Almost Unusable - 5 logs attached

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Stachey, Dec 31, 2014.

  1. Stachey

    Stachey Private E-2

    I'm trying to repair a severely corrupted computer that has multiple pop up windows whenever anything in a browser window is clicked or tabbed to. The windows are nasty, starting downloads, replacing the browser screen that I was on (necessitating back arrow clicking), opening new tabs or overlaying the browser with a whole new window. I'm trying to do this via TeamViewer since I'm 200 miles from my son's laptop.

    I've followed the entire process in the Read & Run Me First and have assembled the logs from the five programs. There is so many things going on it's taken me close to a half an hour to get this posted.

    Thanks in advance for your help.
    Stachey
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Uninstall the below program. If you do not find it or it they will not uninstall, just keep going but tell us later about any problems.
    savernet



    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1:9421;<local>
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)


    After clicking Fix, exit HJT.

    Rerun RogueKiller and have it fix these item:

    ¤¤¤ Registry : 25 ¤¤¤
    [PUP] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670} -> Found
    [PUP] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dfc86759 ("C:\Windows\system32\rundll32.exe" "c:\progra~3\perfor~1\PerformancerSvc.dll",service) -> Found
    [PUP] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dfc86759 ("C:\Windows\system32\rundll32.exe" "c:\progra~3\perfor~1\PerformancerSvc.dll",service) -> Found
    [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Agent (C:\Windows\VPDAgent_x64.exe) -> Found
    [PUP] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\dfc86759 ("C:\Windows\system32\rundll32.exe" "c:\progra~3\perfor~1\PerformancerSvc.dll",service) -> Found
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{859666F2-FBB4-4807-873D-C29105593B7F} | DhcpNameServer : 10.0.10.50 10.0.10.51 [(Private Address) (XX)][(Private Address) (XX)] -> Found
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{859666F2-FBB4-4807-873D-C29105593B7F} | DhcpNameServer : 10.0.10.50 10.0.10.51 [(Private Address) (XX)][(Private Address) (XX)] -> Found
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{859666F2-FBB4-4807-873D-C29105593B7F} | DhcpNameServer : 10.0.10.50 10.0.10.51 [(Private Address) (XX)][(Private Address) (XX)] -> Found
    [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs : C:\PROGRA~3\PERFOR~1\PERFOR~2.DLL -> Found
    [Suspicious.Path] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs : c:\progra~3\perfor~1\perfor~1.dll -> Found[/code]

    Now rerun Hitman and have it fix everything it finds except the Suscpious file named C:\Windows\SysWOW64\SftTree_IX86_U_50.ocx

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :Processes
    explorer.exe
     
    :files
    C:\ProgramData\greaatsaving
    C:\ProgramData\PariceDownloader
    C:\ProgramData\tpEERfeuCtcoupon
    C:\Program Files (x86)\greaatsaving
    C:\Program Files (x86)\tpEERfeuCtcoupon
     
    :reg
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{C52D1191-6264-42C5-BFBB-56F3C1FC53E0}]
    :Commands
    [purity]
    [ResetHosts]
    [emptytemp]
    [start explorer]
    
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach that document back here in your next post.

    Reboot and rescan with both RogueKiller and Hitman and attach the new logs.'


    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Rescan with both RogueKiller and Hitman and save new logs.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXT log
    • the RogueKillerlog
    • the Hitman log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited by a moderator: Jan 1, 2015
  3. Stachey

    Stachey Private E-2

    I've run into a wall with this fix. While running OldTimer I've lost the ability to connect to the machine with TeamViewer.

    I removed savernet from the file list (the machine said it couldn't find the program).

    I did not run MGtools/analyse (HJT) because it wasn't in the original instructions and just appeared here when I refreshed this screen.

    I ran RogueKiller and fixed the items listed in the original post.

    I reran Hitman and had it fix everything (I'm not sure if that included C:\Windows\SysWOW64\SftTree_IX86_U_50.ocx) as that part wasn't on the original post.

    Here's where the problem came in. I ran OldTimer, pasted the Code into the 'Instructions to be Moved' box and hit MOVE. At that point I lost my TeamViewer connection to the machine. I've been trying for the past half hour to reestablish a connection but it doesn't seem to want to hold. Connect/Disconnect immediately.

    Is there something in the instructions to OldTimer that removed my ability to connect remotely? If so and I have to send someone out to restore the connection, what should they be looking for?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Nothing in OTM should have affected your remote connection.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    FYI: Do not work from email notifications. Always come here to the forum to see the most up to date and properly formatted instructions. Use the email notification only as information that you need to come here to your thread to see new information.
     
  6. Stachey

    Stachey Private E-2

    I was at this site using the instructions in this thread and had used the SnippingTool to copy the list of files to be corrected on RogueKiller (and used the pen to check off the ones I had checked). Sometime between when I opened this thread (around 5:00am) and started running OldTimer (around 9:00am) the instructions were edited and included several more steps. That's moot now because I can't connect with the remote machine at all. The machine is available [Ready to Connect (secure connection)] but when I attempt to Connect to Partner it goes through the Connecting to Partner, Connecting, Disconnect sequence in the span of a second.

    I don't know if it was the [resethosts] or [emptytemp] command that reset the connection parameters. According to the usage guide, if [emptytemp] is included "then all processes will be killed automatically at the beginning of a fix and a reboot will be required at the end" so losing the connection wasn't a big issue. I've been able to reboot the machine successfully quite a bit during this process. It's the fact that I can't reconnect now that makes me think the commands or addresses or passwords we've been using through TeamViewer have been reset somehow (would [resethosts] do that?) and need to be changed on the actual machine.

    Any suggestions would be appreciated so that I can talk the person at the remote machine through the re-connection fix.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No this would have no effect on Teanmviewer.


    Where is the PC located that you are working on? How far away?
    You could try having them power it down completely and then back up?

    Also try temporarily uninstalling protection software while attempting to fix this.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also another question to ask the owner of the PC. Can they connect to the internet on there end? That is does browsing work?
     
  9. Stachey

    Stachey Private E-2

    The PC is 200 miles away. They left it running in an office closed for the holidays so that I could try to debug it by Monday. I'll try to get him to go in tomorrow to check out the machine.

    When I hit MOVE on OTM that severed our connection but after a reboot, it appears that the computer is back and connected to the internet (or at least available to TeamViewer). I've rebooted the machine remotely several times after running different scanning programs and the way we have it set up (remove boot password, remember TeamViewer password) I've been able to reconnect after the reboot. Not this time.

    I'll have them try to get into the office tomorrow to reboot the computer and reconnect TeamViewer with my machine.

    The remote machine was running MS Security Essentials. I can disable that once I connect with the machine again. Because of all the problems he was having with Internet Explorer he had switched to Chrome but that program is having serious hijack problems itself.

    I'll reply when I get a connection.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So you are saying you actually can connect to the PC using Teamviewer but that you quickly lose the connection?


    I'll have them try to get into the office tomorrow to reboot the computer and reconnect TeamViewer with my machine.

    I would uninstall because it will keep reenabling after each reboot. Also uninstall Spybot and SuperAntiSpyware too. And then a power cycle would be a good idea.

    Also need to see if using a browser the PC has internet capabilities. It is possible that TeamViewer may need a reinstall.
     
  11. Stachey

    Stachey Private E-2

    On my machine TeamViewer program window shows the remote computer as Online and available to connect. When I click the Connect to Partner button, the status message goes from [green bar]Ready to Connect (secure connection) to [orange bar]Connecting to Partner to [orange bar]Connecting and then immediately back to [green bar]Ready to Connect (secure connection) all in a matter of about one second. Yesterday whenever I rebooted that machine remotely, the connection would be lost but when the machine restarted windows, it would offer me a reconnection with the saved password. That aspect is gone now.
    I'm not sure that I know what a 'power cycle' is. I'll assume that you mean physically turning off the remote machine and turning it back on rather than just Rebooting. I can arrange for that to happen.
    Re: Internet capabilities - All my work yesterday involved downloading the programs to the remote machine using that machine's Chrome browser. It was extremely difficult because any action on the remote browser caused a pop-up window, new tab or site misdirection (and sometimes all three!) however it had internet capabilities and I used them remotely.

    I'll have to see when I can get someone to the office the remote machine is in. Like I said, they were closed for the holiday but maybe we can get in.

    I can't see anything on the TeamViewer screen that would help me get into the remote machine. The options for connection are 1) Remote Control (prompt for confirmation) 2) Remote Control (using password) and 3) Presentation (prompt for confirmation). Since the remote machine is unattended there is no way to obtain confirmation which is why we were using the password access. If you have any suggestions short of having someone go to the machine, I'd really appreciate it.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes this is what I mean.

    It is possible the proxy setting that was shown in the HijackThis fix was a problem.

    This is the problem with remote access! When something goes wrong, you have to manually correct it.
     
  13. Stachey

    Stachey Private E-2

    I never ran the fix in MGtools (HJT) so the Internet Settings, ProxyOverride was never deleted.

    I also went through the recorded TeamViewer session video and the Hitman session had found the suspicious file C:\Windows\SysWOW64\SftTree_IX86_U_50.ocx but had marked it Ignore, so it wasn't changed (it showed up in the Removal Results still marked as Suspicious. I did a remote reboot after that (some files wouldn't be deleted until restart) and connected fine after the reboot.

    It has to be one of the commands in the OTM code that I pasted and then Moved that disconnected the TeamViewer session and won't allow a reconnect.
     
  14. Stachey

    Stachey Private E-2

    Ok, so I'm going to start again. Hitman creates restore points and I was able to restore to the point just before I ran OTM. I'd like to continue with this process but I'm afraid of running the OTM code.

    I can start the whole process over and generate the five log files or continue with the instructions below (skipping to the rescans with RogueKiller and Hitman and running JRT).

    Can I just resume the instructions after OTM or should I restart everything from the beginning of Read and Run Me First?

    Are there any other potential boobytraps that I could run into that would prevent remote connections (I don't think that JRT's resetting my browser home page would be a problem)?
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun all the scans and attach the new logs. We will see were we stand.
     
  16. Stachey

    Stachey Private E-2

    Ok, so now I'm up and running and have a weekend to sort through all of this.

    Some quick specs: Win7 64 bit, MS Office 2013.

    When I lost connectivity and got the owner to check out the remote machine he found that he has lost any functionality to both MS Word and Excel (Office 2013). The programs open but when a file is selected, the program crashes and closes down. It doesn't matter whether it's an existing document or a blank page. On the other hand, Internet Explorer now works (it didn't open at all before this) and is much less affected by the hijacks than the Chrome brower. The Chrome browser is still as hijacked as before.

    I reran the five programs and generated logs. Let me know what you want me to do now.
    Thanks for being so patient.
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Actually, not that much to do.

    Rerun Hitman and have it fix everything it finds except:
    C:\Windows\SysWOW64\SftTree_IX86_U_50.ocx

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Now follow these instructions:
    Reset Chrome to Defaults


    Reboot and rescan with Hitman (attach the new log) and then tell me how things are running.
     
  18. Stachey

    Stachey Private E-2

    I think this one did the trick with the hijackers.

    When I reran Hitman, two of the entries were one of the the registry keys that you included in the fixME.reg script (the middle one). They were marked as Delete but were not deleted by Hitman.

    I ran the fixME.reg script and received a 'successfully added to the registry' message.
    I ran JRT and got the log and rebooted.
    I reran Hitman (only remaining problem was Ask.com - deleted - and saved a log.

    Now I have to figure out what happened to the functionality of the MS Office programs and I'm running the MS fixes as I type this.

    Check out the logs and let me know if I have any hidden problems.

    And Thanks again for your help and patience.
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Delete the Ask.com item in Hitman. For assistance with Office issues, post in the software forum.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds