![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
|
|
#1
|
|||
|
|||
|
Infected by viruses, ran Spybot and Malwarebytes, MWB had been turned off, not normal. Still had problems, so Completed Read Me steps, Still have problems
Computer would not operate in std mode, so steps up to combofix were done in safe mode. Safe mode did not allow uninstall of Java, so this step was skipped. Running Vista 64 so RootRepeal was not done. Everything was fine for a few minutes. Browsed major geeks for a moment and start-up programs seemed fine. When re-enabling user account control, double clicking the EnableUAC.reg brought up the windows does not recognize this file extension, browse to find the correct program. Tried twice, same result. So i did it manually through control panel and rebooted. Everything fine. After re-start, step 6 of Vista instructions, right clicked Computer and things went bad. Computer locked. Tried a few times rebooting and problems got worse. Now in STD mode computer locks or screen goes black. Task manager will not come up to see what apps and processes are running. Sometimes desktop or startmenu will fade to grey and everything locks. Also of note, in STD mode, I get a pop-up window titled Security Alert: You are about to view pages over a secure connection... no one will be able to see pages etc. I closed the window clicked google chrome to nav to Majorgeeks and all seemed well enough. Clicked restore pages, then naving MajorGeeks the browser locked with the message waiting on cache. Now computer boots in STD mode, but erratically. Safe mode with networking is all I can do and still have access to MG. Attaching logs. Also attaching log from Malware Bytes std operation, and then log from first run before Read Me steps. In next post... |
| Sponsored links |
|
|
|
#2
|
|||
|
|||
|
Other MWB logs attached...
|
|
#3
|
||||
|
||||
|
Go to the below link and follow the instructions for running TDSSKiller by Kaspersky
Please also download MBRCheck to your Desktop. See the download links under this icon ![]()
Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished): Run C:\MGtools\analyse.exe by double-clicking it (Vista and Win7 right-click and select Run as Administrator) Choose Do a system scan only and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now: Quote:
Now we need to use ComboFix
Quote:
If after running ComboFix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem. Now run C:\MGtools\GetLogs.bat by double-clicking on it (Vista and Win7 right click and select Run as Administrator) This will automatically update all the logs in MGlogs.zip! Make sure you click Accept on the License Agreement from HiJackThis!/analyse.exe twice (yes twice) if prompted. Then attach C:\MGlogs.zip to your next message (How to attach items to your post) |
| The Following User Says Thank You to thisisu For This Useful Post: | ||
pazzoduc (08-10-11) | ||
|
#4
|
|||
|
|||
|
OK, next steps completed.
TDSSKiller found nothing.... MBRCheck Found the Non-std/infected MBR Logs attached. |
|
#5
|
||||
|
||||
|
You have an infected Master Boot Record (MBR). Since MBR infections are only worsening, we recommend that you make sure you have any important data backed up before proceeding with the below.
Do you have your Windows Vista install DVD? If so,
Now type Exit to exit the Recovery Environment. Note: There is a SPACE AFTER bootrec Note: To start the computer from the Windows Vista DVD, the computer must be configured to start from the DVD drive. For more information about how to configure the computer to start from the DVD drive, see the documentation that is included with the computer or contact the computer manufacturer. You can also view this page for more information on using Bootrec /fixmbr: http://support.microsoft.com/kb/927392 After using the bootrec /fixmbr command, please reboot into Windows Vista and rerun MBRCheck and attach its new log here Also let me know what malware problems you are still experiencing. |
| The Following User Says Thank You to thisisu For This Useful Post: | ||
pazzoduc (08-10-11) | ||
| Sponsored links |
|
|
|
#6
|
|||
|
|||
|
I can't seem to get to the System Recovery options on the Vista disc.
I located the instructions and I am booting from the Cd drive. But vista boots completely, no system recovery option dialog box appears. I checked the Dell support site and found an alternate method to do the MBR repair, but it is only compatible with 32bit systems. This box is 64bit. Any Ideas? Anyone? |
|
#7
|
|||
|
|||
|
OK, A bit of an update while I have some renewed enthusiasm.
![]() I have been running various killer programs and fixing the registry when needed after killing off recurring viruses. A quick recap: Downloaded and ran Roguekiller. Seems to have found a few prickly issues that Malwarebytes, Superantispyware, Spybot and Security Essentials all failed to find. But in removal, the registry was corrupted. So I downloaded AVG Recovery as suggested here: Linky. Ran every possible test and fix the program offered. After the MBR fix portion the CPU would not boot, it only cycled on and off just before the MS start screen. So I rebooted from the Dell/OEM Vista disc and went through the Start-up repair in System Recovery. All seems well except MBRCheck still reports a Faked MBR. At this moment I am confident that there are no active viruses on the machine. If there are, WOW. More power to them I guess. I have run and checked a huge number of diagnostic, fix, kill programs over the past few days. I have attached the MBRCheck log. Is there anyone out there that can read the log to see if it is a true Rootkit problem or just a false negative? (see next post) And if it is an isssue, should I do something like this? Linky At this point I have enough enthusiasm to try to be successful. Rather than just formatting and starting over! |
|
#8
|
|||
|
|||
|
Log attached
|
|
#9
|
||||
|
||||
|
Maybe it was a fluke with MBRCheck. We have another tool to get a second opinion now.
Please download aswMBR to your desktop.
Quote:
|
|
#10
|
|||
|
|||
|
Log Attached
Unknown MBR code reported |
| Sponsored links |
|
|
|
#11
|
||||
|
||||
|
I do not think this is a problem. Especially if you are saying you are not experiencing any problems. Normally with an infected MBR, you'll notice it pretty much right away and in most cases it will prevent you from being able to run tools like ComboFix / TDSSKiller / aswMBR. Anything that checks the MBR basically.
![]() I do not think you have anything to worry about. |
|
#12
|
|||
|
|||
|
Can I run ComboFix? I have a 64bit OS. I was under the impression it would only work for 32b systems?
Is there a similar program that will work on 64b OS's? My only issue with the MBR code is the recurring frequency of viruses even with Malwarebytes and Security Essentials running. I'm curious if it is opening the door? |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Malware Removal Instructions Complete... Problems still exist | marine43302 | Malware Removal | 11 | 07-16-10 05:43 |
| Malware Removal Help-I did all the steps and still have problems | ccml118 | Malware Removal | 6 | 06-05-08 14:32 |
| Malware removal steps completed, problems still around... | Fuelman | Malware Removal | 11 | 11-02-07 21:12 |
| Steps Complete...Need to check logs (Vundo Removal Content) | StuckinaGroove | Malware Removal | 10 | 06-05-07 23:31 |
| Unable to complete steps in removal guide, HELP | captain_justin | Malware Removal | 7 | 11-16-06 02:33 |