2nd Machine For Review -senior Couple Victimized By Phone Scam - Logs Attached

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by axlmastr, Feb 17, 2018.

  1. axlmastr

    axlmastr Private E-2

    Logs attached. Desktop machine victimized by phone scam of elderly couple. I received the machine to help them out. This one still has trojans that AV couldn't remove. Was running slow and had a ton of crap on it. Machine had a 2011 version of Webroot AV w/Spy sweeper on it that didn't work. Malwarebytes Monitor had multiple attacks by websites while scanning. There are 17 networks created on this machine because of the crazy trojans. TimW helped on the laptop.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have RogueKiller and Hitman remove everything they found.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Win10, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now use explorer to find and delete:
    C:\Users\Tom\AppData\Local\kpnvlasy.log
    C:\Users\Tom\AppData\Local\takunjdg.log
    C:\Users\Tom\AppData\Roaming\Microsoft\rsbfaasw


    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now right click start / run and type in
    %temp%
    When the window opens .. select all and delete.

    Reboot and rerun RogueKiller, Hitman and please also attach a new log from running ADWCleaner.
     
  3. axlmastr

    axlmastr Private E-2

    I just emptied the Recycle Bin if anything shows in there in the logs.
    All steps completed. Success on the regedit merge.
    Had to download Unlocker to aid in the removal of the 3 specific noted items found in Appdata/Local & /Appdata/Roaming but they were removed
    Last scans show reference to Tific in the same Appdata location.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looking much better. Rerun RogueKiller and remove these:
    ¤¤¤ Registry : 11 ¤¤¤
    [PUP.Tific] (X64) HKEY_USERS\S-1-5-21-1524501869-2401252847-579344236-1000\Software\Tific -> Found
    [PUP.Tific] (X86) HKEY_USERS\S-1-5-21-1524501869-2401252847-579344236-1000\Software\Tific -> Found

    ¤¤¤ Files : 1 ¤¤¤
    [PUP.Tific][Folder] C:\Users\Tom\AppData\Roaming\Tific -> Found

    Then reopen Hitman and remove this:
    C:\Users\Tom\AppData\Local\Obxics\xrxnpcl.dll

    Reboot and rescan with both. Attach the new logs.
     
  5. axlmastr

    axlmastr Private E-2

    Tasks completed
    Logs attached
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Both clean. Any other malware issues?
     
  7. axlmastr

    axlmastr Private E-2

    Woo hoo!
    No malware issues that I see. Things run quicker and smoother as they should. One issue I still see from the beginning is the Windows Firewall is says "update your firewall settings. Windows Firewall is not using the recommended settings to protect your computer." When I click to the right on the "Use Recommended settings" button a popup message says "Windows Firewall can't change some of your settings. error code 0x80070422"
    I went into Services through and found it "Disabled". I enabled and started it then clicked on the Use Recommended Settings button in windows Firewall and all is green instead of red.

    I believe at this time TimW we are done. I know how to reset UAC and run the MGTools cleaning and all the other things to get things back like they were.

    I probably will delete previous restore points and set a fresh restore point for good measure. That has long been a practice of mine. I don't want any chance of having anything harmful saved in restore points.

    Many thanks
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Now, tell them again and again not to let anyone into their system, no matter what they are told. :)
     
  9. axlmastr

    axlmastr Private E-2

    Yeah you know I will stress that VERY MUCH! I now need to figure what the #$%& they are doing with an AOL CD they received in the mail and why they have a USB modem and NetMeeting configured on this machine. I was told to look at the Dial-up connection and to install an AOL CD provided. Hmmmm they have broadband! I'm a hardware guy with 25 years background. I don't see why they are even using an AOL CD when you can access it through the browser. AND why are NetMeeting and a Dial-up connection established? Hmmmm something isn't right. I'm dealing with this through a friend that the owners of this desktop and the laptop are his colleagues. Guess I'll be asking more questions. I'm just here to help.

    Yours help TimW, was very much appreciated. As always the Majorgeeks Experts save the day!
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem. Good luck. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds