Admin User blocked

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by capparella, Sep 12, 2014.

  1. capparella

    capparella Private E-2

    I was following the steps for Malware removal on a Windows 8 -64 , when I encountered an issue saving the MGTools to the C drive telling me I didn't have the rights. I tried both of my accounts for this computer and logged in but the admin rights were denied on both accounts. I am unable to create a new user account to switch over admin rights to it, and I cannot run Hitman,tdsskiller, or rogue killer at this time. I was able to run CC cleaner, and uninstall any add ons or programs that were not supposed to be there. Any tips to get around the admin rights?
     
  2. capparella

    capparella Private E-2

    I tried to go into safe mode, won't even let me do that through msconfig! :cry
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  4. capparella

    capparella Private E-2

    Thanks, I was able to boot in safe mode however I was still unable to run any of the programs. It wouldn't allow me access because of the administrative rights. It asked me for a password and none of my passwords were working.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    [​IMG] For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    To enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    • Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  6. capparella

    capparella Private E-2

    I was able to run RogueKiller,Malwarebytes,TDSSkiller,Hitman, and MGTools in safe mode with admin rights. I attached all of the logs here. I'm still having the same popups when I'm in an internet browser (IE or Mozilla). My son tried downloading Clash of Clans App and it unleashed a mess on the computer 2 days ago. Any ideas?
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:


    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.




    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.
    Code:
    :Files
    C:\Windows\SysNative\drivers\{5eeb83d0-96ea-4249-942c-beead6847053}Gw64.sys
    C:\Windows\SysNative\drivers\{c5e48979-bd7f-4cf7-9b73-2482a67a4f37}Gw64.sys
    C:\Windows\tasks\APSnotifierPP1.job
    C:\Windows\tasks\APSnotifierPP2.job
    C:\Windows\tasks\APSnotifierPP3.job
    
    :reg
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}]
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Please download AdwCleaner by Xplode and save to your Desktop.

    • Double click on AdwCleaner.exe to run the tool.
    • Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.



    Now (in normal mode if possible) run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  8. capparella

    capparella Private E-2

    When I ran Rogue , there were 4 registry items with the same name
    KEY ---> S-1-5-21-3172471117-74355147-1742499170-1002\Software\Microsoft\Windows\CurrentVersion\Policies\System

    GLOBAL ---> HKEY_USERS

    TYPE ---> PUM.policies

    That was the closest I saw to your instructions for deletion in the registry. Which ones should I do?
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  10. capparella

    capparella Private E-2

    In Rogue I don't see any other details than what I listed, 2 of them have DisableRegistryTools and 2 have DisableTaskMgr under the Value Category. I don't see any details about them being linked to www.trevi at all
     
  11. capparella

    capparella Private E-2

    should I just remove them all?
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No!!!!

    Just re run RogueKiller (just a scan) and attach the log.
     
  13. capparella

    capparella Private E-2

    Here you go, thanks!
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK :) It no longer shows. How are things running?

    Attach all of the other requested logs too though please!
     
    Last edited: Sep 18, 2014
  15. capparella

    capparella Private E-2

    I am still unable to install updates from normal mode. It asks me to enter a password from the user account window, but there is nowhere to enter the password. I can run admin loads in safe mode though. Here are my logs for the past few scans. The pop-up junk seems to be gone, except for the Malwarebytes windows. Thanks for your help, almost there it seems!
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Have adwcleaner remove all it finds. Then tell me what problems remain.
     
  17. capparella

    capparella Private E-2

    I cleaned the findings from Adw and I still cannot run things as an admin when in normal mode. I am needing to do an Adobe update and I cannot, a User account window pops up, says I need a password to log in as an admin, but there is no place to put in the password and the yes button is shaded out. I can't run any of the Fix files(roguekiller,jrt,tdsskiller,mgtools) without being in safe mode either because of the same problem.
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What do you mean?
     
  19. capparella

    capparella Private E-2

    The Malwarebytes kep alerting me that a threat was detected. It is not coming up anymore though. I'm just having issues not being able to install updates because of the admin issue.
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then you can post about that in the software forum. :) best of luck.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  21. capparella

    capparella Private E-2

    I cleaned everything up and all seems well. However, I still cannot do any updates or open any admin files unless I'm in safe mode. I don't even get the chance to enter the admin password in normal mode. It did this with any software I tried opening in normal mode as an administrator.
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Post about this in the software forum, please. (As mentioned previously)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds