Big Box Store says I have a keylogger + virus, I say no..

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by CAVUMark, Mar 18, 2011.

  1. CAVUMark

    CAVUMark Private E-2

    Followed the directions on the readme...

    Log files are below and attached. The non-standard log files are greek to me. The problem is my desktop acted up and just froze.. no keyboard or mouse activity allowed, monitor and video froze on last screen. Seemed to do it with Firefox but also with Outlook. I would need to reset numerous times which would result in just another freeze. I did install and uninstall Chrome a while back and did fix the redirect problem.

    Any assistance is greatly appreciated! Big Box store wants $250 to fix after I paid $70 for the analysis. The result was just spend more money, no useable information. Thanks.

    LOG FILES------------------------


    ROOTREPEAL (c) AD, 2007-2009
    ==================================================
    Scan Start Time: 2011/03/17 07:40
    Program Version: Version 1.3.5.0
    Windows Version: Windows XP SP3
    ==================================================

    Hidden/Locked Files
    -------------------
    Path: C:\hiberfil.sys
    Status: Locked to the Windows API!

    ++++++++++++++++++++++++++++++++++++++++++++++++++
    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org

    Database version: 6083

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 7.0.5730.13

    3/16/2011 11:45:26 PM
    mbam-log-2011-03-16 (23-45-26).txt

    Scan type: Full scan (C:\|)
    Objects scanned: 290472
    Time elapsed: 1 hour(s), 17 minute(s), 44 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    ++++++++++++++++++++++++++++++++++++++
    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 03/16/2011 at 10:22 PM

    Application Version : 4.49.1000

    Core Rules Database Version : 6613
    Trace Rules Database Version: 4425

    Scan type : Complete Scan
    Total Scan Time : 01:04:07

    Memory items scanned : 468
    Memory threats detected : 0
    Registry items scanned : 7118
    Registry threats detected : 0
    File items scanned : 29801
    File threats detected : 0

    +++++++++++++++++++++++++++++++++++++
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware on your system. I am curious about what they put on your system, so if you don't mind:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    DirLook::
    C:\Documents and Settings\All Users\Application Data\Geek Squad
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Attach the new Combo log.
     
  3. CAVUMark

    CAVUMark Private E-2

    As requested... new combfixlog.txt file is attached. Odd thing tonight I would get three pop up boxes for Security alerts, stating the pages I am about to view are secure and no data will be transmitted. This is before any browsers were opened or even considered to be opened. Odd this one.

    COMBOFIx did update to a new program and ran about 50 + checks and did shut down and restart the PC.

    I disabled MS security Essentails real time protection but it looks like the Antimalware Service Executable was still running. MSMPENG.exe

    Thanks for your input.

    Mark
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    They ran numerous scans on your system. You can look in this folder to see if they left any logs that might show some infection:
    c:\documents and settings\All Users\Application Data\Geek Squad

    I am not seeing any malware on your system.

    Please do this:
    eSet Online Scan.
     
  5. CAVUMark

    CAVUMark Private E-2

    Ran eSet online with the following results.

    C:\MGtools\Process.exe Win32/PrcView application cleaned by deleting - quarantined
    C:\System Volume Information\_restore{808F7ECE-97AB-4F44-8597-4DC63058AE48}\RP1440\A0209379.exe Win32/PrcView application cleaned by deleting - quarantined

    I still get the pop up box, Security Alert, You are about to view web pages over a secure connection... it continues until I close the box instead of pushing Yes.

    Checked Geek Squad's files and nothing significant was found, some tracking cookies only. I am going to ask for my money back.

    Thanks for your help.

    Mark
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The first is a false positive that we always get with Eset. The second can only be removed by toggling system restore. I have no idea why you are getting that security message. You might want to post in the software forum for that.

    Since you are not having any malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  7. CAVUMark

    CAVUMark Private E-2

    Thanks to Major Geeks. I have determined that I do not have a key logger but a bigger problem, probably hardware which I will enumerate in a new post.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The second is also a false positive of the same file in system restore. ;)
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I suggest seeing the below link:

    http://support.microsoft.com/?kbid=883740
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds