Yahoo redirect and Mbam wont run

Discussion in 'Malware Help (A Specialist Will Reply)' started by par4me, Mar 11, 2010.

  1. par4me

    par4me Private E-2

    I see I'm not the only one to have this problem. I tried for the last couple of days to try and get malwarebytes to run but it just starts up and then shuts down. No error messages, and it won't update either. I probably did a bad thing by trying to get it to run with various programs but I have finally given up.
    I did my best to run through the "run me first" section but mbam won't run, root repeal wont run and although mgtools extracted nothing ran. I ran analyze.exe that was inside the mg tools folder and am attaching that log.
    I can't seem to find the Superantispyware log but it said no files found.
    I'm sure that I forgot something, and sorry in advance, I'm very frustrated from trying for 2 days to get malwarebytes to run to no avail.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The red is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.

    Attach the logs if you can get them to run.
     
  3. par4me

    par4me Private E-2

    I know that you hear "thank you" alot but I do want to take a second and say thank you for your time before I continue.

    I didn't get any error messages when running the command prompt. Here are the logs created. I'm not sure if the "winfiles" was created or not so I included it too.

    again...thanks
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not really seeing much. Do the redirects happen with all browsers?

    Let's see if you can do this:
    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. It does not save a log.
     
  5. par4me

    par4me Private E-2

    The only thing that it found was 35 tracking cookies.

    As far as the redirects go, I really don't use much other than Yahoo and it only seems to redirect me 1/2 of the time. I guess what's really unsettling it the fact that I cant get some of my programs to run (including Malwarebytes and Rootrepeal) I don't get error messages, they just don't start. Malwarebytes will start for 5 seconds then shut down.

    Before I signed up here, I ran housecall and it found a couple of things , one being a file in my temp folder called "urwrbda.bak" that I can't make go away. It keeps coming back. Unfortunately the log has got deleted amongst the massive cleaning effort before I posted here. Also I have 3-4 svchosts running that when I try shutting them down, they keep restarting.

    I know that I haven't given you much to work with. Sorry about that. It's not intentional I can assure you. It's just kind of tough when all of the tools don't want to run. I haven't and won't try to run anything without intructions since my first posting.... I can always just reformat and be done with it if need be but I was really trying to avoid that. I do it once every couple of years (around Thanksgiving or Christmas) just to tidy up things, and it's such a pain. Thank you again for your time.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    A few things we can try doing.

    First, uninstall MBAM> ( Don't worry about RootRepeal not running, as this is common with some systems).

    Run both CCleaner as well as ATF Cleaner by Atribune.

    Now try downloading and installing MBAM again and see if it will run. Don't worry about updating it as yet.

    We know that MGTools will run, so please run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Attach the new C:\MGLogs.zip
     
  7. par4me

    par4me Private E-2

    ok, I uninstalled MBAM and downloaded it again (calling it mb.exe before saving).
    Then I ran the windows tab of cc cleaner. I didn't know if I was supposed to run other tabs or the registry cleaner so I didn't.
    Then I ran ATF cleaner (with everything checked) and it removed 44.8 mb more.
    I reinstalled mbam and tried a quick scan. It ran 5 seconds and then shut down. Same as before, no error reports, just shut down.
    I then ran GetLogs.bat and have attached the zip file.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    * Please download TDSSKiller to your Desktop
    * Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    * Click Start > Run and copy/paste the following bold command into Run box and hit Enter.

    "%userprofile%\Desktop\TDSSKiller.exe" -v

    * Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    * When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.

    Now see if you can run MBAM. Attach the logs.
     
  9. par4me

    par4me Private E-2

    I couldn't follow the link that you had from my "infected" computer. I had to use my laptop and transfer the file over. (version 2.2.8)
    I ran it as you asked and it didn't ask me to delete anything. The log is attached.
    I then tried MBAM again. Same results. It runs for 5 seconds and then shuts down.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This really doesn't sound like a malware issue, but I want you to try doing something else. Go to the control panel and create a new user account with Admin. privileges. Then from that account, try installing a fresh version of MBAM and tell me if it runs.
     
  11. par4me

    par4me Private E-2

    I got the same result. MBam was on the new users desktop so I uninstalled it and then reinstalled it (all from the new users account) but when I tried a quick scan it ran for about 4-5 seconds then shut off.

    The biggest reason that I thought (or think) that it's a virus is because of the redirects from yahoo. If I type in "majorgeeks" in yahoo and click on the first result, I get a "superpages" site asking about plumbers in my area...(or something similar). It's not just mbam that won't run, I've got an rc simulator that wont run and my nvidia video settings screen won't open. My computer doesn't run slow or anything like that though....

    Sorry, I'm babbling now. If you can't see anything and believe that it's not a virus, do you have any suggestions what I should do next ? I'm starting to feel bad for taking up your time. I'm usually not one to ask for much help.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you checked your device manager for your nvidia video setting?

    Go to start / run / type:
    sfc /scannow and have your windows cd handy. Run it twice.

    Try running this SCAN.
     
  13. par4me

    par4me Private E-2

    I ran scannow twice turning my computer off in between. I can't get the eset scanner to come up though. It's the same problem that I had when I tried to download the tdsskiller. I have attached the screenshot to help explain better.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download a different browser ( FireFox for example) and try the Eset scan again. Tell me what happens.

    Or try one of the other online scanners listed HERE.
     
  15. par4me

    par4me Private E-2

    Whew, not very good news but....

    I downloaded and installed Firefox but got the same result. I did a search and did find a site that would try to start but when asked to install the eset installer it would say "Unknown Process" or something like that so I couldn't run it. The sites address was:

    http://www.esetgr.com/


    I then tried the other scanners on the page you linked too. Only HouseCall would show up. I ran it and have attached the file that it found in a txt file. It's the same one as before and when I try to delete it , it shows back up in less than 10 seconds. All of the others said "Page not found" or something similar. The Strange thing is that I then searched for each one and on clicking the result, I would get redirected to a strange totally unrelated page.....Anytime after that I've searched and click on the result I get... "Page Not Found". Even with Mcaffee and the Windows one which suprised me. I've tried Google and Yahoo.

    I then tried some of the rootkit checkers on the page. Only Panda would run and it gave me an error upon reboot..."Instruction XXX referenced at memory XXX could not be read" , but it found nothing. SysProtect would open but then shut down.

    The only glimmer of hope that I had was when I moved to the offline scanners. I did not try them all but I did manage to get the Avast virus cleaner to run (Log Attached) and the "Trojan Scan" to run. (Log Attached) The "Trojan Scan" didn't leave a very good log but I manually typed in what it found at the bottom (Minus the tracking cookies).

    I'll probably keep trying to get something to run but I figured that I'd give you an update. I know it's a strange question but can I load one of the scanners onto my laptop (which is working fine) and then transfer it to my Desktop to run it ? If so , would you prefer one over another ?... Ok , enough dumb questions from me..... Thanks again !!
     

    Attached Files:

  16. par4me

    par4me Private E-2

    Sorry to double post but I can't see a way to edit my last one...

    I have managed to get at least some of the rootkit revealers to open by right clicking and using "run as" current user. Unfortunately when I try to actually run the processes I get various errors as follows :

    SysProtect - Failed to start service. SysProtect needs admin privileges....Then - error writing to log
    RootkitRevealer - Error copying image to ramdom service image file. Access is denied.
    Rootkit buster - Intregity test failed. Please download a new copy.
    BitDefender - shows an hourglass for a couple of seconds then it goes away. If I look in my task manager it says that its still running using 50 of my cpu.

    I don't know if any of that helps.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing Urwbda.bak in your logs. I am also wondering if this really is a malware problem. Do you have your xp cd? If you do, I want you to try doing a repair installation.
     
  18. par4me

    par4me Private E-2

    Sorry , Urwbda.bak was detected by houscall and It didnt save a log. It was in my local settings / Temp folder.

    I'm not exactly sure how to do that but I have my cd. (its an oem that came with my computer.) I'll probably back up my hard drive programs and documents onto an external drive first in case I screw it up.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    OK. You can do a backup, but we want to be sure you arent backing up any malware.

    To do a repair install, you need to set the bios to have the cd drive as the first boot device. Then you can boot into cd and choose install ( you will have an option to hit "R", but that would take you to the recovery console which we don't want). That will show you the current install of windows and you will have the option to press "R" to do a repair install. It will keep all your programs and files. What I am hoping is that it may straighten out any corrupt files.

    Once that is done, see if you can run the scans.
     
  20. par4me

    par4me Private E-2

    Ok. I've backed up my program files , document and email....Here goes nothing. I'll get back to you as soon as I have results one way or another.

    And thanks for the quick instructions on the repair install. I wasn't too sure about how to do it but it seems easy enough.
     
  21. par4me

    par4me Private E-2

    Well, I think that I messed that up. I never saw the "R" option to repair windows. I just saw the partitions to place windows on. I knew that installing over the partition that I was using (the other one is only 8kb or mb or something like that) that I would keep my program files and previous user so I "installed" over the old version of windows .... deleting the current version. My programs and files still are there and I've also backed them up but I have to reinstall my video drivers, sound drivers, network , e-mail..ect....I had to reinstall MBAM but it ran and I have attached the log. I also ran the Eset online scanner and attached the log.

    I am probably going to reformat my hard drive at this point because I have nothing to lose and I still see the 4 svchosts running in task manager , but before I do I wanted to give you the option of continuing if you think it might help someone else later or just for curiosities sake. I'm still convinced that it was some evil virus and that I probably messed things up by trying to fix it myself before signing up here. I just don't want to waste your time trying to help me when I'm just going to do a fresh install anyway. I saved a backup of my registry on the external hard drive before I did my bad repair job but I don't really know how to scan a backup of a registry or if it's even possible. I won't run any more scans or mess with this until I hear from you or until Thursday morning shows up with no response. Either way though, thanks again very much for your help.
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You forgot to attach the logs. :(
     
  23. par4me

    par4me Private E-2

    Oops, sorry about that. Here you go.
     

    Attached Files:

  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Very good. That helped.
    See if SAS will find anything.

    Go ahead and re-run the C:\MGtools by double clicking the C:\MGtools\GetLogs.bat file.
    (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  25. par4me

    par4me Private E-2

    Everything seems ok now. I got retro-fitted back to Explorer_6 (which I always liked better than 7 anyway). I can visit all of those online scanning sites that were "blocked" before (although I've only run esets online scan) and other than a couple of unscheduled visits to microsoft's home page, everything seems to be running fine. No real redirect issues yet that I can see. I haven't done much searching but I've been trying to go to all of my normal sites through yahoo instead of the address bar to see what happens. I also haven't tried reloading a couple of my games that had quit running in the process of all of this. (Mainly my rc simulator) I'll let you know if it runs when I try it.

    I ran MGtools\GetLogs.bat and have attached the log. I then ran SAS and it found nothing again. I didn't attach the log for that , ( I saved it though if you want it.)
     

    Attached Files:

  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Everything looks fine now. Be sure to install your AV and AS programs.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  27. par4me

    par4me Private E-2

    Awsome!

    Will do on the AV and AS stuff. I was just waiting for the all clear. After I do the final steps I'll put them back in. Thank you again for all of your patience. It's kind of funny that I just noticed the "Thank You" button in the posts. I'll be sure to push it.
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds