Defining Malware?

Discussion in 'Malware Help (A Specialist Will Reply)' started by JimLL, Apr 2, 2011.

  1. JimLL

    JimLL I can't follow the rules

    XP Pro, SP3, current updates, ThinkPad T60p, 3 gigs memory, a formerly undamaged brain

    Although I know of no common anti-malware software that will touch rootkits, my searches here would seem to indicate that MG includes them in the malware category.

    I have reason to believe I may have a rootkit. For one thing ZoneALarm keeps disappearing. I _may_ have reason to believe that the Zlclient PF file had a problem - whether or not that could apply. ZA _seems_ stable since I deleted the PF this evening in response to RootlkitRevealer data.

    Another reason is that RootkitRevealer shows a whole block of report lines on the same date.

    The Sophos Anti-Rootkit recommended here finds absolutely nothing, while the microsoft RootkitRevealer shows 17 lines of results in far less scanning. It showed only 2 the last time I ran it, and those are said to be "normal" false positives.

    I know this is only once-over-lightly, but I'm not certain I'm even in the right place to ask about this, nor do I have any experience that would tell me how to even ask the right questions about rootkits. I've only known they exist for maybe a year.

    But here is one specific question.

    - - Is it normal for HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\System\ to be unopenable using regedit? - -

    I don't want to go on a wild goose chase if none of this is looking at least within possible reason. Comments? Answers? Questions?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The your starting point is this >>> READ & RUN ME FIRST. Malware Removal Guide


    If you meant you have only know about them for a year well that just means you have not been reading up on security tips. ;) If you meant they have only existed for a year, this is not true! The first rootkit type infection occurred around 1986 although much different than modern ones. More modern ones started occurring in 2005 and have grown in complexity and frequency since then.


    On Windows XP, the registry key you mentioned, does not normally exist.
     
  3. JimLL

    JimLL I can't follow the rules

    In all seriousness I should say that I may have heard about them. Since my stroke, my memory is all shot to bits. That also makes getting through procedures difficult, because I can't remember much of the things I'm told to read.
     
  4. JimLL

    JimLL I can't follow the rules

    My first reply following read me first procedures.
     

    Attached Files:

  5. JimLL

    JimLL I can't follow the rules

    Second report.

    The engine @ conduit.com extension reported in gooredfix.txt does not appear in Firefox addons.
     

    Attached Files:

  6. JimLL

    JimLL I can't follow the rules

    OK, I have removed all of my free AV programs, but I had let NONE of them install background guards on the system. They were available as backup scanners only. Only my subscription anti-malware was running constant-watch processes on system functions, looking for suspicious system uses and internet surfing blocking dangerous sites listed on a long and growing list.

    I have carefully watched the likes of Zone Alarm which would install system guards on top of anything else if you aren't on top of it.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run this >>>> READ & RUN ME FIRST. Malware Removal Guide not the Google Redirection sticky that you are running. Step 1 of the READ & RUN ME tells you to run the Google Redirection procedure if you are having google redirection problems and that was not what your problem is and thus you should not be running that.
     
  8. JimLL

    JimLL I can't follow the rules

    I am running the READ & RUN ME. When I got to the redirection thing I did it because Firefox had refused to run some things based on some redirection problem (which problem IE will sail right through).

    I am now way beyond that, trying to run SuperAntiSpyware. SAS is one of the AV's I removed, per instructions. I had never had a moments trouble from it before, but now either the regular version or the portable version will only run for about 15 seconds then disappears.

    MalwareBytes is another AV I removed per instruction. I usually ran it about once a week without problems. Should I skip SAS and go on to MalwareBytes?

    BTW, ZA is still disappearing.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm a little confused by your terminology. Do you mean Firefox would not run? Or do you mean that Firefox ran but when you tried to browse to some partiular websites you were redirected to different websites?

    In your first message you were asking about rootkits. You did not say anything about having redirection problems.

    SUPERAntispyware is not an antivirus program. It is an antispyware program. It needs to be installed not uninstalled inorder to run the cleaning instructions. However if you are having a problem running it, then just skip it and continue as instructed in the READ & RUN ME.

    Also not an antivirus program and we do not ask you to remove it. We actually ask you to keep this and also keep SUPERAntiSpyware.

    Yes ;)
     
  10. JimLL

    JimLL I can't follow the rules

    On some sites Firefox would say the redirection involved would never conclude - or some such word. I got the impression it meant it would go into some sort of endless loop. Firefox would not even attempt to load the site.

    Don't skip this! ;)

    In my OP I specifically stated that it was a once-over-lightly post. I still have no idea _if_ it involves rootkits. I used to be good with this stuff, but now not so much. That's why my system statement included having "a formerly undamaged brain." I remember some stuff (sometimes) and forget some stuff (usually), but there never seems to be a way to explain _briefly_ that I'm now generally computer savvy and have a vocabulary not common among dummies, but that a lot of my computer knowledge has just disappeared - in apparently random fashion. And my memory is sometimes good for about 3 minutes.

    A trial lawyer saying, "You can remember this but not that?" is either a fool or simply being vicious. Everyone remembers some things and forgets some things.

    I was basically asking if the issue warranted looking into. I know most support forums want expert questions, but when I don't know spit about what's going on I don't know what to say about it. I could go on forever and never give you what you needed to know. So I try to give a general outline so someone will know if it's worth asking me specifics. I was surprised when you immediately started me on READ & RUN.

    There have been other problems as well, but I never know whether to think, "That's seems odd," or think, "That is a sure sign of (whatever.)" I haven't found a forum yet that seems to grasp the fact that a non-expert cannot ask complete/expert questions despite "Ask This Way" readme's. Now I can't bring to mind those other problems.

    You obviously know about such nuances.

    You are apparently referring above to MalwareBytes. I'm sorry I missed anything saying these should be kept. I went very slowly trying to cover every detail.

    There are many Anti-xxx programs out there with many odd names. My subscription anti-xxx program does viruses, spyware, cookies, dangerous site warnings, suspicious system events and what else. With every company trying to do everything I had no idea the names of _any_ of the programs could actually mean _anything_.
    I finally got something out of SAS.

    It took me hours to get MalwareBytes to scan. Like SAS, it would run about 15 seconds and disappear. I kept uninstalling, renaming, re-installing until it finally ran this morning. But I don't know where I am in the instructions so I won't include those two logs with this post.

    I think those crap writers have read your renaming instructions and are writing extra code to handle it.
     
    Last edited: Apr 4, 2011
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on what you initially posted, there was nothing that would necessarily make me think you had a malware problem. However, when a user believes something has changed in the behavior of their PC, there is normally some reason for the change. The best way for us to determine whether it is malware related or not is by having the READ & RUN ME completed and have the logs posted for us to make our decision.

    Yes because of what I said above.


    Expert questions don't need to be asked. We just need to exact specifics of problems being experienced. And in most cases, the best way for us to still make a better determination of what may be going on is to have the READ & RUN ME completed since it not ony allows us to either find and remove malware but it also helps us collect a lot of other information that helps us to address many other possible issues. Like explaining why a PC may seem slow to boot up or may be slow during normal operation. Or even why a PC cannot connect to the internet which may not have anything to do with malware......etc.

    Once you complete the READ & RUN ME and attach the logs we ask for, I can attempt to access whether you are having malware problems or not. It may even be necessary that a couple other additional scans from other tools will be needed. This all depends on how many tools from the READ & RUN ME you get to run and have the logs for.
     
  12. JimLL

    JimLL I can't follow the rules

    I'm not trying to be funny here. To me exact specifics are expert. Knowing which to post is as well.

    I'm still working on it. Right now I'm having a lot of trouble getting combofix to work. The "self-propelled" Recovery console download/installation fails, so I'm trying to figure out how to get it off the internet. Everything I've found at MS is all talk and no downloads.

    ComboFix's access to the registry hasn't worked. The error seems to be saying regedit couldn't open it, but it works for me using Start\Run.

    Here are some of the other problems that have popped into my head. I'm assuming you still want them.

    1. Trouble uninstalling apps with "Add or Remove".
    2. A clipboard utility lost all of its config and failed at resetting them until reboot.
    3. Screen zoom in Firefox quit working until reboot.
    4. Wordpad keeps losing its position/size data.
    5. My wireless printer connection quit and I can't even reinstall it. Reboot didn't help that.
    6. I lost my MagicJack screen display to off the screen - my fault. But there was a screen flash/dance and suddenly the display was back onscreen, so that was a good fluke.
    7. Several times I've had a program jump to a sub-routine _AS IF_ I had already selected it from a pick list. It seems to read my mind....
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just continue on as stated in the READ & RUN ME.

    Nothing here is really sounding like malware. These could just as easily be problems with Windows. And # 7 could just be a keyboard or mouse issue. Still need to see logs in order to form proper assessment.
     
  14. JimLL

    JimLL I can't follow the rules

    OK, I think I'm done. In passing - if I had skipped on to the next thing as advised I would have nothing to send.

    That is to say, every single one of the programs on the roster refused to run at least once, often requiring un-installation and attempt after attempt to get results in some cases.

    Yesterday I had the most recent "problem." I don't know if it comes under your category of "probably not malware." I have a folder named "newdown" I have used forever to download files into, with half a dozen folders inside it, including "Installed," "Hold" and "Waiting."

    _Everything_ in the newdown folder just disappeared yesterday sometime, I don't know when. Files, folders, files in folders...

    Of course there are the "problems" mentioned above when the antibug programs stopped running repeatedly. Some ran for several seconds; some ran almost to completion.

    RootRepeal went almost to the end and stopped on an error. This prevented any report.

    Combofix skipped over something (register manipulations?) with an error saying "Registry Editor failed." I don't know if Registry Editor means regedit or not.

    So here goes with the log attaching.
     

    Attached Files:

  15. JimLL

    JimLL I can't follow the rules

    One more log.
     

    Attached Files:

  16. JimLL

    JimLL I can't follow the rules

    I just recalled another problem which someone (right here?) said I was pretty much an idiot for not realizing it was malware. That brought me here after running 6 different malware programs and finding nothing.

    The Desktop tab disappeared from my Display Properties window. It took several days to cure that one.
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well let's just do this and see how things play out from there.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O2 - BHO: Babylon IE plugin - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - (no file)
    • O3 - Toolbar: ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - (no file)
    • O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - (no file)
    • O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
    • O23 - Service: IYLWS - Unknown owner - C:\DOCUME~1\User\LOCALS~1\Temp\IYLWS.exe (file missing)
    • O23 - Service: OAMVOD - Unknown owner - C:\DOCUME~1\User\LOCALS~1\Temp\OAMVOD.exe (file missing)
    • O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe (file missing)
    After clicking Fix exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    Remote Packet Capture Protocol v.0
    IYLWS
    OAMVOD
    File::
    C:\DOCUME~1\User\LOCALS~1\Temp\IYLWS.exe
    C:\DOCUME~1\User\LOCALS~1\Temp\OAMVOD.exe
    Folder::
    C:\Program Files\WinPcap
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know of any problems you may have encountered with the above instructions and also let us know how things are running now!
     
  18. JimLL

    JimLL I can't follow the rules


    • None of the items you listed seem to be in the analyse.exe listing. There is one similar to the O16 one above. It starts with DPF: {E but the rest of the numbers are different with 2883E8F, etc.

      I may have seen them at one time, but I had to reboot and they aren't there now. The reboot was __extremely__ slow. The boot logo screen was up for about 3 minutes, as opposed to mere seconds. Other things were correspondingly slow. I thought my machine had gone belly up because the black screen before the blue screen was showing for about 6 weeks.
     
  19. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Please complete the rest of Kestrel13!'s instructions.

    dr.m
     
  20. JimLL

    JimLL I can't follow the rules

    Attached are the logs.

    Possibly related question: Is there normally a folder in c:\ named IBMWORK (c:\IBMWORK)? I found the c:\newdown folder mentioned earlier _in it_ (c:\IBMWORK\newdown) - and an _empty_ folder of the same name (c:\newdown)in its place in C:\. I can imagine accidentally dragging newdown up into an existing IBMWORK folder (altho my dragging mistakes are invariably _down_), but not having it replaced with the empty folder. (c:\IBMWORK is now empty.)

    (The above happened some time during the process of following READ & RUN. It may or may not be related.)

    Once again running combofix produced 4 errors saying:

    ....."Registry Editor has encountered a problem and needs to close. We are sorry for the inconvenience."

    I noticed in the combofix log the following.

    "c:\docume~1\User\LOCALS~1\Temp\IYLWS.exe"
    "c:\docume~1\User\LOCALS~1\Temp\OAMVOD.exe"

    You probably know what it means but I decided to note that these files do not exist as listed above (or apparently anywhere on c:\).

    ZoneAlarm is still vanishing after maybe 10 minutes. If I restart it it lasts only about a second. I'm going to uninstall and reinstall it _again_.
     

    Attached Files:

    Last edited: Apr 7, 2011
  21. JimLL

    JimLL I can't follow the rules

    While doing READ & RUN, I was at one of the "somewhere else" sites listed there, that was also a malware removal site. They included combofix and said you should remove Recovery Console when done. But I've seen nothing like that anywhere else.

    Do you have an official recommendation about this?
     
  22. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    It is a useful tool to keep.
     
  23. JimLL

    JimLL I can't follow the rules

    Thanks. I figured as much.
     
  24. JimLL

    JimLL I can't follow the rules

    New popup

    Just since I've been doing the READ & RUN thing (apparently) I've had a new popup appearing when I try to run _some_ programs. It asks me if I want to run the program I just clicked on.

    Is there a writeup on this somewhere?
     
  25. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    *Moderator's note: Please do not create multiple threads relating to this machine's issues or the original topic of this thread.

    Thank You,
    dr.m
     
  26. JimLL

    JimLL I can't follow the rules

    If you would tell me what you are referring to it would help. If you mean the networking posts, I figured someone would get all PO'd if I put that in the malware department. Npow it's because I didn't.

    If it helps any, I _certainly_, _certainly_ don't have the brain power to do anything to the computer while my head is full of this mess. And I _have_ read cautions against it. While waiting for answers on the malware reports I thought putting my head onto another subject might reduce the brain stupor.

    If it's about the new pop-up, it came up with the malware stuff, so I asked if it was related for sure.

    I'm not sure what you are irritated about.
     
    Last edited: Apr 8, 2011
  27. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Yes, it's about the new thread in this forum that you created called "New Popup" (which was created in the malware removal forum). If that pertains a new issue that you are having with your machine being worked on in this thread "Defining Malware", then all replies concerning it should be made in this same thread.

    I am not irritated, that is one of our forum rules.
     
    Last edited: Apr 8, 2011
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This thread appears to be getting a little confusing due to too many people jumping with good intentions and trying to help. However it has just confused the issues.

    No malware has been found as of yet and it is likely that there isn't any malware to find. Problems with this PC may be due to the use of registry cleaners which I know you were warned about in the past in at least one thread in the Software Forum.

    As far as this "popup" that you are mentioning, it just sounds like a default warning from Windows that occurs when trying to run executable programs. This is just a normal warning. You may have checked the box in the window in the past to stop Windows from asking you this question. Running some of the tools in the READ & RUN ME will reset some Windows settings back to defaults as a safety precaution because malware often changes some of these same settings. Since it cannot be known for sure whether malware or you have changed the settings, defaults are just reinstated.

    And your ZoneAlarm problems could be just a corruption of ZoneAlarm or an issue from Emisoft AntiMalware and it not playing well together. You can just try uninstalling ZoneAlarm, rebooting and reinstalling.
     
  29. JimLL

    JimLL I can't follow the rules

    If not, at least I can get answers on that forum where the guy keeps telling me I DO HAVE malware. I don't even remember the forum or the issue now. Some forum dealing with a specific program.
    Is there any way to find out for certain? Speaking of which, is it your opinion that the registry should just grow indefinitely, or is there some other way to handle that?
    Thanks
    Thanks. I did that at least 6 times. The last time I did it (last night) I did _not_ run the update. It seems to have worked fine since then.

    I just discovered 5 items in Task Scheduler (c:\windows\tasks) apparently put there by software I tried out in the past, judging from the names. I assume they are intended to bug me about repeating previous trials. But it occurred to me to ask if these things could cause problems. In any case, can there be any repercussions from removing them - referring specifically to the ones named for software I tried weeks ago?

    And I don't know if it is relevant, but they all have an appended switch, "-shakeicon". And the tasks themselves have names like "prismshakeicon" and "expressburnshakeicon." I know my memory is shot to bits, but I'm certain I've never heard of shakeicons before.
     
  30. JimLL

    JimLL I can't follow the rules

    What would make almost all of those malware utilities in READ & RUN refuse to run? They would start then stop or error out. It took me hours on each one of them to get to the log output.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry but I don't know what you are referring too.

    No. Suggestion would be to reinstall and never use a registry cleaner or tweaker again.

    Yes and you really don't need to do anything with it. You will not see any noticeable improvements in performance by trying to reduce the size or by defragging the registry itself. Microsoft has even stated this in their own forums multiple times.


    Quite normal and things like this you can discuss in the Software Forum since they are not malware issues.
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You were able to run all of them eventually. Problems seem to either be with your Windows installation, conflicts with other software that is running, or with what you are doing.
     
  33. JimLL

    JimLL I can't follow the rules

    Reinstall XP Pro!?!?!?
    I guess nothing here was definitive about the absence or presence of malware. (I'm still holding off on major changes, per READ & RUN directions.)
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes.

    As stated previously, no malware was found in any of your logs thus far. We could run lots more scans which probably not find any true issues with malware. Possibly left over minor issues trapped in quaratines or in system restore would be found but those are justy resolved by emptying quaratines and toggling System Restore to disabled and then renabling.


    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. After doing the above, you should work thru the below link:
     
  35. JimLL

    JimLL I can't follow the rules

    Ah. If I had said "thus far" it would have meant I was still digging. So I thought you were still digging.
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We can do more digging if you wish, but I don't think we are going to find any real malware issues. If you would like to run some additional tests, you can work thru the below and attach the logs. I do suggest that you first complete my final instructions before doing the below.
     
  37. JimLL

    JimLL I can't follow the rules

    To the best of my knowledge I've done everything you said to do. At least I tried. Apparently you found something I missed?
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! I'm just responding what seemed to be a question from you about still looking for malware. That is, you still seem to think you have an infection even though we have not found any malware and I had stated that you don't appear to be having malware problems. Thus I was giving you the option to run additional scans if you wanted to still check further.
     
  39. JimLL

    JimLL I can't follow the rules

    Semantics. You say above "we have not found any malware. Earlier you said you hadn't found any _thus far_. I took "thus far" to mean you had farther to go. It's as simple as that.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds