Find & Remove a hidden monitoring software

Discussion in 'Malware Help (A Specialist Will Reply)' started by girlinajar, Apr 17, 2009.

  1. girlinajar

    girlinajar Private E-2

    I have a friend who suspects that their ex of several years had put a monitoring software on the PC they 'inherited'. They are getting weird things happening on it with the ex's name being referenced etc. They never had it "cleaned" and have called on me to the rescue. I have never dealt with this before. Re-installing windows would be best I'm thinking. Not sure that's what they want to do with backing up files etc. Any suggestions on something that can reveal anything hidden? Preferably freeware.
    Thanks in advance!:)
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!


    Please follow the instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.

    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First.
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide


    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. To avoid addtional delay in getting a response, it is strongly advise that after completing the READ & RUN ME you also read this sticky Don't Bump! It Only Hurts You!!!. Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. girlinajar

    girlinajar Private E-2

    Malware removal only MGTools will run!

    No idea what happened but they waited too long to get it fixed. PC has been shutting down, programs won't run. Some Spyware 2009 is popping up I'm thinking this is part of it. I can't get Malwarebytes to run; can't get SuperAntispyware to even install. :cry Please help, beyond me right now! I have attached the logs from HijackThis.

    Thank you Thank you in advance!
     
  4. girlinajar

    girlinajar Private E-2

    Did not find TDSSserv.sys.
     
  5. girlinajar

    girlinajar Private E-2

    OMG finally getting superantispyware to run changing names using alternate scan so we will see already found rootkit / uacfake and adware vundo. I will post again later.
    Thanks again!
     
  6. girlinajar

    girlinajar Private E-2

    Here are all my logs. PC isn't backup'd as of right now(friends livelihood on it) so I am hesitant about running Combo fix.
    Thanks in advance!
     

    Attached Files:

  7. girlinajar

    girlinajar Private E-2

    I'm not bumping:-o

    New happenings! :cry
    AVG is now bringing up WIN32/cryptor threat detections and at 15 instances are being "caught" at that time with most being fixed others being quarantined. It is also finding Trojan Generic and rootkit/gen.

    Thanks!
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did not pay attention to the instructions!! You are running two AV programs:
    AVG Free 8.5
    Avira AntiVir Personal - Free Antivirus
    Uninstall one now!

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    I strongly advise you to cleanup your Desktop. Remove everything but links to run programs. Do not download and save programs here and definitely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    -
    Now run Ccleaner to clean out only temp files and nothing else!

    Then go to these folders and make sure you empty whatever is left ( you will not be able to remove items from today's date):
    C:\WINDOWS\Temp\
    C:\Documents and Settings\Owner\Local Settings\Temp\

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds