email bug got in....suspicion of malware...

Discussion in 'Malware Help (A Specialist Will Reply)' started by scottportraits, Aug 2, 2009.

  1. scottportraits

    scottportraits Private First Class

    Sunday August 2, 2009

    Hello again,

    I think I've picked up a really nasty bug. My e-mail server, "Safe-Mail.net", a 'high-encryption' service from Israel has had some kind of crash and blow-out. Somebody threw a real stink-bomb in there:crap, and it somehow has gotten into my machine. While running Kaspersky's online scanner it spent some seven minutes at the file C:/Docs and Settings/..../mail / local folders......but found no known infections.

    Did all your proceedures (like run CCLeaner, defragmented, and run my own scans) and attached all logs as specified.
    One thing stuck out as noteworthy, Chaslang says in 'Updating Java' that the most recent edition is Java 6, Update 11. Well, I have Java 6, update 13!!:major

    My machine is stuck in 'selective start-up', and even when I change it back to 'NORMAL' it reverts on reboot back to 'selective start-up'.
    OUCH !!!

    Here is some background information....Launched IE7 and tried to do Symantec's online 'security scan', but it aborts and refuses to run. Also, attempted Kaspersky's, and also found it got stopped and would pop off and evaporate. While running Kaspersky's it spent some seven minutes at the file C:/Docs and Settings/..../mail / local folders, then moved on.:crybaby:crybaby

    I run AVG Free Anti-Virus, and have Sygate's Firewall. Also, I have Spybot S&D with teatimer 'off', and SpywareBlaster. I've run SUPERAnti-Spyware Free but lost the log - which came up 'clean'. I've run MalwareByte's and here is the log. I've run RootRepealer, here's the log.

    I ran Combo.fix and here's the log.

    I ran the MGTools....here are the zipped logs.

    Thanks folks, much appreciated,

    -scottportraits
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually the procedure stated the below:
    The keywords are "At the time of writing this" which was 01-27-2008. You are supposed to click the link we give you which will show you the current version is now 6 Update 15. You still need to follow the instructions here since you have 3 outdated versions of Java installed.


    According to your logs, it was installed but not run. It always saves a log automatically and there is none in the below folder which is where it saves them.

    C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs

    Your logs do not show any real malware that would be causing your problems, but I do have some steps for you to perform. First I suggest that you uninstall the below and then reboot and see if there is any change.

    Advanced SystemCare 3
    IObit Security 360
    Windows Defender


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. scottportraits

    scottportraits Private First Class

    Okay, here are your two logs.:-D

    ......more later......gotta go.....talk to ya soon....and thanks !!!

    'bye
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  5. scottportraits

    scottportraits Private First Class

    Friday Sep 7, 2009 1.oopm est

    Chaslang -

    Yes, I have MalwareByte's and SUPER Anti-Spyware, both free editions, and update and run them periodically. I also downloaded and installed SunMicro Java Update 15 and let them have a schedule checker in my start-up run menu....I guess that's a good way to keep current. But I heard somewhere that it was a bad idea, because worms or trojans can slip in through the mesh. Anyway.....

    No, I don't recall using a tool called "Pocket Kill Box" - unless you mean that

    KILLALL::
    Driver::
    BLHWBUQZ
    MAZM
    File::
    c:\docume~1\Owner\LOCALS~1\Temp\BLHWBUQZ.exe
    c:\docume~1\Owner\LOCALS~1\Temp\MAZM.exe

    stuff we ran inside ComboFix (dropped and dragged) text ???

    Yes, I uninstalled ComboFix with the Run > command, and it was successfully deleted.

    Ran the MGClean.bat file. Command screen blipped for a second, then wiped all those items off C:/ drive.

    Switched off 'system restore' on all drives, then purged all restore points. Rebooted, switched it back on, then created a new post-cleaning restore point.

    Have read the 'protect yourself from malware' article. I run AVG Free, my sole anti-virus, with real-time protection. I have SUPERAnti-Spyware and MalwareByte Free installed, and update and run scans weekly. I also use Sygate Free firewall. Spybot S&D and SpywareBlaster are the other apps running. On my start-up RUN menu are 3 items: AVG anti-virus, Sygate Firewall, and java update scheduler.

    Have had and use frequently CCleaner, a very good tool indeed.

    So there you have it. Any other advice or counsel - at this time ??

    Thanks again, and best wishes to all,

    -scottportraits
     
  6. scottportraits

    scottportraits Private First Class

    ....cruising along here, I find everything seems to be pretty ship-shape. My email server had some kind of 'incident', and we are still waiting for them to back-up stuff. Bad scene for them.

    The only thing that is wrong right this second is this: I use Mozilla Firefox, a better browser. I also use IE7 and Google's personal sign-in page as my homepage, iGoogle, featuring several different 'gadgets' that are supposed to script-down and run. One is a calendar, another a clock, and a moon phase dealie, and a weather picture, and several newspaper's top stories.

    Several of these gadgets will not 'run' when I launch my default, Firefox. I am signed in, but they won't download. Yes, I've checked my NoScript allowables, and the other obvious thingsm, but find no cause. Why blocked ??

    Launching IE7 I find they all download very nicely. But I hate to use IE except when necessary. Love Firefox. So, Help !!!

    -scottportraits
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I was not asking you questions. They were simply instructions for you to follow. The "If" part covers cases where we may not have had you run a certain step. ;)

    I cannot help you with your FireFox issues. I suggest that you post those questions in the Software Forum. All I would suggest is to uninstall FireFox, reboot, and then reinstall.
     
  8. scottportraits

    scottportraits Private First Class

    Okay, the rig seems pretty ship-shape now, so I will close this posting with a big thank you and a smile:-D

    :waveThanks chaslang:wave

    -scottportraits
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds