Brief assist with malware log

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Ciik, Jun 14, 2012.

  1. Ciik

    Ciik Private E-2

    I hope I am following protocol, as I really appreciate this site. Never thought to follow it until I suspected an infestation.

    So I followed these steps about Vista and Win 7 Malware Removal/Cleaning Procedure here: http://forums.majorgeeks.com/showthread.php?t=139681

    After doing all that, and getting to the point of having to run ComboFix, I received a blue-screen shortly after it was executed from my desktop. So then I re-started my comp in safemode with networking and ran ComboFix from there.

    I executed it, all seemed fine, walked away and allowed it to do its' thing. I came back and noticed that my computer was rebooted in normal mode and below is the log that was on my screen.

    I'm posting this in the hopes that someone can lend some input to whether there is anything concerning on it, since I am way out of my league when it comes to stuff like this (below).

    ========================================
     

    Attached Files:

    Last edited by a moderator: Jun 14, 2012
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We still need the rest of the logs ATTACHED to your next reply:
    SAS\
    MBAM
    RootRepeal -- If it runs
    C:\MGLogs.zip
     
  3. Ciik

    Ciik Private E-2

    Okay...thanks for the direction! I see what the expectation is. They are attached, but I have a 64bit system, and the malware instructional page said not to run on a 64bit system, so I didnt.

    Now get this, as I'm running MGtools.exe for the first time, a pop-up appears while it is running stating that whoami.exe has stopped working.

    Then after some lenght of time, MGtools.exe completed and my folders created. The the second time, running the .bat file as administrator, everything seemed to run through smoothly.
     

    Attached Files:

    Last edited: Jun 14, 2012
  4. Ciik

    Ciik Private E-2

    So after waiting for some feedback, I also ran SpyBot-SD and found or assume that I have the Win32.Phdet Trojan....this SpyBot-SD stops at trying to figure it out, literally hangs-up when it reaches it at the end of its' scan.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Per the instructions in the READ & RUN ME, you should not be doing this. The below is quoted from the first instructions
    And in fact, you need to uninstall Spybot immediately to avoid having conflicts with the cleaning process and all the other stuff you have installed. You have Microsoft Security Essentials and Spyware Doctor ( which includes Browser Defender and Threatfire ) already installed.



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. Ciik

    Ciik Private E-2

    Thank-you so much. And here is what I did, following the complete instructions. I just wanted to convey my steps and experience accurately.

    1] I dropped the CFscript.txt on top of ComboFix.exe, but even though I personally ended the microsoft essentials process in my task manager prior to this, I still received the pop-up box that it was detected; Image attached.

    In any event, I clicked 'ok' and continued. When ComboFix completed, my computer auto-rebooted. Then ComboFix completed upon restart. ComboFix.txt attached.

    2] Then whn I ran GetLogs.Bat as Administrator, it initiated, ran for a moment, and a dialog box appeared stating "Steelwerx whoamI application" has stopped responding. That little dialog box continued to look for a solution, but when no solution was found, I clicked "ok" to close it. Then GetLogs.Bat continued. The MGlogs.zip is atatched.

    3] After #1 and #2 above completed, I went to execute Firefox to send these reports and reply, and I received a dialog box stating "c:\Program Files (x86)\Mozilla Firefox 4.0 Beta 9\Firefox.exe Illegal operation attempted on a registry key that has been marked for deletion." I rebooted my computer to resolve it, and to provide this report & attachments.

    As a final thought....I don't have problems with my computer running, just that concern that my computer has this Win32.Phdet Trojan on it, and I'm not certain about whether it is there or not.
     

    Attached Files:

    Last edited: Jun 15, 2012
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean. Please complete all of the below final instructions before running any other scans to avoid false detections of things we have already quarantine or left overs from system restore.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  8. Ciik

    Ciik Private E-2

    ohh...my god. Im writing this from a little lap-top. My network connections on my Win7 machine are gone. I completed the uninstall steps, went to reset a new restore point, restarted my computer, and that is when my computer rebooted with one network that I cant connect to now.

    During the course of trying to troubleshoot it and Verizon trying to hand me off to a third party to charge me $114 bucks to restore my netorks, I lost my last saved netowrk connection.

    This laptop is connected to my Verizon Router, but my main PC will not recognize any networks. Any help with that?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please get MGtools.exe back onto the PC ( use a USB stick ) and run a new scan. Attach the new MGlogs.zip

    Also please do the below.


    Please do the below so that we can boot to System Recovery Options to run a scan.

    For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  10. Ciik

    Ciik Private E-2

    I'll do that. My other problem is that I no longer have a restore-point. When I rebooted my computer, my intention was to reboot then turn it back on to reset the restore point, but since I eliminated the previous restore points, I have none.
     
  11. Ciik

    Ciik Private E-2

    Okay...took alot longer for my novice self than I thought. Just thinking to myself, I have no access to the the network and sharing center, cant open it, and my desktop isnt detecting the network.
     

    Attached Files:

  12. Ciik

    Ciik Private E-2

    I cant even find the edit key so I can edit my previous post. Was gonna say that I do have access to the network and sharing center and its' stuck at "identifying" a connection.
     
  13. Ciik

    Ciik Private E-2

    Again, sorry. Wish I had more time to edit and add to a previous post, but here is an image of what Im looking at.
     

    Attached Files:

  14. Ciik

    Ciik Private E-2

    I also ran MiniToolBox.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your NetIO Legacy TDI support driver registry entry has been deleted and this prevents your DHCP service from running thus blocking your ability to get an IP address assigned to your computer.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now reboot your computer.

    After reboot, run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  16. Ciik

    Ciik Private E-2

    Hi Chas...thanks for sticking it out with me during this. I'm on my desk-top now. I just reinstalled my Win7 OS from my boot-disk and called it a day; a long day :)

    I sincerely appreciate your help. This whole thing was a learning lesson, and lead to my first-time OS install as well. All's good.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds