Cannot log in after installing Malwarebytes

Discussion in 'Malware Help (A Specialist Will Reply)' started by troubleshootingmom, Aug 8, 2013.

  1. troubleshootingmom

    troubleshootingmom Private E-2

    I installed Malwarebytes on a Windows 7 machine and ran it and it seemed to solve my problem of very slow internet performance after cleaning off 5 bad files, so I was trying to do the same for my daughter's Windows 7 computer and ran into trouble. I did not refer to this support forum until I began having problems with my daughter's computer.

    This is the order in which I performed tasks:
    Computer was running very very slowly so I downloaded Malwarebytes. It kept stalling and download interrupting. I would resume until download completed. Twice during the interruption Windows defender found dangerous Trogan, (can't remember name) and I cleaned it and continued on until download completed. Then executed install, and after it installed it said it was 128 days out of date so it began updating virus file, I walked away and when I came back the computer was hung up at blue screen with Windows logo. You could not cntl-alt-del and the power off button didn't want to work, but finally it did. Then when powered back up and after logging in it hung up and would not complete log in process and just hung. Then would not turn off and had to pop the battery out. Now I can only start in Safe Mode. It will not log on or off properly. I have to log off, let it hang, pop the battery, then I can start in safe mode.

    Then I referred to your ReadMeFirst link in your support forum to see what I did wrong and followed the following steps:

    Skipped Step 1 because it seemed moot at this point. I skipped steps due to not being able to connect to internet. Now in hindsite, if I connect in safe mode with networking option, maybe I could connect to internet? I had missed the part about downloading programs to CD if you could not connect to internet.

    Step 2. I uninstalled McAfee Antivirus.
    There was a program called WebRoot SecureAnywhere that I tried to uninstall but it said that you had to be connected as Administrator. Did not know if you are connected as Administrator in safe mode or not. Clicked okay, then it asked me if I wanted to uninstall, which I found weird and suspicous so I just left it. Since I had installed MalWarebytes I thought if I got to the point that if I could run the scan, maybe it would clean it off if it was malware.

    Step 3. No problems.

    Step 4 & 5. Skipped because I thought I could not connect to internet. (I have now realized that I can connect by choosing Safe Mode using Network option.)

    Step 6.
    Step 1 of 6. Skipped programs because i thought I could not connect to internet, but I already had Malwarebytes.

    Step 2 of 6. Disabled.

    Step 3 of 6. This had already been done prior to reading the ReadMeFirst support forum. Ran MBAM quick scan.

    Step 4 of 7. Logs attached.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to download the other tools we requested that you run and run them too and attach the other logs. If you cannot download them with this PC then use another PC to download them and then copy to this PC. Without the other logs we really cannot help you properly.
     
  3. troubleshootingmom

    troubleshootingmom Private E-2

    Do I need to uninstall Malwarebytes since I did not perform Steps 4 and 5before doing the quick scan in Safe Mode?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No just continue with the others. Try to run in normal boot mode ( if possible ) especially MGtools.
     
  5. troubleshootingmom

    troubleshootingmom Private E-2

    **** WARNING ****
    Skip running CCleaner or any other disk cleaning program if you are missing icons, items from your Star Menu, from All Programs....etc.

    I am missing icons. Is this because I am running in safe mode? Should I go ahead and perform this step? Or skip this one for now?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I cannot really tell until I see the logs. Thus you can skip it for now.
     
  7. troubleshootingmom

    troubleshootingmom Private E-2

    I downloaded Defogger to a CD. When I right clicked on it to copy it to my Desktop I received a Popup that told me what it was and I clicked Enable. After it finished I don’t remember seeing an OK button. The Enable button was still darkened like it hadn’t been pushed. I was not asked to reboot. Felt unsure that it had worked, so I right clicked again and this time it allowed me to copy to my desktop. Executed it again. This time the Application window appeared, which had not on the first instance so I clicked Disable. This time I noticed that it said not to click Disable again (it might have said this the first time too, but I don’t remember.) So when it asked if I wanted to Continue I clicked no.

    After running Rogue Killer after it finished scanning it notified me that I was not connected to a network. Was I supposed to be running this in Safe Mode with Networking options turned on? It created an RK_Quarantine File Folder and an RKreport(0)…. Which is attached.

    The link for HitmanPro instructions seemed pretty out of date. I.E. mine read HitmanPro 3.7.7 – Build 203 second opinioin anti-malware…
    Under settings the “List files that fail the Authenticode certificate check as Suspicious” was checked but greyed out, like it was disabled.”
    I tried to get back to point where I could choose Safe Mode with Network Options and accidentally entered System Bios. Now I am stuck and not sure how to get out Esc does not work.
     

    Attached Files:

    Last edited: Aug 9, 2013
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You will have to figure out how to exit your BIOS menus. Normally they all tell you how to save and quit or how to just quit without saving.
    If you cannot figure it out then just hold in the power button until your PC powers down. Wait a minute, and power back up.

    I still need the log from MGtools.

    Is the below something you installed?

    [RUN][SUSP PATH] HKCU\[...]\Run : Hunger games countdown clock (C:\Users\owner\AppData\Roaming\Hunger games countdown clock\DesktopContainer.exe [-]) -> FOUND
     
  9. troubleshootingmom

    troubleshootingmom Private E-2

    My email message only contained

    Here is the message that has just been posted:
    ***************
    I still need the log from MGtools.
    ***************



    Is the below something you installed?

    [RUN][SUSP PATH] HKCU\[...]\Run : Hunger games countdown clock (C:\Users\owner\AppData\Roaming\Hunger games countdown clock\DesktopContainer.exe [-]) -> FOUND

    I watched a hunger games trailer at one point. But I never intentionally installed anything. My daughter may have though.

    I didn't read your e-mails until late yesterday afternoon and it had occurred to me that my whole focus was on her machine because it had reached such a critical level. I realized that I probably needed to do READMEFIRST on this machine after I read your e-mails instead of hers, but it was too late, I had already posted what I could on your forum and it was all about her computer instead of this one.

    I think My Windows Live Mail account has been hacked. I was going to start the READMEFIRST for this computer but wasn't sure where I should start.

    Was I supposed to have disabled my Antivirus Software prior to running Malwarebytes? I know that I have a firewall turned on in Avast, but I am not sure how to check for other firewalls.

    My CD drive has stopped working. All of the files that I had copied for use on my daughters computer were updated last night on the CD ROM on this computer and it no longer works. I don’t know how this was possible because I had shut my computer down before I went to bed.

    Also, the last time I tried to log in to your forum was yesterday evening some time. The first attempt failed. The second time I tried to log in my password completely disappeared and redirected me. I think someone on your bulletin board has hijacked my account. Is there a way that we can verify this? I am now afraid to log back onto the bulletin board. I will attempt to post this message now through the link you provided.

    I know your last e-mail said that I should run MGTools, but I never ran HitmanPro either because I got stuck in her System CMOS screen inadvertently. Your e-mail provided no instruction on what to do about that. .Anyway, all of the troubleshooting I was doing was for my daughter’s computer which is now toast. Please tell me where to start on troubleshooting this computer, which might have been the root of her problem. Oh, also please note that my 3 successful posts were done directly on your bulletin board and not through the link you had provided in the e-mail.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I suggest that you only use the emails as a notification that a message was posted. DO NOT work from them. You need to come to the forum and read the messages to see the real content with formatting. If we update/change a message, you will not see it in an email and emails do not maintain formatting.

    If you did not install anything then you should delete the folder.


    New/different computer belongs in a new thread please. I assume the logs is this current thread are from one computer and I assume it is your daughters, if that is not the case then you can see why one computer per thread is required. ;)

    It would not hurt but probably is not necessary for this. Do you really have a firewall in Avast? Are you running a paid version of the full security suite?

    If you changed something while in the BIOS that could be the cause. Make sure the drive is not disable. This has nothing to do with malware or what we have been doing.

    Sorry but not very likely at all. The problem is something on your end especially since you appear to be logging in right now.

    All instructions are in the READ & RUN ME which is what you should be working from. Again, please work from messages posted in the forum too. DO NOT attempt to work from emails.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds