Final inspection

Discussion in 'Malware Help (A Specialist Will Reply)' started by dadpad, Jul 26, 2009.

  1. dadpad

    dadpad Private E-2

    I have worked through the read and run me thread.

    superantispywear found no problems

    Malwarebytes found no problems

    attached are logs for combofix, mgtools and root repeal.

    Root repeal gave me the following messages
    could not load our kernel please contact author
    could not read the boot sector try adjusting the disk access Level in the options dialoge box
    device control error error code oxc0000001.
    Root repeal would not run in the files TAB. I have atached a crash report.

    I have become concerned that someone has access to my computer from a remote system but it is difficult to put a finger on why I think this might be so. sometimes i am unable to x out of browser, high cpu loads (but only occasionally not all the time) with task manager reporting multiple instances of google chrome being open.
    A browser game i play (evony) reported another computer had accesed my account
    Perhaps I'm just being paranoid.

    Thank you for taking the time to look. Please advise if i have not completed the appropriate steps or if you require further information
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, dadpad

    I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Our queue is working the oldest threads first.

    Thanks for your patience.
    dr.m
     
  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, dadpad

    It is normal for Task Manager to show Chrome 5 to 9 times depending on how many tabs you have opened.

    The below fixes are specific to your problem and should only be used for issue(s) on this machine. Also, please do not install any other software while we are still working with you unless instructed. Once we have given you the all clean and final instructions you will be free to install what you want.

    I strongly recommend that you clean up your Desktop [C:\Documents and Settings\Keith\Desktop ] immediately leaving only links. Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least it can have an effect on your PCs performance.


    *It is a very bad idea to give all users of this pc "Admininstrator Accounts".

    You need to double your installed RAM in this machine.
    Question: What can you tell me about this: C:\K.CWG

    Step 1:
    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it definitely did not work.

    Step 2:
    Using Windows Explorer - navigate to and delete:

    c:\program files\temp01

    Step 3:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!


    Step 4:
    There has been a new SUPERAntiSpyware version release:
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new "Quick scan" of your system then attach this new log.

    Step 5:
    Open MBAM and click on the "Update" tab and click the Check for Updates button. After it has updated, click on the "Scanner" tab and then "Perform quick scan". Attach this log.

    Step 6:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • C:\MGlogs.zip
    • updated SASlog.txt
    • updated MBAM-log

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
  4. dadpad

    dadpad Private E-2

    Thank you for taking the time to assist.

    Noted. Is it possible that some of the ram is not working correctly? Can you reccomend a method of checking the RAM.

    Thank you for your advice. I have removed a few files that i no longer require.

    i will explore options, however this is the only way i am able to give all users reasonable access. All users are adult members of my family.

    Associated with a prehistoric game called CASTLE OF THE WINDS. i have deleted the game folders and all K.cwg files i can find at this time. I will <search> later.

    Successful. what was this for, what did this do?

    Step 1 navigate to and delete
    c:\program files\temp01
    .........deleted

    Step 2:
    Using Windows Explorer - navigate to and delete:
    c:\program files\temp01
    ..............done

    Step 3:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!
    .................done

    Step 4:
    There has been a new SUPERAntiSpyware version release:
    ..............done, ...........log attached.

    Step 5:
    Open MBAM and click on the "Update" tab and click the Check for Updates button. After it has updated, click on the "Scanner" tab and then "Perform quick scan". Attach this log.
    .............done........ log attached.

    Step 6:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it.
    .........done..... log attached.

    FURTHER INFO
    avira anti virus identified akamai associated files as suspect files. I have deleted the akamia folder and sub folder(s) using safe mode (would not allow delete in normal mode). These appeared to return so i disconnected from the internet and re deleted the files in safe mode. In addition, i removed akamai access from the windows firewall, again having to dsconnect from the internet, move to safe mode, uncheck and delete from <exceptions>. NB I have no knowledge of this program which appeared to be associated with a program called <Administrative Assistant.exe> or <admin assitant.exe> or a similar name.

    Internet explorer no longer connects to the net. I rarely use this so its not much of a problem. I can delete and re download later.

    At what appears to be random intervals a pop up appears stating Your request can not be completed because windows live ID sevice could not be found or did not respond which i assume is associated with IE not connecting.

    Thank you again for your assistance. I await your further advice.
     

    Attached Files:

  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, dadpad

    Removing a left-over from AVG.

    * Neither akamai, Administrative Assistant.exe, nor admin assitant.exe are now found in your latest logs.

    Your logs look good! If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:

    Ans 1: Yes it is possible but even if it is working perfectly, you still don't have enough RAM installed.

    Ans 2: In the below link is a RAM testing procedure.
    http://forums.majorgeeks.com/showpost.php?p=1344485&postcount=2

    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
  6. dadpad

    dadpad Private E-2

    Thank you for taking the time and trouble to assist me.
     
  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :major

    You're very welcome, dadpad!

    dr.m
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds