MBR plus wha? Issues

Discussion in 'Malware Help (A Specialist Will Reply)' started by Shenpen, Nov 18, 2011.

  1. Shenpen

    Shenpen Private E-2

    The relevant window opens, "serchbar" moves across the adress line, but the window is never filled with the relevant items and remains blank.

    Actual printing is malfunctioning too: atempts to print will hang the application from which the priting is attempted.

    This symptom dos not persist after using post #9 script.
     
  2. Shenpen

    Shenpen Private E-2

    I should perhaps add that windows update is also not functional now.
     
  3. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Stop running any of the previous fixes, I posted. You may think they are helping, but eventually you are going to break something I can't fix.

    Press the Windows Key + R on your keyboard and type this command: regedit

    The Windows Registry Editor will open. Navigate to the following Registry Key:
    Code:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Providers
    There should only be 2 subKeys under that registery key: "Internet Print Provider" and "LanMan Print Services" delete any other subKeys present.

    Do not delete anything in the right window pane and do not delete anything under the "Internet Print Provider" and "LanMan Print Services" subKeys.

    Reboot and try to open Printer & Faxes in the control panel.
     
  4. Shenpen

    Shenpen Private E-2

    Nothing there to delete besides "Internet Print Provider" and "LanMan Print Services".
    After reboot symptoms are unchanged.
     
  5. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    OK, let's look for RootKit's.

    Download and Run Scan with GMER

    We will use GMER to scan for rootkits.
    If it detects rootkit activity, you will receive a prompt to run a full scan. Click NO.

    If GMER doesn't work in Normal Mode try running it in Safe Mode

    Note: Do Not run any program while GMER is running
    *Note*: Rootkit scans often produce false positives. Do NOT take any actions on <--- ROOKIT entries
     
  6. Shenpen

    Shenpen Private E-2

    No positives.
     

    Attached Files:

  7. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    The gmer log is completely empty.
     
  8. Shenpen

    Shenpen Private E-2

    I agree.
     
  9. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    It shouldn't be empty.
     
  10. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Changing tactics.

    Download Windows Repair by Tweaking.com to your desktop.


    • Double-click tweaking.com_windows_repair_aio.zip and extract the Tweaking.com - Windows Repair folder to your desktop.
    • Now open this folder and double-click Repair_Windows.exe.
    • Click the Start Repairs tab on the far right.
    • Click Custom Mode so there is a bullet in it.
    • Click the Start button (bottom right)
      Note: When asked if you would like to create a restore point. It is recommended just in-case something does not go as planned.
    • Click Unselect All
    • Put a checkmark in the following items:
      • Reset Registry Permissions
      • Reset File Permissions
      • Remove Policies Set By Infections
      • Repair Windows Updates
      • Set Windows Services To Default Startup
      Note: Leave everything else unchecked
    • Put a checkmark in Restart System When Finished
    • Now click the Start button (bottom right)
     
  11. Shenpen

    Shenpen Private E-2

    Ok.

    No idea why its empty.
     
  12. Shenpen

    Shenpen Private E-2

    Had to manually reboot it, but it is now installing updates.
     
  13. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Still having problems with Printers & Faxes in the Control Panel?
     
  14. Shenpen

    Shenpen Private E-2

    Yes. And Microsoft Security wont update citing "connection failure".


    Services.exe is running 886.740 Kb of mem, and some system process is using a core at 50%.

    Controlpanel for printers and faxes stil dosn't show anything but a searchbar and a white window.
    Network (local) doesnt seem to work either.


    On the bright side: Browser is running fine now, even flash video is functional.
    Windows update is back online and all important updates are done.
     
  15. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Let's make sure this isn't a permissions issue.

    To reset permissions to system defaults, do the following:
    Start -> All Programs -> Accessories -> Right click "Command Prompt" -> "Run as administrator"
    Click"OK" on any alerts.

    The Command Console will open

    Enter the following commands, at the Command Prompt. The commands must be entered exactly as shown.

    Press the Enter Key after the command. Wait for each command to finish before proceeding to the next command.
    Code:
    secedit /configure /cfg %windir%\inf\defltbase.inf /db defltbase.sdb /verbose
    exit
    This will take some time to run.

    Any change?
     
  16. Shenpen

    Shenpen Private E-2

    secedit /configure /cfg %windir%\inf\defltbase.inf /db defltbase.sdb /verbose
    exit

    Der opstod en udvided fejl.

    Opgave blev udført med en fejl.
    Der er flere oplysninger i logfilen %windir%\security\logs\scesrv.log.

    Translation:
    En exeteded error occured.

    The task was executed with an error.
    There are more information in the logfile %windir%\security\logs\scesrv.log.

    No visible change in behaviour:
    No acces to printer panel, printing from applications hang the applications, no acces to network, no updating of MS Security Essentials.
     
  17. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download the latest MGtools.exe to the root of your c: drive.
    • Replace your existing MGtools.exe with this one.
    • Now run this new MGtools.exe by double-clicking it. (Vista/7 right-click and select Run as Administrator)
    • When it is finished, attach c:\MGlogs.zip to your next message. (How to attach)
     
  18. Shenpen

    Shenpen Private E-2

    Do you perhaps mean the root of my d: drive?
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes. ;)
     
  20. Shenpen

    Shenpen Private E-2

    This one seems to get around some of what stopped the old one.

    What is your take on present situation?
    Is there still a risk of infecting other systems?
    Are the HDs MBR infected or clean?

    I got a SSD a few days back and trying to plan how to get essential data from this to new system.

    Edit:
    Preliminary: System seems to be back to health now...
     

    Attached Files:

    Last edited: Dec 21, 2011
  21. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Other than the Printers & Faxes issue, earlier, everything else appears to be fine.

    The MBR's appear to OK and there is no other signs of infection.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds