Red X network (still works), delete hang & can't use Malwarebytes in regular mode

Discussion in 'Malware Help (A Specialist Will Reply)' started by nektar72, Jul 12, 2012.

  1. nektar72

    nektar72 Private E-2

    I've been having some issues with my laptop for a few days now. It all started when I wanted to stream Netflix and it kept erroring out. I then noticed that the Network "Red X" was showing, even though I had an internet connection and was browsing. I came back to it to research the next day and I noticed that I couldn't run Malwarebytes, AdAware or Internet Explorer. That's always my first sign of a problem. Got it running in safe mode but it didn't find much. The network connection doesn't show the "Red X" in safe mode. I'm also experiencing a hang time when I delete files and when I add a new folder to the desktop. This doesn't occur in safe mode either. I had to run all of the tests in safe mode as they wouldn't work in regular mode. I also read TDSSKiller with no unusual results.

    The last time I had a major virus was in November I believe and that fix knocked out my ability to use Windows Update. I haven't figured out how to recover that yet.

    So, lots of problems and no solutions. I'm enclosing my log files per the forum instructions.
     

    Attached Files:

    Last edited: Jul 12, 2012
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Your logs are all clean but logs from normal boot mode would be much more useful.


    Are you sure that your red x is not just for the below Wireless Network
    Code:
    Wireless LAN adapter Wireless Network Connection:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . : 
       Description . . . . . . . . . . . : Atheros AR5007EG Wireless Network Adapter
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    
     
  3. nektar72

    nektar72 Private E-2

    Thanks for your quick response, Chaslang. Yes I'm sure because the no network symbol doesn't occur in Safe mode.

    The 4 programs that this site asks to use (RogueKiller, Malwarebytes, HitmanPro & MGtools) don't work for me if not in Safe mode. RogueKiller gets hung up on update (even though I have an internet connection), Malwarebytes just shows up in processes but nothing else happens, HitmanPro said "searching" but no meter movement for several minutes and MGtools seems to be stuck as well right now.

    Any more tips on what I can try? Nothing works in regular mode and safe mode is showing all clear with every scan I perform (Malwarebytes, Avast (in regular mode and on boot), Trend Micro Housecall, TDSSKiller, SuperAntiSpyware, CCleaner).
     
  4. nektar72

    nektar72 Private E-2

    Thought I'd add a couple of logs. As I said, most scans wouldn't work in regular windows mode, but only in safe mode. Here are a hijackthis log and a combofix log that I performed today.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you actually attempt to run MGtools in normal mode? It is the log we need the most. If you ran it and it does not run, tell me exactly what happens.

    HijackThis logs are of almost no help to anyone anymore. They are a thing of the long past.

    Nothing helpful here other than you have signs of multiple antivirus programs and other protection programs. Avast, AVG, & Ad-Aware. I suggest that you uninstall ALL of them and reboot and see if anything changes.
     
  6. nektar72

    nektar72 Private E-2

    MGTools gives me this when using it NOT in safe mode:

    Running scan with the GetRunKey.bat
    NOTE: Ignore any error messages about not finding registry keys!
    Just wait for the program to finish running!!


    And then nothing else happens.

    Hmmm, AVG should be long gone. I switched from AVG to Avast the last time a nasty virus got through. I will uninstall all, reboot and let you know what happens.
     
  7. nektar72

    nektar72 Private E-2

    Seems like an uninstall and reinstall of Avast did the trick.

    No more hang on delete, file creation, no red X and a reinstall of silverlight seems to have Netflix working again.

    I will do some testing tomorrow and call it closed if all is good.

    Thanks!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Glad to hear you have it fixed.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. nektar72

    nektar72 Private E-2

    Finally getting back to this issue after a heavy workload. It seems the problem was with Avast Antivirus. Every time I try to reload, I get the same problems. I don't understand why this happened all of the sudden. Must've been an Avast update that killed it. I guess I'm gonna go back to AVG Antivirus, but I didn't ever catch any malware in the act like Avast did.

    Thanks for all the help!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Try using Avira ( mentioned in the How to protect yourself link. You will see AVG is not in that link anymore....for quite some time ).
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds