Don't even know what is wrong!

Discussion in 'Malware Help (A Specialist Will Reply)' started by beanny, Jan 7, 2012.

  1. beanny

    beanny Private E-2

    Hello I have a windows 7 32-bit system I bought about 9 months ago. Everything was fine until my system began crashing, everything was sluggish and my google chrome was acting weird: When I go to hotmail on it it would show no messages like a clean inbox but on IE9 I could see I had emails. I did everything in the READ ME FIRST thread but combofix and rootrepeal could not run. I am attaching the logs. To replace rootrepeal I did a GMER scan instead. I hope it's ok with you guys. One other thing I scanned with malwarebytes on quick scan and it found 2 items. I did another scan but Full scan and it found other things. I am attaching both.
     

    Attached Files:

  2. beanny

    beanny Private E-2

    GMER logs
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
     
  4. beanny

    beanny Private E-2

    Hello, thank you for your assistance. Here are the logs.
     

    Attached Files:

  5. beanny

    beanny Private E-2

    Excuse me but I am still waiting. I posted the logs but you did not check them. Thanks
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Don't Bump! It Only Hurts You!!!

    I had a busy weekend at work. Your patience would be appreciated. Thanks.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What is inside of these folders?

    C:\Users\Sebastien\AppData\Local\{319F8BC2-D680-4F04-A7EE-7B38B44833E9}
    C:\Users\Sebastien\AppData\Local\{7215AF9E-AC9B-42BF-8C6F-41DC6223C5F3}

    Re run Malware Bytes and attach the new log.

    Address this:
    Are your searches being redirected at all?
     
  8. beanny

    beanny Private E-2

    Hi, both the folders are empty. No my searches are not being redirected but as I said before, but on google chrome when I go on my hotmail it would show an empty inbox but in IE9 everything appears though it did not do that lately. Maybe it was the doing of the trojans that malwarebytes deleted. I did another quick scan with malwarebytes and I am attaching the logs...
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So delete those empty folders. Are there any actual malware issues remaining now? Or are you ready for final steps?
     
  10. beanny

    beanny Private E-2

    Ok I will delete them. I saw that the MBR was infected or was it a false positive? Thanks
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    UNKNOWN MBR Code does not mean infected. ;) This is why I specifically asked if you were having any browser redirection at all because it is one of the main symptoms of an MBR infection. In fact, if you had an MBR infection, you would definately still be having issues. If I was to have you fix that now it could all go belly-up.
     
  12. beanny

    beanny Private E-2

    In that case everything is good. There are no browser redirection. Thank you
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. :) Safe surfing.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds