Friend's computer clean now?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Miss M, Mar 23, 2010.

  1. Miss M

    Miss M Private E-2

    Hi, I'm back with another friend's computer! I know I am not finished with it yet; it is quite clogged and has leftover partial uninstalls and undesirable programs on it. I just need to know, after having finished the Read & Run, if it is still infected.

    I was advised by my friend's daughter when I received this computer that after about 15 minutes of being on, it would start putting up numerous cascading black windows that you could not stop. So instead of beginning immediately with the Read & Run, I put MalwareBytes (renamed) on a usb flash drive, transferred it to this computer, and then hooked up internet just long enough for it to update. I then ran a full scan. The following day, I updated and ran the directed scan in the Read & Run. I will attach both MB logs so you can get the full picture.

    McAfee was difficult to disable, and I wasn't going to keep it on here anyway, so I finally uninstalled it. I was told as well with the last computer I cleaned up that Ad-Aware is no longer a very effective tool, so I removed it while I was at it.

    When I tried to run RootRepeal, I got an error message: "Error: FOPS - Device Io Control Error! Error Code = 0x0000024, Extended Info (0x00000114)". After looking it up, it seemed that the problem stemmed from Vista not having current updates. So I updated Vista, installed SP1, updated that, installed SP2, and updated that -- it's now completely current! Then I ran RootRepeal again. This time I got "Warning -- Unrecognized partition type 6 (0x6)!"

    I was told also by my friend that she knew there was porn on this computer, the result of her teen son having a few friends over to grandma's (where this computer was) and going places they shouldn't have. I have not yet begun removing it. I just figured I'd disinfect it first.

    Thank you for any help you can give me! :)
     

    Attached Files:

  2. Miss M

    Miss M Private E-2

    RootRepeal and MGTools logs...
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please run SAS and MBAM on all user accounts.

    Then use window explorer to find and delete:
    c:\users\Abby\AppData\Local\Wnuxejoguxabok.bin
    c:\users\Abby\AppData\Local\Ssebewoteh.dat

    Attach any log that shows infection ( save with a user name ).

    Then, run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  4. Miss M

    Miss M Private E-2

    Hi, TimW! Sorry it took me so long! :)

    I ran the scans you asked for. There are four user profiles, and I am attaching the logs for the scans that showed problems. This will take me two posts. I thought it was interesting that the one thing found in both Hannah and John Wesley's profiles by SAS was found in Abby's folder.

    I deleted the two files you indicated, and am also attaching the new MGlogs.

    When I went into Abby's profile, Windows Defender came up with a warning about Trojan:Win32/Hiloti.gen!D - this is what it said:
    Category: Trojan
    Description: This program is dangerous and executes commands from an attacker.
    Advice: Remove this software immediately.
    Resources: process: pid:4524
    process: pid:5152
    process: pid:3320
    regkey: HKCU@S-1-5-21-2786847773-3535864445-686843180-1002\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\Etapon
    runkey: HKCU@S-1-5-21-2786847773-3535864445-686843180-1002\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\Etapon
    file: C:\Users\Abby\AppData\Local\ujulihiwekesu.dll

    It says it successfully removed it. Windows Firewall also came up and said it had blocked BitTorrent. I guess that makes four file-sharing programs I need to ditch.

    The computer is booting much better now! Once it gets into a profile, it takes a while, because a whole bunch of stuff loads automatically. I need to go through and make these things manual. It's loading Skype, MySpace IM, Yahoo messenger, Kodak EasyShare, and Weather Desktop. But I can most definitely tell the difference. ;)
     

    Attached Files:

  5. Miss M

    Miss M Private E-2

    Here are the rest of the logs. :)
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks much better. We have a few reg keys to remove, but other than that, you look clean.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    You do have a few things loading at startup, so I would suggest you use this to control them:
    Startup_CPL

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  7. Miss M

    Miss M Private E-2

    Thank you, TimW!! It worked just fine! ;)

    Sorry for the long time, I'm also packing to move! I'm insane, working on this computer, but she's a good friend, and her daughter needs this computer for school this coming year, so, whaddya do? :)

    I'll go ahead and do the finishing steps now.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are quite welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds