Assistance Would Be Appreciated, Please.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Thwack, Apr 19, 2017.

  1. Thwack

    Thwack Private E-2

    I currently have friends PC that I have been unsuccessfully trying to remove a virus from.
    Each time the scan finds and removes Trojans etc, more appear at the next boot and scan.

    On the 14th April 2017 my friend clicked an email link, that she immediately knew, she should not have done. The email was deleted before the PC was handed over to me.

    The symptoms, in addition to what the various scanners find, are a slow PC, the McAffee Live Safe software being disabled (from time to time!), Windows defender fining suspicious files (while McAffee is not running) and bizarrely the System Properties window opening on the Hardware tab with, the Device Manager button highlighted!

    I have tried various scanners etc before following your guide.
    I believe I have followed everything in your guide to the letter.
    My logs are attached

    You help and assistance would be very much appreciated.
    Regards
    Danny
     

    Attached Files:

  2. Thwack

    Thwack Private E-2

    Emails also seem to be sent out from contacts in Outlook. They have a title of "Invoice 0000078 from Gemma Piper ()"
    The Gemma Piper being a contact in Outlook.

    The content of the email is, (I have deliberately broken the link below, so no-one falls foul of an accidental click...)
    You have received an invoice from Gemma Piper () for £2,132.51. To view, print or download a ZIP copy of your invoice, click the link below:

    h t t p : / / kanchan.net / view-report-invoice-00001952 / lwn4pg-y04-vr.inv/

    Best regards, Gemma Piper
    ()


    Just thought I should mention it.
    Thank you
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not seeing any major issues in your logs. Let's dig a little more.

    First please delete the below file:
    C:\WINDOWS\system32\tasks\Mkmhijqwipf


    Now please download the latest version of FRST the below link.

    Farbar Recovery Scan Tool and save it to your Desktop.

    • See the download links under this icon [​IMG]
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I also have a question about what is in the below folders:
    Code:
    d-----w                 0 2017-04-13 12:26:02  C:\Users\HilaryW\AppData\Roaming\5IcS
    d-----w                 0 2017-04-13 13:20:52  C:\Users\HilaryW\AppData\Roaming\ClientsideMutation
    d-----w                 0 2017-04-10 16:07:23  C:\Users\HilaryW\AppData\Roaming\RDC
    d-----w                 0 2017-04-17 08:27:51  C:\Users\HilaryW\AppData\Roaming\tGTyhs
     
  5. Thwack

    Thwack Private E-2

    Thank you so much for your assistance. I do really appreciate it.

    C:\WINDOWS\system32\tasks\Mkmhijqwipf - Now deleted
    The contents of the folders above are as follows.

    Directory of C:\Users\HilaryW\AppData\Roaming\5IcS
    13/04/2017 13:26 <DIR> .
    13/04/2017 13:26 <DIR> ..
    16/07/2016 12:42 74,752 sigverif.exe
    1 File(s) 74,752 bytes
    2 Dir(s) 391,629,373,440 bytes free

    Directory of C:\Users\HilaryW\AppData\Roaming\ClientsideMutation
    13/04/2017 14:20 <DIR> .
    13/04/2017 14:20 <DIR> ..
    0 File(s) 0 bytes
    2 Dir(s) 391,629,037,568 bytes free

    ***This directory appears to used by the Redsky Accounts software Hilary installed*****
    Directory of C:\Users\HilaryW\AppData\Roaming\RDC

    10/04/2017 17:07 <DIR> .
    10/04/2017 17:07 <DIR> ..
    10/04/2017 17:07 7,163 bxclient.ini
    03/04/2017 13:10 86,016 crprint.mdb
    22/10/2014 09:37 <DIR> forms
    22/10/2014 09:38 <DIR> images
    23/10/2014 10:29 <DIR> reps
    22/10/2014 09:37 246 summit.theme
    10/04/2017 17:07 1,060,864 wordlist.mdb
    4 File(s) 1,154,289 bytes
    5 Dir(s) 391,630,520,320 bytes free

    Directory of C:\Users\HilaryW\AppData\Roaming\tGTyhs
    17/04/2017 09:27 <DIR> .
    17/04/2017 09:27 <DIR> ..
    13/04/2017 11:04 344,068 q0k3YrEs.xP1
    1 File(s) 344,068 bytes
    2 Dir(s) 391,630,561,280 bytes free



    The two log files from FRST64.exe are as attached.

    Thank you again for looking at this for me.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you install TightVNC yourself? It is a legit program but it could be used for non-legit reasons. If you installed it then it is fine. Just make sure that it is properly protected with a strong password.

    Download the attached fixlist.txt file found at the bottom of this message and save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)

    Now attach the Fixlog.txt file

    At this point we are basically finished with any possible malware cleaning. So are you having any problems.
     

    Attached Files:

  7. Thwack

    Thwack Private E-2

    Thank you so much!
    I had an "error" when I started FRST64.exe - it said "failed to update(1)" which I guess is expected as the network cable was unplugged.
    Fixlog.txt attached.

    Many thanks for your time helping with this, I (obviously) couldn't have done it without you.
    ATB
    Danny
     

    Attached Files:

  8. Thwack

    Thwack Private E-2

    I'll leave it running over night (it is 20:10 here) and see what arises in the morning.
    With kind regards
    Danny
     
  9. Thwack

    Thwack Private E-2

    All clear - thank you.
    Back with my friend now.
    ATB
    Danny
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Since you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    3. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your Windows version in this link: Disable And Enable System Restore
      • For Windows 8 and 8.1 system restore see this link: Win 8 System Restore - How to enable/disable
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds