Please review my logs for malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by pdogs, Nov 11, 2010.

  1. pdogs

    pdogs Private E-2

    I visited a coupon website I haven't been on for a while and not only was it down, Avira stated my computer was infected with HTML/Infected.webpage.gen. I ran a scan with Avira and the file was quarantined and I deleted it. However, ever since then my Avira scan reports come back with no viruses found, but I have about 96 warnings. Prior to getting that virus, I had zero warnings after each scan.

    Now Avira frequently has pop-up warnings indicating that it is blocking access to c:autorun.inf.

    I went through Major Geeks recommended steps for malware removal. Both SuperAntiSpyware and Malbytes Anti-Malware came back with no findings, therefore I did not attach the logs. Everything went through, except rootrepeal kept crashing for me, so I never got a log from that program.

    Could someone please review my logs and let me know if I have a bigger issue here?

    Thank you.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    However I would like you to attach them anyway. :)

    Reviewing your logs and will get back to you with a response as soon as possible.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode, if you haven't done so already.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    RegLock::
    [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
    @Denied: (2) (LocalSystem)
    "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
       d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a0,1e,46,5e,51,ff,16,4b,be,16,73,\
    "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
       d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a0,1e,46,5e,51,ff,16,4b,be,16,73,\
    Folder::
    C:\WINDOWS\7E7D778E121D4BBDBA29FAA81B9FBD8C.TMP
    C:\WINDOWS\A13A764803C54B6AB7C118CB04588E52.TMP
    File::
    C:\WINDOWS\winstart.bat
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{A67AC368-D438-42E5-92E5-FE1EC2715FCF}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{A67AC368-D438-42E5-92E5-FE1EC2715FCF}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    You can also take a look at this:

    Disabling AutoRuns

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  4. pdogs

    pdogs Private E-2

    I just saw both of your post. I'll run everything and post the results. Thanks!
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I'll be here waiting. :)
     
  6. pdogs

    pdogs Private E-2

    Kestrel13!,

    I did as you instructed. Attached are the logs.

    I noticed my computer boots quicker, but Avira's Guard is still frequently telling me that it is blocking access to the file C:\autorun.inf.

    I'm going to run the autorun disable you suggested right now.

    Does the ComboFix-quarantined-files.txt in the Qoobox folder indicate the malware that is currently on my computer?

    Thanks for your help!
     

    Attached Files:

  7. pdogs

    pdogs Private E-2

    Kestrel13!,

    I just tried to load the update patch for my Vista 32bit OS. I clicked on the link "Update for Windows Vista (KB950582)" from the forum for my OS and I keep getting the message "the update does not apply to your system." I checked my update log and I do not have that particular update yet.

    Could it be that it's being blocked by Malware?

    Thanks.

    pdogs
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Important Notice: A new version of SUPERAntiSpyware is available.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later.
    Did you try this yet?

    Qoobox is combofix's back up folder, any malware/files/folders that it removes or I remove using a CF script, it holds there in case a mistake has been made my either combofix or us. Restorations can then be made.

    Have you any external devices plugged in?

    For the external Hard Drive and a USB stick.

    Insert your flash drive before we begin. Hold down the Shift key when inserting the flash drive until Windows detects it to bypass the autorun feature. This will keep the autorun.inf from executing automatically.

    Please have all your removable storage devices ready for disinfection.

    Download Flash Disinfector by sUBs and save it to your desktop.

    • Double-click Flash_Disinfector.exe to run it.
    • Your desktop and icons may disappear. This is normal.
    • It will do a cleanup of removable storage devices, and write a protected Autorun.inf file to help prevent re-infection.
    • Follow any prompts that may appear.
    • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
    • Wait until it has finished scanning and then exit the program.
    • There will be no GUI interface or log file produced.
    • Reboot your computer when done.

    Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder. It will help protect your drives from future infection.

    I don't know yet.

    Run this and attach the results.

    Using ESET's Online Scanner

    is your anti virus still detecting it?
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  10. pdogs

    pdogs Private E-2

    I have a couple of hard drives that I use to back up my windows files through an external dock, I think it's called Thermal Dock. I lent it to my friend. I'm going to get it back tomorrow, fire it up and run everything as instructed below. I'll attach the log once its finished.

    Thanks.
     
  11. pdogs

    pdogs Private E-2

    I ran the latest version of SuperAntiSpyware and it did not find anything.

    I ran the ESET. It took 14 hours to complete. The only thing it listed as a virus was MGTools. I restored MGTOOLS from the ESET quarantine before exiting the program.

    I tried several different times to run the Flash Disinfector with no luck with Avira disabled. I downloaded it to my desktop and ran it as an administrator and nothing happen. I tried it in Safe Mode and nothing happen.

    When I enabled Avira, Avira said the Flash Disinfector was a virus, "Virus or unwanted program 'APPL/NirCmd.2 [program]'
    detected in file 'C:\Users\PdoG\Desktop\Flash_Disinfector.exe." I ignored the warning.

    A little later Avira came up with the following message, "Virus or unwanted program 'APPL/NirCmd.2 [program]'
    detected in file 'C:\Users\PdoG\AppData\Local\temp\uU7Kcnk3.exe.part.
    Action performed: Deny access"

    Should I be concerned, as this is the same unwanted program APPL/NirCmd.2 [program] is now in my temp folder with a different name "U7Kcnk3.exe.part"?

    I attached the latest logs.

    Thanks for your help!
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good.
    .Yep. False positive.

    Another False positive...

    Another false positive.

    No, it's fine. nircmd is a valid tool from NirSoft ( see http://www.nirsoft.net/utils/nircmd.html ) It was put on your PC by ComboFix.

    What malware issues are you currently having?
     
  13. pdogs

    pdogs Private E-2

    The only issue I have left is not being able to successfully use the MS update to correct the autorun inf. disable and not being able to load the Flash Disinfector, there are no other issues... I guess.

    Should I uninstall everything? If yes, can you provided me with the 411 on how to properly do so.
     
  14. pdogs

    pdogs Private E-2

    One last thing. I am running Vista home premium 32 bit automatic file backup. I back the files up to an external hard drive. That hard drive was not hooked up when I initially did the combofix and mgtools. Should I run those programs again with my external hard drive hooked up to make sure there's no malware sitting in that hard drive?
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run SAS and MBAM with the external plugged in yes, and attach the logs.
     
  16. pdogs

    pdogs Private E-2

    The last SAS and MBAM I attached was with the external hard drive plugged in, however it was not plugged in when I ran the combofix.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, go ahead and run Combo with the external plugged in and I will check the log. ;)
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, sorry, I meant combofix!
     
  19. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, pdogs
    I often receive pop-up notices from Avira about autorun.inf being blocked.
    One suggestion on the Avira forum is to disable "Block autostart function" in Avira
    • go to Avira's configuration
    • tick Expert Mode > Guard > Scan > Further actions
    • untick the "Block autostart function" option
    • click Apply
    • then install Panda USB Vaccine

    *According to my research - KB950582 is already included in Service Pack 2 for Vista.
     
  20. pdogs

    pdogs Private E-2

    TimW and Kestrel13!,

    I ran all the test again. Rootrepeal crashed again. I attached the logs for combofix, MGlogs, SAS and MBAM.

    dr.moriarty, Thanks for the info on the "KB950582 is already included in Service Pack 2 for Vista" . I'll disable the Avira autorun.inf block. I have the Panda USB Vaccine installed.

    Thanks to everyone for their assistance!
     

    Attached Files:

  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  22. pdogs

    pdogs Private E-2

    Much Thanks for all the HELP!!!
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds