This site serves as public record of my activities as Technology Coordinator for Southwest Arkansas Education Co-op. This site will be used in conjunction with travel forms, calendars, minutes and other pertinent data, when used together, to build a robust view of the services I perform which help my main office, participating school districts, statewide initiatives, and the furthering of K12 education in Arkansas.
Tuesday, November 15, 2011
As matter of record
PC had random pop-up windows, evident of traditional malware infection. As a matter of course, I fired up ComboFix to clear the infection. ComboFix ran for a time, but froze up the computer. i have seen this happen before, and the general "fix" is to reboot the machine and start ComboFix again. Did that. Froze up again. Not good.
I managed to get MalwareBytes installed and updated, then ran that on the computer. That program found one infection and supposedly cleaned it. Upon reboot, however, the machine exhibited the same behavior as before.
I noticed that iexplore.exe was showing up in the Task Manager as soon any user logged in, though the process was not found in the registry as part of any normal start-up locales. It occurred to me that I needed to delete the dllcache files, so I did. The program would still fire up on its own. I renamed iexplore.exe in the Program Files folder, but it would reappear in a matter of moments.
Upon the suggestion of a local tech, I installed Avast free and ran the Boot-up Scanner. That found several infections and supposedly cleaned them. However, upon reboot, the problem returned immediately.
After doing some research, I ran GMER with the suggested settings (see below) and the program found no altered files. I tried to run TDSSKiller but the program would never launch - just show a brief hourglass then do nothing. Even in Safe Mode, Killer would not execute.
At this point, I had spent almost the entire day on Monday and a good hour or so on Tuesday working on this. It was time to blow away Windows and reinstall. I saved the user's Favorites to a flash drive (or tried to. After Windows was reinstalled, the Favorites folder was not on the drive, even though the system had said it copied it. Must have been something with the infection).
I spent the next hour or so putting Windows back on, getting the computer into the Domain and installing our standard software (along with her printer software). When reinstalling Windows, I deleted *ALL* the listed partitions, then did a long format on the drive. Neither of those may have been required, but I wasn't taking any other chances. I was tired and ticked - not a good combination for infections.
*GMER suggested settings: UNCHECK Modules, Process, Threads, Show all, and Files. DO check IRP Hooks and NTAPI Registry scan
Monday and tuesday
Thursday, April 14, 2011
Thursday - Early Childhood Visits
Documents and Settings\UserName\Start Menu\Programs\Windows Repair\Uninstall Windows Repair.lnk
Documents and Settings\User Name\Start Menu\Programs\Windows Repair\Windows Repair.lnk
Documents and Settings\UserName\Start Menu\Programs\Windows Repair
Documents and Settings\UserName\Desktop\Windows Repair.lnk
Documents and Settings\All Users\Application Data\[RANDOM CHARACTERS].dll
Documents and Settings\All Users\Application Data\[RANDOM CHARACTERS].exe
Documents and Settings\All Users\Application Data\[RANDOM CHARACTERS]
I right-clicked on each folder in C:\ then chose Properties. in there, UNCHECK the "Read Only" box and UNCHECK the "hidden" box. I realize this is overkill and may actually serve to subject Windows to other issues at some point, but I needed the system up and running.
Once the attributes were changed, I rebooted and logged in as an Administrator. I updated Malwarebytes. I also disabled System Restore and deleted all the Temporary Internet Files (manually through a command prompt).
I scanned the machine and found three infections, which Malwarebytes cleaned up.
I rebooted and everything appeared normal.
After that, I headed to the Supt's office, but he was out of town.
I went to Texarkana to work on their computers.
I had to install new A/V software on two machines. I set up a user password on one machine. That went smoothly, except on my way back to the office, the teacher called to tell me her computer was now runnig VERY slowly. I will be back there to check that out.