Jump to content

Recommended Posts

Hi 

 

I was advised by one of the kind helpers in Malwarebytes Anti-malware Help Forum to seek help in this forum because the logs show some questionable entries in system's event logs. 

 

This following thread is the one I created there 

https://forums.malwarebytes.org/index.php?/topic/175443-mbam-premium-was-unable-to-load-anti-rootkit-driver-error-20025/

 

I had this pop up box (picture below) from MBAM Premium on PC start up 5 days ago which I haven't seen since but have been alarmed about my PC security ever since.

 

post-160583-0-48438900-1448980396_thumb.

 

Apart from the mentioned MBAM warning box I am having problems almost at every PC start up. Some icons don't load up in the system tray in the notification area. The icons which are mainly affected are MBAM and MSE Anti-virus. I have also caught Skype about 3 times "Not Responding" but it still manages to recover every time and carry on doing the job it is meant to do. These other problems I mentioned  are visible to me but there are probably things going under the hood I am not even aware about. 

 

I've attached the FRST logs from yesterday. Let me know if I need to create new ones,please.

 

Your help would be very much appreciated. 

 

Thank you  :)

 

FRST_30-11-2015_11-35-59.txt

Addition_30-11-2015_11-35-59.txt

Link to post
Share on other sites

Hello,

    

 

They call me TwinHeadedEagle around here, and I'll try to help your with your issue.

 

     

    

Before we start please read and note the following:

  • We're primarily oriented on malware removal here, so you must know that some issues just cannot be solved and you must be prepared for this. Some tools we use here will remove your browser search history, so backup your important links and all the files whose loss is unacceptable.
  • Note that we may live in totally different time zones, what may cause some delays between answers.
  • Don't run any scripts or tools on your own, unsupervised usage may cause more harm than good.
  • Do not paste the logs in your posts, attachments make my work easier. There is a More reply options button, that gives you Upload Files option below which you can use to attach your reports. Always attach reports from all tools.
  • Always execute my instructions in given order. If for some reason you cannot completely follow one instruction, inform me about that.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
:excl: I can't foresee everything, so if anything not covered in my instructions happens, please stop and inform me!

:excl: There are no silly questions. Never be afraid to ask if in doubt!

 

 

 

  warning.gif Rules and policies

 

We won't support any piracy.

That being told, if any evidence of illegal OS, software, cracks/keygens or any other will be revealed, any further assistance will be suspended. If you are aware that there is this kind of stuff on your machine, remove it before proceeding!

The same applies to any use of P2P software: uTorrent, BitTorrent, Vuze, Kazaa, Ares... We don't provide any help for P2P, except for their removal. All P2P software has to be uninstalled or at least fully disabled before proceeding!

 

Failure to follow these guidelines will result with closing your topic and withdrawning any assistance.

 

 


51a612a8b27e2-Zoek.png Scan with ZOEK

Please download ZOEK by Smeenk and save it to your desktop (preferred version is the *.exe one)

Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

createsrpoint;autoclean;emptyclsid;emptyalltemp;ipconfig /flushdns >>"%temp%\log.txt";b
  • Right-click on 51a612a8b27e2-Zoek.png icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.
  • In the main box please paste in the following script:
  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)
Post its content into your next reply.
Link to post
Share on other sites

Hi TwinHeadedEagle.Thank you for helping me :) .

 

I had a problem scanning with Zoek. As soon as I clicked on "Run Script" it started running for a split second but out of nowhere a box popped up ( picture below) saying that "DaS21 Has Stopped Working". 

 

post-160583-0-46444200-1448988381_thumb.

 

I didn't know what to do so I left my PC alone for 20 minutes with both Zoek and the DaS21 warning box alone. After 20 minutes of no progress from Zoek I clicked on "Close Program" in the "DaS21 warning box" and Zoek started to run again and produced the logfile I attached. 

zoek-results.log

Link to post
Share on other sites

Yes, I wanted to see if Zoek will find something. No need to run more scans.

 

 

Thanks for your help,TwinHeadedEagle.

 

I am still worried about the icons not loading up in the system tray on some occasions at PC start up but as long as it is not caused by an infection I am just about to live with that. 

 

Would you be so kind and tell me how to correctly and safely remove the Farbar Recovery Scan Tool and Zoek,please. 

 

Thank you

Link to post
Share on other sites

Since there are no more problems, we can declare this PC clean thumbs_up_smiley.gif

Now, we can proceed with post-cleanup procedures. Let's remove my tools and create a new, non infected restore point concurrently deleting old ones.

Step 1. - Creation of system restore point and tools removal.

Download DelFix by Xplode and save it to your desktop.

  • Run the tool by right click on the 51a5ce45263de-delfix.png icon and Run as administrator option.
  • Make sure that these ones are checked:
    • Remove disinfection tools
    • Purge system restore
    • Reset system settings
  • Push Run and wait until the tool completes his work.
  • All tools we used should be gone. Tool will create an report for you (C:\DelFix.txt). I don't need it for review.
Tool deletes old system restore points and creates a fresh system restore point after cleaning.

Step 2. - Tips and tricks to keep your computer clean, safe and in a good shape.

Security tips - highly recommended reading:

Maintenance tips:Additional software that I personally use and install on all my clients devices:
  • Malwarebytes' Anti-Malware (paid version highly recommended) - to scan your system from time to time in search for malware.
  • Malwarebytes' Anti-Exploit - to prevent plenty of mostly exploited vulnerabilities.
  • McShield - to prevent infections spread by removable media.
  • Unchecky - to prevent from installing additional foistware, implemented in legitimate installations.
  • Adblock - to surf the web without annoying ads!
  • Qualys BrowserCheck - cloud service that scans your browsers and plugins to see if they’re all up-to-date.

My help is free for everybody.

If you're happy with the help provided and/or wish to buy me a beer for the assistance you received, then you can consider a donation: btn_donateCC_LG.gif

Thank you!

Stay safe,

TwinHeadedEagle :)

Link to post
Share on other sites

  • Root Admin

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.