Logs for a Malware Expert

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Big_Ragu, Mar 7, 2009.

  1. Big_Ragu

    Big_Ragu Private E-2

    Thank you for taking the time to read this. I think the site is great.

    About my problems … I believe they started back at the end of January but I cannot be 100% sure. There are three users and three computers on my home network and they share a readynas duo central storage drive. I am guessing they came from downloading music or videos files (I have since read your warnings and advice but that does not help me now).

    Anyway I think all three computers became infected but I know it is one computer per post so I will only describe the problems of the one pc I am posting logs for but if you want to know more details about the others just ask. All computers have been disconnected from the internet & LAN for protection/fear of causing more problems. If you want me to connect one and rerun the read me first steps I happily will but I thought I should wait for you to tell me.

    This pc began acting strangely like there is something running in the back ground but nothing is showing in task manager. It was becoming hard to do anything. Windows media player would play but the display was black – no picture. The desktop changed and the recycle bin is now in the bottom right hand corner. When I delete a file it does not go into the recycle bin (and may in fact not be deleting). When I try to access the properties it tells me they are unavailable even though I am the administrator. When it tried to run some tools it would say could not initialize or check to see if I have admin rights (and I am signed in as the administrator). When I clear the check boxes to show hidden files if I go back in they are checked again. When I tried to use SFC I get RPC server is unavailable. Have also seen messages like system admin has set policies to prevent this installation. Spy Sweeper is popping up messages like wmiadap.exe is attempting to delete wmiaprpl and svchost.exe is attempting to delete tcpip. Not sure if this is normal. Searchfilter.exe is appearing red in my process viewer.

    I did my best to follow the read me first instructions. Had trouble uninstalling Java. It was no longer listed in add/remove programs but I could see folders for it still on the computer. Also had trouble installing updated Java (policies preventing error message) but was able to finally get it to work in safe mode. Hopefully everything is correct.

    There was no button or option to empty my Norton 360 quarantine and I could not figure out how to do that.

    I don’t think viewing of hidden files is staying enabled … but I could be wrong.

    Well here are my log files please let me know what you think and if you need me to redo any steps. Your help is very much appreciated. Thank you!
     

    Attached Files:

  2. Big_Ragu

    Big_Ragu Private E-2

    Final Log
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\windows\system32\REN6E.tmp
    c:\windows\system32\REN6D.tmp
    c:\windows\system32\REN6C.tmp
    c:\windows\system32\REN66.tmp
    c:\windows\system32\REN65.tmp
    c:\windows\system32\REN64.tmp
    c:\windows\system32\REN5E.tmp
    c:\windows\system32\REN5D.tmp
    c:\windows\system32\REN5C.tmp
    c:\windows\system32\REN56.tmp
    c:\windows\system32\REN55.tmp
    c:\windows\system32\REN54.tmp
    c:\windows\system32\REN4E.tmp
    c:\windows\system32\REN4D.tmp
    c:\windows\system32\REN4C.tmp
    c:\windows\system32\REN45.tmp
    c:\windows\system32\REN44.tmp
    c:\windows\system32\REN43.tmp
    c:\windows\system32\REN3F.tmp
    c:\windows\system32\REN3E.tmp
    c:\windows\system32\REN3D.tmp
    c:\windows\system32\REN36.tmp
    c:\windows\system32\REN35.tmp
    c:\windows\system32\REN34.tmp
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now I want you to do this:
    Using BitDefender Online Scan.

    When finished run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combo.
     
  4. Big_Ragu

    Big_Ragu Private E-2

    Hi Tim (my name is also Tim) thanks for getting back to me. I did my best to follow your instructions but ...

    The computer had been off and disconnected from the internet (I had been emailing from an unaffected PC) so when I turned it on everything started(Norton/Spysweeper/etc). Your instructions did not say to disable any programs so I just did what they said. When I ran combofix I got a message about Norton so I turned it off (was not connected to the internet yet anyway). Also Spy Sweeper started giving me messages (maybe 20?) about things being deleted/install/modify. I saved the log files for Spy Sweper if you would like to see but I am not sending as I have seen it said in the forum not send additional files unless asked. Anyway I allowed everything because I did not know if it was related to combofix.

    I could not run a bitdefender scan. The program failed to update the virus definitons and the virus signatures failed. I was given the option to scan anyway which I did but the scan failed to so no log. I tried this more than once just to be sure. I should mention that when I connected to the internet everything wanted to update of course from having been down for so long. But I did wait until the updates were finished before trying the bitdefender scan. Also this might be worth noting too - I did try a Trend Micro online scan before I came to this website/forum and it also could not run.

    Here are the new logs and I can't say enough how much I appreciate the help. I hope it is okay shutting it down until I hear from you or do you prefer the computer to be left on? Can I at least disconnect it from the internet? I am not sure Norton is working correctly or what my problems are. Please let me know. Thanks
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only thing that showed up in the combo log was this, which you should use windows explorer to find and delete:
    c:\windows\TEMP\SST-C407BB07-AB4A-4CBA-AE05-70547BE90A3A.tmp

    And if it was sending emails, then it is an infected email which only you can deal with:
    You have a few choices:

    1. delete the whole file which is not an option you normally want to use
    2. load the email folder that contains the infection and delete ALL unnecessary emails (hoping to remove the problem email) and then use the Mailbox Cleanup option to delete all old emails. Then compact the Outlook database to permanently remove data. See http://support.microsoft.com/kb/196990 If you do not cleanup and compact the databases, the deleted emails may still be leaving hidden information in the database that you just cannot see but a scanner may still pickup on it.
    3. create a new folder and move only emails you really need into the new folder and then delete the infected folder.

    You need to tell me what problems you are having.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds