Malware Problems run readme but still probs

Discussion in 'Malware Help (A Specialist Will Reply)' started by Bassman, Jul 18, 2008.

  1. Bassman

    Bassman Private E-2

    Hi hopefuly someone can help.
    My friends pc recently got attacked by som malware which put virus alerts on her pc, with popups and restricted all the administrator accounts so they couldnt do anything but unplug the pc.

    I have gone through the process of cleaning the pc with all the malware tools suggested inth read me first post and think the majority of the Malware hass been cleaned hoewver, the VIRUS ALERT message where the clock is still exists, and the accounts are still restricted (with some kind of group policy I presume).

    Origionally before cleaning I created a new admin user and this was restricted, now after cleaning an administrator account which is newly created is ok.

    I will attatch all the relevant logs etc from the readmefirst process.
    If anyone can help that that will be great.

    p.s. there are 3 sas logs as I have run it 3 times.
    the other logs ill post shortly.

    Regards.
     

    Attached Files:

  2. Bassman

    Bassman Private E-2

    Rest of logs.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What happened between the three SAS scans?

    Please uninstall one of these:
    McAfee VirusScan Enterprise
    Norton Internet Security

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now tell me what malware problems you may still have.
     
  4. Bassman

    Bassman Private E-2

    Hi TimW, thanks for your help and speedy reply.

    Firstly there were multiple saslogs as I had a really hard time getting things installed and run, the first one was as default downloaded definitions, I then downloaded the latest updates and manually updated, started to run for the second time and realised I had left it on default settings, cancelled the scan, ammended the settings then reran the full scan.

    I have run the steps you have asked.

    the Malware problems I still have mainly relate to the 2 origional Users I had set up (Bob and Emma).
    They are set up as administrators but their accounts have been locked down i.e. cannot access the control panel, cannot see the fixed drives, no run cmd, ctrl alt del does not work to name a few.

    There is also a virus alert message in the clock window.

    there were a lot of internet access problems like unable to visit certain sites and I couldnt get Norton to register or update (this seems to be ok now but I have only tried a couple of sites and a quick virus update) I will continue to check internet access and update post if neccesary.

    Again thankyou very much for your time and help.

    Bassman
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to run SAS and MWB's on both those accounts. Then go back to the administrator account (or the user with admin rights) and run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.

    Attach the scans marking them as each user account plus the new MGLogs.zip.

    What does the icon look like and what happens if you click on it?
     
  6. Bassman

    Bassman Private E-2

    Hi TimW, thanks for the reply.

    Finally got through all the scans.

    Here are the logs for Emma along with the zip for you to review, I will post the Bob details in the next post.

    The system looks pretty clean, all admin has been restored, the Virus Alert msg in the clock window has now gone.
    Internet access seems to have been restored.

    So fingers crossed :)

    Bassman.
     

    Attached Files:

  7. Bassman

    Bassman Private E-2

    Bob account.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    More to do:

    From the MGLogs (assuming this is from the Emma account) ....first To Disable Spybot's TeaTimer

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it(Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Use windows explorer to find and delete:
    C:\Malwarebegone

    Then please delete everything you can in these folders:
    C:\Documents and Settings\Emma\Local Settings\temp\
    C:\WINDOWS\TEMP\

    I should also see a MGLogs from the Bob account.
     
  9. Bassman

    Bassman Private E-2

    Here are the log files from the Bob account.

    I havnt run through the latest set of tasks, wanted to give you the Bob logs first.

    I am going through the tasks as set out in your last post now and will post when completed.

    p.s. Just to let you know I have installed the latest Java 6 update 10.
     
  10. Bassman

    Bassman Private E-2

    I guess it would be a good thing to attach the logs.
     

    Attached Files:

  11. Bassman

    Bassman Private E-2

    All tasks on Emmas account has been completed.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Remove this also from Emma's account:
    C:\Malwarebegone

    I want you to run this on each account:
    Run thisDisable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Then run this on any admin account:
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Tell me if you are having any other problems.
     
  13. Bassman

    Bassman Private E-2

    Thanks TimW, your a star!

    Everything seems back to normal now.

    What of the below installed programs do you think is worth keeping?

    SuperAntiSpyware
    Malwarebytes
    Combofix
    CCleaner
    MGTools
    ATFCleaner

    Regards

    Bassman.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    MalwareBytes, CCleaner and ATFCleaner. :)

    If you are not having any other malware problems, it is time to do our final steps:

    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)

    * Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    * "%userprofile%\Desktop\combo-fix" /u
    o Notes: The space between the cf" and the /u, it must be there.
    o This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    * Delete the C:\cf folder from combofix.

    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    8. Go to add/remove programs and uninstall HijackThis.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Vista, Windows XP or Windows ME, do the below:

    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds