Found non-standard or infected MBR - Logs Attached

Discussion in 'Malware Help (A Specialist Will Reply)' started by Qapla, Nov 21, 2011.

  1. Qapla

    Qapla Private E-2

    While reading posts that a search of "googleads.g.doubleclick.net" netted, I came across a thread that said to run MBRCheck.exe.

    I did this and have attached the log.

    I regularly rum MBAM, SAS, SB-S&D and have Norton AV and Firewall. All of them report a clean system though SAS finds a number of "tracking cookies" and gets rid of them.

    I do have a slow-loading IE and when I try to go back a page I often have to hit "back" several times to get to the previous page. If I use the "down arrow back - the one that shows immediate history - there are several links with "googleads.g.doubleclick.net".

    Please let me know what to do.

    Thanks

    View attachment MBRCheck_11.21.11_11.06.59.txt
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. Qapla

    Qapla Private E-2

    I have been running the scans you requested.

    When I run "RootRepeal" it seems to hang. I know the instructions said that it could take a while and to be patient. But I wanted to ask if this is "a while" or what to do:

    After it scans for a while it displays "C\i386 as the location it is scanning and displays "Looking for hidden/locked files" in the status bar at the bottom (I can't remember the exact words). After more then 4 hours it was still at this same place.

    I checked "Task Manager" and it reported that system idle process was between 92%-98% and process for "RootRepeal.exe" was 0%

    Is this normal?

    I will continue the other scans while I wait to hear back.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Skip RootRepeal and continue.
     
  5. Qapla

    Qapla Private E-2

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log from MBRcheck indicates that you may have a master boot record infection. Since you do not have a Windows XP CD, you will have to make one containing the Recovery Console only.



    Preferably from a clean computer, I need you to download the below:
    Create a bootable CD for the aboe ISO files. You can use ImgBurn do this.



    Now reboot from the Windows XP Recovery Console CD and execute the following commands. ( you may need to change to boot order in your BIOS to get it to boot from the CD if not prompted. You must make sure you boot from the CD. )
    • fixmbr
    • exit
    Once back in Windows, rerun MBRcheck and attach a new log.
     
  7. Qapla

    Qapla Private E-2

    Does the "clean computer" I d/l and burn the CD on have to also have XP? or can it have Vista or newer?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It can be any computer as long as you can burn the ISO image file on it.
     
  9. Qapla

    Qapla Private E-2

    I d/l the programs and made the boot CD.

    When I ran the CD and typed in "fixmbr" I got a warning that it could change my partition tables and make my computer un-bootable.

    Is this a real concern or should I proceed?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Typically this works without a problem. The warning you are getting is likely due to the fact that you have an HP PC and they have an HP Recovery Partition to restore your PC to factory state from. Many vendors do this instead of doing the right thing and giving you the CD/DVDs needed to fix your PC when problems arise.

    Repairing the MBR could make the Recovery Partition no longer usable. But it may have no effect on it whats so ever. Since the malware could have already corrupted the ability to use this partition, it may not matter.

    So here are your choices:
    • Live with the malware. Not recommended and dangerous to your security.
    • Back up important data ( somewhere external to this PC) to avoid possible loss and then continue with one of the below choices
      1. Restore the PC from the HP Recovery Partition to put it back into the state it was shipped. This erases all you current settings and saved data.
      2. Try using the method of running fixmbr. If it works, everything will be in tact the way you last had it.
     
  11. Qapla

    Qapla Private E-2

    OK - I did it!

    I will have to say that it is a bit :eek when you hit that <ENTER> key after hitting the <Y> and letting it run ... But .............

    It Worked!

    I have attached the log as requested.
    View attachment MBRCheck_11.22.11_18.00.56.txt

    On another note:

    I'm not sure where you :major get the time to help us unfortunate users - not only do you look at logs I couldn't begin to grasp and recommend the right solutions, you have written so many helpful programs that you offer at no charge. I would like to give you a :highfive for all you do for those of us who have been fortunate enough to find this forum.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your log is good now. Are you having any more malware problems?
     
  13. Qapla

    Qapla Private E-2

    I have noticed an overall faster computer. My browser and email are loading much faster.

    However,
    This has not changed. It does not seem to do it at every site I visit but it is very consistent at the sites where it does happen. Also, it does not seem to happen if I use Mozilla FireFox.

    In fact, I just hit the down arrow to look at what is there. It has as the top 3 entries listed:

    The first entry is Bold and has a check in front of it (it is this page)
    If I hit the back key, I will still have this page and the top two entried will change places. The one for this page will still be bold with a check.

    If I hit back again, I will return to the page before this one.

    Sometimes, there will be 3 or 4 of the "http://googleads.g.doubleclick.net/page" entries and each time I hit "Back" it will keep the page I am on until I back through them all - or I can use the down arrow and click the page I want to return to.
    I have attached a screen shot of the "Back Arrow" menu. Hope this helps.
    back.jpg
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not malware. Speak to google. ;) Empty your browser caches and history. Or try posting in the Software Forum.




    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds