1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Windows Help removing returning malware (Optimizer Pro)

Discussion in 'Tech Support' started by Otis1337, 24 Jul 2014.

  1. Otis1337

    Otis1337 aka - Ripp3r

    Joined:
    28 Nov 2007
    Posts:
    4,711
    Likes Received:
    224
    So my friend asked me to help her with her laptop, it was full of desktop pop ups and random malware.

    After a few hours iv removed all of it but one which i cant seem to permanently remove for good as it keeps coming back after reboot.

    Its called Optimizer Pro, after its uninstalled, it comes back with a desktop icon.

    I have Avast and Malwarebites installed and although they have both removed loads of crap they are not picking up Optimizer Pro at all. Also tried Kaspersky's rootkit removal tool (tdsskiller).

    Google search come up with lots of people with the same problem but no fix's.

    Thanks in advance!
     
    Last edited: 25 Jul 2014
  2. dancingbear84

    dancingbear84 error 404

    Joined:
    16 Oct 2010
    Posts:
    2,192
    Likes Received:
    73
    Try safe mode, or look in start up folder for a link, or something like that. In the past I have found a link in the start up folder that looks odd, trace it round to a folder with the dodgy software. There is also another place to look, but after midnight my brain turns to mush. I'll dig it up in the morning,

    The other thing to try would be a Linux live boot disc, then scanning with some Linux av/malware, as it won't run anything like exe's or dll's etc that would otherwise be running in a windows environment ...
     
  3. theshadow2001

    theshadow2001 [DELETE] means [DELETE]

    Joined:
    3 May 2012
    Posts:
    5,284
    Likes Received:
    183
    Msconfig? Scheduled tasks?
     
  4. Otis1337

    Otis1337 aka - Ripp3r

    Joined:
    28 Nov 2007
    Posts:
    4,711
    Likes Received:
    224
    After digging around in appdata and removing edgy looking files seems to of done the trick.
    Will report back after a day or two to be sure its gone for good.

    Thanks for the replys.
     
  5. dancingbear84

    dancingbear84 error 404

    Joined:
    16 Oct 2010
    Posts:
    2,192
    Likes Received:
    73
    Yup exactly what I was thinking of thanks! My brain was in a lot of different places last night, none of them had my full concentration.
     
  6. Otis1337

    Otis1337 aka - Ripp3r

    Joined:
    28 Nov 2007
    Posts:
    4,711
    Likes Received:
    224
    Well been pottering about on the laptop for a few hours with a number of reboots and seems to of gone!
     
  7. JohnRogers24

    JohnRogers24 What's a Dremel?

    Joined:
    22 Jul 2014
    Posts:
    20
    Likes Received:
    0
    For future reference, try Revo Uninstaller. Will pick up almost everything, and will wipe every file that came along with it.
     
  8. Pookie

    Pookie Illegitimi non carborundum

    Joined:
    4 May 2010
    Posts:
    3,566
    Likes Received:
    176
  9. Shirty

    Shirty W*nker! Super Moderator

    Joined:
    18 Apr 1982
    Posts:
    12,937
    Likes Received:
    2,058
    If all else fails, manually ripping out registry entries usually prevents the return of the mack(ware).
     
  10. boiled_elephant

    boiled_elephant Merom Celeron 4 lyfe

    Joined:
    14 Jul 2004
    Posts:
    6,914
    Likes Received:
    1,195
    And for a fire-and-forget tool to deal with rubbish like this, Combofix very often gets it. It gets everything in the grey area between real infections and legitimate nuisanceware. Then ADWC and JRT get the latter. They only automate a process you can go through yourself with CCleaner, autoruns and digging through various folders, but they can be a time saver.
     
  11. mansueto

    mansueto Too broke to mod

    Joined:
    31 Aug 2007
    Posts:
    3,784
    Likes Received:
    110
    Something I like to do is to take the drive out, put it in an external enclosure, and scan it from another pc. Removes the safe mode hassle and all that. Plus, I'm usually too lazy to mess about with cables and connections (speaking for fixing desktops at least). Personally, I've yet to find something that malwarebytes hasn't been able to remove, but I'd imagine there are some more advanced viruses and malware that would require more effort to remove.
     
  12. Otis1337

    Otis1337 aka - Ripp3r

    Joined:
    28 Nov 2007
    Posts:
    4,711
    Likes Received:
    224
    Thanks everyone! Gave autorun a go and picked up one last thing lurking about. cheers.
     

Share This Page