Unable to sync BB; $RECYCLE.BIN: malware removal logs

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ChemMD, Jun 5, 2013.

  1. ChemMD

    ChemMD Private E-2

    Hello. Here are my notes on the problems I noticed on my notebook. I followed all the steps in READ AND RUN ME FIRST. I have two HitmanPro logs because I saved the log too early while following the instructions. Posting both here. Thanks!

    Problems
    1. I started having trouble synching my Blackberry smartphone with my notebook computer after using it without problems for months.
    2. An error message about an unknown port appeared. When I checked Device Manager, one device icon on USB Controllers is labeled “Unknown Device.” Details show “Windows has stopped this device because it has reported problems. (Code 43)”. This was NOT corrected when I did the ff: (a) update the device software (it is up to date), (b) disable device, then reboot, and (c) uninstall device, then reboot.
    3. I followed ?? When I showed hidden files, I noticed $RECYCLE.BIN on my c:\ drive
    4. While running TDSS, two errors appeared: (a) can’t initialize log, and (b) a 2nd I don’t remember. I can’t find the log, but when the scan finished I got a report that no threats are found.
    5. While running MGTools.exe, this error message appeared:
    ProcessDll.exe – Common Language Runtime Debugging Services Application has generated an exception that could not be handled. Process id=0xd64 (3428), Thread id=0x1084 (4228). Click OK to terminate the application. Click CANCEL to debug the application.

    I clicked OK. At the end, I got a message that c:\MGLogs.zip failed to create.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is this the same PC you had networking issues with in the below recent thread?

    http://forums.majorgeeks.com/showthread.php?t=275398


    There are no problems showing in the logs you attach so I tend to doubt there would be anything of signficance in MGtools logs too. You probably are not having malware problems.
     
  3. ChemMD

    ChemMD Private E-2

    YES, it is. The reasons I suspected that it is a malware program are: (1) the effect is on devices, and (2) the $RECYCLE.BIN folder. I vaguely remember that this or something similar is an effect of one of the worms or Trojans identified while you were helping me that time.

    I did NOT believe this could be infected because I followed the rest of the steps in your Next Steps, including How to Protect from Malware. I did notice that Comodo Firewall sometimes asks me for permission to grant access to svchost.exe for someone trying to access me from outside. I always blocked it but did NOT terminate because it might be something important.

    I started another thread because I was not sure if it is a new problem or not.

    Immediately after running READ and RUN ME FIRST, I noticed the next time I used to computer that the error message Unknown Device was gone. The error message is back again. I also did the scheduled weekly scan using Malware Anti-bytes and MSE which turned out clear. The $RECYCLE.BIN folder is still there.

    Out of curiousity I looked into the MGTools folder and found that there are logs inside. I wonder if I should re-run MGTools, but how do I get it to successfully make the MGTools.zip folder?

    Thanks for your reply.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    More frequently this is related to Windows OS problems.

    Nope. This is part of Windows

    You have to be careful what you stop from having access. svchost.exe is part of Windows and many processes/services use it.

    Yes it created many logs before the error you mentioned occurred. You can do the below but I'm no expecting to see any real malware.

    Right click on C:\MGtools\ReZip.bat and select Run As Administrator, then look in the C:\MGtools folder for a slightly different zip file named MGlogsR.zip Attach it to your next message.
     
  5. ChemMD

    ChemMD Private E-2

    Uh-oh. I don't like the sound of that. Will deal with it when we get there :)

    That is good to hear. This malware business encourages paranoia hehe

    I understand. That is why I don't terminate. Didn't notice any problems till the failed BB sync.

    Am sending the logs using the optional process you mentioned. Hope to move on working on Windows OS problem you mentioned if my logs are clear and you think there is no malware.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What exactly do you have installed from Comodo? Is it just the firewall or is it the full security suite?

    These logs are clean.

    Is the Proxy Server you are using required by your ISP? I see the below:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 182.18.209.6:3128
     
  7. ChemMD

    ChemMD Private E-2

    I have only the firewall installed for Comodo. I still have to check with my ISP provider, but the proxy server settings may be due to my ISP provider or for the network at work. I no longer use the latter.

    On the BB sync, I may have to uninstall and re-install Plan Plus and Blackberry Device Software. I'd rather NOT because I lost some data when I tried to use another laptop while my notebook was infected. Do you have any other ideas?
     
  8. ChemMD

    ChemMD Private E-2

    Hello again. Thanks for continuing to work with me. I have verified with my ISP provider that proxy server setting is NOT required.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well I would have said try using an old System Restore point but it appears that you had disabled System Restore. So the only other thing I would suggest is to properly backup the data you need and then reinstall your BB software. Since your problems are not malware. I have to send you to the Software Forum to continue this.

    The Proxy Server is a non-issue since it is disabled. You could just delete the entry from Internet Explorer conntections settings if you wish but it has nothing to do with your problems.


    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     
  10. ChemMD

    ChemMD Private E-2

    Great news! I got my BB sync'ing successfully. Here's how. I took your cue about doing a System Restore to an old restore point on my backup external drive. Worked on How to Protect Yourself from Malware. I then re-scanned with Malware Anti-bytes and MSE before doing another back-up.

    You said System Restore is disabled on my system. It is NOT. Glad I have an old restore point.

    Thanks for all your help!
     
    Last edited: Jun 11, 2013
  11. ChemMD

    ChemMD Private E-2

    Hello again. I could not follow the steps in How To Protect yourself from malware as stated in two instances. First on Disabling Autoruns, there is none described on windows 7. I used a Microsoft Fixit program to do this. Second on an alternative web browser, the link for Google Chrome does not work. I downloaded directly from their site. Does this mean you no longer recommend Google Chrome?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I was just going by your logs which showed no restore points for some reason.

    No that's not it. The links needed updating because the browsers have been changing so much and there are many many versions that people like to keep around. I updated them now. We have lots of Firefox and Google Chrome versions in are Browser File Directory. And dozens more browsers. See the below link to all Browsers.

    http://www.majorgeeks.com/mg/sortname/browsers.html
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds