Sons PC infected- hopefully clean now

Discussion in 'Malware Help (A Specialist Will Reply)' started by maglib, Sep 17, 2011.

  1. maglib

    maglib Private First Class

    Windows 7
    x64
    This is my 13 year olds pc. No clue when the problems started. I know he recently got infected by a keylogger through an email but based on all the problems, it appears he's had issues for a very long time. His own email account was hijacked and sent keylogger to all his contacts. Yes we changed his password on a seperate machine.

    1. this is fixed was that when you used the windows key and typed anything into run or find, it came up completely blank.

    2. He supposedly does not sign on using the admin account but I only signed on as admin. In the admin account priveleges weren't working. I didn't have access to all the pc. I had issues saving the downloads to c: and there isn't a c:\desktop. I would save them to the admins file and then copied them to c: and then sent to desktop as needed.

    3. I could not install a new version of google chrome. Would get errors that "your preferences can not be read", probably related to security issues from 2.. I have not tried again. I want to ensure the pc is completely clean first.

    4. I have not signed into the user account he uses. I only ran all this as administrator. Please note that I did not originally follow the sticky and listened to someone else first so I had downloaded all the files and ran them errorneously and still had issues. Only then did I follow the words that I know to work of majorgeeks. So I may have other log files if they saved that are earlier attached.

    Thank you for helping. Please let me know if there's anything else he should do other than the system restore and enabling UAC again. I'll do those 2. Of course he's got to learn to be safer.....

    I appreciate all help and advice. I will do whatever is needed to make sure this doesn't happen again including never letting the child on the PC for anything other than homework. LOL.

    Take care.
     

    Attached Files:

  2. maglib

    maglib Private First Class

    other log files. Again I know that some were originally not done in accordance with directions but I realized that the original errors may be in them so attached them along with the ones that I did in the correct order.

    Thanks a bunch.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There isn't supposed to be such a folder!

    Your son's Desktop is >> C:\Users\Mattman45\Desktop
    The Administrators is >> C:\Users\Administrator\Desktop


    Then you are not fixing any problems that may exist on his user account. You need to run the scans on his account.


    MBRcheck indicates an unknown Master Boot Record. Do you have your Windows 7 Boot DVD so that it can be used to boot to the System Recovery Environment to repair the MBR?
     
  4. maglib

    maglib Private First Class

    sorry on the issues. I'm not that adept. I do realize it didn't work anyway as once I restarted the search under windows icon wasn't working again on the admin account. I already reenable UAC and disabled system restore on this admins account. Mattman45 is the administrator..... or supposed to be. he has another account which is just mattman.

    So does this mean I have to run all this on every accounts desktop individually?

    I have the disks to reboot which are the backup we created when we first got the pc? Or isn't there also an extra drive D:? SOrry not sure which you want.

    What should step 1 be and which account should I start with, the admin or his? Plus there is a extra account.

    How would the admin account get infected if nobody signs in as the admin?

    Thanks. I will do whatever is needed. It was scary the first time we ran SAS on this pc. Seems he was using multiple antivirus and possible one was corrupted as he had Norton and Mcaffee and AVG so when I said to him did he run, I'm not sure what he was running as we weren't paying for Norton nor Mcafee and not sure where they came from.....

    Gracias. i will await whatever you say.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No that is not technically correct! This is just an account that has some admin privileges. There is only one true administrator account and it is name Administrator with a capital A.

    Actually the below other restricted user accounts exist:
    EVERYONE ELSE
    HomeGroupUser$
    mattman


    For any account that is having malware problems, you would need to run the steps. However, the MBR is not account related. It is whole PC related.

    No! You need a Windows 7 bootable disk.

    Fixing the MBR is the first step. You need a bootable Win 7 DVD/CD for this.

    The Adminstrator account was probably not infected but if the Mattman45 account had been getting used which has admin priviledges, then any infection that occurred while logged into this account can impact all other user accounts because of the admin priviledges. An infection could even change all of your passwords if it wanted to since it would have the privies of an admin at this time.
     
  6. maglib

    maglib Private First Class

    Sadly we don't have a bootable windows 7 DVD as they provided all the software on D: as the backup.

    Is there any way to use the D: recovery drive?

    If not, I guess I can contact HP and if I do as it's still under warranty, what would I explain that the MBR possibly has a virus?

    Thank you for the amazingly fast response time. I was just reading the forum logs and was shocked on how quick you were.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    No! In most cases these are used to return the system to out of box condition which means that you would lose everything you put on the PC. In most cases, this is something people would like to avoid unless it is the only choice.

    You're welcome.
    You should see if you can get on OS DVD from them anyway for possible future issues. In my opinion, vendors are being negligent in not providing boot CD/DVDs with each PC. Malware and Windows problems, require these CD/DVDs all the time. Recovery partitions and having you make recovery CDs ( while they have a purpose ) are not the answer in this day and age.


    Let's see if you can create the below bootable CD and boot from it. However I will warn you that it would be prudent to backup important data before continuing. Most of the time a repair of the MBR goes without an issue, but with malware, this is always a chance that things can go wrong.

    You need to burn the below CD as an image ( see the instructions ) to make it bootable.

    http://digiex.net/downloads/download-center-2-0/applications/2659-windows-7-32-bit-x86-recovery-disc.html

    Once you can boot from the CD, you can follow the instructions in the below link to get to the Command Prompt.

    http://www.bleepingcomputer.com/tutorials/tutorial161.html

    Once at the command prompt, you will follow the below instructions to repair the MBR

    Now type in:bootrec /fixmbr and press ENTER afterwards.
    Note: There is only a SPACE after bootrec
    Now you will see:
    http://img19.imageshack.us/img19/4114/operationcompletedsucce.png
    Type exit and press ENTER.
    Now restart your computer WITHOUT booting off the DVD again (don't press a key when it says... "press any key to boot from cd/dvd...")
     
  8. maglib

    maglib Private First Class

    Thanks again. I'll do this but, I want some free time to run it all and will try to find time tomorrow. What account should I sign into when I try it?

    I tried to sign on to my sons account and got an error message that his password expired and must be changed. I didn't think they expired on Windows 7 Home edition. I've never seen this before as he's not on a network so I was weary of doing any changes. Is it ok to set up a new password?

    When I enable UAC I can't search and the windows menu search feature doesn't work either. Is there any issue keeping it disabled?

    I tried to print on the wireless printer and it didn't work. i wanted to print out all the instructions. Is there any relation of not being able to print with all the stuff we've run? Should I try to reinstall the printer?

    In the meantime I did all the runs correct this time in the account that has admin rights (still not my sons). all came out clean this time. Still have the same issue though it appears with MBR so tomorrow I'll work on something new and exciting. I'm going to post the clean logs in the meantime JIC so all info is there.

    Have a great evening.:zzz
     

    Attached Files:

  9. maglib

    maglib Private First Class

    Missed 10 minute cut off so another question as the instructions have me downloading Imgburn to burn the disc. Isn't this software ridden with ads and is it safe or is there another software to burn the CD that I can get?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You will not be booting Windows.

    Yes.

    I did not ask you to enable UAC and you should not be doing anything I don't ask you to do. So you need to keep is disabled anyway.

    No!

    I did not ask you to rerun the scans nor do we need them rerun on the account that was not infected.

    As stated in my previous message, the first thing to do is to fix the MBR.
     
  11. maglib

    maglib Private First Class

    OK I did the fixmbr what is the next steps? UAC is off still.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Rerun MBRcheck and attach a new log so we can verify if it worked.

    Also tell me whether you are still having any malware problems.
     
  13. maglib

    maglib Private First Class

    Q. Does it matter which account I run mbrcheck from?

    So far the account mattman45 that has admin rights is fine and I still haven't signed onto his actual mattman account.

    I'll run it in the account I've been running it in and see what happens.

    If it gets a clean bill of health, I'll then do all the steps on the mattman account.

    Much warmth and regards.
     
  14. maglib

    maglib Private First Class

    Here is log. Ran from mattman45 account with admin priveleges.
    Wierd it has the time at AM and not pm.
    Should I fix the time clock?
    Let me know if I should sign on into sons account. He admits to using the admin privilege account hence all the issues mattman45 has. Not sure about mattman user account yet.

    should I do all the spyware in order on the mattman account now? or which ones?

    I can no longer print from this account. I was able to prior to all the runs.

    Thanks again.
     

    Attached Files:

  15. maglib

    maglib Private First Class

    oops I reran as I forgot to shut off all security first.
    Here's a new run.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to properly follow the instructions I'm giving you. I did not ask to run MGtools and attach a new log. I asked you to run MBRcheck and attach a new log. And as stated earlier, MBR infections are not related to which user account, they are hard disk related and thus impact every user account.
     
  17. maglib

    maglib Private First Class

    Sorry for confusion as I thought it was part of mgtools as I don't remember running it before.

    Here it is and hopefully it's clean.

    Thanks.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See your first post. It was one of the logs you attached which is how I knew your MBR was a problem. It is good now.

    Are you having any remaining malware problems now?
     
  19. maglib

    maglib Private First Class

    Haven't been using the pc. What has been on the mattman45 has been fine. If I sign into mattman account which was the primary account my son used, should i do all the steps again or only specific ones (this is the account that hasn't been signed onto and needs a new password, I'm sure it will have issues in other words).

    Thanks
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Give it a new/different password and check it out. If it has "malware problems" not Windows software problems, then run the cleaning procedure on that account but it will have to be temporarily changed to an admin account to get all tools to run properly.
     
  21. maglib

    maglib Private First Class

    New logs.
    1. time on pc is still backwards saying pm when am. should i fix this?
    2. I could not uninstall google chrome even using cccleaner removal too. I was trying to remove it as on mattman45 it was removed and I couldn't reinstall it, when I saw it still listed on mattman account I figured this may be a problem.
    3. is registry mechanic an ok program as it keeps popping up?
    4. Combofix was showing up as read only originally so I reinstalled and changed name to run it.
    5.malaware bytes showed 10 issues fixed
    6. sysmain superfetch? when i was shutting off running processes. Don't believe I've seen that before.
    7. I still can't print wirelessly.

    Thank you.
     

    Attached Files:

  22. maglib

    maglib Private First Class

    other files since 4 max
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Other than the MyWay stuff MBAM removed, your logs are clean. You should post about your non-malware problems ( like your wireless printer )( in the Software Forum. You may need to reinstall drivers for it.

    Yes.

    Don't use CCleaner to uninstall programs. Use the uninstaller that came with the program. If that fails, use the below:

    Revo Uninstaller


    It is not malware but I don't recommend using it or any other registry cleaners. They are almost never needed and can cause more harm then good. Reg Mechanic also is very full of false indications of problems. You do have it installed. If it is just a trial then you definitely should uninstall it. If you paid for it, still consider removing it.


    Sounds like a Windows issue for to ask about in the Software Forum. See the below:

    http://www.blackviper.com/wiki/Superfetch

    http://social.technet.microsoft.com/Forums/en-US/w7itproperf/thread/89286b32-dc3c-47c6-b8e8-f22306189039/




    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  24. maglib

    maglib Private First Class

    Thank you so much. I tried using revo and got an error message that it could not open INSTALL.LOG file.

    Is this a software issue or possibly still malware?

    This is such a wonderful sight and amazing.
     
  25. maglib

    maglib Private First Class

    I also found bttr.exe to be set to run at startup and understand that to be malware. Should I run something else? I'm still signed into my sons account
     
  26. maglib

    maglib Private First Class

    If I go to Start and type anything in the search box it finds nothing. Even excel, powerpoint, msconfig. I can choose from menu options but once I type in the search box it's blank.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just a software issue. You could try reinstalling Chrome and then uninstalling it.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There was no such startup showing in your logs. Are you sure you have the correct name. There were bluetooth type applications like bttray.exe and others that are bluetooth related.

    The search finds nothing?

    "Even excel, powerpnt, msconfig" what? Do you mean you type this strings into search and when you run the search, nothing is found.

    So now I'm not sure what you meant above. Did you mean that performing a seach finds nothing, or do you mean that when you type characters into the search box that the characters do not show.

    All of this just sound like software issues ( i.e., problems with Windows ).
     
    Last edited: Sep 25, 2011
  29. maglib

    maglib Private First Class

    I choose start and all the start menu comes up including the blank search box. Once I enabled UAC per your last post, now whenever I type in that box then the actual menu above disappears like it's finding nothing. Basically the search feature is disabled. Although if I leave the box blank and choose all programs I can find them. Even if I type msconfig it's blank but if I choose run and type msconfig it works. So the feature got disabled somehow.

    the bttr.exe was bluetooth,so it's then okay?

    I'm not having an issue with Windows updates on the pc. I did sfc /scannow to fix the missing .dll file and the scannow.txt file was completely blank when I tried to open it in notepad, using edit function gave me that edit was not valid.

    so the sqmapi.dll file is missing. I tried to find it on the Windows 7 disc and couldn't . Is there a safe place I can get this file and how and where should I put it on the PC?
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I suggest that you report these problems in the Software Forum and continue there to resolve issues with Windows. This is the first time you mentioned anything about a missing DLL file. Normally files required by Windows can be found on the CD/DVD within the i386 folder. Sometimes they are compressed and need to be extracted. The extracted file name would be sqmapi.dl_ You can address this in the Software Forum too or you can check out the below:

    http://www.dll-files.com/dllindex/dll-files.shtml?sqmapi
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds