restricted admin rights, no control panel

Discussion in 'Malware Help (A Specialist Will Reply)' started by ctalmage, Nov 19, 2008.

  1. ctalmage

    ctalmage Private E-2

    Hi - I'm working on a friend's computer which had a major problem with spyware popups - running XP just upgraded from SP2 to SP3. I've run thru the read and run me first and XP cleaning instructions. I had problems installing SAS but got past that, ran all cleaning and then ran SAS again.

    Now, I think I'm free of the popups but still have limited admin access - sort of. The computer has 4 users set up on it, all with admin rights but only one has access to control panel, program files, etc. Also, on the three logons with the issues, the taskbar has VIRUS ALERT! in the bottom right with the clock next to it in 24hr mode.

    I'm not sure what to do next. I read the first 15 pages of of problems/resolutions but didn't find anything that matched my issues.

    Can you assist?

    Thanks,
    Cal
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to pick one of the user accounts to start with and run the full cleaning procedure on it and attach the 4 requested logs. After this account is cleanup, we can move on to the next account.
     
  3. ctalmage

    ctalmage Private E-2

    Hi - I ran the cleanup on the one user with full access. Logs are attached. No malicious files found in mbam so I didn't attache the log (only 3 attachments max). I'll try to run the cleanups on the other users. I tried this last night but on the first user Spybot S&D would freeze 1/3 of the way through on virtumonde.dll - had to cancel the scan to get out of it.
    Please let me know what you think once you have a chance to review the logs.
    Thanks for all your great help! Cal
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please always attach all logs as requested in the READ & RUN ME. This allows us to verify proper versions of programs and databases are being used to run scans.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    Java(TM) 6 Update 4
    Spybot - Search & Destroy 1.4
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    Is the below something from MSN Gaming Zone? If you are not sure then just fix it too.
    O24 - Desktop Component 0: (no name) - C:\Program Files\Common Files\promyfs.html

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!


    After finishing with the fix for the above user account, just run MBAM, SAS, and MGtools on the next account to check and attach these new logs. Name them according to the user account name so we can easily recognize them.
     
  5. ctalmage

    ctalmage Private E-2

    Thanks for your help so far. I followed your instructions - attached are logs from the scans - will send several replies to send them all (11 total). Logs have user name imbedded in the log name. Please let me know what the next steps are. Pop ups and hijacks seem to be gone but system is running slow.
    Thanks again - Cal
     

    Attached Files:

  6. ctalmage

    ctalmage Private E-2

    2nd set of logs
     

    Attached Files:

  7. ctalmage

    ctalmage Private E-2

    3rd set of logs
     

    Attached Files:

  8. ctalmage

    ctalmage Private E-2

    4th set of logs
     

    Attached Files:

  9. ctalmage

    ctalmage Private E-2

    forgot one thing - My Way Search Assistant is still listed in the list of installed program on the control panel add/remove programs. Is this a problem - should it be removed? How?? Thanks!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not run the below step. Please run it now.
    We missed another old Sun Java version to uninstall. Uninstall Java(TM) 6 Update 3


    As I was worried about, you are way out of date with Malwarebytes. You need to update it so that you have the correct version and also the correct databases. Do this immediately and then run a new scan and attach the new log. It may or may not find anything but you need to be updated anyway.

    The reason for you system being slow may not be malware. It is more likely due to an inadequate amount of RAM. You have 512 MB. You need at least twice the amount that you currently have (i.e., 1 GB) Also you are loading a bunch of unnecessary items at startup. None of the below are necessary startups. All of them can be removed with the analyse.exe (hijackthis) program. You can do similare for each user account where these are loading at startup.

     
    Last edited: Nov 28, 2008
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    For Jack's, Megan's, and Kate's user accounts, just login as them (one at a time) and just do the below for each account.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  12. ctalmage

    ctalmage Private E-2

    Hi - First of all, thanks so much for all your help. Everyone at majorgeeks are the best!

    Per your 11-28-08 14:33 POST, I ran the disable/remove windows messanger step with no problems.

    Next, I removed Java 6 Update 3.

    I then updated Malwarebytes and reran it for the Harry user account - log is attached. According to the scan, no malicious items were found. I only ran it for the Harry user account - do I need to run for all accounts?

    As suggested, I then removed the unnecessary start up items with analyse.exe for all accounts.

    I'll try adding the additional ram to speed up the system.

    Per your 11-28-08 14:51 POST, I ran the fixme.reg (bold type) for Jack's , Megan's and Kate's accounts. All 3 gave a success message after adding to the registry.


    After you check out the attached log, please let me know if I need to do anything else.

    Thanks,
    Cal
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Your log is clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds