|17 Jul 2012||#1|
Removed 2 malwares, now need help with DEP
I was having some browser issues and the IE9 people linked me a Fixit program Fix Internet Explorer issues to make IE fast, safe and stable
and it works great, but it keeps finding the same problem after every restart, which is that DEP is disabled.
I suppose the little malware buggers are the culprits, did something that keeps disabling DEP with every bootup. Is there an easy permanent fix?
In all the many years of surfing the net since the Win 95/dialup days I've never had a malware problem until now. Microsoft's security scanner found a dozen or so "Exploit: Severe" alerts involving "Java/Blacloe...." I should have know something was up when I kept getting prompts from Sun to update but when I clicked on them the prompts just vanished. I didn't know what was happening. The only thing I even need Java for is the occasional line quality test for Speedtest.net.
|My System Specs|
|17 Jul 2012||#4|
I used this site Malware Removal Guide for Windows - Select Real Security after finding the 2 I mentioned and nothing showed up, and yes, Malwarebytes are what found them yesterday.
Ran it a few more times yesterday and today and it found nothing.
|My System Specs|
|17 Jul 2012||#8|
Let's bring out the big guns and blow your malware out of the water.
HOW TO USE WINDOWS DEFENDER OFFLINE ON A USB STICK
Windows Defender Offline
· is a free standalone, bootable malware and virus remover from Microsoft.
· performs an offline scan of an infected PC to remove viruses, rootkits and other advanced malware.
Download Windows Defender Offline (about 764 kB)
You will have the choice of downloading the 32bit version (x86) or the 64 bit version (x64).
The link will help you determine whether you are running a 32 bit version or 64 bit version of Windows
NOTE!! You can download and prepare a 32 bit version using a 64 bit version of Windows
NOTE!! You can download and prepare a 64 bit version using a 32bit version of Windows.
You run the 32 bit version on a 32 bit version of Windows.
You run the 64 bit version on a 64 bit version of Windows.
The 32 bit download file name is: mssstool32.exe
The 64 bit download file name is: mssstool64.exe
For the curious, this program was originally name Microsoft Standalone System Sweeper.
You will need an Internet Connection.
Insert 512 mB (Microsoft’s 256 mB is no longer accurate) or larger USB stick into a usb port.
Run the downloaded program--mssstool64.exe or mssstool32.exe
Choose the option On a USB flash drive that is not password protected
The install program will format the usb stick using the NTFS format.
The install program will download about 210 mB.
The install program will name the USB stick WDO_Media32 or WDO_Media64
The WDO_Media32 usb stick will have used space of 255 mB (268,140,544 bytes)
The WDO_Media64 usb stick will have used space of 282 mB (296,165,376 bytes)
You can expect the number of mB to increase as more malware appears.
UPDATE Windows Defender Offline USB stick:
· reinsert the usb stick
· run the installation program, mssstool64.exe or mssstool32.exe, again.
· the update will download about 66 mB (mssstool32.exe) and 68 mB (mssstool64.exe).
Since the malware database is sometimes updated several times in a day, always update before running.
PERFORM AN OFFLINE SCAN
Bootup your computer from the USB stick
Windows Defender Offline will automatically perform a quick scan.
After the quick scan finishes, Choose Full Scan
Select all of your drives
The initial, full scan can easily take several hours, but
Remember, your computer is being very thoroughly checked for all types of malware.
RESULTS OF THE SCAN
The results will be in 4 log files on your computer's disk in:
|My System Specs|
|17 Jul 2012||#9|
I went back into safe mode and re-ran Malwarebytes, then HitmanPro, just to make sure. MWB came up empty but Hitman found a bunch of cookies it didn't like and removed them. Rebooted and Fixit still showed DEP disabled.
Then I ran |MG| Tweaking.com - Windows Repair 1.7.5 Download as suggested by the Malware Removal site posted earlier. It had me run CHKDSK and the same sfc /scannow before it repaired anything. It found and repaired 21 registry errors, rebooted, and I STILL found DEP disabled upon startup.
Before I try your suggestion, Karl, I have Windows Defender but Microsoft Security Essentials disabled it by default. Is that going to be a problem running it from a usb stick with MSE installed?
|My System Specs|
|Similar help and support threads|
Almost 85 PUP Malwares not Detected by Avast Free Antivirus 2015....
I am using "Avast Antivirus Free 2015".When i ran the Full System Scan,the Antivirus didn't found a single Virus or Malware. I had seen somewhere on youtube that,having "Malwarebytes Anti Malware" works great along with your regular Free/Complete Antivirus Software for complete protection.So,i...
cmd startup in Win 8 after McAfee removed 1 virus + 7 malwares
Dear Sirs and Madams, I was recently given a brand new Acer Aspire E11 to update and install MS Office and other softwares in it but I decided to update McAfee first and run its full scan because every time I plugged in my usb stick, everything in it just turned into shortcuts...sounds familiar...
Login name removed after ransom virus removed
Please help! After a ransom virus was removed from our desktop computer (originally a display model at Sam's), my administrator account is no longer visible...Only "Kiosk" and "Other User" . I have checked to see that net user administrator /active yes is successful but still do not see my user...
malwares from a wifi router?
can malwares or viruses come from a wifi router in a public; a coffee shop, a public library, a restaurant, or school?
I removed U3 from FD, but it has old name still?
Ok I was finally able to remove U3 software & format the sandisk flash drive. I have given it a new name, but yet it still has the old name U3 had given it? Here is a couple of pics It SHOULD now be JohnnyScience Cruzer (as it does under disk management) But instead its still showing as...
© Designer Media Ltd
All times are GMT -5. The time now is 22:26.