Malware cleanup

Discussion in 'Malware Help (A Specialist Will Reply)' started by cuddlepuppy, Jan 21, 2009.

  1. cuddlepuppy

    cuddlepuppy Private E-2

    Hi, my name is Eric and I'm a minor geek. (like an admission, like AA) :) It seems I am the "puter fixer" for my church, and I am fixing two right now, AND educating them on proper computer care. On the first one, I did all the "R&R me First" I don't have an AV yet installed (it is also not connected to the internet). Attached are the 4 logs, what should I do now? and what prog's should I leave running (ie:SupAntiSpy, MalWareBytes, etc.) I use Avast on mine and like it. I am a minor geek, I salute to You "Major Geek"
     

    Attached Files:

  2. cuddlepuppy

    cuddlepuppy Private E-2

    Zip Log
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This question will be address in the link in my final instructions below. Remember that the free versions of SUPERAntiSpyware and Malwarebytes have no active protection. They are just after the fact scanners.

    You have a little more minor cleanup to do. The cleaning procedures have already removed you malware.

    First you have an incomplete uninstall from McAfee which must be fixed. So run the below and then reboot:

    McAfee Consumer Product Removal Tool


    Now uninstall the below software:
    Viewpoint Manager (Remove Only) <-- should have been uninstalled in step 1 of the READ ME
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    O2 - BHO: (no name) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - (no file)
    O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)

    After clicking Fix, exit HJT.


    Now if you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  4. cuddlepuppy

    cuddlepuppy Private E-2

    Well wouldn't you know, after all this both computer owners are upgrading HD's and ram.
    This one is fine. when I finish scanning the other I'll post the final logs for this one, then post the first logs for the other one in a seperate post.
    That sounds confusing LOL. But I want both computers free of malware before I ghost into new HD's. They both have data they don't want to lose.

    I do thank you for all this help.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. This computer's logs were already clean which is why I gave final instructions.
     
  6. cuddlepuppy

    cuddlepuppy Private E-2

    It seems to have lost "User Accounts" in the control panel. they show up at startup (with no required passwords).

    What happened?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nothing as far as I saw. The below accounts showed in your logs:

    Code:
       Yes    | Administrator
       Yes    | Davene Burks
              | Guest
              | Julian Burks
              | Malachi Burks
       Yes    | Richard Burks
              | Whitney Burks
    The Guest account should be disabled since it is a security risk. Also note, when you say "no passwords required" do yo mean you set them this way or do you mean that they all had passwords and now they do not? Nothing in our scans touch any of these settings. What the malware may have done, I cannot guarantee.
     
  8. cuddlepuppy

    cuddlepuppy Private E-2

    No guest account shows, R/D/and admin are admin accounts (I was going in to fix this just now). J/M/W are passworded and still are. Just don't have access to user accounts in control panel. I think it was still there before I put in this bigger HD (I use WesternDigitals program as they were both WD Hd's) went from 80g to 250g I still have the 80g untouched, just pulled it out)
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like you may have disabled those other accounts which is really a topic for the Software Forum, but try the below.

    Click Start, Run, and enter lusrmgr.msc and click OK. This should open the Local Users and Groups window. Select Users in the left column. Then in the right window pane, look at each user name that is not showing up. Does it have a red x on it? If so, it is disabled. Double click on the user name and uncheck the Account is disabled check box. For the Guest account, make sure you actually put a check in the Account is disabled check box to truly disabled it. Then reboot and see if there is any change.
     
  10. cuddlepuppy

    cuddlepuppy Private E-2


    Not doable, I get this message,
    "This computer is running Windows XP Home Edition. This snapin may not be used with that version of Windows. To manage user accounts for this computer, use the Users Account Tool in control panel"

    I put the 80g HD back in and it still has the same problems. It also won't ctrl-alt-delete.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run the Windows Registry Editor and navigate to the below registry key:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList

    Do you see any of those user accounts listed here?
     
  12. cuddlepuppy

    cuddlepuppy Private E-2

    Nope, here's what I have:
    aspnet
    helpassistant
    IUSR
    IWAM
    netshowservices
    sqlagentcmdexec
    tsinternetuser
    vusr_
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I may be sending you to the Software Forum with this soon since it is not a malware problem.

    If you click Start, Run, and enter control userpasswords2 and click OK. Do the missing user accounts show up here? If so, select one and click Properties then click the Group Membership tab. Which Group is the user account shown in?
     
  14. cuddlepuppy

    cuddlepuppy Private E-2

    Yes they showed up there. All user's "group" listings are the same in "properties". I have no idea what ASPNET is, it has "user" access, it was the only one that showed up in "regedit" and it doesn't show up anywhere but regedit and "control userpasswords2".
    Though this isn't your or my fault, didn't these window burps (ie: user accounts, no Ctl-Alt_Del, no "search" capability) happen during the malware removal? Wouldn't logic dictate the fix would be here? I do appriciate your help with this, I am just trying to save thier data and a Windows reboot.

    Thank You
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but what are they?

    Normal. It is Microsoft related.


    I don't know that they occurred here. Based on what was fix here, it has nothing to do with what we have done. They appear to indicate registry settings changes that could have happened at anytime. Also if anyone has been running anykind of registry cleaning or defragging, you are immediately going to be told to work it outside of the Malware Forum since we do not recommend using any tools like this. I'm not saying you ran any. I'm just making a general statement.

    What exactly do you mean by "not CTRL-ALT-DEL"? What happens? Does it happen on ALL user accounts? Does it happen in safe mode?

    Not if it is just registry settings that we cannot see during malware removal procedures. It is best to try in get more general Windows help in the Software Forum since the related keys are more than likely things we never look at.

    Huh?
     
    Last edited: Feb 1, 2009
  16. cuddlepuppy

    cuddlepuppy Private E-2

    {delineates me replying}

    "I am just trying to save thier data and a Windows reboot."
    {they have many files (She's a principal at a grade school) and programs installed/saved. and save myself the slow proccess of installing a "Dell WinXP" I should have said reformat?}

    My wife says I can be very "not detailed" sometimes. And I in no way am angry or pointing fingers (I mean this puter came to me "ToBeFixed") Just curious. And you guys are very helpful. Thank You again!
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are going to format anyway then what are we trying to do? Just save the data you want to save and then do your reinstall.

    There is nothing we can help you with in this forum anyway since you are not having malware problems.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds