Am I clean now?

Discussion in 'Malware Help (A Specialist Will Reply)' started by nstickels, Apr 24, 2008.

  1. nstickels

    nstickels Private E-2

    I have a laptop with Vista which has been running into some problems of late. After running for a year with no blue screens, I have had 5 in the last week alone (one of them even happened when it was finishing combofix.exe, so I am a little worried that it might not have finished?)

    Also, I typically see processes like the following running in my task manager every time I start my computer (the actual name changes every time):

    c:\windows\temp\ym8506.exe

    I open up that directory, and see the file in there, and once I stop the process, the file disappears. There will be no other suspicious looking files in there. Then the next time I reboot, there is something else in there.

    There were several things that were cleaned during this whole process, but I still saw that exact process listed above when I finished everything, so I think there is still something going on.

    Attached are my logs from running everything...
     

    Attached Files:

  2. nstickels

    nstickels Private E-2

    Just to attach the last logs....
     

    Attached Files:

  3. nstickels

    nstickels Private E-2

    Another question that I had was about the large number of svchost.exe processes that are typically running. At the time of this posting, there are currently 15. When I looked up on google about this, there were some sites that mentioned that this could be indicative of a problem, but those were mostly about xp. I am not sure if that is the case for vista or not.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Is your copy of CounterSpy a paid version or free trial version?

    Uninstall the below old versions of software:
    J2SE Development Kit 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 11
    Java 2 Runtime Environment, SE v1.4.2_13
    Java 2 SDK, SE v1.4.2_13
    Java(TM) SE Runtime Environment 6

    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. nstickels

    nstickels Private E-2

    So now that I am going in and trying to do what you have said, I keep getting an error when I try to run combofix.exe:

    "Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item."

    This isn't the only file that I am having this problem with. This has happened a few times the last week or so. I have tried deleting it and redownloading combofix, and I get the same thing. I have changed all of the permissions repeatedly, and I keep getting the same thing.

    My user is an Administrator on this box, and it is a file that I downloaded with this user on my desktop, so I don't see why I wouldn't have permission to it. I have cygwin, and I even tried chmod'ing the file to 777 in there, and still nothing.

    Any idea what is going on?

    By the way, in answer to your earlier question, it is the full version of counterspy that I paid for, not the trial.
     
  6. nstickels

    nstickels Private E-2

    Well, I managed to get the combofix.exe to work. I had to turn on UAC, run it as my user, and say it was ok to run it, and then I said no not to run it when it popped up the little window asking me if I wanted to run it. Then I turned off UAC, rebooted, and it worked.

    So here are the logs. Two quick notes:

    1) After rebooting, while combofix.exe was finishing, there was a couple "Access is denied" error messages in the blue text box that it was running in.

    2) After that reboot as well, there was another of those mysterious "C:\windows\temp\XXXXX.exe" processes. I don't remember the exact name, but I saw it in the combofix log, so you should see it there as well.

    Let me know if there is anything further that looks suspicious.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have some stuck services that TrendMicro never properly removed when you uninstalled it. Let's fix these.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Trend Micro Client/Server Security Agent RealTime Scan
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below Services (if you do not find them or get any errors, just continue):
      • Trend Micro Central Control Component
      • Trend Micro Protection Against Spyware
      • Trend Micro Client/Server Security Agent Listener
    • Click OK until you get back to Windows.
    • Next, run C:\MGtools\analyse.exe which is really HijackThis, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste ntrtscan into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below Services (if you do not find them or get any errors, just continue):
      • PcCtlCom
      • PcScnSrv
      • tmlisten

      [*]Now exit HJT and reboot when it tells you it needs to.

    After reboot run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the new C:\MGlogs.zip file

    If everything working okay, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  8. nstickels

    nstickels Private E-2

    TrendMicro should be installed. It is the anti-virus program that my company installed and wants me to use on the laptop.

    So if those are the only things, then does that mean it is ok?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But it may be having problems. Based on your logs it does not seem to be installed and running properly. Some of the service files show up as missing and I don't see all of the things I would expect to see running. You may need to reinstall it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds