Training Part 1 - Lev

Discussion in 'Malware EDU' started by Lev, Jul 9, 2008.

  1. Lev

    Lev MajorGeek

    Everything went smoothly as per the instructions for XP. Attached are the 4 logs.
     

    Attached Files:

  2. Lev

    Lev MajorGeek

    MBAM attached
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay do you see anything in your logs at all that you think should be commented on (whether malware or not)?
     
  4. Lev

    Lev MajorGeek

    Mbam log - looks ok.

    Combofix log - Recovery console is not installed
    - unvise32.exe - trojan? (located in C:\Windows)
    - AOL remaining files/folders need cleaning up (and You've Got Pictures)
    - Mcafee files/folders need cleaning up (no longer installed)

    SAS log - looks ok

    GetUnKey log - update .net Framework v 1.1.4322

    Newfiles.txt log - C:\Windows\psexesvc.exe - trojan vulnerability?
    - dxdiag.exe - trojan?
    - fontview.exe - trojan?
    - shmgrate.exe - trojan?

    Runkeys.txt log - Error - value "Pendingfilenameoperations" does not exist
    - Error: key: regfile\shell\merge\command does not exist
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Added comments inline in purple.

    Questions for you. ;)

    What about the below from HijackThis?
    What do you think of the below folder from newfiles.txt?
    Code:
    "C:\"
    8E374C~1      Jun 13 2008              "8e374c254408229fb8cd4533399636"
    
    What do you make of the below from newfiles.txt?
    Code:
    "C:\WINDOWS\system32\"
    set18e.tmp    Apr 22 2008      826368  "SET18E.tmp"
    set18f.tmp    Apr 22 2008      233472  "SET18F.tmp"
    set190.tmp    Apr 22 2008     1159680  "SET190.tmp"
    set191.tmp    Apr 22 2008      105984  "SET191.tmp"
    set197.tmp    Apr 23 2008     3591680  "SET197.tmp"
    set198.tmp    Apr 22 2008       52224  "SET198.tmp"
    set199.tmp    Apr 22 2008      459264  "SET199.tmp"
    set19a.tmp    Apr 22 2008       27648  "SET19A.tmp"
    set19d.tmp    Apr 22 2008      267776  "SET19D.tmp"
    set1a0.tmp    Apr 22 2008     6066176  "SET1A0.tmp"
    set1a2.tmp    Apr 22 2008      383488  "SET1A2.tmp"
    set1a8.tmp    Apr 22 2008       63488  "SET1A8.tmp"
    set1ab.tmp    Apr 22 2008      124928  "SET1AB.tmp"
    
    What about the below from newfiles.txt? What does this mean to you?
    Code:
    "C:\WINDOWS\system32\drivers\etc\"
    hosts         Jul  9 2008          27  "hosts"
    What about the below from newfiles.txt?
    "DisplayName"="Spybot - Search & Destroy 1.3.1 TX"


    What kind of important info can be obtained from the procdll.txt log?

    What kind of important info can be obtained from the sysinfo.txt log?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Oh and I almost forgot to mention the most important thing on your PC. Uninstall the below huge POS

    Emco Malware Destroyer

    This thing should be on the rogue removal tool list. I ran it on a perfectly clean system and it invented all kinds of non-existent problems. It was pointing out non-existent files and registry keys as problems. On one file that really did exist, it was just a text file name lsa.txt that had a dump of some registry entries and it called it a Trojan that it says "hooks libraries and monitors user logins". That is quite a feat for a harmless text file.

    I also ran it on a PC with about a dozen or so very basic problems that should easily be detected by any scanner. It did not find any of the problems.

    Evens it's presentation of the data and what it calls things is terrible. Probably the worst I have ever seen. Even other rogue tools did a better job or presentation or naming things. :(

    The other amazing thing is that the installer program is over 30 Mb. That is ridiculous for a piece of junk like this that does nothing but lie to you.

    I cannot believe that Tim made this available for download. But he also keeps the RemoveIT Pro XT program available and it is crap too. Always has been! I may have to mention something about this Emco program to him to get his opinion.
     
    Last edited: Jul 15, 2008
  7. Lev

    Lev MajorGeek

    Duly noted, thank you.

    Browser Helper Object - how do you know when they are good or not? Because it has no file associated with it, is it "dead" and needs removing from registry? I need reading material around this area to increase understanding.
    Acronis is messed up as I downloaded and used just the trial version that was free for 15 days when my laptop died, to recover my data from my Passport external drive. This is why no scheduler works with it as 15 days has expired and I need to uninstall.




    First part (8E374C~1) looks like a color code, but tbh...I don't know.

    Temporary system files used to update Windows

    Hosts file location for XP


    Exploit fix for S&D


    What dll's are installed - helps to identify non-genuine windows ones.

    Entries that are made in the windows registry of the PC.

    Duly uninstalled.Long time ago when I had some virus, it was THE removal tool for that specific thing in it's day. It worked, but have to say it has never removed another single thing since!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If it looks like this with no name and no file you should always remove it. You can search on the CLSID to try and get info on what it may be from. For 7E853D72-626A-48EC-A868-BA8D5E23E045 you will find that it is from Windows Live Messenger. When searching, don't always believe a single site to be correct about what a CLSID or a file name belongs too. Many people have no idea what they are saying. Some would even tell you the above CLSID is from a virus. A useful list of CLSID has been collect here:

    http://www.castlecops.com/CLSID.html


    But was it already uninstalled? Why is the log showing (file missing) ?


    No not a color code. Look in the folder and you should be able to see it is from failed Windows updates. Often these are left around when an installation fails. Although they are not malware, they can be removed since they are not needed.


    Yes it is from Windows Update. Although they are not malware, they can be removed since they are not needed.

    Yes but I was looking for something more specific related to the file itself. ;)


    Yes but why do you have it installed????? Look at the version number. It is 4 years out of date. It was only for a bug in a specific version of 1.3.


    No quite. It is a list of what DLLs are being loaded/hooked into specific processes. It will not help you determine which are Microsoft's or any other valid ones. You have to learn that by experience. If you find some logs from Vundo infections, especially ones with O2 - BHO lines & also O20 lines you will see in the procdll.txt log that the DLL will get hooked into various processes. The most frequent processes are winlogon.exe, explorer.exe, & iexplore.exe but others may be used too. And even if you do not see O2 or O20 lines, things could still be hooked into the processes. The procdll.txt was more important in the past in cleaning Vundo, Winlogonhook, Look2Me and simiar malware. New tools that we have now make cleaning easier. However if you don't see any obvious malware in other logs, you should always try looking at through the procdll.txt log to see if anything questionable appears.

    Not really what I mean. Look at the log and tell me what kind of info may be important and what user type comments about problems they are having would make you want to look at this log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds