Malware on my friends comp

Discussion in 'Malware Help (A Specialist Will Reply)' started by MadEddi, Aug 3, 2006.

  1. MadEddi

    MadEddi Private E-2

    Either tomorrow or the day after i am going to have a look at my friends comp. I am certain it has some malware on it. He tells me, that whenever he tries to run Adaware or CounterSpy, it crashes(no BSOD) and restarts. The same happens when he tries to defrag.

    He is not connected to the internet at the moment, so i was wondering what the best thing(s) to do were. For example, is it going to be necessary to update his spyware if the malware attached before the software was out of date.

    He has Norton AV and firewall, i might suggest that i remove that for him, and replace it with AVG and ZA (free).

    Any tips or advice would be greatly appreciated. I will of course follow the standard malware removal instructions. I will keep a close eye on this thread so i can provide more info if necessary.

    TIA
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your best bet is to take over a CD with all the tools from the READ ME. Also get updates for the programs to like Spybot which can be installed manually since you have not internet. Make sure you are referring to the current READ & RUN ME since it recently changed. Run as much as is possible and do it in safe mode as requested (it may run better in safe mode).

    Attach the logs as requested and we will go from there.

    There could be other non-malware issues at play.
     
  3. MadEddi

    MadEddi Private E-2

    Great. That is more or less what i thought. Better to be sure.

    He did tell me that he ran CCleaner and as he is not that clued up on these matters i have a feeling he has deleted some important files.

    I will follow the READ & RUN ME to the letter as much as is possible.

    Many thanks.
     
  4. MadEddi

    MadEddi Private E-2

    AAAH I've just realised my friends comp has 4 or 5 user accounts for his whole family.

    This is gonna be fun ??? :rolleyes:
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If he deleted any Windows system files, running System File Checker (sfc /scannow from a command prompt) may help to restore them.
     
  6. MadEddi

    MadEddi Private E-2

    Unfortunately, despite all my efforts, i left one or two files off the disc i took to my friends comp. So all I have to present to day is, GetRunKey & ShowNew report files. Within the next 5-7 days i 'll go round with all the right software, and get the reports you want.

    I was not able to boot to safe mode, some system files have been deleted, don't know which. "sfc /scannow" got 1/3 rd of the way through and requested many files from boot disk, so although the comp has XP Home serial number on the side, the owner doesn't have original disc. Equals missing files not replaced and scan did not indicate what files needed replacing.

    However, i replaced the CMOS battery, hoovered the dust out of the inside and fan vents. Ran Adaware, Spybot and System Mechanic 6.

    It has stopped restarting, and appears to be significantly improved.

    So even though, in my haste i forgot to take HJT round and a couple of other files, these are the two info files i have for you.

    View attachment runkeys111.txt

    View attachment newfiles111.txt

    Can supply more info.
     
  7. MadEddi

    MadEddi Private E-2

    Have i uploaded the files wrong?

    Should also mention that his comp would not boot into safe mode.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have the PC set for selective startup with MSconfig & you have Spybot's Teatimer possibly being used. Both of these are items we ask you not to do in the READ ME. You must select Normal Startup and you must not use Teatimer.

    Also I see BearShare. This contains bundled malware. Uninstall it and don't use it anymore.

    Sun Java versions are out of date!


    What are the below files? Is it somekind of screen saver? I would delete them.
    C:\WINDOWS\Bobsaver.exe
    C:\WINDOWS\mickey32.dll

    Definitely delete the below files:
    C:\WINDOWS\NDNuninstall6_98.exe
    C:\WINDOWS\NDNuninstall7_14.exe
    C:\WINDOWS\NDNuninstall7_22.exe


    Other than the above, there are no other problems based on these logs! You need to get the correct Windows CD and get the sfc /scannow to finish running. This part, however, is not an issue for this forum.
     
    Last edited: Aug 12, 2006
  9. MadEddi

    MadEddi Private E-2

    Ok.
    I uninstalled bearshare for him, i think it was on selective start up because i turned some unneccessary applications off and forgot to leave msconfig on normal. Removing those files and completing(i didn't finish the sfc scan because it was taking a long time and malware removal seemed more important) the sfc scan shouldn't be a problem at all.

    Many thanks. Hopefully i won't have to post in this thread again.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well just a few other notes!

    This PC is seriously out of date with it's Windows updates and this is a major security risk.

    After removing all malware you should make sure the below steps are followed.

    Go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link (make sure your friend reads all of it and understands it too):

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds