Friends Desktop

Discussion in 'Malware Help (A Specialist Will Reply)' started by thedon01, Nov 30, 2013.

  1. thedon01

    thedon01 Corporal

    I'm trying to help a friend fix her desktop and i came into a problem when removing malware infections.

    Specs:
    HP Pavillion p6230f desktop
    AMD Phenon II x4 820 Processor 2.8Ghz CPU
    1 TB WD Green Caviarwith 860GB Free
    8GB RAM
    Windows 7 Home Premium 64bit

    What I've done:

    1. Initially when i received the PC i notived an absurb amount of bloatware, so i removed nearly 60 unwanted programs (including 2 virus removal programs, mcafee & notorn) via revo uninstaller.

    2. The computer hasn't been used in a while and was in major need of windows updates, approx 100 different updates which i did.

    3. Initials scans
    (a). with Eset Scanner (no longer installed) found 4 infections, 3 of which were successfully removed.

    (b). MBAM scan found another 4 infections which were successfully removed.

    (c). AVAST scan found 207 infected files but the program froze and crashed upon removal. This dilemma brought me here.

    4. Opened Hidden Files and Folders

    5. Proceeded with CCleaner

    6. Disabled UAC and restarted

    7. Ran Rogue Killer, MBAM, TDSS Killer, Hitman Pro, and MGTools from desktop. All logs are attached

    Thank you in advanced for your assistance!!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - (no file)
    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - (no file)
    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
    O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe (file missing)
    O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\Windows\system32\mfevtps.exe (file missing)

    After clicking Fix, exit HJT.


    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Services
    McAfeeFramework
    mfevtp
     
    :Files
    C:\Program Files (x86)\McAfee
    C:\ProgramData\McAfee
    C:\ProgramData\Norton
    C:\ProgramData\Tarma Installer
    C:\Program Files (x86)\Common Files\Symantec Shared
    C:\Windows\TEMP\*.*
    C:\Users\Dave\AppData\Local\Temp\*.*
     
    :Reg
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{36D7F151-C479-461E-BBDD-418A122AAACE}]
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{52F4DFA4-78BE-470A-8BBF-8327EC8D1D52}"
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{36D7F151-C479-461E-BBDD-418A122AAACE}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{FEB6F089-8287-476B-A3D7-3847E820BB1E}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{80922ee0-8a76-46ae-95d5-bd3c3fe0708d}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Conduit]
    [-HKEY_USERS\S-1-5-21-2859958999-484422056-689598667-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXTlog
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. thedon01

    thedon01 Corporal

    thanks chaslang!

    i followed your instructions to the letter and have attached all the logs you requested.

    i have three questions:

    1. while running the getlogs.bat file i had a "steelwerX WhoAmI app has stopped working" window appear. i chose to close it, but not sure if that is an issue. Either way i wanted to let you know and ask, is this something i should be concerned with?

    2. How can i learn or where do i begin to learn how to read and decipher these log reports so i can either assist on this site or refrain from clogging up traffic with any issues i may come across in the future? Is a degree required or is this something a person can learn on their own?

    3. are there any other steps i need to take from here?
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean, but you need to stop using MSconfig to control startup processes. You should be in Normal Startup mode. See Dealing with Startup Process

    Not a problem. The command prompt window from MGtools even showed this to you.


    See this >> Becoming A Malware Forum Helper
     
  5. thedon01

    thedon01 Corporal

    i went ahead and read the link you provided in regards to "dealing with startup processes".

    i'm going to assume that i can use C:\MGtools\analyse.exe as you referred to it previously as being hijack this.

    i've noticed there are a lot of programs under "normal startup mode" that i don't want running but not sure how to actually remove them via hijack this. Any advice?

    I've also noticed that when i run a scan only in hijack this i find certain results that have (missing files) at the end. Is that normal?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That would be for permanent removal. Not recommended if you may want to reenable startup items at some time.

    You need to be the one to decide what you need and do not need. No one can know better than you what you use on your PC. A basic rule of thumb should be "if you can run it only when you need it and it works properly then you don't need to have it run at startup and always be running for no reason at all."

    Yep! HijackThis is a buggy outdated tool with lots of misleading info which is why only experts should be interpreting logs. Also it is the least important tool in our tool boxes.
     
  7. thedon01

    thedon01 Corporal

    so
    msconfig = to temporarily stop a program from loading
    fix a result in hjack this = permanently remove

    am i correct in this understanding?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! MSconfig is to be used only for temporary debugging of problems. It is not a long term startup manager and improperly using it can cause problems as noted in Dealing With Starup Processes.
     
  9. thedon01

    thedon01 Corporal

    okay im getting it now. Now what do you do when you want to stop a program from running, but can't uninstall it, yet you don't want to totally lose the program, just don't want it to start with windows?

    it appears that you suggest using spybot S&D or Autoruns for disabling programs with the option of enabling them in the future.

    So we have:

    MSconfig = temporary disable for debugging purposes

    Hijack this = permanently disable without the ability to enable in the future

    Spybot S&D, auto run/defender = enable/disable options per user's preference now and into the future

    Do i have it all correct?
     
    Last edited: Nov 30, 2013
  10. thedon01

    thedon01 Corporal

    i've tried using spybot and can't find a way to disable startup options. Windows defender's software explorer is removed from windows 7, tried to install startup cpl and can't find the program after installing.

    So im sort of stuck, any advice?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Forget Spybot. Use AutoRuns.
     
  12. thedon01

    thedon01 Corporal

    using autoruns now. i noticed many entries that are highlighted, under their image path it says "file not found".

    Is this something i should be concerned with?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nope! Likely dead registry entries and not a malware forum issue either. ;)


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  14. thedon01

    thedon01 Corporal

    thank you!! i appreciate your time and effort in assisting me. after following these instructions should i then hide hidden files and folders?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    If you follow all of them, that should already be performed when MGclean.bat is run.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds