Gateway Win 7 Computer with Malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by parhamjl, Aug 24, 2014.

  1. parhamjl

    parhamjl Private E-2

    I was brought a relative’s computer that was infected with huge amounts of malware, and at least one virus. There were no backups to revert to. With my attempts to clean up the computer, using some malware programs, I was able to get Internet explorer to work, and get Windows to update. I removed more than 16 million files from one Temp subdirectory. Norton 360 still will not run, nor will the DVD writer. None of the virus programs, like Malwarebytes and CCleaner, will download. I get a notice that they are viruses and it gets deleted. I assume that is the virus doing that. I downloaded the various virus programs on another computer and transferred them to the infected computer with a flash drive.
    The computer is a Gateway, Windows 7 Home Premium, 64 bit, 6GB memory, 1 TB HD.
    I have gone to Step 4 in the “Vista, Win 7 and Win 8 Malware Removal/Cleaning Procedure “at Major Geeks. I enclosing the log files of “Rogue Killer 64”, ‘Malwarebytes”, TDSSKiller’ and ‘MGtools’. ‘Hitman Pro 64’ would not move past the initializing stage.
    Any help would be much appreciated.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    A virus is malware. ;) Malware is a generic term covering all malicious software.

    These are not antivirus programs especially CCleaner.

    Most likely it is your broken Norton 360 that is the problem. It may be best to start by uninstalling it and then run the below to make sure it is removed:

    http://www.majorgeeks.com/files/details/norton_removal_tool.html

    Is the installed copy of SUPERAntiSpyware a paid version or the scan only free trial version?

    Run Malwarebytes and empty the quarantine which is getting quite large.

    Uninstall the below programs. If you do not find them or they will not uninstall, just keep going.
    Smootherweb

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: PrestoSavings BHO - {61FC239E-FFCD-4F74-B709-47772F636B57} - (no file)
    O2 - BHO: (no name) - {C3BD0237-0C8B-49F8-A381-2CAE3A705715} - (no file)
    O3 - Toolbar: (no name) - {9754A33D-37F9-4629-B1EB-C65CF8F526D5} - (no file)
    O4 - HKLM\..\Run: [PC HealthFix] "C:\ProgramData\PC HealthFix\PCHealthFix.exe" /runscan
    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
    O23 - Service: pcmaxservice Service (pcmaxservice) - Unknown owner - C:\Program Files\pcmax\pcmax.exe (file missing)

    After clicking Fix, exit HJT.


    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Services
    pcmaxservice
    C:\ProgramData\PC HealthFix
     
    :Files
    C:\Program Files\pcmax
    C:\Windows\tasks\APSnotifierPP1.job
    C:\Windows\tasks\APSnotifierPP2.job
    C:\Windows\tasks\APSnotifierPP3.job
    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    C:\Windows\tasks\Quick PC Booster64 startups.job
    C:\Program Files (x86)\ESET
    C:\Program Files (x86)\Smootherweb
    C:\Windows\TEMP\*.*
    C:\Users\Tina Bailey\AppData\Local\Temp\*.*
     
    :Reg
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "PC HealthFix"=-
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\windows\currentVersion\Run]
    "PC HealthFix"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{61FC239E-FFCD-4F74-B709-47772F636B57}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C3BD0237-0C8B-49F8-A381-2CAE3A705715}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{9754A33D-37F9-4629-B1EB-C65CF8F526D5}"=-
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{5a15c091-f3c2-4c8f-8964-e3434a2a4a95}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{8F8DEEEB-442E-409A-A75F-CA92CD7B2F08]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXT log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. parhamjl

    parhamjl Private E-2

    Norton 360 Uninstall stopped at 82%, but I then used the Norton Removal tool. I still have Norton PC Checkup 3.0, Norton PC Checkup, and Norton Installer subdirectories in the Programs (x86) subdirectory but they may not be active.
    Superantispyware is the free version but it's logo comes up whenever I reboot.
    I see no problems yet, except I still cannot download any of the tools directly to this computer. I get a box that says it contains a virus and is deleted. I have to add these tools via flashdrive from another computer
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay Norton still has quite a lot of items running so have more work to do in removing all of it. Please first boot into safe boot mode and run the Norton Removal Tool again. Thn reboot into normal mode to continue with the below where we will also manually force some items out.

    Did you forget to uninstall Smootherweb. I still see it. If you already tried to uninstall, just tell me what happend. Was there an error. I will be force deleting it below.


    Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
    :Services
    gupdate
    gupdatem
    NOBU
    Norton PC Checkup Application Launcher
    PCCUJobMgr
    pcmaxservice
     
    :Files
    C:\Program Files (x86)\Norton PC Checkup
    C:\Program Files (x86)\Symantec
    C:\Program Files\pcmax
    C:\Program Files (x86)\Smootherweb
    :Reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "SUPERAntiSpyware"=-
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\windows\currentVersion\Run]
    "Norton Online Backup"=-
    "HP Software Update"=-
    [HKEY_USERS\S-1-5-21-3686454100-3877287528-1835012583-1000\Software\Microsoft\Windows\CurrentVersion\run]
    "SUPERAntiSpyware"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Smootherweb]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. parhamjl

    parhamjl Private E-2

    When booted for this session, computer ran ChkDsk for 2:30 hours checking 25 million files. Found only minor problems, 3 unindexed files.

    Previously forgot to try to remove Smootherweb. Could not be removed because It said it was already removed. I removed the Smotherweb icon from the 'Uninstall or Change programs. Booted into Safe Mode and ran Norton removal tool again. Rebooted and ran OTM and MGlogs. Log files attached.

    No change in computer. Seems to run ok, tools that I download still get deleted as viruses.
     

    Attached Files:

    Last edited: Aug 26, 2014
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please post a snapshot of what you are seeing because there does not appear to be any malware on your PC that is responsible for this.
     
  7. parhamjl

    parhamjl Private E-2

    No '.exe' can be loaded. I tried several, getting the enclosed messages. It was immediate since there was no time to actually download the program for it to be deleted. Non executable files such as .jpgs were OK. I backed up some ITunes files on a flash drive and tried to make a CD using my other computer. When I tried to check the files on the CD, it tried to load a virus on my computer, but was caught by Norton. The files on the CD were Mobile Applications, ".ipa". Afterward, I noticed several blocked attempts to load files on my computer. I think the attempted to load files were [Large number].qbd. These could be OK, I'm not sure.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What are the below programs I see loading at startup but that do not appear in your installed programs list?


    O4 - HKLM\..\Run: [EMBIRD.Searcher] C:\Program Files (x86)\EMBIRD32\SEARCHER.EXE /MINIMIZE
    O4 - HKLM\..\Run: [Gameiki] C:\Program Files (x86)\Gameiki\Gameiki Mod Installer\Gameiki Mod Installer.exe Update
    O4 - HKUS\S-1-5-19\..\Run: [Exetender] "C:\Program Files (x86)\Free Ride Games\GPlayer.exe" /runonstartup (User 'LOCAL SERVICE')



    Now please do the below so that we can boot to System Recovery Options to run a scan.

    For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  9. parhamjl

    parhamjl Private E-2

    FRST.TXT enclosed. Here are some additional notes.
    1. EMBIRD program is an embroidery program. This computer is used with a computerized sewing machine, and I assume this is part of that and needs to remain.
    2. Gamiki and Gplayer.exe appear to be associated with computer gaming. A 9 year old had free access to the computer for a time, downloading numerous games, and apparently causing the present problem. Attempts have been made to delete all those games. These items can be deleted.
    3. When I made Google Chrome as my default browser, I had no problem downloading and saving '.exe' files to the hard drive. That problem (saying the downloaded programs contains viruses) is only seen in Microsoft Internet Explorer.
    4. Computer appears to try to install 'the same?' single update whenever the computer is re-booted. I assume it is unable to successfully install it, so is making multiple attempts.
    5. The only program I have found so far (other than Norton 360) that does not run properly is Nero (CD/DVD writer software.) It says "Failed to start because side by side configuration is incorrect."
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download this >> View attachment fixlist.txt



    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows and continue with the below.


    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • Fixlog.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!

    Almost forgot, please run another scan with RogueKiller and attach the new log. Also see if you can get HitmanPro to work now.
     
  11. parhamjl

    parhamjl Private E-2

    Have tried to run HitmanPro 64 bit without success. Downloaded it again but still would not run. In both cases it went to the Scan screen, showing it was 'initializing' but was stuck there in one case an hour & a half. The time would continue to update, so it was not frozen. After hitting cancel, it would not do anything except say 'Cancelling'. I had to use 'Windows Task Manager' to close it.

    No change on the Nero CD/DVD writing software. Just would not run. However, I could format a CD-RD and save a file to it. Without Nero, I don't have a program installed to write to a regular DVD or CD (CD-R or DVD-R). I haven't checked, but the computer owner may have a copy of Nero Software so I can re-install it.

    Other than seeming to be a little slow, I haven't found any other problem with the computer. I can now use Microsoft Internet Explorer to download and save '.exe' files, without the previous error.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try running it in safe boot mode, but not sure at this point we really need it since you are not having malware problems now. The problems with Nero need to be discussed in the Software Forum not here. My suggestion would be to uninstall it, reboot and reinstall.
     
  13. parhamjl

    parhamjl Private E-2

    Thanks for your assistance in removing this Malware. It is very much appreciated. Never got Hitman Pro 64 to run, even in Safe Mode, but the computer runs OK except for some lingering damage to Nero software, either from the malware or the long term tinkering of a young boy.

    I guess we should consider this case closed.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  15. parhamjl

    parhamjl Private E-2

    I did all the requests in the last post, including all Windows updates. I tried to delete ‘iTunes’ since I thought a virus resided there at one time, but it would not let me. It said that another file was installing and to try another time. Nothing was being installed at the time.

    I then checked with Microsoft Update again, and it told me that Windows was up to date. I could see that there were several attempts to update Skype, but the update failed. I download Windows Security Essentials and ran a full scan. It detected the following malware:
    Trojan: Win64/Sirefef
    Browser Modifier: Win32/Zwangi
    Trojan: JS/Medfos.B
    Trojan: Win32/Sirefef!cfg
    Trojan: Win64/Sirefef.AO

    After quarantine and removing these, I was able to uninstall ‘iTunes’. I was going to uninstall Skype because of the update problem, and since it had never been used, but it was not listed in the Windows ‘Uninstall’ list. I ran Skype and updated it. Afterward, it was listed in Windows Uninstall, so I uninstalled it.

    I now wonder if the computer is truly clean?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It was clean when I last checked your logs. Things found with MSE could just have been leftover registry entries or things already quarantined by other procedures. Could even have been things in System Restore if you ran MSE before removing old restore points and before running MGclean.bat too.

    You problems with Skype were software issues not malware issues. Whereas the previous ZeroAccess/Sirefef infection that you had ( and we had finished the removal of it ) may have cause some damage to Windows itself which cause your issues with Windows Update. But Windows update is notorious for having problems and most of them are not related to malware. Many times it is a registry problem.
     
  17. parhamjl

    parhamjl Private E-2

    Thanks. Was just concerned that these were found with the scan. I can see no real problem with the computer at this point, except the failure of Hitman Pro 64 to run, either in regular or safe mode. I tried several times, but it would go to 'initializing' and never move. Had to use Task Manager to stop it from running, and also found that it was still listed under the Processes tab.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your' welcome.

    You don't need Hitman anymore anyway and as part of my final instructions should have removed it. It only gives a 30 day trial for free anyway. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds