Malware - Ran the Read Me Procedure

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cgoldnsp, Dec 17, 2010.

  1. cgoldnsp

    cgoldnsp Private E-2

    I ran your most excellent Read Me tutorial on malware/virus removal and want to attach the logs below as instructed. Still to come: SAS txt file and Malwarebytes log in next text, providing I can find them!

    Thanks,
    Cal
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    LOgs for SAS:

    C:\Documents and Settings\cgoldsmith\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs <--- found here.

    Logs for MBAM:

    C:\Documents and Settings\cgoldsmith\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs<--- found here. Attach the most recent, log showing what it removed.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    C:\WINDOWS\SYSTEM32\12543.js <--- Delete this using windows explorer. Let me know if it deleted sucessfully.

    Java(TM) 6 Update 22 <--- Uninstall outdated Java.

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some data on it
    • Right click on the screen and select > Select All
    • Press Control+C
    • Open a notepad and press Control+V
    • now please ATTACH that report to this thread

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!

    Don't forget to attach the Mbam and Sas logs! :)
     
  4. cgoldnsp

    cgoldnsp Private E-2

    Attached are the other two files required; Symptoms initially were very slow processing of commands, eventual (10 -15 minutes) freeze up of screen.

    At startup I get a black box entitled "C:\WINDOWS\System32\cmd.exe" that gives a list of system errors 67, 85, 53, sometimes multiple times, and says local device already in use. Goes away in 30 seconds or so and allows me to continue.

    The at some point during the session, usually less than 20 minutes into it, I get a message saying Generic Host32 has encountered a problem and must close, after which nothing responds.

    I also get pop up advertisements out of nowhere for various unwanted stuff. Seems to happen when I access an unrelated website.

    Thanks for help. I need it!
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, now complete the rest of my instructions. :)
     
  6. cgoldnsp

    cgoldnsp Private E-2

    I was able to delete the sys32\12543.js file, but only by booting in safe mode.

    Java update removed.

    TESSKiller log attached. A file was removed.

    MBRCheck link didn't work, but went to geekstogo website and searched on MBRCheck, and found a link that then seemed to run it for me. Log attached.

    I'll reboot and load Java and then run MG tools again right after I send this.

    Thank you!
    Cal
     

    Attached Files:

  7. cgoldnsp

    cgoldnsp Private E-2

    Java loaded. Went to their website. The MajorGeeks link didn't have it for some reason.

    MG tools run. Log attached.

    I have completed everything you suggested. Mbam and SAS files were attached to earlier reply.

    Hopefully this does it! Thank you very much for your help. I'll let you know if I still have any recurring issues.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look good, but I want to recheck some things.

    First I want you to re-run ComboFix and attach the new log.

    Now please do this:

    Download MBRBackup
    to your Desktop.


    • Double-click MBRBackup.exe to launch the program.
    • Click SaveMBR (top left corner) and save the backup file to your Desktop.
    • It will have a name similar to MBR_2010-10-06.bin where the numbers correspond to the date the backup was made.
    • Exit the program.


    Next.

    Upload File/Files for testing

    Please go to jotti.org or Virustotal

    Now navigate to the MBRBackup file you just created on your desktop.
    Press Submit - this will submit the file for testing.
    Please wait for all the scanners to finish then copy and paste the results in your next response.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Link works for me. It's the same link for the file here as it is at g2g.
    Again, link worked fine for me.
     
  10. cgoldnsp

    cgoldnsp Private E-2

    Here is the virustot.com scan of the MBR Backup files. Also attached the ComboFix log just run.

    Most problems seem to be gone, but do still get a delay in typing once in a while, like the system is tied up doing something else.

    Thanks for your help.
    Cal

    VT Community Sign in ▼ My account ▼ Sign out Signing out... Languages ▼

    VirusTotal's website has changed, we need new translations, do you feel like helping the community?
    info@virustotal.com
    Sign in to VT CommunitySafety ratings and user comments (disinfection, in-the-wild locations, reverse engineering reports, etc.) on malware and URLs, free and easy.
    email
    password
    Keep me logged in
    Sign in Signing in, please wait...
    Login failed, please try again
    Forgot your password? Create an account

    Edit my profile
    View my profile
    Inbox

    Virustotal is a service that analyzes suspicious files and URLs and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

    0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this URL is benign. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this URL is malicious.
    Submission date: 2010-12-20 17:13:43 (UTC)
    Current status: queued error, please try again queued (#1) analysing finished

    Download progress: 0 bytes

    Antivirus report: View downloaded file analysis Not available

    Webscan result: VT Community

    not reviewed
    Safety score: -
    Compact Print results
    URL analysis tool Result
    Firefox Clean site
    Google Safebrowsing Clean site
    Opera Clean site
    ParetoLogic Clean site
    Phishtank Clean site
    Additional informationShow all
    Normalized URL: http://mbr_2010-12-20.bin/
    URL MD5: 034911d65a63b76e534cd442840c9de9
    Content-Type: text/plain


    VT Community

    0
    This URL has never been reviewed by any VT Community member. Be the first one to comment on it!
    VirusTotal Team
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    For some reason your ComboFix log was truncated. Could you re-run it and attach the new log?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds