m_cat12's Logs

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by m_cat12, Apr 24, 2011.

  1. m_cat12

    m_cat12 Private E-2

    2 day's ago, I got the fake 'Windows Recovery' virus popup. After running the suggested programs in this forum, this seems to have been fixed.

    My file folders on my desktop disappeared leaving only my programs. After running the suggested programs, this also seems to have been fixed as all of my files are in tact.

    Im still having a problem with the 'redirecting' on Firefox and IE.

    MalewareBites did not find any problems.

    I could not run RootRepel. Keep getting several error windows.
    "FOPS - DeviceIoControlError! Error Code = 0xc0000024
    ExtendedInfo (0x00000128)
    Could not initialize driver! Please contact the Author!"

    Am also getting frequent popup 'Script Errors'.
    "Line, 1129, 1120
    Char 53
    then some random website is listed like thefablife.com"

    I tried to run Kapalarsky, and renamed it, but the program would not start.

    Thanks for your help.

    Matt
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You mean you tried to run TDSSKiller?

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode, if you haven't done so already.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\Users\Matthew\AppData\Local\6umds8y8841yn3rbmki0sbvbk5so35gq
    C:\Users\Matthew\AppData\Roaming\20E6.D13
    C:\Users\Matthew\AppData\Roaming\Microsoft\Windows\Templates\6umds8y8841yn3rbmki0sbvbk5so35gq
    C:\ProgramData\32366344
    C:\ProgramData\34397960
    C:\ProgramData\6umds8y8841yn3rbmki0sbvbk5so35gq
    C:\ProgramData\~32366344
    C:\ProgramData\~32366344r
    C:\ProgramData\~34397960
    C:\ProgramData\~34397960r
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. m_cat12

    m_cat12 Private E-2

    Hi Kestrel13!

    Thanks so much for responding :) I will be running your suggestions below this instant.

    Wanted to report another symptom which I forgot to add to the redirecting issue. When I try and use Firefox, along with the redirecting to random sites, I also get a 'Opening Search' box.

    "Opening search
    search
    which is a: application/json
    from: http://www.google.com"

    Then it asks to open/Browse or Save file.

    The only way that I am able to get to the MajorGeeks site, is to keep hitting the back button like 50 times and eventually I'll get to the MajorGeeks site instead of redirected. Then, I have to click 'cancel' like 50 times to get rid of the Opening search boxes.

    Ok, Im going to run your suggestions now. Thank you again!
     
  4. m_cat12

    m_cat12 Private E-2

    I have attached the ComboFix and MGTools logs here.

    Notes:
    -I disabled my Symentec in the systray by right clicking and disabling. However ComboFix kept saying that it was running. I went ahead and continued with ComboFix.

    -ComboFix restarted my cpu.

    -During MGTools, I received another random script error.

    That's all for now. Thanks again!
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The logs look good. :) How are things running for you?
     
  6. m_cat12

    m_cat12 Private E-2

    Everything seems to be fixed. :) Only 1 leftover issue: I still keep getting this Script Errors. Any clue on how to fix them?

    I ran a Symantec and Malewarebyte full scans and both came out clean.

    When you say Im ready, I'll do the UAC, restore setting, etc. Put everything back to normal. Just let me know. Thanks so much :)
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What script errors? You mean the one from MGTools?

    EDIT: Ahh you mean this?
    Are you being redirected still? At what point do you get these errors?
     
  8. m_cat12

    m_cat12 Private E-2

    Yes. These 'script errors' are like popups. They are coming up fairly frequently. I dont think that im getting redirected anymore. The popups look like official Windows errors. But i know that they are not.

    They also have different numbers, web addresses, etc included in the script errors. I could send a screenshot if you would like? (and if its allowed)
     
  9. m_cat12

    m_cat12 Private E-2

    Hi.

    I just realized that the redirects are back. The 'script errors' are still there but Im not sure they are related.

    I use Firefox and have Win7.

    Thanks for your help :)
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do you have your Vista install disc? If not:

    Vista and Win7 Recovery disc


    For fixing the boot issues:
    To run the Bootrec.exe tool, you must start Windows RE. To do this, follow these steps:

    1. Put the Windows Vista or Windows 7 installation disc in the disc drive, and then start the computer.
    2. Press a key when you are prompted.
    3. Select a language, a time, a currency, a keyboard or an input method, and then click Next.
    4. Click Repair your computer.
    5. Click the operating system that you want to repair, and then click Next.
    6. In the System Recovery Options dialog box, click Command Prompt.
    7. Type Bootrec.exe, and then press ENTER.

    Then you can do this:

    Bootrec.exe /fixmbr
     
  11. m_cat12

    m_cat12 Private E-2

    OK. I completed the steps below. I fortunately still have my Win 7 CD.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Use the PC, surf a while, let me know then how things are running for you.

    Please run the below also.

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some data on it
    • Right click on the screen and select > Select All
    • Press Control+C
    • Open a notepad and press Control+V
    • now please ATTACH that report to this thread
     
  13. m_cat12

    m_cat12 Private E-2

    OK. Here is the MBRCHeck Log.

    I will surf for awhile and post any findings.
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So in a couple hours let me know how things are running :)
     
  15. m_cat12

    m_cat12 Private E-2

    Ok. So here is an update:

    -Redirects are happening.
    -Fake Script Errors are happening.
    -Also additional Script Error (new - attached txt)
    -New: Seems that a 'commercial or ad' is running in the background intermittently. Even when my browser is closed.

    Thanks for your help.
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then are you NOW able to run TDSSKiller?

    Those errors you mentioned relate to yahoo mail I think.
     
  17. m_cat12

    m_cat12 Private E-2

    Still cant run TDSKiller.

    I ran rkill.svr from BleepingComputer.

    Also ran ESET Online Scanner.

    Logs attached. I have not restarted my cpu.

    Thank you. :)
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Okay then move the TDSSkiller.exe file ( or redownload it ) to your root folder so that you have C:\TDSSkiller.exe to make it much easier to run.

    Then reboot your PC with your boot DVD and then get into the command prompt window. The enter the below and hit enter ( it is case insensitive ):

    C:\tdsskiller.exe

    Hopefully it runs okay. Then reboot normally and see if things are working better of not. Attach the log from TDSSkiller if it made one in your root folder.
     
  19. m_cat12

    m_cat12 Private E-2

    I cant believe I actually got TDSSkiller.exe to run! :)

    I have attached the log here.

    I have restarted in normal mode and have done nothing else except use IE to send this note.
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Excellent. :) Use the computer a while and let me know how things are running. Remember I can't help you much in the way of the yahoo error. We are very busy dealing with malware removal.
     
  21. m_cat12

    m_cat12 Private E-2

    So the good news is that it looks like we are making progress. The bad news is that there are still issues...

    Currently:
    -I have reverted back to an old version of Yahoo Mail. But I dont think that this has anything to do with my current problems.
    -I have uninstalled my Firefox and uTorrent. Until I get my cpu cleaned, I will not be installing these.
    -Music and/or commercials and ads are still playing sproadically in the background. This happens when I am not on the internet also.
    -Still getting the random 'script errors'
    -Ran full Symentec and Malewarebytes and both showed nothing.
    -NEW: When searching in IE, it takes SO LONG for the search to complete. Internet seems to be running slow (I have high-speed cable)
    -NEW: I noticed that when I run CCcleaner, the IE temp internet files folder fills up rather quickly. Like I will run CCcleaner, then run it immediately after, and the IE temp folder will quicly add up with random files.

    Googling 'script errors' and 'music and/or commercials and ads playing in background on cpu' does absolutely nothing.

    Is there no answer to these issues? Should I just wipe my cpu clean since I have my Win7 install disk? Maybe I should start the MajorGeeks process over?

    Thanks for your help. :)
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmmm, let's try the below.

    • Download bootkit_remover.rar
    • Click the underlined DOWNLOAD text to download the file and save it to your Desktop.
    • You then need to extract the remover.exe file from the RAR using a program capable of extracing RAR compressed files. If you don't have an extraction program, you can use 7-Zip
    • After extracing remover.exe to your Desktop, double click the remover.exe file to run the program.
    • Attach or post inline here, the output from remover.exe

    NOTE: The Command Prompt window text can be copied to the clip board by right clicking on the top bar of the window and using the Edit commands to Mark, Copy, and Paste.
     
  23. m_cat12

    m_cat12 Private E-2

    bootkit remover logs attached here.
     

    Attached Files:

  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm I am running out of options. Seems like you have an MBR infection but why the steps I had you go through didn't clear it I don't know. Let's try something else.

    • Click Start, Run and copy and paste the below into the Run box and click OK.

    • Now reboot your PC and after reboot continue with the below instructions.
    • Run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Make sure you tell me how things are working now!
     
  25. m_cat12

    m_cat12 Private E-2

    Error Message: Windows cannot find...Make sure you typed the name correctly and try again.
     
  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Is remover.exe on the desktop out of the zipped file?
     
  27. m_cat12

    m_cat12 Private E-2

    Sorry. I had to pull the program out of the zip file.

    I have attached the message here.
     

    Attached Files:

  28. m_cat12

    m_cat12 Private E-2

    MGTools zip file attached.
     

    Attached Files:

  29. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Bear with me, I am struggling to find the cause of this. I have a question, do you use a router? There is a little button on the bottom ( on most models ) to reset it to factory settings. Do that. You may then need to go back into it to set any special setting that you may have set up originally. But do that first and see if that doesn't take care of it.

    You can test this theory by connecting directly to your modem and if the redirects/random music stop, then you know it is the router that is infected.
     
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  31. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Also very important. TDSSkiller did not give a complete log last time so please re run it and attach the new log.
     
  32. m_cat12

    m_cat12 Private E-2

    Sorry Im a bit late. Had a few things to do yesterday.

    I have attached the gmer log here. I wish I could also post all the processess it lists too but I wasnt able to copy/paste.

    I ran the tssdkiller using the dvd function and it did not produce a log. I checked my root folder and my desktop for the log but nothing was available.

    I've reset my modem/router. Things seem to be getting a bit better. However, I still have redirection issues and the random ad/commercial being played in the background.

    Over the last day or so, I've also rerun all of the tests and programs listed in the original malware removal thread. I also have not reinstalled firefox.

    Thanks for your continued help.
     

    Attached Files:

  33. m_cat12

    m_cat12 Private E-2

    ran otl.exe. could only attach the one log b/c the other log was too big.
     

    Attached Files:

  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's see if we can figure out what is going on with this. We need this to run and create a log. If it is stopping at about 80%, it is a sign of a new MBR infection going around. So let's make sure you are doing it right. ;)
    • Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123tdk.com).
    http://forums.majorgeeks.com/chaslang/images/TDSSkiller/tds1.jpg

    • Click on Run to allow the application to run properly.
    • If you see any popup warnings from your antivirus or firewall about it trying to access the nework or similar, make sure that you allow it to run/have access.
    • It will start the scan and run rather quickly and will not.ify you of whether anything is found or not.
    You will then see the below window
    http://forums.majorgeeks.com/chaslang/images/TDSSkiller/tds2.jpg

    • Click on the Start scan button to begin the scan and wait for it to finish. When it finishes, you will see a window similar to below accept you may have one indicating infections were found.
    http://forums.majorgeeks.com/chaslang/images/TDSSkiller/tds3.jpg
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should already be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
    • Reboot and the infection should hopefully be removed.
     
  35. m_cat12

    m_cat12 Private E-2

    Hi Chaslang-

    Im not able to run tdsskiller from my desktop either way. So, I ran it again through my Win 7 dvd. It seems to run fine and does not find any issues. I have attached the log here.

    Thanks for your help.

    Matt
     

    Attached Files:

  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What exacly does this mean? What happens?

    What exactly does this mean? What did you do exactly? If TDSSkiller is not running from your Desktop in normal operation this is something wrong.

    This is not a complete log. Check again.

    See an example of what a complete log should look similar to in the attachment in the below link:

    http://forums.majorgeeks.com/showpost.php?p=1617568&postcount=2
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After looking the TDSSkiller log again, I see it shows X:\Windows. Thus you did not have it scan the proper drive. Your infection is on drive C and you need to fix drive C.
     
  38. m_cat12

    m_cat12 Private E-2

    This morning, I ran the Kaspersky Virus removal Tool. I have attached the log here. The program restarted my cpu several times. It found 2 items:
    MEM: Rootkit.Win32.SSta and Virus.Win32.TDSSE.e......= volsnap.sys.

    After running the above, I was then able to run TDSSKiller directly from my desktop. Complete log is attached. :)

    Thanks so much for your help.
     

    Attached Files:

  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes this is the type of infection behind the reason we were trying to get TDSSKiller to run properly. It would have found and fix this too. It's good to know that Kaspersky's VRT program was able to run when TDSSKiller would not.

    How is your computer working now?
     
  40. m_cat12

    m_cat12 Private E-2

    Sorry, I havent been at my cpu in a few days. I will get back to you as soon as possible. On first glance, it seems to be working fine now. (ie. no redirects, and not ads/commercials).

    Would you recommend I run a few programs and attach them as a final check up?

    Or, would you rather I button everything up?

    Thanks,

    Matt
     
  41. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes let's have you do the below so that we can check one more time for any remaining issues before wrapping up.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  42. m_cat12

    m_cat12 Private E-2

    Hi-
    New MGLogs Log attached here.

    If everything is going well, I'd like to use the CPU for a few days and see how it runs before we button everything back up. Im not working at this CPU as much lately so I need to find the time to really spend the time. I'd also like to reinstall Firefox.

    Note: It says 'Internet - Protected Mode: Off on the bottom right of my screen. Will this be corrected when we put things back together?

    Thanks for your help. MUCH appreciated :)
     

    Attached Files:

  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Complete the below final instructions and see if it changes afterwards. When UAC is turned back on this should change back.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  44. m_cat12

    m_cat12 Private E-2

    Just wanted to let you know that I have not had time to perform the 'clean up' steps below. I will do this as soon as I can.

    Thanks so much for your help.
     
  45. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. safe surfing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds