could you look at these logs for me please

Discussion in 'Malware Help (A Specialist Will Reply)' started by Jan Scrivens, Sep 19, 2010.

  1. Jan Scrivens

    Jan Scrivens Private First Class

    Hello, could you look at these logs for me please?
    The main reason I did these scans was because I received about 20 'mail delivery system-delivery status notification (failure)' emails. I had opened a couple before I realized there were so many and that they opened onto a site picked up by McAfee as unsafe. I bounced them all back to sender and blocked the sender, ran CCCleaner then did a system restore. I am not actually noticing any problems yet but am worried that the system has been infected.
    I have worked through your 'Read & Run' instructions.
    I have included 2 SAS logs for you. The first was run before following your set up instructions, the second afterwards.
    I have attached the MBAM log.
    I am sorry but I got mixed up with the different instructions for Mgtools, so did some for W7 then jumped to XP. I did end up with a ziplog which I have included, but I then uninstalled MG tools and started again sticking to the W7 instructions. These 2 logs are attached to the reply post following this post.
     

    Attached Files:

  2. Jan Scrivens

    Jan Scrivens Private First Class

    Here are the 2 MGtools logs. Thanks for your help.:)
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  4. Jan Scrivens

    Jan Scrivens Private First Class

    Much appreciated. Thanks:)
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What do you know about this file? Any information in the properties of it when you right click it?

    • C:\Windows\˜óm

    Go to VirusTotal.com and upload the following file for analysis

    • C:\Windows\˜óm

    Could you please get this: ˜óm into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:

    log retrievable @ C:\collect.zip


    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :files
    C:\Windows\TEMP\CR_27FA.tmp
    C:\Users\rodjanria\Local Settings\TEMP\Low
    C:\Users\rodjanria\Local Settings\TEMP\svlm6.tmp
    
    :reg
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  6. Jan Scrivens

    Jan Scrivens Private First Class

    Thanks for the help. I have sent the file to 'virus tool' and attached it here for you as requested. I will now work through the rest of your instructions. Appreciate the help. Jan
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you let me know the results from virus total? Did any of the scanners report anything?

    Also if you have run the OTM script dont forget this part too afterwards:
     
  8. Jan Scrivens

    Jan Scrivens Private First Class

    Hello, this is what I have so far from Virus Total:-

    This is basic info regarding the sample itself and its last analysis:
    MD5: f9f4905664c5b42b49e78efa12d1a6b6
    Date first seen: 2009-04-22 23:01:10 (UTC)
    Date last seen: 2010-09-16 23:28:43 (UTC)
    Detection ratio: 0/43

    The fuller result sheet is attached.

    I have attached the OTM and MGtools logs as requested.

    Thanks, Jan
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  10. Jan Scrivens

    Jan Scrivens Private First Class

    Thanks very much for your help. I am sorry it has been so long before my reply but I've been on holiday.
    :) Thanks again, Jan
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're most welcome, Jan. Safe surfing. :)
     
  12. Jan Scrivens

    Jan Scrivens Private First Class

    Hello Kestrel 13!
    Just when I thought everything was fine, I have started having lots of problems again.
    I ran my regular scans on 4/11 and got some bad results.
    Firstly I ran CCleaner on windows and applications, and also ran the registry cleaner. I backed up before this and have this back up saved.
    I updated and ran SpywareBlaster.
    Next I ran SuperAntiSpyware which found 'Trojan.Agent/Gen-SSHNas[fake alert] in C/WINDOWS/SYSWOW64/SSHNAS21.DLL
    My McAffee routine scan found and removed a Trojan, but I have no details of it. It merely flashed up to say it had been removed and no further action was required.
    Then I ran MalwareBytes Anti-malware and have attached the report which identifies 12 infections inc Trojans.

    Apart from these scans, I have had 2 'blue screen' crashes in 24 hours and various things keep being flagged up as having 'stopped working' eg Skype; Incredimail; desktop.

    I have tried to do a back-up to an external hard drive which I have used for back-ups before, but the back-up will not complete, giving error code 0x800700001.

    I am quite worried now about what has and is happening. The laptop seems to be functioning as normal apart from these things. Can you help me please?

    Jan:confused
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to run and attach all the requested scans again.
     
  14. Jan Scrivens

    Jan Scrivens Private First Class

    Thanks for the reply and help.
    I'm sorry but I'm unsure which scans you mean. Should I work through the 'read and run me first' instructions?
    These problems have just started, and as yet I have not been asked for any specific scans.
    Jan
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, please repeat the steps in the Read and Run first instructions. Attach the requested logs;
    SAS
    MBAM
    ComboFix
    C:\MGLogs.zip
     
  16. Jan Scrivens

    Jan Scrivens Private First Class

    Because I cannot do a back-up, Ihave just tried to copy and save 'my documents', but when I highlighted the items to copy I got a pop-up box entitled
    MICROSOFT VISUAL C++ DEBUG LIBRARY
    Debug Error
    Program:/C:/Windows/ExplorerEXE
    Module:/C:/Program Files (x86)/EgisTec/MyWinLocker 3/x64/mwl shell ext.dll
    File:Run Time Check Failure[hash]2-Stack around the variable 'sz Temp' was corrupted.
    (Press retry to debug the application)

    I tried retry and got 'windows explorer stopped working'

    I will now work through R&R me first and post the logs asap.
    Thanks
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, like Tim says you will have to run the scans again. But please create a new thread before you attach logs as piggybacking off of this one will make it long and drawn out and difficult for me to follow. :)
     
  18. Jan Scrivens

    Jan Scrivens Private First Class

    OK thanks.
    Do I need to re-post the information I sent yesterday in the new thread?
    Do I need to entitle the new thread for your attention specifically, or name it something special?
    Do you want me to keep a copy of all the error messages I keep getting and send them also?
    Thanks again, Jan :confused
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Copy and paste it if it's easier.

    Just name it what you like. :)

    Yes.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds