Not sure what my problem is...

Discussion in 'Malware Help (A Specialist Will Reply)' started by Sage009, Nov 21, 2012.

  1. Sage009

    Sage009 Private E-2

    MBRCheck says there's a problem with my boot record, my bandwidth jitters even though nothing's using it and Windows Live Messenger hangs/freezes every time i mouse over it.
    I've run scans with Spybot Search & Destroy, but the fixes it made didn't change anything :(

    Attached is my MBRCheck log.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. Sage009

    Sage009 Private E-2

    Good point. I ran TDSSKiller too, said no threats.
    Guess I should finish the rest of that guide
     
  4. Sage009

    Sage009 Private E-2

    Can't edit my last post, so here's my logs.
    Didn't do MGtools yet because I don't like the idea of disabling UAC so I'm hoping I won't have to run it
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    To be thorough, I would rather you did. :) I would also like a log from Malware Bytes. Thanks.
     
  6. Sage009

    Sage009 Private E-2

    Here's malwarebytes and MGTools.
    Do I have to keep UAC disabled after running the scan? :confused
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall this garbage.

    • Messenger Plus! 6


    You must keep UAC disabled until we are done unless you want many more complications. Sorry.Enable it in between us working, but when coming back here and before running my instructions, UAC needs disabling.

    Run Hitman and have it delete:
    • C:\Users\Sage\Drivers\explorer.exe
    • C:\Users\Sage\Drivers\FirewallUpdate32.exe
    • C:\Users\Sage\Drivers\msconfig.exe
    • C:\Users\Sage\Drivers\win32.exe
    • c:\windows\dassvcmgr4.exe
    You can also have it delete Potentilly Unwanted Programs and cookies.

    Now re run Hitman again, just a scan, and attach the newest log too.
     
  8. Sage009

    Sage009 Private E-2

    Latest log here.

    Uninstalled Plus! 6...
    By the way, why is Messenger Plus! 6 considered bad? I've used it for 8 years without any problems on multiple computers.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Messenger Plus invites in infection. Lop to name but one.

    Re run HitmanPro and have it delete these!

    Potential Unwanted Programs


    Run this and attach the results.

    Using ESET's Online Scanner

    and then...

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    After reboot, check to see if your firewall is working.
     
  10. Sage009

    Sage009 Private E-2

    Here's the log.
    What next? I use a router on my firewall, not Windows Firewall.
     

    Attached Files:

  11. Sage009

    Sage009 Private E-2

    Also, my problem still hasn't gone away
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not malware related, you can ask about it in the software forum. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  13. Sage009

    Sage009 Private E-2

    Alright, thanks anyway.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No prob, I can only go as far as checking for malware and removing that. Anything non malware related belongs in another forum to keep things tidy. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds