MG tool logs

Discussion in 'Malware Help (A Specialist Will Reply)' started by Atlantic44, Nov 29, 2011.

  1. Atlantic44

    Atlantic44 Corporal

    Hi Magor Geeks! I have been running the steps of malware removal because I believe I might have some. So I ran the GMtool that was in one of the steps, and successfully ran but during the scan I saw that it said "c:\windows\assembly\GAC_32\desktop.ini Access Denied"

    Why does it matter? Well my anti-virus(ESET 2012) has found the Same Thing in a scan and keeps saying it will "remove" it after thePC restarts, but it never does

    So can you guys looks at the logs, and maybe find some way to help with this problem? Thanks Guys!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to finishing running ALL of the READ & RUN ME FIRST and attach all of the logs. It is likely that you have a Zero Access infection.

    I don't know what you are typing to put these into your message, but you need to stop. They caused you message to be trapped in the SPAM filters. These are not valid or useful or necessary characters.
     
  3. Atlantic44

    Atlantic44 Corporal

    Sorry, must of been from my smileys on my custom keyboard. :) Thanks for the welcome. If I have the type of virus that you say, is that very bad? Also I want to run the root-kit detector but my system is 64bit, so what do I do there?
     

    Attached Files:

  4. Atlantic44

    Atlantic44 Corporal

    Ok, I ran the all the scans(except the root-kit one, since I have 64-bit) and I have the logs. All the problems seem to be fixed, and at least I know ESET is not screaming at me about some Trojan that it can't delete. :)
     

    Attached Files:

  5. Atlantic44

    Atlantic44 Corporal

    Is there anything else I should do now?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It looks like you recently installed STOPzilla! Did you purchase this to help you with your problems? If not, uninstall it now. It is not recommended.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - URLSearchHook: (no name) - - (no file)
    R3 - URLSearchHook: YouTube Downloader Toolbar - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - (no file)
    R3 - URLSearchHook: (no name) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - (no file)
    R3 - URLSearchHook: (no name) - {f689bafc-70f0-4550-9001-dc2a1cc8c0dd} - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: YouTube Downloader Toolbar - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - (no file)
    O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - (no file)
    O3 - Toolbar: YouTube Downloader Toolbar - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - (no file)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. Atlantic44

    Atlantic44 Corporal

    For some reason my C:\MGtools folder does not have the exe file for me to run. Does that mean I uninstalled it or something? Because I don't think I did. Anyway, what do I do now?
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you still have the C:\MGtools folder. Then the file is still there. It showed in your last logs. Make sure you are looking in the C:\MGtools folder. You folder listed the below in your logs.
    Code:
    ******************************************************************************
    C:\MGtools\                                                        
    [B][COLOR=darkred]----a-w           388,608 2010-04-23 07:18:58  C:\MGtools\analyse.exe[/COLOR][/B]
    ----a-w             6,806 2010-10-07 06:11:50  C:\MGtools\BamFix.bat
    ----a-w               372 2010-12-04 23:49:02  C:\MGtools\bamRCfix.txt
    ----a-w             6,146 2007-06-07 06:24:58  C:\MGtools\chodefix.bat
    ----a-w             1,954 2009-12-13 21:25:22  C:\MGtools\config.reg
    ----a-w             3,114 2011-10-14 02:54:22  C:\MGtools\DebugMGT.bat
    ----a-w               120 2007-08-02 04:13:18  C:\MGtools\DisableUAC.reg
    ----a-w            61,440 2008-08-07 20:27:00  C:\MGtools\download.exe
    ----a-w               120 2007-08-02 04:13:30  C:\MGtools\EnableUAC.reg
    ----a-w               202 2011-11-29 21:28:35  C:\MGtools\ffinfo.txt
    ----a-w             4,668 2011-11-29 21:30:56  C:\MGtools\filelog.txt
    ----a-w               320 2009-04-18 07:48:00  C:\MGtools\FindOVL.bat
    ----a-w             2,027 2010-08-14 20:40:22  C:\MGtools\FindRN.bat
    ----a-w             6,355 2011-11-05 17:19:08  C:\MGtools\FixACLS.bat
    ----a-w             1,588 2011-05-27 19:08:14  C:\MGtools\FixAttr.bat
    ----a-w             1,897 2008-07-10 06:50:46  C:\MGtools\FixBagle.bat
    ----a-w             3,765 2009-01-27 05:27:00  C:\MGtools\fixBagle.reg
    ----a-w             1,623 2010-12-04 23:42:06  C:\MGtools\FixbamRC.bat
    ----a-w             1,034 2009-01-14 05:28:26  C:\MGtools\FixCF.bat
    ----a-w               581 2009-01-03 02:44:16  C:\MGtools\fixCF.reg
    ----a-w               738 2007-06-07 06:14:42  C:\MGtools\fixChode.reg
    ----a-w               438 2008-12-29 06:29:42  C:\MGtools\FixFA.bat
    ----a-w            23,678 2011-05-27 18:35:44  C:\MGtools\fixFA.reg
    ----a-w             7,584 2011-08-31 04:41:22  C:\MGtools\FixPerm.bat
    ----a-w               439 2010-08-14 20:12:16  C:\MGtools\FixSBM.bat
    ----a-w            12,924 2006-12-04 19:20:56  C:\MGtools\fixSBM.reg
    ----a-w           245,760 2006-10-30 17:17:58  C:\MGtools\GetDetails.exe
    ----a-w            11,615 2011-11-09 05:03:32  C:\MGtools\GetLogs.Bat
    ----a-w             3,054 2010-12-24 02:38:20  C:\MGtools\GetMBR.bat
    ----a-w            24,236 2011-11-29 04:21:16  C:\MGtools\GetNetInf.bat
    ----a-w           121,455 2011-11-24 05:35:18  C:\MGtools\GetRunKey.bat
    ----a-w           256,984 2011-11-29 21:28:29  C:\MGtools\GetUnKey.txt
    ----a-w             2,949 2009-01-23 22:00:52  C:\MGtools\GetUnKeys.bat
    ----a-w            80,412 2003-04-14 06:00:00  C:\MGtools\grep.exe
    ----a-w           123,213 2011-11-24 05:35:16  C:\MGtools\GRK64.bat
    ----a-w               393 2009-06-23 03:48:06  C:\MGtools\hide.reg
    ----a-w            47,242 2011-11-29 04:24:30  C:\MGtools\history.txt
    ----a-w             6,606 2009-03-06 08:30:14  C:\MGtools\HTAfind.bat
    ----a-w             1,756 2004-04-03 00:44:50  C:\MGtools\IEFIX.reg
    ----a-w            11,254 2005-01-14 03:41:48  C:\MGtools\locate.com
    ----a-w            13,184 1986-10-28 17:51:06  C:\MGtools\ltime.exe
    ----a-w               220 2010-03-05 05:39:34  C:\MGtools\mbrfix.bat
    ----a-w             5,783 2011-09-17 18:01:04  C:\MGtools\MGclean.bat
    ----a-w            10,154 2011-11-23 23:22:16  C:\MGtools\MiscInfo.bat
    ----a-w             1,414 2011-11-29 21:30:56  C:\MGtools\newfiles.txt
    ----a-w            15,447 2011-11-10 16:59:14  C:\MGtools\NwkTst.bat
    ----a-w             1,200 2011-11-29 21:28:32  C:\MGtools\nwktst.txt
    ----a-w            53,248 2003-06-06 02:13:46  C:\MGtools\Process.exe
    ----a-w             6,656 2006-08-01 14:14:52  C:\MGtools\ProcessDll.exe
    ----a-w               145 2007-04-18 18:55:40  C:\MGtools\Regfix.bat
    ----a-w               497 2009-07-31 04:09:10  C:\MGtools\RemMWS.bat
    ----a-w            77,520 2011-11-29 21:30:55  C:\MGtools\runkeys.txt
    ----a-w               195 2009-06-16 03:01:52  C:\MGtools\RunMB.bat
    ----a-w                52 2011-11-29 21:28:29  C:\MGtools\scantime.txt
    ----a-w            98,816 2000-08-31 14:00:00  C:\MGtools\sed.exe
    ----a-w           116,652 2011-11-10 16:59:12  C:\MGtools\ShowNew.bat
    ----a-w           127,321 2011-11-10 16:59:18  C:\MGtools\SN64.bat
    ----a-w           156,160 2007-12-16 23:36:08  C:\MGtools\swreg.exe
    ----a-w            66,048 2007-12-16 23:47:26  C:\MGtools\swwhoami.exe
    ----a-w             5,841 2009-09-11 05:37:58  C:\MGtools\SysBU.bat
    d-----w                 0 2011-11-29 21:30:56  C:\MGtools\temp
    ----a-w               213 2007-08-03 22:11:38  C:\MGtools\unhide.reg
    ----a-w             1,755 2010-05-31 00:15:48  C:\MGtools\UnKeys.bat
    ----a-w             3,004 2010-05-04 04:11:18  C:\MGtools\UserInfo.bat
    ----a-w            49,152 2007-12-28 20:42:12  C:\MGtools\vfind.exe
    ----a-w               861 2007-12-28 21:16:16  C:\MGtools\VunFind.bat
    ----a-w           126,976 2005-01-14 03:41:50  C:\MGtools\zip.exe
     
  9. Atlantic44

    Atlantic44 Corporal

    I do still have folder, but it's not in it. The picture I put in my last post shows the contents of the folder. And there is no exe files in there.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The snapshot you attach appears to be a temp folder not the MGtools folder. Let's check it out. Click Start, Run, and copy and paste the below bold print test into the Run box and click OK.

    dir c:\mgtools > C:\filelist.txt

    Then attach the C:\filelist.txt file to your next message.
     
  11. Atlantic44

    Atlantic44 Corporal

    (Sorry, I meant for this to be an EDIT for my last post, you responded too fast. :-D) Well I ran MG tool again and the exe file showed up. So I ran it and found all the check boxes I could from the list you gave.(showed in the picture in this attachment) And I ran combofix and have the log for that too.
     

    Attached Files:

    Last edited: Dec 3, 2011
  12. Atlantic44

    Atlantic44 Corporal

    Also these two "hidden" desktop.ini files showed up on my desktop.(Had to rename them to desktop and desktop2.txt to post here.)
     

    Attached Files:

  13. Atlantic44

    Atlantic44 Corporal

    ESET has stopped complaining about the Trojan in the memory, and I don't seem to have the Google problem anymore. So am I good now?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These were not problems. They are part of Windows. You just never saw them before while you had hidden and system file viewing disabled.

    Your logs are clean.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  15. Atlantic44

    Atlantic44 Corporal

    I never saw the desktop files there before and I always allow me to view hidden files and folders so I can view the files if I need. So I don't know why I have never seen them before. Would it be a problem if I removed them you think?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But did you have viewing of system files enabled too.

    You don't need to but you can if you wish. One is for Windows and and the other was from Norton software you installed.

    These files are used to customize and adjust settings for the Windows folders where the file is located. The desktop.ini file can be safely deleted from any directory; however, this file may have settings associated with the folder that contains it. Thus deleting this file will change these settings back to default. So if the folder containing the dekstop.ini file has a different icon and you delete this file the default folder icon will be re-enabled.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds