Malwarebytes update

Discussion in 'Software' started by Andrei, Dec 26, 2009.

  1. Andrei

    Andrei Private E-2

    hello there. im new here too.
    im andrei from romania, and i found this site when looking for info about how to get rid of it. didnt find the info yet but im still trying. will make a post with detailed info about my problem.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: About myself _ new member

    Yes, it would help to know what your problem is. And welcome. :)
     
  3. Andrei

    Andrei Private E-2

    Re: About myself _ new member

    i can update my malwarebytes and access antivirus manufacturer sites again. looks like my problem is gone ... for now.
    Sophos conficker removal kit showed me the dll i had to remove. thanks to them. i had to ask a friend to dld it for me and pass it to me as my virus was blocking my access to virus removal tools.
    i tried the basic steps described on this site, everything worked except RootR which blocked my puter or ended in a critical error blue screen. blocked puter even in safe mode.
    thx for the advices i found here, now i just need to find that crytical windows vulnerability patch and i'll be okai.
     
  4. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi Andrei

    What Windows version do you have as some malware applications wont run in Vista or Windows 7 with out running as Admin (right click the app and choose Run as Administrator) or they just wont work in those Windows versions.

    Run Windows update and you should find whatever Windows vunerability patch that is applicable to your Windows version or if you know what the patch was to fix let us know and we maybe able to locate the manual download of it, but Windows Update shoudl do this for you.
     
  5. Oldphil

    Oldphil Sergeant

  6. Andrei

    Andrei Private E-2

    yes, it was conficker.
    removing the only hidden dll in system 32 made wonders for me.
    i can now access all anti-virus websites and i can update malwarebytes. some sophos conficker removal tool said that the virus was located there and in C:\System Volume Information. that's wat gave me the ideea to remove that dll. now i dunno how to deal with C:\System Volume Information as it's an empty folder or, atleast that's what windows says. but all the rest is working fine, that link to test for conficker now show's me as not having it, all the scans are showing me clean, except RootR which blocks my computer.
    i run XP SP2 and now i fixed the 08-067 vulnerability, installed firewall, updated java and deleted MS java and old updates, i pretty much followed all the advices i found on this forum, including reg clean, delete windows messenger, upgraded to IE 8, but i now know i should use FF more. i have FF, IE and Chrome, i sometimes create webpages and i wanna see how they look in diff browsers.
     
  7. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi Andrei

    You'll need to turn off System Restore and reboot then turn it back on to flush the System Restore points as thats whats stored in System Vol Information folder. How to toggle System Restore HERE
     
  8. Andrei

    Andrei Private E-2

    turned it off and the system restore tab is gone. i right click my computer properties, and the tab is no longer there.
    also, i installed Sygate Personal Firewall. but i am not sure what traffic should i allow and what traffic should i block. like ntoskrnl, svchost and ndisuio. is it normal that these are requesting to access the network?
    thx heaps again.
    happy new year and best geek new years eve party !
     
  9. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi Andrei


    Yes its very normal in the first week or so for a newly installed firewall to be in learning mode, and many things will pop up just go through them slowly, if you know what they are allow them if you dont check before allowing.

    ntoskrnl, svchost, ndisiuio are system files and normal to want network access, its not always internet access these files need but network, even if you dont have a network, for instance my defrag application is O&O defrag and you'd not think a defrag app would need to go through a firewall but this one uses TCP/IP to work so needs network access or it no work.

    So in summary, if in doubt on any file, do a quick search with your favoured search engine.
     
  10. Oldphil

    Oldphil Sergeant

    You not having the "restore tab" anymore seems to me there is still something wrong, it may take finer minds then mine to sort it out.

    Phil
     
  11. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi Andrei

    Forgot about the restore tab bit to your question, you may well still have malware on your PC and causing this but try this first HERE

    then take a trip to our malware forum and run this guide then start a new thread and attach the requested logs as described
     
  12. Andrei

    Andrei Private E-2

    regarding my firewall, it seems to me that even when i click yes every time i am asked to allow something to access the network, i still can't browse normally.
    i can access major geeks, i can log in with my name, i can push reply but when i push submit it fails to submit my message. i can open my yahoo mail, login, go to inbox, but when i click a mail i fail to open it. that happens even when i click allow to all i am asked for. makes me wanna check whatever i set as always blocked and don't ask me again again. i'll go check that list, hope its easy to find.
    as for my 2nd problem, " If you experience any of the above, it is likely caused by a corrupt <DriveLetter:>\System Volume Information folder." i'll try what i see there. i do suspect a corrupt C:\System Volume Information. that's y i turned off system restore in the 1st place.
     
  13. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    Try uninstalling that firewall and once uninstalled, run CCleaner and its Cleaner and Registry tools and then reboot and see if your internet is quicker?

    Also please name all the security applications you have installed as too many of the same type can cause this and also malware can, so yes do run through the Read Me Guide and if it finds anything start a new thread in the malware forum, explain your problems and attach the logs as I do feel you still have some lingering malware on your PC.
     
  14. Andrei

    Andrei Private E-2

    hi
    1st i wanna tell that the trick with deleting that folder worked, i had to do it in safe mode for my main drive ( C ) and now system restore tab is there and working.
    the firewall is the only "live" application i run, other that that i only use applications i found mentioned on this forum and only use em to scan, not to monitor.
    listed from Add/Remove Programs:
    CCleaner
    Malwarebytes
    SUPERAntiSpyware free edition
    Sygate Personal Firewall
    i too feel i mite have remains of some malware on my puter, superantispyware and malwarebytes wont find anything, i'll start the rest and tell what happens
    if i can't run RootRepeal, should i run GMER instead ? i did but i can't really read those logs.
     
  15. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Andrei

    Just move on to the next steps and complete them -- then attach the requested logs in a new thread in our Malware Removal Forum with a description of your remaining problems.

    *Your thread with then be in our work queue, where we work the oldest threads first.

    dr.m
     
    Last edited: Dec 29, 2009
  16. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi Andrei

    Yes do follow what Dr M posted above and attach the logs as it stated in the guide and out malware experts will be able to help you, their is a small lag in time to get to new posts as its the holiday season but they will get to you and they are very good at hunting out malware on your PC.


    So good luck
    David
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds