Here are my logs, help! (Part 1)

Discussion in 'Malware Help (A Specialist Will Reply)' started by BigBrother70, Feb 16, 2010.

  1. BigBrother70

    BigBrother70 Private E-2

    Hey all. This site has helped me once before and I love the thorough steps, so here I am again, albeit in a bittersweet moment :)

    I followed all the steps and am attaching my logs here just to be sure. I also took note of any abnormalities or idiosyncrasies I encountered along the way. Here they are:

    1. My machine is a MacBook running XP via Bootcamp. As a result, I have two partitions, one for each OS. I made the decision to only scan C:\ (the Win one) and not E:\, (the Mac one), in order to substantially cut down on scan time. I assumed given the different file systems this would be ok. If not, I'll go back and scan E:\ as well.

    2. Early in the SAS scan, I needed to pause to uninstall a huge .NET dev environment I forgot about to speed up the scan time. It needed a reboot. On reboot, even in safe mode, it would then stall at isapnp.sys- I could not get Windows going again. I did some searching online, and found a .sys file of zero size in system32/drivers, called uvxyy.sys or something to that effect. I deleted it, was able to start up Windows again normally, and restarted SAS normally.

    3. The SAS update didn't work, had to do it manually per the instructions.

    4. After updating SAS, there was some step where I had to restart it. But SuperANTISPYWARE.exe was now renamed SuperANTISPYWARE. exe (note the extra space before the extension). I renamed it back and it ran fine.

    5. Combofix asked me to update itself 2 or 3 times, and went through the process each time. Thought that was slightly weird.

    6. Early in the process, Combofix warned me that "cd emulation was on", and had to turn off.

    7. During Combofix, at the MS Windows recovery console step, I received this error message: "Boot partition cannot be enumerated correctly." Note however that I've run through this whole cleaning process before and Windows has since then always prompted me at boot up to choose between a recovery version and normal XP. In any case, I got that message this time from Combofix, clicked ok, and it kept working.

    That's about it. Attached are half the logs, I'll be posting the rest afterwards.

    Thanks a lot everybody- you really provide an invaluable service here!
     

    Attached Files:

  2. BigBrother70

    BigBrother70 Private E-2

    Here are my logs, help! (Part 2)

    As promised, here are the rest- MGLogs to be exact.

    Thank you so much!
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Why am I not seeing any anti-virus software?

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Driver::
    ._isapnp
    
    File::
    C:\Documents and Settings\Alex\Local Settings\Application Data\R4AlO7HdsW5
    c:\windows\system32\drivers\._isapnp.sys 
    C:\.fseventsd
    c:\windows\system32\drivers\isapnp.sys
    C:\Documents and Settings\Alex\Local Settings\temp\jna868.tmp   
    C:\Documents and Settings\Alex\Local Settings\temp\temp0.jar  
    
    Folder::
    C:\.fseventsd
    C:\Documents and Settings\Alex\Local Settings\Application Data\R4AlO7HdsW5
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  4. BigBrother70

    BigBrother70 Private E-2

    OK, couple of things:

    1. Thanks a lot for answering me Tim!

    2. Re: antivirus, I had AntiVir but deleted it sometime in the past few days, after the infection and before I ran the Major Geeks steps. I couldn't stand its interface or the way it operated, so I will soon get an alternative. Any recommendations? I read the thread on here, but it seems like most have caveats.

    3. You mentioned to tell you how things are working now- tough to say as they already appeared normal after I ran the battery of steps yesterday. So, in summary, no change from yesterday, when it was already apparently back to normal.

    4. ComboFix ran with all the same hiccups as before:

    Attaching logs here as requested.

    Thanks again for everything!
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The logs on this user account are clean. I would just like you to use windows explorer to find and delete:
    C:\Documents and Settings\Alex\Local Settings\temp\jna45933.tmp
    C:\Documents and Settings\Alex\Local Settings\temp\temp0.jar

    Now I suggest you log into the other user account that has Admin. privileges and run SAS and MBAM on that account. Let me know if it finds anything.

    If it doesn't, then it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to tahe cleaning procedures ian step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  6. BigBrother70

    BigBrother70 Private E-2

    Tim, when I reboot now, it hangs and says "Windows cannot start because the following file is missing or corrupt:

    C:\windows\system32\drivers\isapnp.sys"

    then a bunch of info on how to restore it from CD.

    I checked via Mac OS, and the file is indeed completely missing- I'm assuming from my last combofix step.

    Please advise. I did have my brother email me his copy of that file- I can just copy that into the drivers directory, or do anything else you suggest.

    Thanks.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, copy it back into the drivers folder. That was a mistake on my part and I apologize.
     
  8. BigBrother70

    BigBrother70 Private E-2

    Hey Tim.

    So, SAS is acting strangely. In fact, I can't run it at all (and this is under the main account I've been using all along).

    The folder in the start menu only has three items - BootSafe, SAS Alternate Start, and SAS Help.

    Running the Alternate Start brings up a message: "Unable to locate SAS program files."

    Navigating to the actual dir. in Program Files, I tried running RUNSAS.exe, also got the same error.

    I tried uninstalling and reinstalling it multiple times. In each case, no desktop icon is created, and no other executables become available in either the start menu folder or the program files folder than those I already mentioned.

    Erg?
     
    Last edited: Feb 18, 2010
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try this LINK and scroll down to the technical issues. See if you can get some help with that.
     
  10. BigBrother70

    BigBrother70 Private E-2

    Hey Tim. So we're not out of the woods yet :(

    On my main account (Alex), SAS was not running in any way shape or form. From this page:

    http://www.superantispyware.com/supportfaqdisplay.html?faq=71

    even RUNSAS.exe wouldn't work, I could only get it running with SASSAFERUN.com. It found nothing. It also refused to scan my E: drive (the Mac partition), even though it used to be able to.

    Then I tried MBAM. Updating would not work. So I simply ran it, and it found nothing.

    Then I logged into a different account (Aron). SAS would also not work with anything but SASSAFERUN.com. It found two problems and cleaned them, but it asked me to reboot and afterwards, there was no log to save for you since, I assume, it's a self-contained executable without an installation and thus no log-saving capability. This was what it found, to the best of my recollection:

    Browser Hijacker.Internet Explorer Zone Hijack
    Trojan.Agent/Gen-FA[SMSS32]

    I believe it found them in the C:\QooBox directory.

    Under this account (Aron) it also would not scan E:\ for some reason, even if it was selected.

    On a slightly brighter note, MBAM did run and update under Aron, and it found and cleaned some stuff. Log attached here.

    Sigh, so what do I do now?

    Thanks a lot for your help,
    BB
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, something was in your IE trusted zone, but got removed. It may be why you couldnt install SAS or get it to run properly.

    Re-download MGTools.exe and run it and let me see the new logs, please.
     
  12. BigBrother70

    BigBrother70 Private E-2

    Tim, I ran MGTools as you said. I did it under Alan, the main account. MGTools.zip is attached here.

    Of interest:

    You'll see the Qoobox directory is still in MGTools.zip, including the CF script. They were dated from three days ago (2-17). The only reason they're now 2-20 is because I had to move the archive around before attaching it.

    Also, the combofix.txt file was dated 2-17. If you open it up you'll see the timestamp.

    So for some reason these two files - combofix.txt and the Qoobox directory/CF script file both made it into MGTools.zip today but were not made today. Weird?
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Don't worry about the Combo logs. They will get collected by MGTools. So not an issue.

    Let's do this and see if it will get your SAS working again:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\system32\sazakawe
    C:\Documents and Settings\Alan\Local Settings\temp\jna21823.tmp
    C:\Documents and Settings\Alan\Local Settings\temp\jna32497.tmp
    C:\Documents and Settings\Alan\Local Settings\temp\jna54631.tmp
    C:\Documents and Settings\Alan\Local Settings\temp\jna63129.tmp
    C:\Documents and Settings\Alan\Local Settings\temp\jna63805.tmp
    C:\Documents and Settings\Alan\Local Settings\temp\SAS_SelfExtract
    C:\Documents and Settings\Alan\Local Settings\temp\temp0.jar
    C:\Documents and Settings\Alan\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\SUPERAntiSpyware Scan Log - 02-16-2010 - 13-54-42.log
    C:\Documents and Settings\Alan\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\SUPERAntiSpyware Scan Log - 02-16-2010 - 16-04-40.log
    C:\Documents and Settings\Alan\Desktop\SASDEFINITIONS.EXE
    C:\Documents and Settings\Alan\Desktop\SASSAFERUN.COM
    
    Folder::
    C:\WINDOWS\system32\sazakawe
    C:\Program Files\SUPERAntiSpyware
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now reboot and run CCLeaner, both the cleaner and the registry ( make sure you do the backup when prompted).

    Now see if you can download and run SAS.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  14. BigBrother70

    BigBrother70 Private E-2

    Hey Tim- first off, thanks again for your continued help. *So* very appreciated!

    Ok, good news- both SAS and MBAM installed, updated, and ran without a hitch or any detection.

    Attached are the two files you requested.

    I'm going to do full scans with the other account (Aron) while you check these out, just to see if they turn up with anything.

    Let me know how these look, and thanks,
    BB
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just some junk to remove, so copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Make sure to run CCLeaner.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to tahe cleaning procedures ian step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  16. BigBrother70

    BigBrother70 Private E-2

    Excellent Tim- the registry step worked.

    Every possible scan I tried turned up nothing, under both accounts.

    Thank you very, very much! Two last things:

    1. How can I help you out via thanks or recognition? Looking here for what I can do to highlight your commendable (volunteer!) work in helping me through all this.

    2. Which anti virus do you personally use/recommend? I was using AntiVir for a bit and hated it. Thoughts?

    Thanks again!
    -BB
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. If you want, you can support the site by just purchasing a t-shirt. ;)

    I have used AVG ( before it got so bloated), Avira, Avast and now Microsoft Security Essentials as tests. But my surfing habits are probably not yours. Plus I know what to click on and what not...LOL> so it comes down to which AV program you feel comfortable with, keeping it updated and periodically doing scans with SAS and MBAM to keep yourself clean.
     
  18. BigBrother70

    BigBrother70 Private E-2

    I gotchya. To be honest, the two times I've needed this site's help were from very deliberate clicks on either torrent info sites or the like. Both times have caused me to change my browsing habits, so I guess I'm kind of in your boat now. In other words, I've found it's quite a simple formula: bad = bad ;)

    Thanks again for your help!
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, I would say that 99% of the threads I deal with have a torrent program installed. Makes you wonder.

    And you are very welcome.
     
  20. BigBrother70

    BigBrother70 Private E-2

    Since we're already chatting...

    This was precipitated by simply going to piratebay.org. No joke- no torrents, no ad clicks, nothing. Typed it in, went, and BAM - a literal torrent of junk infestation.

    Now, I know in general the world of torrents is a wretched hive of scum and villainy, but I had always assumed pirate bay was at least the whitest hat wearing of the bunch. Or is this a case of the hackers being hacked (?)
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    roflmao.......I wouldn't be surprised!! Do you have WOT or McAfee Site advisor installed on your browsers? Plus, if the torrent program is set to run on startup....your system is already open to invasion. :major
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds