Extremely suspicious activities

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by fr0sty2012, Oct 20, 2013.

  1. fr0sty2012

    fr0sty2012 Private E-2

    Hello MajorGeeks,

    Recently my PC started acting up. Today, it randomly opened the CD tray so I am not sure if I'm RAT'd or just imaging. Any help is appreciated.

    The logs are attached.

    Regards,
    fr0sty2012
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. fr0sty2012

    fr0sty2012 Private E-2

    I did get all of the logs and attached them to my main post, but they do not show (wtf)?

    Anyway, now that I'm trying to get the MGTools logs I keep getting the following error:

    [​IMG]

    And when I run the GetLogs.bat batch I get "Access is denied" error. Also, I tried googling it but I wasn't able to find any relevant information. Plus, it doesn't even detect the OS version properly, it says that I have 32Bit version - which I don't, I have 64Bit.

    When I run Command Prompt as An Administrator and run the GetLogs.bat from there it loads fine, detects my OS properly but it also gets the Access is denied error.

    One more thing, the RougeKiller doesn't even create report log so I have to do it manually. When I do do it manually, it creates empty text file. Solution to this would also be appreciated!
     
    Last edited: Oct 27, 2013
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well obviously they were never attached as you can see. ;) I would guess that you selected the files by browsing to them but you probably forgot that you have to click the upload button too to actual upload them. See the instructions given for attaching files.


    Never saw this before. Have you shutdown ALL protection software and is UAC disabled.

    I need to see some logs to know better.

    Did you follow the instructions given for running it that were given? Did you run it as Administrator?
     
  5. fr0sty2012

    fr0sty2012 Private E-2

    Hello,

    I apologize for not posting. I was really busy with school. Anyway, it seems that I have problem with permissions. For some reason, even when I disable the UAC (and restart), I can't write to specific regions of the disc. For instance, I wanted to create a bootable USB for Ubuntu installation but I kept getting "Access is denied" error every time I attempted to do so, since it was writing to the Temp directory. Is there a way to fix this?

    Regards,
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. I think that particular issue may be out of the boundaries of the malware forum. What you can do however, is attach all of the logs Chaslang requested a way back. Chaslang is away for a short while, so I will be working your thread.
     
  7. fr0sty2012

    fr0sty2012 Private E-2

    Well, I just gave an example. The reason why I even mentioned it was because I wasn't able to extract ANY logs with MGTools.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Oh I'm sorry, when you typed:

    I thought that you had all of the logs. Hang in there, I'm having a think.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download OTLPE and save it to your desktop:

    OTLPE

    Double click the OTLPENet icon on your desktop
    "Do you want to burn the CD?" choose Yes
    ImgBurn will automatically extract and load the OTLPE Iso to be burned to CD
    Place a blank CD in your CD-Rom.
    Click [​IMG] to start the burn process.

    You will see a dialog "Operation successfully completed"
    Boot the non-working computer using the boot CD you just created
    In order to do so, the computer must be set to boot from the CD first.
    Note : For information click here.

    Your system should now display a REATOGO-X-PE desktop.
    Double-click on the OTLPE icon.
    Select the Windows folder of the infected drive if it asks for a location
    When asked "Do you wish to load the remote registry", select Yes
    When asked "Do you wish to load remote user profile(s) for scanning", select Yes
    Ensure the box "Automatically Load All Remaining Users" is checked and press "OK"
    OTL should now start.
    Push the RUN SCAN button.
    When finished, the file will be saved in drive C:\OTL.txt
    Copy this file to your USB drive.
    Please attach the C:\OTL.txt file in your next reply.
     
  10. fr0sty2012

    fr0sty2012 Private E-2

    I've just burned a CD, basically wasted it, because I got multiple BSoDs while trying to boot it.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please try running this, I just want to see if at least something will run and if any malware is present, this should pick up on it.

    [​IMG] For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    To enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    • Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  12. fr0sty2012

    fr0sty2012 Private E-2

    When I select my OS it says that it cannot be recognized or something along those lines. This is really starting to annoy me, I think it might be completely messed up.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I have not asked you this yet, but did Hitman and Malware Bytes not run either? :confused
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds