Cleaning parents desktop

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by victorydoc, Feb 3, 2011.

  1. victorydoc

    victorydoc Private E-2

    Hi MGs,

    A couple of months ago, my parents' desktop had some crud on it, which my brother-in-law cleaned by following the R&R, which ostensibly cleared everything up.

    Fast forward to today, where I am visiting and just doing some background cleaning. No known issues/problems, but while doing the maintenance my parents don't do, SAS picked up stuff only in the System Restore (waiting for the go-ahead to toggle it).

    Would've called it a day, but MBAM didn't seem to complete, and Avast! kept popping up during the scan, something which it hasn't done before.

    CF log is attached.

    RR never got past the initialization.

    MGtools did not get past GetRunKey.bat and a likely empty log is attached.

    Thanks for your help.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please shut down all AV and AS software while you do the following.

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
     
  3. victorydoc

    victorydoc Private E-2

    Hi TimW,

    Thanks for such a rapid response.

    Tried both commands, no dice. No error message, just a blinking cursor. Just sits there and nada. Here's a screen shots of ShowNew. Oddly enough, HJT was able to run.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just to keep you going until Tim gets back, and so we can glean more information, try running the below.

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  5. victorydoc

    victorydoc Private E-2

    Hola Kestrel13!,

    Program ran well. Computer plugging along without any noticeable issues.

    Thanks again for the work you all do.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach that log.
     
  7. victorydoc

    victorydoc Private E-2

    Hi TimW,

    Here's the HJT log. I ran it via MGtools, as I was curious to see if this would work.

    Didn't attach it the first time (ran it again), since you didn't ask for it.

    TIA.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. What issues are you having, if any?
     
  9. victorydoc

    victorydoc Private E-2

    Hi TimW,

    There haven't been any noticeable issues. Just the items detected in System Restore by SAS, MBAM getting flagged by Avast!, and MGtools not being able to run.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  11. victorydoc

    victorydoc Private E-2

    Hey TimW,

    Parents' computer still appears to be running fine.

    Went through the clean-up procedure, toggled System Restore, and ran the command for removing Combofix.

    However, C:\Qoobox remains. Should I just delete it?

    Thanks.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes you can just delete it. :)
     
  13. victorydoc

    victorydoc Private E-2

    Hi Kestrel13!,

    Can't delete it.

    Apparently, access is denied to delete "BackEnv", and to make sure that the disk is not full, write protected, or in use.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Had you run MGclean.bat yet? If not, try running it before having to try the below.
    Try deleting the lower level files and folders first and then work your way back towards the top. This is a fairly common bug in Windows.
     
  15. victorydoc

    victorydoc Private E-2

    Hi Chaslang,

    MGclean.bat worked like it should.

    I had to leave yesterday but will ask my brother-in-law to complete this last tidbit.

    Thanks again.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  17. victorydoc

    victorydoc Private E-2

    Sorry to dredge this up, but I am up visiting the parents and looks like my BIL didn't finish this.

    Try to delete Qoobox, get the error box stating that cannot delete BackEnv: Access is denied and to make sure that the disk is not full, write protected, or in use.

    Go to open the BackEnv folder, tells me access is denied.

    Go to delete the BackEnv folder, same deal.

    I was able to use the FileAssasin in MBAM to delete the files inside, but can't get at the Qoobox and the BackEnv folders.

    Thanks.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to the lowest level, which I assume is the BackEnv folder. Right click it and see if it has a security tab. If it does, make "Everyone" have all rights. Then do the same for the Qoobox folder. See if you can then remove them.
     
  19. victorydoc

    victorydoc Private E-2

    Hi TimW,

    Right click shows "Sharing and Security..." on the menu, but no Security tab, per se.

    When I click on the "Share this folder on the network" and/or "Allow network users to change my files", I get the error box, "An error occurred while trying to share BackEnc. Access is denied. The shared resource was not created at this time."

    I could do it with Qoobox, but then it won't let me delete it because of BackEnv.

    Thanks in advance for the help!
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Right click and chose properties. Then see if you get a security tab.

    When the below box shows click Continue

    [​IMG]

    then click Security tab link in the below box

    [​IMG]

    then click Continue

    [​IMG]

    Click Allow under Full Control and Apply > Ok > Ok (close if the original permissions error box is showing) .

    [​IMG]

    and then delete the main Qoobox folder.
     
  21. victorydoc

    victorydoc Private E-2

    Thanks TimW,

    The parents have XP-Home-SP3, so, those items don't show up.

    I've attached a shot of what I see with the right click and attempt to "share" the file, though I doubt this is the right track.

    BTW, will be flying back home and won't be back up 'til Mother's Day. I'll see if someone else can try to work on this whilst I am gone.

    Thanks for all of your help.
     

    Attached Files:

  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What do you get when you right click the Qoobox folder? Under properties? Is there a security tab there?

    You may need to just re-download combofix.exe and then do the uninstall script again. "%userprofile%\Desktop\combofix" /uninstall
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since time is short, just do the below which should hopefully work.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Then you can delete all the Avenger related files and folders afterwards.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds