Malaware blocked laptop

Discussion in 'Malware Help (A Specialist Will Reply)' started by heath630, Jun 27, 2012.

  1. heath630

    heath630 Private E-2

    One of our family's laptops has been blocked by an e-crime pop-up (no-one is admitting blame), which apparently only happened to start with going on the internet but now comes up on start-up — hence my involvement.

    I have attached the requested logs etc after running the requested programmes. Anyone help to bring the accusing glances in our household to an end?
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member


    Java(TM) 6 Update 22
    <--- uninstall outdated java.


    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\Users\AH\AppData\Roaming\er_00_0_l.exe
    C:\Users\AH\AppData\Roaming\er_00_0_l.exe
    
    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "Update"=-
    "Application Restart #0"=-
    "Application Restart #1"=-
    [HKEY_USERS\S-1-5-21-577396084-863450808-3845464523-1002\Software\Microsoft\Windows\CurrentVersion\run]
    "Update"=-
    "Application Restart #0"=-
    "Application Restart #1"=-
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
    "NoActiveDesktop"=-
    "NoActiveDesktopChanges"=-
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


    Install the most current and up to date version of Java available here at the below link:

    Java Runtime 6



    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. heath630

    heath630 Private E-2

    I couldn't find any location for Java Update 22, this might be because I am running in Safe mode because the pop up is blocking my real access. Searched in the Start/Search programs and files for it but nothing came up.

    I ran OTM as requested (should I have done that?) and here is the log:

    All processes killed
    ========== FILES ==========
    File/Folder C:\Users\AH\AppData\Roaming\er_00_0_l.exe not found.
    File/Folder C:\Users\AH\AppData\Roaming\er_00_0_l.exe not found.
    ========== REGISTRY ==========
    Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Update deleted successfully.
    Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Application Restart #0 not found.
    Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Application Restart #1 not found.
    Registry value HKEY_USERS\S-1-5-21-577396084-863450808-3845464523-1002\Software\Microsoft\Windows\CurrentVersion\run\\Update not found.
    Registry value HKEY_USERS\S-1-5-21-577396084-863450808-3845464523-1002\Software\Microsoft\Windows\CurrentVersion\run\\Application Restart #0 not found.
    Registry value HKEY_USERS\S-1-5-21-577396084-863450808-3845464523-1002\Software\Microsoft\Windows\CurrentVersion\run\\Application Restart #1 not found.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoActiveDesktop deleted successfully.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoActiveDesktopChanges deleted successfully.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Alan H
    ->Temp folder emptied: 3963032 bytes
    ->Temporary Internet Files folder emptied: 27900856 bytes
    ->Java cache emptied: 217728 bytes
    ->FireFox cache emptied: 31825216 bytes
    ->Flash cache emptied: 19804 bytes

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Public

    User: UpdatusUser
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 170 bytes
    %systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
    %systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 753 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50333 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 749 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 61.00 mb


    OTM by OldTimer - Version 3.1.21.0 log created on 06282012_124848


    I then downloaded the latest Java Runtime 6 but again because I am in safe mode it would not let me install. So I came back on to update you. Is there a way to do this? And did I make a mistake in the first step? Apologies if I did.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No just continue on with the other instructions. :)
     
  5. heath630

    heath630 Private E-2

    Logs attached as requested.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member


    Code:
    :Files
    C:\Users\Alan H\AppData\Roaming\er_00_0_l.exe
    
    :reg
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\windows\currentVersion\Run]
    "Update"=-
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  7. heath630

    heath630 Private E-2

    Logs attached as requested.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    How are things running for you now? :) The logs look good.
     
  9. heath630

    heath630 Private E-2

    I was waiting to check until given the all clear - having now done so everything seems to be ticking along nicely. No sign of the pop up yet and hopefully not in the future.

    Many, many, many thanks for your help.

    For the future, can you recommend any further steps I should take to protect the laptop? I will be installing parental controls to prevent any future 'wandering' to sites that might pose problems - any good programmes for that? Also having seen the anti-virus etc protection on the laptop is there anything else you would recommend?

    All the programmes downloaded, should all these now be uninstalled and does the laptop need cleaned in any other way?

    Once again very grateful thanks to you and to Major Geeks website - it really is the saviour for the mini geeks like us.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are *most* welcome. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds