Virus found Root.MBR & PUP.Softronics

Discussion in 'Malware Help (A Specialist Will Reply)' started by harvastmoon, Jan 9, 2014.

  1. harvastmoon

    harvastmoon Private E-2

    MS Office home and students 2010 has started to act strange. I cannot open any documents anymore. also system has slowed down and sometimes deletes icons. I have read through steps for malware cleaning/removal and have attached first log: RKreport.
    It says Infection : Root.MBR

    also just ran Malwarebyte Pro version and it found PUP.Optional.Softronics.A which I will remove after I have posted this.

    Any advice would be appreciated. thanks
     

    Attached Files:

  2. harvastmoon

    harvastmoon Private E-2

    Adding more logs to my post...

    FYI, Have run these additional logs.

    1. MBAM-log-2014-01-09 (21-49-12)before.txt (2.1 KB)
    2. mbam-log-2014-01-09 (21-42-05)after.txt (2.1 KB)
    3. TDSSKiller.3.0.0.19_09.01.2014_21.58.48_log.txt (198.9 KB)
    4. HitmanPro_20140109_2301.log (2.0 KB)
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    • Are you deliberately set up to use a proxy?
    • You forgot to attach the MGLogs.zip from running MGTools.exe.

    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  4. harvastmoon

    harvastmoon Private E-2

    Hi, thanks for your help,

    and to answer your questions, No I am not aware of deliberately setting up to use a proxy.

    also, I forgot to run MG Tools but will do it now as well as MBRCheck.

    BRB :-o
     
  5. harvastmoon

    harvastmoon Private E-2

    MGLogs & MBRCheck for Virus found Root.MBR & PUP.Softronics

    MGLogs & MBRCheck have now been attached.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman and have it delete the Potential Unwanted Program (Softonic item) Also have it fix the item under the heading "repairs" - that should deal with the proxy.

    Then reboot the machine and re run RogueKiller and attach log.
     
  7. harvastmoon

    harvastmoon Private E-2

    New Log Virus found Root.MBR & PUP.Softronics

    Followed your instructions and attached RogueKiller log.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    How are things running now? (I realise the RK log still says infection: ROOT MBR but I am putting that down to a false positive after having had you run other tools to confirm there isn't one.)
     
  9. harvastmoon

    harvastmoon Private E-2

    Attached Files:

    Last edited: Jan 13, 2014
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's topic for the software forum. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    8. After doing the above, you should work thru the below link:
     
  11. harvastmoon

    harvastmoon Private E-2

    Well, everything seems to be in order now. Thank you so much. :)
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're most welcome. Safe surfing! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds