Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Tuesday, November 15, 2011

As matter of record

The machine that gave me fits on Monday/Tuesday finally succumbed to a complete Windows reinstall. As a matter of recording everything I did, I offer the following:

PC had random pop-up windows, evident of traditional malware infection. As a matter of course, I fired up ComboFix to clear the infection. ComboFix ran for a time, but froze up the computer. i have seen this happen before, and the general "fix" is to reboot the machine and start ComboFix again. Did that. Froze up again. Not good.

I managed to get MalwareBytes installed and updated, then ran that on the computer. That program found one infection and supposedly cleaned it. Upon reboot, however, the machine exhibited the same behavior as before.

I noticed that iexplore.exe was showing up in the Task Manager as soon any user logged in, though the process was not found in the registry as part of any normal start-up locales. It occurred to me that I needed to delete the dllcache files, so I did. The program would still fire up on its own. I renamed iexplore.exe in the Program Files folder, but it would reappear in a matter of moments.

Upon the suggestion of a local tech, I installed Avast free and ran the Boot-up Scanner. That found several infections and supposedly cleaned them. However, upon reboot, the problem returned immediately.

After doing some research, I ran GMER with the suggested settings (see below) and the program found no altered files. I tried to run TDSSKiller but the program would never launch - just show a brief hourglass then do nothing. Even in Safe Mode, Killer would not execute.

At this point, I had spent almost the entire day on Monday and a good hour or so on Tuesday working on this. It was time to blow away Windows and reinstall. I saved the user's Favorites to a flash drive (or tried to. After Windows was reinstalled, the Favorites folder was not on the drive, even though the system had said it copied it. Must have been something with the infection).

I spent the next hour or so putting Windows back on, getting the computer into the Domain and installing our standard software (along with her printer software). When reinstalling Windows, I deleted *ALL* the listed partitions, then did a long format on the drive. Neither of those may have been required, but I wasn't taking any other chances. I was tired and ticked - not a good combination for infections.



*GMER suggested settings: UNCHECK Modules, Process, Threads, Show all, and Files. DO check IRP Hooks and NTAPI Registry scan

Monday and tuesday

Well, I spent nearly the whole day on monday troubleshooting an infected machine to no avail. Tried running tdsskiller and it would not launch.  Decided that reinstalling windows would be best solution. Who knows what the rest of Tuesday will look like.

Thursday, April 14, 2011

Thursday - Early Childhood Visits

On Thursday, I had to run to the office to kick-start the mail server. After I took care of a few other issues in-house, I headed down to Fouke and to Texarkana for some troubleshooting. In Fouke, one of the student machines got infected with the "Windows Repair" drive-by fake spyware program. I sincerely *HATE* these stupid fake spyware programs. They pretend to scan your machine and report all kinds of problems, when in fact the program itself is causing the problem! In this case, Windows Repair "scans" the computer, but what it is really doing is resetting all the attributes to HIDDEN and READ-ONLY for every single file it can get its hands on. Naturally, this produces all kinds of "drive errors" because the system cannot write to read-only files! It is brilliant in its simplicity. It is also a bugger to get rid of! I tried to run Malwarebytes, but that was futile. Even in Safe Mode it was worthless because of the attributes, plus the program was outdated. So, time for the "hard way:" I deleted the following files from Safe Mode: Documents and Settings\All users\Application Data\(random gibberish filename).exe Documents and Settings\infected-username\Application Data\(random gibberish filename).exe Unregistered and Removed this: Documents and Settings\All Users\Application Data\(random gibberish filename).dll Then removed these:

Documents and Settings\UserName\Start Menu\Programs\Windows Repair\Uninstall Windows Repair.lnk


Documents and Settings\User Name\Start Menu\Programs\Windows Repair\Windows Repair.lnk


Documents and Settings\UserName\Start Menu\Programs\Windows Repair


Documents and Settings\UserName\Desktop\Windows Repair.lnk


Documents and Settings\All Users\Application Data\[RANDOM CHARACTERS].dll


Documents and Settings\All Users\Application Data\[RANDOM CHARACTERS].exe


Documents and Settings\All Users\Application Data\[RANDOM CHARACTERS]


I right-clicked on each folder in C:\ then chose Properties. in there, UNCHECK the "Read Only" box and UNCHECK the "hidden" box. I realize this is overkill and may actually serve to subject Windows to other issues at some point, but I needed the system up and running.


Once the attributes were changed, I rebooted and logged in as an Administrator. I updated Malwarebytes. I also disabled System Restore and deleted all the Temporary Internet Files (manually through a command prompt).


I scanned the machine and found three infections, which Malwarebytes cleaned up.


I rebooted and everything appeared normal.


After that, I headed to the Supt's office, but he was out of town.


I went to Texarkana to work on their computers.


I had to install new A/V software on two machines. I set up a user password on one machine. That went smoothly, except on my way back to the office, the teacher called to tell me her computer was now runnig VERY slowly. I will be back there to check that out.