Malware logs

Discussion in 'Malware Help (A Specialist Will Reply)' started by paulhalf, May 19, 2013.

  1. paulhalf

    paulhalf Private E-2

    Hope I'm postig this in the right place!

    I've worked through the READ ME FIRST thread and worked through all the steps. The logs are attached.

    The problem I continue to have is that I can't donwload any files via either IE or Firefox. So - I go to a site and want to download a document and I get a message - "this file contained a virus and was deleted". This message is called from the browser NOT from anti-virus software. I don't get it if I open a pdf in a seprate browesr window and do the usual "save as". I get a similar message in firefox, and the effect s the same - attempted downloads are deleted.

    You'll notice that the MalwareBytes log shows no infection - HOWEVER, before I came to MajorGeeks I ran MB and it found five infections which I removed. THE DOCUMENT DOWNLOADING PROBLEM WAS RESOLVED, UNTIL I REBOOTED WHEN IT RETURNED - MAKING ME THINK IT'S A MALWARE ISSUE. That's when I came here. I still have the log from a few days ago which identified the malware - I can post that earlier log if required.

    Hoping you're able to help - and many thanks for your time. View attachment HitmanPro_20130519_1935.log

    View attachment mbam-log-2013-05-19 (15-20-14).txt

    View attachment RKreport[1]_S_05192013_02d1231.txt

    View attachment TDSSKiller.2.8.16.0_19.05.2013_19.12.11_log.txt

    View attachment MGlogs.zip
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Uninstall the below very old versions of software:
    Java(TM) 6 Update 37
    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - (no file)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O4 - HKCU\..\Run: [dertm] "C:\Windows\System32\rundll32.exe" "C:\Users\Paul\AppData\Roaming\dertm.dll",GetFunction2
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)

    After clicking Fix, exit HJT.

    Please download OTM by Old Timer and save it to your Desktop.
    • Run it by double clicking on it (Note: if using Vista, Win7, or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Users\Paul\AppData\Roaming\dertm.dll
    C:\Users\Paul\AppData\Local\Temp\launchie.vbs
    C:\$recycle.bin\S-1-5-18\$af371bd003a32cd7f7e5648814b76cfb\@
    C:\$recycle.bin\S-1-5-21-2377422814-4180449838-3438438577-1001\$af371bd003a32cd7f7e5648814b76cfb\@
    C:\$recycle.bin\S-1-5-18\$af371bd003a32cd7f7e5648814b76cfb\U
    C:\$recycle.bin\S-1-5-21-2377422814-4180449838-3438438577-1001\$af371bd003a32cd7f7e5648814b76cfb\U
    C:\$recycle.bin\S-1-5-18\$af371bd003a32cd7f7e5648814b76cfb\L
    C:\$recycle.bin\S-1-5-21-2377422814-4180449838-3438438577-1001\$af371bd003a32cd7f7e5648814b76cfb\L
    C:\$recycle.bin\S-1-5-18\$af371bd003a32cd7f7e5648814b76cfb
    C:\$recycle.bin\S-1-5-21-2377422814-4180449838-3438438577-1001\$af371bd003a32cd7f7e5648814b76cfb
    C:\Windows\Temp\*.*
    C:\Users\Paul\AppData\Local\Temp\*.*
    :Reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "dertm"=-
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{043C5167-00BB-4324-AF7E-62013FAEDACF}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{924A0AF3-8D4D-4D3A-9EC1-98F61B2295BB}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9B1A1BD0-4FA7-4C43-BF68-9451AA26A2C2}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{80922ee0-8a76-46ae-95d5-bd3c3fe0708d}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\s]
    [-HKEY_USERS\S-1-5-21-2377422814-4180449838-3438438577-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXTlog
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. paulhalf

    paulhalf Private E-2

    OK, gone through all that - the logs are attached.

    However I am still getting the same message when I try to download anything from the web - ""file" contained a virus and was deleted". As I said in my original post, this seems to be called from the browser rather than any antivirus or anti-malware programme.

    Sorry its taken me a couple days to reply - I had to borrow another machine to download the fixes!

    Again, many thanks for your time.


    View attachment 05232013_093704.log

    View attachment JRT.txt

    View attachment MGlogs.zip
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall AVG 2013 and then reboot. After reboot, continue with the below.


    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. paulhalf

    paulhalf Private E-2

    Thanks chaslang

    I've attached the log - I still have the same problem though. I'll avoid going on the web until I've reinstalled AVG - I'll keep it off until I've run all your fixes?

    Again, thanks for the time.

    View attachment MGlogs.zip
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which problem is that? The last fix resolved the problem I saw related to networking. Previously you had the below issues in your logs. See the red highlight.
    Code:
    =====================================================================================  
    Checking Base Filtering Engine Service State and Dependencies 
    [COLOR=red][B]Base Filtering Service               is NOT running[/B][/COLOR]  
            C:\Windows\system32\bfe.dll exists  
       Remote Procedure Call {RPC}- Service is running  
       DCOM Server Process Launcher Service is running  
    =====================================================================================  
    Checking Windows Firewall Service -MpsSvc- State 
    .
    [B][COLOR=red]Windows Firewall Service is NOT running[/COLOR][/B]  
            C:\Windows\system32\FirewallAPI.dll exists  
    =====================================================================================  
    Checking Windows Firewall Authorization Driver Service -mpsdrv- State 
    .
    [B][COLOR=red]Windows Firewall Authorization Driver Service is NOT running[/COLOR][/B]  
            C:\Windows\system32drivers\mpsdrv.sys exists  
    =====================================================================================  
    These are all fixed now. Are you saying that you cannot connect to the internet? If that is true, power down your PC and make sure that all cables are connected properly to your router and modem...etc and make sure they are on. Then power up your PC again. If you are using wireless then try a wired connection.

    Did you run Windows Repair from your Desktop as requested? Did it run all the way thru to the end and did you select all the options requested? I did not see the typical repair logs it would create when run.
     
  7. paulhalf

    paulhalf Private E-2

    Hi Chaslang

    no, the problem I have is that I can't download content from websites - for example, I had to use another machine to download the various programmes you instructed me to use. I can't download documents either.

    In Explorer I get a message saying that "the file contained a virus and was deleted", and in Firefox I get a message saying there was an error - the file has been deleted. These messages seem to be called from the browser, not from any anti virus or security software.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is AVG still uninstalled? Is your Windows Firewall enabled or disabled? If enabled see if disabling it changes anything. Also note that during our process, we requested that you disable UAC and leave it disabled. Per your logs, I see it is enabled.

    Run the below on Firefox:

    Reset Firefox to Defaults

    Does this help with Firefox
     
    Last edited: May 27, 2013
  9. paulhalf

    paulhalf Private E-2

    Chaslang - reading through the forum this guy - http://forums.majorgeeks.com/showthread.php?t=277008 - seems to have the same problem as me?

    In answer to your questions - I've reinstalled AVG Free. The problem persisted when there was no AV software.

    Windows Firewall was on. I've switched it off, but the message still comes up - "[this file] contained a virus and was deleted".

    Re the UAC - could've sworn I switched it off! I've done so now - and still the same problem. If I didn't switch it off during your various repairs could that have affected their effectiveness?

    Re Firefox - I reset to the factory settings, and it still won't download files. The error message I get is "file cannot be found". I've just tried it on four or five very different sites, including my own project management site (Binfire) and I can't download documents from any of them.

    As I said at the top, I would have assumed it was a settings problem if it weren't for the fact that it seems to affect both of my browsers?

    Many thanks again.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Has similarities but his infection is obviously still present and when present, it could cause this problem. Your infection is apparently gone, but there is still residual damage.

    I noticed that the Windows Defender service entry has also been deleted from the registry. Let's see if we can fix this and see if it has any affect. Since you reinstalled AVG, you need to disable it before continuing:


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
    Now reboot your PC. After reboot, run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).





    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!

    I have a feeling the above will not change anything. We may need to delete Windows Defender folders. I'm wondering it it got infected. In fact if the above does not help, our next step will be to try renaming the Windows Defender folders ( there are a few on x64 ) to see what happens.
     
    Last edited: May 29, 2013
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  12. paulhalf

    paulhalf Private E-2

    Hi Chas

    ok, I've attached the log from after I'd run your fixme.reg fix. I've downloaded the beta fix and I'll run that too, then run the MGtools again and post that.

    All the best!

    View attachment MGlogs.zip
     
  13. paulhalf

    paulhalf Private E-2

    OK, I've now run the malware bytes rootkit removal beta. I've attached the log from the beta, plus I've run the MGtools.bat as well.

    And the downloading problem has gone! Huzzah!

    View attachment 199508

    View attachment 199509
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you did not make valid attachments. I would still like to see them.

    However we can also continue on with the below now.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  15. paulhalf

    paulhalf Private E-2

    Whew! Done all that. Many thanks again Chaslang.

    I notice there is no donate button on the site. Drop me a PM if there's a charity you like supported and I'll send them a few bucks by way of thanks.

    This is a great service you people provide and I'll bet everyone who benefits is grateful. There's no way I could have fixed my problem myself and it was having an impact on my business.

    Have a good day - I've attached the MBAR log again.

    :)

    View attachment mbar-log-2013-06-02 (09-38-55).txt
     
    Last edited: Jun 5, 2013
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you wish, either of the two are in my favorite charities ;)
    • American Cancer Society
    • Make A Wish Foundation
    Thanks!
     
  17. paulhalf

    paulhalf Private E-2

    OK, done.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Excellent. Thanks! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds