons\CouponPrinterService.exe) -> Found
[PUP|VT.not-a-virus:AdWare.Win32.Coupons.w] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\CouponPrinterService (C:\Program Files (x86)\Coupons\CouponPrinterService.exe) -> Found


Make sure those entries are Checkmarked (ticked) also ensure that all other entries are not Checkmarked.

Open the Tasks tab and locate the following detections:

[suspicious.Path] \4736 -- wscript.exe (C:\Users\owner\AppData\Local\Temp\launchie.vbs //B) -> Found

 

Make sure those entries are Checkmarked (ticked) also ensure that all other entries are not Checkmarked.

Open the Files tab and locate the following detections:

[PUP][File] C:\Users\owner\AppData\Roaming\Microsoft\Windows\Recent\uninstall.lnk [LNK@] C:\Program Files (x86)\Coupons\Uninstall\uninstall.xml -> Found
[PUP][Folder] C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001} -> Found
[PUP][Folder] C:\ProgramData\{ADCBF7A8-716E-4B21-AF03-E3F11C06C309} -> Found
[PUP][Folder] C:\ProgramData\{B3C2C1CD-6B77-4A96-B670-F734AC2A1CBC} -> Found
[PUP][Folder] C:\Program Files (x86)\Conduit -> Found
[PUP][Folder] C:\Program Files (x86)\Coupons -> Found
[PUP][Folder] C:\Program Files (x86)\File Type Helper -> Found
[PUP][Folder] C:\Program Files (x86)\JustCloud -> Found
[PUP][Folder] C:\Program Files (x86)\W3i -> Found

 

Make sure those entries are Checkmarked (ticked) also ensure that all other entries are not Checkmarked.


Hit the Delete button, when complete select "Report" in the next window select "Export txt" the log will open as a text file post that log... Also save to your Desktop for reference.
 

Post that log.....

 

Try Malwarebytes again, post log if it runs and completes...

 

Thank you,

 

Kevin

Link to post
Share on other sites

Run the following:

 

Download AdwCleaner by Xplode onto your Desktop.

  • Double click on Adwcleaner.exe to run the tool.
  • Click on the Scan in the Actions box
  • Please wait fot the scan to finish..
  • When "Waiting for action.Please uncheck elements you want to keep" shows in top line..
  • Click on the Cleaning box.
  • Next click OK on the "Closing Programs" pop up box.
  • Click OK on the Information box & again OK to allow the necessary reboot
  • After restart the AdwCleaner(C*)-Notepad log will appear, please copy/paste it in your next reply. Where * is the number relative to list of scans completed...

 
Next,
 
thisisujrt.gif Please download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts. (re-enable when done)
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.


 

Next,

 

dr_web_cureit_zpse80d87bf.jpg
Download Dr Web Cureit from here http://www.freedrweb.com/cureit save to your desktop. (Scroll to bottom of page)

  • The file will be randomly named
  • Reboot to safe mode <<<<<------------ http://support.eset.com/kb2268/
  • Run Dr Web
  • Tick the I agree box and select continue
  • Click select objects for scanning


    drwebselect.JPG

  • Tick all boxes as shown
  • Click the wrench and select automatically apply actions to threats


    drwebfolders.JPG

  • Press start scan
  • The scan will now commence


    drwebscan.JPG

  • Once the scan has finished click open report <<<--- Do not miss this step


    drwebscancomplete.JPG

  • A notepad will open
  • Select File > Save as..
  • Save it to your desktop



This log will be excessive,  Please attach it to your next reply…
 

Next,

 

Run FRST one more time, ensure all boxes are checkmarked under "Whitelist" but only Addition.txt under "Optional scan" Select scan, when done post the new logs....

 

Let me see those logs,

 

Thank you,

 

Kevin
 

Link to post
Share on other sites

Download attached fixlist.txt file (end of reply) and save it to the Desktop, or the folder you saved FRST into.
NOTE. It's important that both FRST and fixlist.txt are in the same location or the fix will not work.

Run FRST and press the Fix button just once and wait.
The tool will make a log on the Desktop (Fixlog.txt) or the folder it was ran from. Please post it to your reply.

 

Can you run Malwarebytes in Normal mode?
 

Fixlist.txt

Link to post
Share on other sites

Run the following then try Malwarebytes again...

 

Download RKill from here: http://www.bleepingcomputer.com/download/rkill/

There are three buttons to choose from with different names on, select the first one and save it to your desktop.

  • Double-click on the Rkill desktop icon to run the tool.
  • If using Vista or Windows 7/8/10, right-click on it and Run As Administrator.
  • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • A log pops up at the end of the run. This log file is located at C:\rkill.log. Please post this in your next reply.
  • If you do not see the black box flash on the screen delete the icon from the desktop and go back to the link for the download, select the next button and try to run the tool again, continue to repeat this process using the remaining buttons until the tool runs. You will find further links if you scroll down the page with other names, try them one at a time.
  • If the tool does not run from any of the links provided, please let me know.

 
Post that log, if Malwarebytes fails to run again try a clean istall...
 
Please download MBAM-clean and save it to your desktop.

  •    Right-click on mbam-clean.exe icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  •    It will ask you to reboot the machine - please do so.
  •    Run the cleaner tool again, re-boot when complete.



Download & install the newset MBAM version.

51a46ae42d560-malwarebytes_anti_malware.

Please download 51a46ae42d560-malwarebytes_anti_malware.Malwarebytes Anti-Malware

  •    Install the progam and select update.
  •    Once updated, click the Settings tab, in the left panel choose Detctions & protection and tick Scan for rootkits.
  •    In the same tab, under PUP and PUM detections make sure it is set to Treat detections as malware.
  •    Click the Scan tab, choose Threat Scan is checked[/b and click Scan Now.
  •    If threats are detected, click the Apply Actions button. You will now be prompted to reboot. Click Yes.
  •    Upon completion of the scan (or after the reboot), click the History tab.
  •    Click Application Logs and double-click the Scan Log.
  •    At the bottom click Export and choose Text file.



Save the file to your desktop and include its content in your next reply.

 

Thank you,

 

Kevin

Link to post
Share on other sites

Try this please:

 

Download Shortcut-cleaner from here:

http://www.bleepingcomputer.com/download/shortcut-cleaner/dl/172/ save to your Desktop.
 

Right click on sc-cleaner and select "Run as Administrator"
 

When complete the tool will save a log to the same place the tool was ran from "sc-cleaner.txt" post to your reply

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.