Internet explorer volume, bluescreen & advert pop ups

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Nutmegking85, Dec 1, 2010.

  1. Nutmegking85

    Nutmegking85 Private E-2

    Hi guys,

    I'm using windows 7 64bit on a HP laptop......for some reason my internet explorer volume keeps muting its self when ever I start up windows......Ive also had the bluescreen happen 3 times and some random pop up adverts.

    It's getting very annoying.

    if you could help that would be much appreciated.

    thankyou,

    Nutmegking85
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    • Download bootkit_remover.rar
    • Click the underlined DOWNLOAD text to download the file and save it to your Desktop.
    • You then need to extract the remover.exe file from the RAR using a program capable of extracing RAR compressed files. If you don't have an extraction program, you can use7-Zip
    • After extracing remover.exe to your Desktop, double click the remover.exe file to run the program.
    • Attach or post inline here, the output from remover.exe

    Then follow through with the below too:

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. Nutmegking85

    Nutmegking85 Private E-2

    When I go to the ''bootkit_remover.rar'' my anti virus ''Trend Micro Internet Security Pro'' notifies me that this site is ''dangerous''......What do I do??
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It's a false positive... allow it.
     
  5. Nutmegking85

    Nutmegking85 Private E-2

    Ok first bit is done......here is the output from ''remover.exe''.....hope this is the right information you need.

    Nutmegking85
     

    Attached Files:

    Last edited by a moderator: Dec 2, 2010
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No. Not the correct information. What I need to be seeing is something like the below:

    It might be better if you re-ran it and just took a screenshot.
     
  7. Nutmegking85

    Nutmegking85 Private E-2

    Im just about to do step 7 on the ''READ & RUN ME FIRST. Malware Removal Guide''.......is it still ok to do so or shall I do the ''remover.exe'' bit again first??

    Obviously I've also done step 6 which is to ''Disable Any Disk Emulation Software (like Daemon Tools..etc)''......to do this I downloaded ''DEFOGGER'' like it said in the link.......What shall I do?

    Sorry to be so annoying.

    Nutmegking85
     
    Last edited by a moderator: Dec 2, 2010
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do everything else first and then run Remover.exe.

    With what? Defogger? Run it as per the instructions! :)
     
    Last edited: Dec 3, 2010
  9. Nutmegking85

    Nutmegking85 Private E-2

    No problem will do that and let you know.

    Thankyou,

    Nutmegking85
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I'll be here waiting. :)
     
  11. Nutmegking85

    Nutmegking85 Private E-2

    Hello again,

    File logs have been attached from the scans as per the instructions on the ''READ & RUN ME FIRST. Malware Removal Guide''. There should be three files attached one of them being a ''ZIP'' file.

    Shall I enable my ''UAC'' now before I run the ''BOOTKIT REMOVER'' or ''REMOVER.EXE'' or shall I run it while ''UAC'' is disabled?

    Also you mentioned in your previous post that the information I posted before from ''REMOVER.EXE'', the output, was not the right information and you asked to do a screenshot. How is this done?

    Regards,

    Nutmegking85 :)
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there.

    Do it with UAC disabled.
    Hit the PRTSC button usually located to the top right of the keyboard a few keys away from DEL. Then Open up Paint Start > all progs> accessories > paint. Then from the menu choose "paste" and save the image to your desktop for easy retrieval to attach here for me.
     
  13. Nutmegking85

    Nutmegking85 Private E-2

    Hi Kestrel13!,

    I've hit the ''PRTSC'' button located top right of keyboard but nothing happens.

    I've tried holding shift as well as it's got ''INSERT'' on the same button with ''PRT SC'' underneath.

    Plus after ''REMOVER.EXE'' has finished running it says to hit ANY BUTTON to QUIT, so when I hit the ''PRT SC'' button it closes the program.

    What do I do?

    Again sorry to be a pain,

    Nutmegking85
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    When you hit PRTSC button nothing APPEARS to happen but what you have done is put information onto the clipboard. The next step was opening up Paint as I described.
     
  15. Nutmegking85

    Nutmegking85 Private E-2

    I've done like you said but it wouldn't allow me to paste in paint for some reason, which is why I was puzzled, so I managed to paste in a ''txt document'' instead. I never knew this procedure of copying info could be done. Suppose you learn something new everyday, lol.

    Anyway that's done now so I'll attach it to this reply, let me know if this is the information that you require from ''REMOVER.EXE''.

    Is there anything else which needs to be done or do I wait for instructions?

    Much appreciated,

    Nutmegking85
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do you know what these files are for?
    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.
    Code:
    :files
    C:\Windows\system32\rvitliisaitfw.exe 
    C:\Windows\SysWOW64\rvitliisaitfw.exe
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Don't forget to answer my questions about those files. Also you must tell me how things are running now.
     
  17. Nutmegking85

    Nutmegking85 Private E-2

    hello Kestrel13!

    Just to say my volume for internet explorer is fixed, I'm not getting any more problems with that, so that's ok. When I kept getting the blue screen, which was 3 times, there was roughly about a month, maybe a bit longer between each one and now I haven't received one as yet, so even that seems to be fine at the moment.

    As for the random adverts which open up unexpectedly in a new browser window, a few seem to be still appearing but doesn't look as if it's causing any problems, I hope not anyway. So above all I think everything is fine, those anti malware programs must of worked very well for me.

    Those files which you mentioned,

    C:\ProgramData\DVD.exe
    C:\ProgramData\Games.exe
    C:\ProgramData\Karaoke.exe
    C:\ProgramData\MPV.exe
    C:\ProgramData\MobileTV.exe

    I have no idea what they are. The symbol of the files is a ''circle'' with a blue background with an italic white coloured ''f'' inside the circle. Maybe it's ''FLASH PLAYER'' not totally sure.

    Shall I paste one of those files on here to show you the symbol?

    Anyway I shall do these steps which you posted and post you the info.

    Sorry for writing an essay, lol :)

    Thankyou,

    Nutmegking85
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    They all appeared on the 8th Nov this year. Ring any bells?

    Let's scan a couple:

    Please go to virustotal and upload the following files for analysis, and let me know the results.

    No need. You would have to take a screenshot anyway.

    Yes please! I'll be here waiting. Also let me know the virustotal results. :)
     
  19. Nutmegking85

    Nutmegking85 Private E-2

    Hi Kestrel13!

    I've done the ''OTM step'' and the files are attached........I've created two as I wasn't sure if the first 1 was correct.......as the scan finished, the computer shutdown and I was unable to copy......when my laptop restarted the ''Run'' menu popped up for the OTM program even before windows was fully started up, I selected cancel. I re-opend OTM and a notepad came up with the results, so I saved that. So I followed your instructions on what to do afterwards about retrieving the results and created another notepad hence two outcomes.

    Let me know if this is the right information.

    I also ran the ''C:\MGtools\GetLogs.bat''.......I had a few problems as the registry menu I think it was kept popping up. First I kept selecting ''YES''.......then afterwards ''NO''.......after that I kept pressing the ''X'' button at the top right as the instructions bar kept popping up.......finally finished but the ''MGLOGS.ZIP'' file was not created........Any idea why?

    Sorry for late reply,

    Nutmegking85
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You did not attach the virus total results, youattached an OTM log twice. :)
     
  21. Nutmegking85

    Nutmegking85 Private E-2

    Hello Kestrel13!

    Sorry for late reply i've been very busy lately which is why I never got back to you with those virus results. Will try to get them done as soon as possible.

    Any idea of why my MGTOOLS didn't work properly as I mentioned in my previous post?

    Thanks,

    Nutmegking85:)
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Perhaps you had forgotton to disable UAC.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds