Cleaning Uncle's Computer... long distance.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Miss M, Jan 25, 2010.

  1. Miss M

    Miss M Private E-2

    Hi! My uncle's computer was infected some time ago... at least a couple of years. He pretty much hasn't used it since then, having no idea what to do about it. He used to use NetZero for minor internet access and e-mail, but now is unable to connect at all. Around the time (not sure how close) his computer got infected, he had completed his first online purchase and had his identity stolen.

    My mom is staying with him for a while to take care of things after the death of my grandmother. I sent her with a CD with all the Read & Run programs with their updates. This was before the ComboFix bug; around January 3 or 4. I should also note that I completely forgot to provide the Windows Recovery Console on the CD. We forged ahead with the ComboFix scan without it. My mom mistakenly sent me a registry backup instead of the ComboFix log, so I will upload it in a followup post as soon as I have it.

    Meanwhile, I am attaching what I have, which is SAS, MB, and MGTools. RootRepeal would not run, and did something to the computer that required a chkdsk to repair. Please forgive me the vagueness of my notes; it was a hectic time, and I didn't write things down like I normally do.

    Thank you in advance for any assistance you can give me with this computer! It would be nice to get the thing up and running right again. :)
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in my next post.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Your Uncle needs to upgrade to at least SP2 if not SP3 and should be running IE8. (I understand he uses NetZero though)

    1. Important Notice: A new version of SUPERAntiSpyware is available.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later.

    2. Open up Malware Bytes > let it update > run a new scan > fix all it finds > and attach the log it produces into your next reply here.

    3. The version of MGTools that you have is current, but I would like for you to download a fresh copy anyway, ensuring that you save it and run it from your C Drive. We will run it in a step further down, simply download it for now:

    Now go to this MGTools and download the new version of MGtools.exe. Overwrite your previous MGtools.exe file with this one.

    4. Ad-Aware SE Personal <--- Outdated and useless, I suggest it is uninstalled.

    5. If your uncle finds his computer isn't running too smoothly then this could be part of the reason why:

    XP needs minimum 500MB to run and it needs 1GB to run smoothly. He might consider a memory upgrade, especially since he has no anti virus installed currently and once he does so, he will find he has even less resources available.

    6. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.


    7. Delete the copy of combofix that you have and download to the desktop the current version: (But do not run it yet! And be sure to attach the log from the old version that ran)

    Combofix

    8. Use Windows Explorer to find and delete the below bold file:

    9. Now run the new MGTools.exe that you have on your C Drive and attach the C:\Mglogs.zip file that will be created by running this and also attach the logs from running combofix (the old version you had) and the logs from MBAM and SAS.

    10. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  4. Miss M

    Miss M Private E-2

    Hi, Kestrel13! Thank you for your quick response! :)

    It's going to be a bit slow to work with me, because I'll need to burn disks to send to my mom, and then she has to get the logs to someone to email them to me. I'm not sure right now what's keeping the internet connection down, but hopefully we can figure that one out soon!

    I know that with at least SAS (or is it MB?), the manual updates are significantly behind the live updates. But until I can fix the internet connection, that's the best I'll be able to do. I hope that's okay. I'll work on that connection as a top priority.

    I had no idea that Ad-Aware had fallen behind like that. If it's of no use, we'll certainly remove it.

    I had not even looked at his memory yet, and I'm amazed it has done as well as it has on that little memory. We'll be talking to him about an upgrade! :) I'll also put SP2 and SP3 (or do I just need SP3?) on a disk and send it off. And IE8... and Firefox! But if he insists on using IE, at least he'll have IE8. I hadn't noticed yet that he was running SP1... I was just trying to get the infection off first.

    I forgot to tell you that there is no antivirus installed because it did have Norton on it, and we removed it pretty much first thing. I was hoping that would restore the internet connection, but it didn't. I sent copies of Online Armor firewall and Avast antivirus to install after we were finished with Combofix... I understand OA and Combofix don't play well together. ;) Oh, and I need to get the Recovery Console on the disk too.

    I saw the keygen on there when I had a quick look at the computer in December! I knew my uncle hadn't put it on there, so I figured its presence was a symptom of whatever virus the computer had. I didn't know if I could just delete it or not, so I didn't. Glad we can go ahead and do so.

    Did you see any infection that got cleaned off?

    I will get back to you as soon as I can, but it could be a week or so. I'll try to get the internet connection up so we can proceed a bit more quickly. :) Thank you so much!
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes let's leave that until last, and deal with malware related items first.

    I wasn't seeing an awful lot to do, no. But those logs were old and I would need to see new logs for the new status of the machine and also new logs to see if the small fix I gave above actually worked. So I understand it's going to take you a while but I will be here waiting :)
     
  6. Miss M

    Miss M Private E-2

    Just letting you know, I'm just waiting for my mom to find a computer to email the logs to me! I'll post again as soon as I have them. :)

    The computer is not being actively used in the meantime. At most, my mom plays solitaire on it sometimes.
     
  7. Miss M

    Miss M Private E-2

    Okay! Here are 4/5 logs, I'll post the 5th one next.

    I had forgotten, we did a couple of scans before we decided to do the Read & Run... I know one of the scans was with Spybot S&D... I know it cleaned some stuff off, but the log folder was empty, so I don't remember what exactly... I seem to remember looking one of them up and finding out it was some sort of trojan.

    At any rate, here is the first Combofix log, without Windows Recovery Console installed. Also, you will find the second Combofix log, before which my uncle found his XP disk and we installed the Recovery Console.

    There are the SAS and MB logs, and I will post the MGtools log next. These are all from Saturday and Sunday, I believe, except for the first Combofix log. We haven't removed Ad-Aware yet, and we need to remove the keygen still, I think. We were in a hurry to get all the logs Saturday so she could give the logs to a friend Sunday so he could send them to me. Then it turned out they couldn't go to church, so she wasn't able to get the logs to someone.

    Thank you for your patience! MGtools log below. :)
     

    Attached Files:

  8. Miss M

    Miss M Private E-2

    MGtools log... I've also priced memory for my uncle's computer, so I'll be hearing about that soon. I sent an XP SP3 disk (apparently you don't have to install SP2 first, you just have to have SP1) and IE and Firefox. I have a feeling the IE is just a downloader that needs an internet connection, though, which he doesn't have yet. We'll see. I've had lots of trouble installing IE8. It's failed quite a few times for me, for no apparent reason. I think I still have one computer I haven't been able to get it on. Do you know where the link is where you can download the entire thing? I know you can do that somewhere, I just can't figure out where it was.

    Thank you again!!! :)
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let's deal with the malware removal before anything else now. :) Any other non malware issues can be worked out and resolved in the software forum after we are done here.

    You are most welcome.

    Now then, we'll start with this:

    1. Before we continue I would like for you to ensure that MGTools.exe is indeed directly on your C Drive and not in any other location, such as the desktop.

    2. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DirLook::
    c:\windows\system32\bits
    
    Registry::
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    3. SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind 
      qmgr.dll
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt

    4. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix. & the log from SystemLook.
     
  10. Miss M

    Miss M Private E-2

    Okay, we'll get on this!

    Is it okay if we try turning on Windows Firewall and installing Avast, and then attempt to figure out what is up with the internet connection? That way, my mom could download this directly, instead of waiting for a disk. And she could email me the logs without burning a disk and going to Kinkos.

    We weren't going to do IE8 or SP3 yet, I was just talking too much. ;) I'm good at that.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes. :)
     
  12. Miss M

    Miss M Private E-2

    Wow! New avatar! :)

    I think I'm turning into your worst nightmare... a good bit has changed. I sent the files my mom needed, only to discover Combofix was out of date. I sent her a new copy. Meanwhile, we tried to fix the internet connection. Avast would not install, so she tried Online Armor (We coudn't find Windows Firewall, or the Security Center -- SP1 didn't have it! I didn't remember that!). It produced an error and rendered the computer incapable of completing booting.

    I had her go into safe mode and remove it. It hadn't completely installed, so she couldn't uninstall it. Reluctantly, I had her simply delete the folder in which it was contained, and then run CCleaner. Thankfully, that worked, and the computer booted.

    I found out that the problems we were having were due to the computer being only at SP1. So, with a sigh of "Forgive me, Kestrel!" I had her upgrade to SP3. It went perfectly, but, of course, that means the configuration has changed.

    Then my uncle finally divulged that his internet connection problems started right after something had happened -- like a storm or something -- FOUR YEARS ago! So I concluded the modem had been fried, and had died saving the computer itself. I had a computer in the past that didn't have such a considerate modem.

    I happened to have an old modem on hand, and decided to go through the old memory I had as well. Turned out I had a stick identical to what he already had. I talked my mom through installing the memory and the modem. The computer recognizes the memory (so now it has 512MB), and, even though it really said it wanted a disk for the modem, the modem is working. However, we discovered at this point that not only had the modem been fried, the phone line itself has too much noise on it (probably as a result of that same 4-year-old event) for the modem to hear a dial tone. So now we're waiting on the phone company.

    (In all fairness to my uncle, he had been caring for his mom for the last several years as her health slowly declined, so when he started having phone trouble and internet trouble, it got put onto the back burner... as long as the phone still mainly worked, it didn't get dealt with. It's only getting dealt with now because my grandmother passed away, and my mom is over there helping him get everything taken care of.)

    So, with all that's changed, I don't know if the new logs are very useful to you, but I will attach them anyway. Systemlook gave us an error message... what was it... oh drat. Still gave us a log, though.

    Please don't kill me! :duck
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Fcopy::
    C:\WINDOWS\ServicePackFiles\i386\qmgr.dll | c:\windows\system32\qmgr.dll
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  14. Miss M

    Miss M Private E-2

    Hi! We came up with a way to get this turned around faster. I have the Combofix log, but I forgot to have my mom do MGtools before she left to send it to me. So I'll upload that one hopefully tomorrow.

    I'm really sorry about all the craziness that happened in the last couple of weeks. I hope I didn't do too awfully bad. :-o

    I'm glad it looks like the infection he had was probably cleaned off before I even started the Read & Run. I like it when it comes off easily.
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, please do.

    SAS removed threats and also the c:\windows\system32\qmgr.dll was infected. I used one tool to locate another safe uninfected copy and replaced it using combofix in my last script.
     
  16. Miss M

    Miss M Private E-2

    Oh, okay... I didn't realize SAS had found anything. I could see that we were replacing qmgr.dll, but I had no idea why! :)

    Thank you so much for all your help with this computer, and your extreme patience with me! I've been on here a few times for help cleaning up friends' computers, and I promise I'm not normally this much trouble! :-o

    Here's the MGtools log zip file. Mom's renting a computer at Kinko's to transfer back and forth. Hopefully, we can get the phone line fixed soon.
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You've been no trouble at all. :)

    Those logs are clean I am pleased to say. Time to install some anti virus. A list of reccommended is included in the anti virus section in the last link in my final steps below:

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  18. Miss M

    Miss M Private E-2

    I appreciate that, I was sure that at some point in there, you were ready to kill me. :-D

    YAY!! It's so great to have this computer clean again!! We worked through the rest of it, and ran CCleaner, and Defraggler. The machine is running so smoothly now, it's like a new computer!

    My mom says to thank you so much for helping us and being so patient, and that it's nice to know there are people out there like you who are willing to help others get their computers running again!

    We'll be installing Avast and Online Armor now, and Firefox. That should go fine this time, since the computer is at SP3. Eventually, we'll be working on some real upgrades to the hardware... maybe I'll build him a new computer. But whatever happens, I'll be able to transfer all his stuff from this drive to a new one, without worrying about it being infected! :cool
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    hehe... not at all... I have bucket loads of patience and you worked with me great! :)
    That's good to hear.
    You tell her she is welcome.

    Take care :)
    Kes
     
  20. Miss M

    Miss M Private E-2

    You take care too! :)

    Marilyn
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds