Malware Chinese Characters

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Bluesbreaker, Feb 2, 2016.

  1. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay. Then before you put the .arn file into a ZIP file, take a look at the file size. Then look in the ZIP file afterwards and see if it shows the same size for the file inside the ZIP.
     
  2. Bluesbreaker

    Bluesbreaker Corporal

    ok so lets try this bad boy. I think we got what we need here!
     

    Attached Files:

    Kestrel13! likes this.
  3. Bluesbreaker

    Bluesbreaker Corporal

    note the file I saved is 9.2kb approx, the file in the zip is about 9.3kb...
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You have already downloaded SystemLook... so do this:


    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      Baidu
      Tencent
      :regfind
      Baidu
      Tencent
      
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  5. Bluesbreaker

    Bluesbreaker Corporal

    hi - ok here is the SystemLook output file....
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hey Blues, that found an awful lot of remnants, give me some time, and I'll post back again.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member





    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.


    Once done, re run Systemlook in exactly the same way and upload NEW log please.
     

    Attached Files:

    • reg.txt
      File size:
      50.6 KB
      Views:
      10
  8. Bluesbreaker

    Bluesbreaker Corporal

    ok thanks Kestrel13! I will do this tonight...this is one pervasive and invasive piece of caka.
     
    Kestrel13! likes this.
  9. Bluesbreaker

    Bluesbreaker Corporal

    Question...I have OTM.exe from like 2013. but I cant find an updated OTM, rather OTL.exe. Is this what I'm running now? OTL.exe or my old OTM.exe?
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  11. Bluesbreaker

    Bluesbreaker Corporal

    Thanks Kestrel13! So it looks like it got to the last 6 lines of instructions and is not responding, with the blue spinning wheel...should I wait this out or what
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What happened in the end? Only just seen your message...
     
  13. Bluesbreaker

    Bluesbreaker Corporal

    Still spinning when I left. Shall I shut T program down?
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you using the older version of OTM by any chance?
     
  15. Bluesbreaker

    Bluesbreaker Corporal

    No. New one I downloaded just and deleted old file
     
    Kestrel13! likes this.
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Have you copied and pasted everything exactly as I have it in that text file I uploaded? (reg.txt)
     
  17. Bluesbreaker

    Bluesbreaker Corporal

    Yes. From :reg to boot.

    It didn't create the text file yet E in c:_otm
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try running it in safe mode. Follow my previous instructions on how to access safe mode. ;)
     
  19. Bluesbreaker

    Bluesbreaker Corporal

    can I close the program?
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes of course, you will have to close it to boot into safe mode. :)
     
  21. Bluesbreaker

    Bluesbreaker Corporal

    O. Stopped program now in safe mode. Will try again in a bit....
     
  22. Bluesbreaker

    Bluesbreaker Corporal

    I was anxious that some reg instruction would render my system inoperable. Thanks Kestrel
     
    Kestrel13! likes this.
  23. Bluesbreaker

    Bluesbreaker Corporal

    so it did the same thing. got all the way down to these last lines and got the "not responding" and spinning wheel. running in safe mode btw...

    [-HKEY_USERS\S-1-5-21-1277821213-748431931-1829802651-1000_Classes\VirtualStore\MACHINE\SOFTWARE\Wow6432Node\Tencent]
    [-HKEY_USERS\S-1-5-18\Software\Tencent]
    :Commands
    [emptytemp]
    [Reboot]

    thing is, it adds another [Reboot] in the field where I paste instructions. your instructions have one [Reboot] but at the end, it shows the text I pasted above PLUS another [Reboot]
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sigh.

    OK, we'll do a series of reg patches... (in normal mode) this will take a few posts I'm afraid. The forum limits me on how much I can post in one fix and there is alot to fix of the junk remnants...

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  25. Bluesbreaker

    Bluesbreaker Corporal

    ok. this one did NOT work. it says cannot import C:\Users\lil-nicky\desktop\fixME.reg:The specified file is not a registry script. You can only import binary registry files from within the registry editor.
     
  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did you do this?
     
  27. Bluesbreaker

    Bluesbreaker Corporal

    ok I rebooted and rekicked this off and it worked. it was saved earlier as a all files. this is driving me nuts.
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Indeed.... :(

    So you got a sucess message?
     
  29. Bluesbreaker

    Bluesbreaker Corporal

    but having you here makes it better.
    I got the success.
     
    Kestrel13! likes this.
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK onto round 2... ;) (Delete the other reg patch!! (fixme.reg)

    Copy the bold text below to notepad. Save it as fixME2.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  31. Bluesbreaker

    Bluesbreaker Corporal

    ok. is Encoding set to Ansi this is new
     
  32. Bluesbreaker

    Bluesbreaker Corporal

    it should be set to Unicode even my <snip> question mark key is not working. É

    *Edited by dr.moriarty - inappropiate language
     
    Last edited by a moderator: Feb 20, 2016
  33. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Are you using Notepad as instructed or some other text editor?
     
  34. Bluesbreaker

    Bluesbreaker Corporal

    I am. For some reason, it now, when I went to save the file, asked if I wanted Ansi or whatever option. Apologies for the language. Also, my question mark is back. When I saved, it brought up an alert saying This file contains characters in Unicode format which will be lost if you save this file as ANSI encoded text file. to Keep the unicode information, click Cancel below and then select one of the unicode options from the Encoding drop down list. Continue?
     
  35. Bluesbreaker

    Bluesbreaker Corporal

    I will try this tomorrow...I'm going to bed. Thanks for all your guys help so far...
     
  36. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Save as type All Files (*.*)
    Encoding: ANSI
     
  37. Bluesbreaker

    Bluesbreaker Corporal

    So continue to save. As ansi despite the warning above?
     
  38. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The Unicode is most likely due to the two Uninstall lines with Chinese characters on them. If it becomes an issue, just leave these out of the registry patch for now.
     
    Kestrel13! likes this.
  40. Bluesbreaker

    Bluesbreaker Corporal

    Thank you. I will try this shortly.
     
  41. Bluesbreaker

    Bluesbreaker Corporal

    ok! successfully added....next up!
     
    Kestrel13! likes this.
  42. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK delete the previous reg patch again.... now continue on...


    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  43. Bluesbreaker

    Bluesbreaker Corporal

    successfuly added!
     
    Kestrel13! likes this.
  44. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Two more reg patches to go....

    OK delete the previous reg patch again.... now continue on...


    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.


    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  45. Bluesbreaker

    Bluesbreaker Corporal

    ok! successfully added again...

    one thing - I am still only able to access my desktop, etc from CTRL-SHIFT-ESC. and through the file-open-notepad, file-open-explorer to access said desktop. this is to be expected, correctÉ
    thanks again Kestrel13!
     
  46. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi Blues, we will get to the other issue... we think we can correct it. But first I want to finish off removing remnants from Baidu and Tencent, to be thorough....
    Last reg patch.... :)

    OK delete the previous reg patch again.... now continue on...


    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.


    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  47. Bluesbreaker

    Bluesbreaker Corporal

    Good morning Kestrel13! I will be trying these later today. Thanks again for helping....
     
    Kestrel13! likes this.
  48. Bluesbreaker

    Bluesbreaker Corporal

    Hi there - ok successfully added!
     
    Kestrel13! likes this.
  49. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      KernCap.vbs 
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  50. Bluesbreaker

    Bluesbreaker Corporal

    hi - ok here's the output of the systemlook
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds