Malware or Hijack!?

Discussion in 'Malware Help (A Specialist Will Reply)' started by bozner, Jan 17, 2009.

  1. bozner

    bozner Private E-2

    Hello! Hope you can help....

    I followed all steps in the Vista Cleaning Procedure (http://forums.majorgeeks.com/showthread.php?t=139681), however I'm still having problems.

    Problem - Logged in under my sons account it appears as if the computer is being controlled remotely, attempting to create shortcuts and utilizing right clicks. This appears to happen whether connected to the internet or not. My account is admin and I do not seem to have the issue. I don't believe my other machines on the network are affected, but they are all turned off just in case (2 other desktops, 1 laptop, 1 whs).

    I am not sure what was happening at the time, but I believe he was playing Call of Duty World at War. I have the McAfee running and up to date and he can't surf to many sites (parental controls as he is under 12). I have a Linksys wrt600n and thought I had it locked down...so I'm not sure how this happened.


    I am running Vista 64 bit, so I had a challenge with the combofix and mbtools. All results are attached as instructed (see next post for other two).
     

    Attached Files:

  2. bozner

    bozner Private E-2

    Here is the other attachments per directions. Combofix did not run properly.

    Thank you again!
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Why? What exactly happens? MGtools did not run properly either. Have you followed instructions for Vista properly? You must shutdown UAC as stated and you must reboot afterwards. Also you must use Run As Administrator. Please make sure you have done this and then also shutdown your protection software. Then try running ComboFix and MGtools again per the instructions. Tell us exactly what happens if something does not work. Watch for error messages like those given on the Using MGtools page.
     
  4. bozner

    bozner Private E-2

    First, thanks for the reply, most appreciated. I did have UAC turned off. I think my challenge was disabling Mcafee - i shut down the services but maybe that did not do the trick. I'll try to shut it down and try both again and re-run both of those utilities.
     
  5. bozner

    bozner Private E-2

    MG tools ran - log attached. Combofix states that it won't work on Vista - screenshot attached. Thank you again! db
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually this is not true and it is not what it is saying. ComboFix supports Vista. It just does not support any x64 versions of Windows like many other programs do not support it. Even MGtools does not fully support x64. The logs produced are limited.

    The logs that you have attached do not show any malware problems. You do need to uninstall the below as requested in step 1 of the READ & RUN ME

    Java(TM) 6 Update 7
    Viewpoint Media Player

    Then you need to reboot and after reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Other than that, I suggest you try to provide much more specific info on your problem and post in the Software Forum. If your PC was disconnected (cable unplugged) from the internet then there is no way that anything was remotely controlling it.......unless you are on wireless and then you would need to shutdown the wireless connection to be disconnected.
     
  7. bozner

    bozner Private E-2

    Thanks for taking the time to review the logs. I must have missed the viewpoint and java items...sorry. They are corrected now. Problem of 'remote control' still exists but only on one account, so I guess I'll simply remove that account and keep my eye on things. Thanks again for your help!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is this the account you attached logs for? And I repeat, it cannot be a remote control issue if it happens while you have physically disconnected to cable to the PC.
     
  9. bozner

    bozner Private E-2

    It occured with and without being connected to the internet. I've since deleted the account and all seems well. The logs were not from that particulate account as I could not stay on the account long enough to run any utilities. Again, thanks. I'll be back if the problem re-occurs.

    ps...i've dealt the malware issues before and have never had to 'reach out'..this was about the oddest thing I've ever encountered.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Then the logs would not be as useful since they would have to be from the problem account.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  11. bozner

    bozner Private E-2

    Followed all of the instructions...thanks again for all the help. No longer using IE on any of the PCs or laptops. Working on all the other items tonight. Can't thank you enough for the help.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds