popups, sound issues and clicking sound

Discussion in 'Malware Help (A Specialist Will Reply)' started by tm920, Jul 19, 2010.

  1. tm920

    tm920 Private E-2

    I am having the same issue that many others are having and I have tried SuperAnti Spyware, Malwarebytes, ComboFix, nothing has worked. I am attaching the Mglogs.zip file, MBR check file and the Bootkit remover file also. If someone could help i would greatly appreciate it.
    Thanks.
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks, tm920

    Is Drive G bootable or for storage?

    Do you have all important data backed up? You really should do this before continuing since we will need to rewrite your MBR to fix this and while most times this can be done without any problem, these infections can react badly and that could result in a PC not being bootable. You really don't have much choice though since these infections are too dangerous to your security to leave on a PC.

    Also note if you have a Dell PC which uses a non-standard MBR ( or another manufacturer's who does similar to Dell) , fixing the mbr may prevent access the the Dell Restore Utility, which allows you to press a key on startup and revert your computer to a factory delivered state. There are a couple of known fixes for said condition, though the methods are somewhat advanced. If you are unwilling to take such a risk, you should not continue but you risk serious problems leaving this infection in place and thus your only other option would be to try using the Dell Restore Utility to return a factory ship state which will remove everything you additional you have put onto the PC.

    dr.m
     
  3. tm920

    tm920 Private E-2

    Thanks for the response. The drive G is for storage and I have backed up everything I need. My comp is not a Dell and I'm definitely willing to take whatever risk to fix the prob.
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    *First - you need to run MSconfig and put your PC into normal startup mode as requested in step 4 of the READ & RUN ME guide.

    Use MSconfig to setup for Normal Startup Mode

    Then disable Spybot's TeaTimer
    How to disable Spybot's TeaTimer

    Now if you wish to continue and fix the malware - please do the following:
    • Run MBRCheck.exe
    • Wait until you see the following lines:

      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
      • Options:
        [1] Dump the MBR of a physical disk to file.
        [2] Restore the MBR of a physical disk with a standard boot code.
        [3] Exit.
        Enter your choice:
    • Please push the 'Y' key and then press Enter
    • When the program asks you to Enter your choice: enter 2 to Restore the MBR and press the Enter key
    • Now the program will ask you to "Enter the physical disk number to fix (0-99, -1 to cancel):"
      • Enter 0 and press the Enter key.
    • The program will show Available MBR codes
    • Please enter 0 and press the Enter key
    • The program will prompt for confirmation. Type 'YES' and hit Enter.
    • Left click on the title bar (where program name and path is written). From menu chose Edit -> Select All
    • You will see all the text in the window get highlighted.
    • Hit the Enter key on your keyboard to copy all of the text into the clipboard.
    • Paste that text into Notepad, save it to your desktop as MBRfix.txt
    • Restart your PC.
    • Attach the MBRfix.txt file to your next message..

    Please also attach the requested SuperAnti-Spyware and Malwarebytes' logs.
     
  5. tm920

    tm920 Private E-2

    EDITED by dr.moriarty: Removed unnecessary post quote.
     
    Last edited by a moderator: Jul 21, 2010
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You didnt attach anything.
     
  7. tm920

    tm920 Private E-2

    EDITED by dr.moriarty: Removed unnecessary post quote

    I went thru the steps in the order you listed them, when I ran the MBRCheck.exe this option never came up (Enter 'Y' and hit ENTER for more options, or 'N' to exit) I did run Combofix.exe last night again and I have not had any popups or sound issues since. Still not sure my comp is clear of the problems which is why I decided to go thru the steps you have listed.
     

    Attached Files:

    Last edited by a moderator: Jul 21, 2010
  8. tm920

    tm920 Private E-2

    Sorry about that they did not upload properly. I uploaded them in another message.
     
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Now go to this link MGTools and download the new version of MGtools....overwrite your previous MGtools.exe file with this one.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the new C:\MGlogs.zip file to your next reply.
     
  10. tm920

    tm920 Private E-2

    Here is the Zip file.
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds