Bluetooth Network or Browser Hijacked ??

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by AudioHavok80, Mar 22, 2012.

  1. AudioHavok80

    AudioHavok80 Private E-2

    I suspect my new Dell N5110 laptop's network has been Hijacked? Files seem to change names on their own and appear out of nowhere. Scipting seems to be involved. Need help or I'm thinking it might possibly better to just somehow clean install? with this prefab setup from Best Buy not even sure if a clean install is possible. Any advice would be greatly appreciated. scan logs: hijackthis.log, mbamlog.txt file, and SAS log file and an extra dds.txt logfile hoping it might help as well). Thanks in advance. -AW80
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We do not require a DDS log. You need to ensure that you have followed our instructions here and then attach the rest of the required logs. ;)

    READ & RUN ME FIRST. Malware Removal Guide

    I will then have you run a couple more tools.
     
  3. AudioHavok80

    AudioHavok80 Private E-2

    yes i followed that guide thoroughly before i posted. forgot to post the rest one sec =]
     
  4. AudioHavok80

    AudioHavok80 Private E-2

    here are the rest of the logs thanks again.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. I am not seeing any problems.

    What files change and appear? ? :confused

    Don't know what you mean.

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
     
    Last edited: Mar 23, 2012
  6. AudioHavok80

    AudioHavok80 Private E-2

    kapersky found nothing. the mbr found something wrong with my boot drive or something like that. in any event here is the log and for some reason its not letting me attach the file *scratches head*, so ill just copy and paste it. thank you.
     

    Attached Files:

    Last edited by a moderator: Mar 23, 2012
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Unkown MBR code does not mean BAD. :) Don't worry about that one, if it said Faked then there would be need to be concerned.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  8. AudioHavok80

    AudioHavok80 Private E-2

    i did everything as instrcuted but im comcerned with the last part of the scan
    "Found non-standard or infected MBR.
    Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    Options:
    [1] Dump the MBR of a physical disk to file.
    [2] Restore the MBR of a physical disk with a standard boot code.
    [3] Exit."

    should i have proceeded any further? non-standard or infected doesn't sound good. i'm thinking i should have fixed it somehow?

    btw to elaborate on the problems i was having even further; things like programs i have installed seem to have updated install dates in the add or remove programs section also like i said before i will save files in my user profile downloads or backup files folder and they will disappear. i've also had weird things like credentials i never created appear in the windows vault or cardspace area, whatever it's called. it seems as if something isn't right. but i'll trust u if u say my system is good to go. ^^ thanks again.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're fine. ;) You have a Dell, so you have a non standard MBR.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds