Request For Log File Analysis (malwarebytes, Rogue, Tdss , Hitman Pro, Mg Tools And Adware)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by John Jr., Dec 16, 2016.

  1. John Jr.

    John Jr. Private E-2

    Hello,

    I think my laptop is infected despite my antivirus (Kaspersky Internet Security) did not detect nothing.
    I followed the Malware Removal Guide for windows XP.
    I obtained six log files from Adware Cleaner, Malwarebytes Anti-Malware, Rogue Killer, TDSS Killer, Hitman Pro and MG Tools).
    I attached five of them to this thread.
    I did not attach the Adware Cleaner log file.

    ----> Please, could you analyse them and explain me how to remove/clean the infection and how to avoid a new infection ?
    Would you need the Adware Cleaner log file ?

    I fear my mobile WD drive is infected.

    ----> Should I follow some kind of Malware Removal/Cleaning Guide for mobile drive ?
    If yes, what would be this guide ?

    Yours sincerely,

    John
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. However, we can clean up a few items.

    Rerun RogueKiller and have it remove these items:

    ¤¤¤ Files : 5 ¤¤¤
    [Hidden.ADS][Stream] C:\WINDOWS\system32:7DC99477_Abn.gbp -> Found
    [Hidden.ADS][Stream] C:\WINDOWS\system32\drivers:GbpKmAp.lst -> Found
    [Hidden.ADS][Stream] C:\WINDOWS\system32\drivers:IncompleteBoot.cnt -> Found
    [Tr.Generic][File] C:\Documents and Settings\FLOR\Dados de aplicativos\uTorrent\updates\3.4.9_42973\utorrentie.exe -> Found

    Once done, reboot and rescan with RogueKiller and attach the new log.
     
  3. John Jr.

    John Jr. Private E-2

    Hello Tim W,

    Thank you very much for your answer !

    I did what you asked.
    I attached the new Rogue Killer log to this message.
    You will see the line [Hidden.ADS][Stream] C:\WINDOWS\system32\drivers:GbpKmAp.lst is still there.

    Regards,

    John
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun RogueKiller and have it remove this item:
    ¤¤¤ Files : 2 ¤¤¤
    [Hidden.ADS][Stream] C:\WINDOWS\system32\drivers:GbpKmAp.lst -> Found

    Reboot and rerun RogueKiller and attach the new log.
     
  5. John Jr.

    John Jr. Private E-2

    Hi Tim W,

    Thanks for your answer!

    I did what you requested.
    Nevertheless, the line [Hidden.ADS][Stream] C:\WINDOWS\system32\drivers:GbpKmAp.lst is still there.
    I attached the new Rogue Killer log.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download OTL to your desktop.

    Double-click OTL.exe to start the program.
    • Copy and Paste the following code into the Custom Scans/Fixes textbox. Do not include the word Code
    Code:
    :processes
    :killallprocesses
    
    :files
    [Hidden.ADS][Stream] C:\WINDOWS\system32\drivers:GbpKmAp.lst
    
    :commands
    [PURITY]
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    
    
    • Then click the Run Fix button at the top.
    • Click the OK button.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. Just close notepad and attach this log from OTL to your next message.
     
  7. John Jr.

    John Jr. Private E-2

    Hi Tim W,

    Thanks a lot for your answer!

    I attached the OTL log to this message.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What issues are you still having?
     
  9. John Jr.

    John Jr. Private E-2

    In the OTL log, the following line appeared : " File\Folder [Hidden.ADS][Stream] C:\WINDOWS\system32\drivers:GbpKmAp.lst not found. "

    Later, I ran Rogue Killer.
    I noticed in the Rogue Killer log the line " [Hidden.ADS][Stream] C:\WINDOWS\system32\drivers:GbpKmAp.lst -> Found " was still there.

    I do not understand what is happening.

    Please, would you know what should be done ?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having issues, the removal of the "file" is not significant. Are you having issues?
     
  11. John Jr.

    John Jr. Private E-2

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can, but if you are not having issues, you can skip it.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8 or 10, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     
  13. John Jr.

    John Jr. Private E-2

    . I am running Win XP Sp3.
    You wrote I should renable my Disk Emulation software with Defogger if I had disabled it in step 4 of the READ & RUN ME.
    --->Please, what is this disk emulation software ? I do not remember having disable a disk emulation software.
    Where could I find the Read&Run Me?

    . My antivirus is Kaspersky Internet Security. Malwarebytes Anti-Malware is also installed on my laptop.
    I was told I should consider adding CryptoPrevent, MBytes Anti-Exploit and SpywareBlaster
    ---> Are these three freewares good options along with Kaspersky Internet Security and Malwarebytes Anti-Malware?

    ---> Is Kaspersky Internet Security a satisfactory protection?

    ---> Would you have special recommendations to protect my laptop against malware under win XP sp3 about anti-virus, firewall, temp file/cookies cleaner, antispyware tools, sun java, autorun eater, etc. ?
    I know Microsoft does not give any more updates for Win XP.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Windows XP is very outdated. You would be wise to upgrade. You can add those programs if you think it will help, but the best advice is to be careful when you are surfing and be wary of email attachments. Don't worry about the disc emulation.
     
  15. John Jr.

    John Jr. Private E-2

    Thank you very much for your answer!

    ----> Please, should I use now Tweaking in order to repair the possible problems caused by the malwares that have been removed from my laptop ?


    My 2 Gb WD portable external hard drive is often connected to this laptop.

    ----> Does it exist some kind of Malware Removal/Cleaning Guide for mobile drive ?
    If yes, what would be this guide ?
    If no, what programs should I use on this external drive to check and to remove malwares, trojans, spywares, etc. ?
     
  16. John Jr.

    John Jr. Private E-2

    Hi everybody,

    Please, could someone answer to the last questions I asked in my last message ?
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can use the Tweaking software if you are afraid that something is amiss. And you can also use MBAM to scan your external drive.
     
  18. John Jr.

    John Jr. Private E-2

    Hi TimW,

    Thanks a lot for your answer!

    On one hand, prior to the use of Rogue Killer, TDSS Killer, Hitman Pro, MG Tools and Adware Cleaner to create log files, I remember that Kaspersky Internet Security and Malwarebytes Antimalwares did not detect anything on my laptop. Adware Cleaner and Rogue Killer, for instance, did detect something.
    On the other hand, when I ran Kaspersky Internet Security and Malwarebytes Antimalwares on my external drive, the same happened : they did not detect anything.
    So, I am thinking that may be this external drive should be scanned and treated with other programs to ckeck it and to disinfect it if necessary.

    Please, what would be your suggestions ?
     
    Last edited: Dec 28, 2016
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't think it is necessary.
     
  20. John Jr.

    John Jr. Private E-2

    Thank you very much for your answer !

    May be you remember Rogue Killer and OTL were used to remove the line C:\WINDOWS\system32\drivers:GbpKmAp.lst

    Today, I checked the registry of my laptop with "regedit" and I found GbpKmAp as the datas of two REG_SZ file 001, one located at HKEY_CURRENT_USER \ Software \ Microsoft \ Search Assistant \ ACMru \ 5603 and the other located at HKEY_USERS \ S-1-5-21-1177238915-1844237615-839722115-1003 \ Software \ Microsoft \ Search Assistant \ ACMru \ 5603


    Please, do you think it would be wise

    1- to erase :
    -> these two REG_SZ file 001 from the registry
    -> or the value datas GbpKmAp of these two files or their binary values 0000 47 00 62 00 70 00 4B 00 G.b.p.K 0008 6D 00 41 00 70 00 00 00 m.A.p... 0010

    2- or to do nothing and let these in the registry ?
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just leave them alone.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds