Malware removed? Can only connect to internet in Safe Mode

Discussion in 'Malware Help (A Specialist Will Reply)' started by FWLtiger08, Feb 22, 2013.

  1. FWLtiger08

    FWLtiger08 Private E-2

    Yesterday I was on Facebook and my internet connection suddenly went out. I could not connect and when I restarted my Zone Alarm would not start and Microsoft Security Essentials were turned off. Suspecting a virus I ran MBAM but it found nothing. I ran Rogue Killer and it found something and I foolishly deleted it as it told me to. However I am now able to connect to the internet but only in safe mode with networking. In normal mode the internet connects but only for a short while (after the computer is done booting all the programs I'm assuming). I ran Rogue before it found:

    ¤¤¤ Registry Entries: 1 ¤¤¤
    [HJ] HKLM\[...]\System : EnableLUA (0) -> FOUND

    After the "fix" it was no longer there. But now RogueKiller will no longer complete a scan. It stays stuck on Searching Updated Registrys or something.

    I did everything from here: http://forums.majorgeeks.com/showthread.php?t=139681 and am attaching the logs for those and RogueKiller before I did the "fix".

    Please help if you can. Thanks
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman and have it delete Potential Unwanted Programs.

    Also... http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    And...
    Run this and attach the results.

    Using ESET's Online Scanner

    Can you now connect in normal mode?
     
  3. FWLtiger08

    FWLtiger08 Private E-2

    Now Hitman won't run... It says it is waiting for internet connection but I have a connection in safe mode. I tried running in normal mode but it does not work. Should I run the other things you asked in safe mode instead?
     
  4. FWLtiger08

    FWLtiger08 Private E-2

    Ok sorry Hitman is running now. I had to use the Early Warning thing. I will post logs when the scans are completed.
     
  5. FWLtiger08

    FWLtiger08 Private E-2

    Ok I ran the scans you suggested and followed your instructions. The logs are attached. ESET found 3 threats and removed them automatically. Do you want me to close ESET and restart in normal mode?
     

    Attached Files:

  6. FWLtiger08

    FWLtiger08 Private E-2

    Ok sorry for the continued posts but everything seems to be working although shutting down seems to take longer now. You guys are amazing and I can't thank you enough for your help.

    I turned off UAC. Should I turn it back on? Do you recommend doing more scans just to be sure?

    Please let me know.

    Thanks so much again!
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    When you re run Hitman, does it still find Potential Unwanted Programs?
     
  8. FWLtiger08

    FWLtiger08 Private E-2

    No I just ran Hitman and it found 0 threats. Does this mean my system is now clean?
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, I think we can safely say so. ;)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  10. FWLtiger08

    FWLtiger08 Private E-2

    Combofix was installed from a while back when I was told to install it and run it. It was never uninstalled however.

    When I go to try to uninstall it, it prompts and extracts all these files, then it prompts and tells me that I have to disable my antivirus software. Is it trying to run? Because I don't want to run it.

    Is disabling AV required for the uninstall?
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, disable antivirus, and it appears that it's starting to run as normal, but it will begin the uninstallation process.....
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds