IE odd behavior, CF question

Discussion in 'Malware Help (A Specialist Will Reply)' started by TaneMarduk, May 24, 2008.

  1. TaneMarduk

    TaneMarduk Private E-2

    I followed the Read Me, and it was going fine, wasn't getting any detections.
    I ran CF and it rebooted, but I missed the message it displayed before doing so.
    I checked the log file, but I can't seem to find whether or not if found anything, and if I need to continue running the rest of the steps.

    I initially ran ReadMe because of what appeared to be an attack by a webpage, in IE, with umpteen billion cookies trying to set, add-ons trying to install, and forced site changes. I denied everything it sent at me, but IE abruptly closed when I tried to send a PM to someone on the site I was on, without warning of multiple tabs closing.

    I decided that due to the previous 'attack' whether it was or not, I needed to make sure nothing got on my system, so I ran everything in the ReadMe up to CF. As of right now, IE was set back to my default browser instead of Firefox, I had an internet connection without having to reboot, but my clock is still in 24-hour time.

    I have the logs from SAS, MalwareBytes, and CF, but only CF did anything odd, both the other two found nothing.

    Any help or advice would be most appreciated, thank you.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to complete ALL instructions in the READ & RUN ME including MGtools and attach the 4 requested logs so that we can best help you determine if there is any malware present.
     
  3. TaneMarduk

    TaneMarduk Private E-2

    All right, I wasn't sure if something would have been better done before the steps were completed. Thanks. :)
     
  4. TaneMarduk

    TaneMarduk Private E-2

    Here are the first 3 logs, then.
     

    Attached Files:

  5. TaneMarduk

    TaneMarduk Private E-2

    And the CF log now.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not seeing any obvious malware!

    Is the below something you installed? Is this Snaptrap?

    O4 - HKLM\..\Run: [SQ931STI] C:\WINDOWS\SQ931STI.EXE

    The only other questionable files are the below hidden/system files which may or may not be issues. I'm not sure what they are from. Do you know? Their names are suspicious but the fact that they are marked with hidden and system attributes makes them very suspicious. Do you have or did you install Super video converter
    What actual malware problems are you currently having if any?
     
  7. TaneMarduk

    TaneMarduk Private E-2

    Never heard of Snaptrap, and I'm not good with remembering convoluted names of program processes.

    Yes, I have Super, but I don't need it if it's a problem.

    This was mostly a preemptive run to make sure the suspicious activity from IE I described didn't let anything onto my system.

    Why, though, did CF not reset my clock?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then maybe something else you run makes use of that process which is a SnapTrap MFC Applications. It may be part of your USB Video Camera.

    No it is not a problem.

    Normally it is a sign that it did not finish running properly. I want to use ComboFix to get info on those files and then I will give you a fix for your clock.



    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    You can fix your clock from Control Panel ->Regional and Language Options and then on the Regional Options tab click the Customize button then on the next form click the Time tab. Then change the Time format to what you want. It explains there what the lower case and upper case letters will do. Upper case H is giving you 24 hour clock settings.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Then attach the new C:\combofix.txt log
     
  9. TaneMarduk

    TaneMarduk Private E-2

    All right, the registry edit was successful, here's the new log.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those files are okay.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    8. Go to add/remove programs and uninstall HijackThis.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  11. TaneMarduk

    TaneMarduk Private E-2

    All right, thank you very much. :D
    I've completed all the steps and I believe I'm good to go.

    I have one last question, what could be using the snaptrap thing? What is it/what does it do?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    I believe I answered that in message # 8 where I said
     
  13. TaneMarduk

    TaneMarduk Private E-2

    Ah, I'm sorry, I completely missed that last part of that message. :eek:
    Anyway, thanks again. :)
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds