Check my logs, please

Discussion in 'Malware Help (A Specialist Will Reply)' started by Lydster, Jan 18, 2006.

  1. Lydster

    Lydster Private First Class

    I ran through ALL steps in your READ THIS FIRST post. I've got a Sony Vaio laptop running WIN2000 Pro. The user says that he's getting pop-ups all the time when on the internet, but he couldn't be more specific than that. I went thru all the steps with no problem. (I even ran the special WinFixer program under "Special Removal Procedures" because the one thing the user did mention was getting a WinFixer pop-up often.)

    Could you look at the attached logs from BitDefender, Panda, and HJT and let me know if you think I still have anything left to get rid of?

    Thanks for your help?
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure you ran CCleaner? I'm surprized it did not delete all the C:\FOUND.000\FILE00xx.CHK files. These are really temp files created from scandisk/chkdsk.

    You should just delete all those FILE00xx.CHK files yourself unless the user is saving them for some reason.

    Also delete the below:
    C:\Documents and Settings\Trey_Warman\Local Settings\Temp\iinstall.exe
    C:\Documents and Settings\Trey_Warman\Local Settings\Temp\cfout.txt
    C:\Documents and Settings\Trey_Warman\Start Menu\Programs\Power Scan

    Do you know what the below suspicious item is:
    O4 - HKLM\..\Run: [Yvnkr] C:\Program Files\Ktnboc\Tfvg.exe
     
    Last edited: Jan 18, 2006
  3. Lydster

    Lydster Private First Class

    Yes, CCleaner is the first one on the list -- I'm pretty sure it was the one with all the check marks in the left nav panel within the program (deletes temp files, IE history, and a bunch of other stuff.). I will run it again, if you think I should. Or should I just run "cleanmgr" at Run? Will it accomplish pretty much the same thing or not?

    I'll delete the others you mention.

    Regarding Ktnboc\Tfvg.exe, I have no idea what this could be. It rings no bells with me as being a legit program that our agency runs; however, I'm not the regular user of this laptop. As this is a company-owned laptop (and if I don't recognize this as a necessary program), what do you think of me removing it?
     
  4. Lydster

    Lydster Private First Class

    I just ran CCleaner again, and apparently it did the trick this time (I don't know what I did wrong last time). It removed a huge amount of stuff, and when I went to look for those files you mentioned in order to delete them, they don't seem to be there.

    Here's another HJT log.

    Thanks.

    (Let me know what you think about that weird Program File you mentioned before.)
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I really did not need another HJT log. Nothing was changed.

    READ THIS WHOLE MESSAGE BEFORE DOING ANYTHING!

    Yes I would have HJT fix the below line:
    O4 - HKLM\..\Run: [Yvnkr] C:\Program Files\Ktnboc\Tfvg.exe

    It may or may not delete the file. If it does not delete the file, just goto the C:\Program Files\Ktnboc folder youself and rename the Tfvg.exe file to Tfvg.xxx

    You may have to do the rename after HJT has fixed the line and you have rebooted.

    Then see how things are running without that process loading.

    As an alternative before doing the above, you could submit that file to this online file scanner site to see what the scanners say about it:

    http://www.virustotal.com/flash/virustotal_en.html
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds