Virus disables firewall

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by emilyhasbooks, Apr 2, 2014.

  1. Hello, First timer here. My girlfriend suggested you. I have the paid version of Avast! I have the free versions of SuperAntiSpyware and Malware Bytes.

    A friend downloaded a movie and I think that is where I got the virus.

    What I can tell it is doing so far:
    It stops me from connecting to any website on any browser.
    It disables my Avast! Firewall.

    Thank you,
    Homes
     
  2. I thought I attached the stuff, oops.. Here it is.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You still have quite a bit more to attach. ;)

    I still need logs from:
    • Malware Bytes
    • Hitman Pro
    • RogueKiller
    • MGTools

    Thanks.
     
  4. Here are the files, I accidentally clicked delete on two HKey files in RogueKiller.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman and have it remove what it finds please.


    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    After reboot, check to see if your firewall is working.


    Please download AdwCleaner by Xplode and save to your Desktop.

    • Double click on AdwCleaner.exe to run the tool.
    • Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  6. Firewall is on now, Thank you.

    In the AdwCleaner file:
    I'd like to keep my preferences for chrome, if possible.

    Here are the files. Thank you again.
     

    Attached Files:

  7. I missed the first step... I apologize. I didn't notice the instruction to re run Hitman. Should I go back and redo all of this?
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No need. :) Just do the Hitman step.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes you can keep your preferences for Chrome.

    MGTools did not run to completion. Run it again this time taking special care to ensure that UAC is disabled, your anti virus is indeed disabled, and that you did run it as admin. THEN attach the new MGlogs.zip for me to look at.
     
  10. I try to run Hitman, but before it scans it tries to connect to the internet and says there is no connection, then it closes. My internet IS working though.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do not worry about that step. What it's finding is really not important.
     
  12. I hope this is complete:
     

    Attached Files:

  13. A piece of info I forgot to include:
    I still can't get any site to load on my browser.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Browser or browsers? Tell me exactly which browsers are affected. Is it still all of them??
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Is the below file visible to you? Are you able to delete it? If so, after a reboot, when you navigate back to where it was, is it still gone or not?


    C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini



    Download Cleano 0.61

    Download it to your desktop, Right click the cleano.exe file and run as admin > and place check marks in the boxes as follows (click on link below to see image)

    View attachment 148092
    Click clean now and exit the program.

    Any better?
     
  16. Chrome does not work. IE works.
    I was able to see and delete the file EEB...
    Upon restart it was gone.

    I ran Cleano, chrome still won't load webpages.
     
  17. Avast! has popups that say it isn't adequately updated and attempts to download updates but cannot reach the host. This is similar to the issue with HitmanPro. I can play online games and use voice communication like Teamspeak, however.
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall Google Chrome with Revo Uninstaller and then reinstall. Let me know if it works.
     
  19. I downloaded the uninstaller and uninstalled Chrome. IE is now also not loading web pages. I downloaded the Chrome.exe installer on a flash drive from my girlfriends computer and tried to run it on my computer but I get an error code: 0xa0430721

    I have no other browsers.

    Avast! keeps giving me a message that updates are not loaded properly and it needs to update, but cannot connect to online in order to do so. As I said before, I can connect other software live voice communication to the internet, so I know I have a connection.
     
  20. I downloaded the uninstaller and uninstalled Chrome. IE is now also not loading web pages. I downloaded the Chrome.exe installer on a flash drive from my girlfriends computer and tried to run it on my computer but I get an error code: 0xa0430721

    I have no other browsers to use.

    Avast! keeps giving me a message that updates are not loaded properly and it needs to update, but cannot connect to online in order to do so. As I said before, I can connect other software live voice communication to the internet, so I know I have a connection.
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi. :)

    At this point, I think you should post about your remaining issues in the software forum.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds