BigBrother70 Log files attached

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by BigBrother70, Aug 19, 2010.

  1. BigBrother70

    BigBrother70 Private E-2

    Hey all. I've used MajorGeeks multiple times in the past for infections and the help has been AMAZING. Well, my friend recently got infected and I knew where to head :). I conducted all the steps via remote desktop, which was a fun experience. Anyway, here are the log files, and below are any idiosyncrasies we encountered:

    The first step, removing old java installs and installing the latest, couldn't happen. Normal mode was completely messed up and safe mode wouldn't allow us to install anything (this is Vista).

    - We had to run in safe mode until after the SAS step

    - DeFogger showed no cd emulation

    - SAS and MB were both already installed. I couldn't manage to uninstall SAS and reinstall, so I merely updated. It seemed to run just fine (I've seen SAS ran before when it's messed up - it really seemed okay here), after being updated. MB was done through the traditional route.

    Post cleanup:

    - Still a bit of wonky behavior. Haven't used the system too extensively, but already we notice:
    - anytime I hit ctrl+f , I get "The Active Domain Directory Services is unavailable".
    - in Normal mode, hitting the r key causes 'Run' to trigger, always.

    Anyways, here are the logs (only three files since Vista). Thanks all as always for a phenomenal, immensely helpful job!
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Currently reviewing your logs and will get back to you with a set of instructions asap.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Why are you using this machine with no anti virus protecting you?

    Please go to Add/Remove programs and uninstall the following software:

    • Java(TM) 6 Update 18

    If you did not deliberately set this proxy yourself then please include it in the HJT fix below:

    • R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6522

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    • R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6522
    • O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files (x86)\DNA\btdna.exe"
    • O4 - Startup: Yuuguu.lnk = C:\Users\Gil\AppData\Roaming\Yuuguu\yuuguu.exe

    After clicking Fix exit HJT.


    Tell me what is inside of this directory, without clicking on any of it's contents.
    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.

    Code:
    :Files
    C:\Users\Gil\AppData\Local\rdnfgynqq
    C:\Users\Gil\AppData\Local\Rsupegigusobo.dat
    C:\Users\Gil\AppData\Local\Utagohomalo.bin
    C:\Users\Gil\Desktop\Antivirus Support.lnk
    C:\Users\Gil\AppData\Roaming\Yuuguu
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Run Ccleaner at this point.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Answer any questions that I may have asked, particularly regarding the folder whose contents I wish to know about.

    Let me know how things are running for you now, please. :)
     
  4. BigBrother70

    BigBrother70 Private E-2

    temp
     

    Attached Files:

  5. BigBrother70

    BigBrother70 Private E-2

    Sorry, the message below was to be a placeholder for some attachments, but it won't let me go back and edit, so here was the intended body:

    Hey, thanks so much for the response! So, here goes:

    1. I followed all the steps with respect to Yuuguu- not sure if you know this app, but it's the screensharing tool I use for remote access (www.yuuguu.com). Nonetheless, I went through everything and it's now non functional, which was to be expected. No worries, but wanted to let you know.

    2. Re: proxy settings, at the very beginning when we got this infection, I had to set proxy to use system proxy settings - we couldn't use FF, IE, Yuuguu, etc. without this step, even in safe mode with networking. So in answer to your question, it may have been user-specified, but I followed your steps since I wasn't sure. Throughout this process, btw, internet connection would die out, sometimes requiring a reboot, etc.

    3. The contents of the directory are in a screenshot shown here- mostly Chrome stuff. But bear in mind I don't think we ever installed Chrome, and the dates of modification are all at the time of infection!

    4. OTM had an error on reboot re: disk corruption. We took a screenshot and it's attached in the message below.

    5. Minor detail, but our first run of GetLogs generated an endless request for Access permission, since we double clicked it per the instructions. We rebooted and ran it per the Vista prescribed method - Run as Admin, and it ran just fine. MGLogs attached in the message below.

    That's about it. Thanks so much for your help,
    BB
     

    Attached Files:

  6. BigBrother70

    BigBrother70 Private E-2

    Woops, forgot OTM. Attached here:
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am so sorry for that. :( Can you use something such as Revo uninstaller or Your Uninstaller to remove what is left and then re-install?

    It's firefox related.

    Look inside of the chrome folder where there should be another folder called "content", open up that folder and tell me what's inside.

    Also tell me the contents of this folder:

    C:\Users\Gil\AppData\Local\{0C152C29-FFF1-4492-B85A-4A4251ACB5D0}

    Run Ccleaner.
     
  8. BigBrother70

    BigBrother70 Private E-2

    Hah, no worries. You have quite a bit to go before running a karma deficit with me here ;)

    Ok, attached are the dir contents you requested. I ran CCleaner afterward.

    Thanks,
    BB
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sorry for not responding again until now. I have had a very busy weekend at work.

    Let's have you use windows explorer to find and delete this folder:

    Then, considering it's been a couple days...

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know how the machine is behaving now! :)
     
  10. BigBrother70

    BigBrother70 Private E-2

    No problem at all- I really appreciate your help!

    Attached are the latest logs. Behavior-wise, the machine has been fine.

    Thanks,
    BB
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to install some anti virus as I said before. Should you ever need help from us again you could be refused because of the fact you have no AV protecting you.

    Now run Ccleaner to rid yourself of a few temps

    • Please double-click OTL.exe to run it.
    • Click on the CleanUp! button at upper Right corner. When you do this a text file named cleanup.txt will be downloaded from the internet. If you get a warning from your firewall or other security programs regarding OTL attempting to contact the internet you should allow it to do so. After the list has been download you'll be asked if you want to Begin cleanup process? Select Yes.
    • This step removes the files, folders, and shortcuts created by the tools I had you download and run.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  12. BigBrother70

    BigBrother70 Private E-2

    Hey Kestrel, ok, everything done, and I installed PC Tools Antivirus (which, I must say, comes with a bit more bloatware/add ons than I would have liked :), but whatever)

    Couple of things:

    1. Everything appears okay on our end- I assume the last MGLogs indicated a clean status to you? Would you sign off on this now as clean?

    2. What should the proxy settings be for FF and IE, since we had to futz around with them originally?

    Thanks again, I really appreciate it!
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes I believe you are clean now. Your last MGlogs.zip revealed no malware, hence I gave you final steps. ;)

    You can see this regarding proxies

    Proxy Server - Changing Settings
     
  14. BigBrother70

    BigBrother70 Private E-2

    Thanks Kestrel. I ran antivir (the pc tools one sucked, so I went with antivir instead). It found two things, which were quarantined and removed. Attached is a screen shot and the log. Thoughts on this?
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    My thoughts are:

    • It was not showing up on your logs so it wasn't something that was present at the time of me giving you final steps.
    • Your antivirus is doing it's job ;)

    Run scans regularly with both MalwareBytes and Superantispyware. Say once a week or once a fortnight or something.
     
  16. BigBrother70

    BigBrother70 Private E-2

    Great. Thanks you!!
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds