malware logs part 1

Discussion in 'Malware Help (A Specialist Will Reply)' started by hutchy74, Nov 29, 2008.

  1. hutchy74

    hutchy74 Private E-2

    im about to attach my logs but unfortunately im still infected with the cekar am virus/spyware.
    my virgin media anti virus reports that it is still there and can`t delete it.

    I have had the infection for almost two weeks and more than likely got it from downloading adult content.

    I have attached mglogs.zip on this thread and will post the other three in the next thread.

    thanks

    Ryan
     

    Attached Files:

  2. hutchy74

    hutchy74 Private E-2

    Re: malware logs part 2

    here are my other three logs.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to use windows explorer to find and delete:
    Code:
    C:\Documents and Settings\Ryan\My Documents\Random Stuff\Useful Program Downloads\Novation Bass Station 1.0 VST.  .exe
    
    Note the space after 1.0 vst --- .exe

    What problems are you still having as the scans appear to have removed most of the malware.
     
  4. hutchy74

    hutchy74 Private E-2

    thanks for the reply,

    my virgin media pc guard antivirus seems to pop up saying that it cant delete the cekar am.

    I will delete the file you have metioned on sunday and see if theres any change.

    The antivirus displays the location of cekar am so i will post it the next time it pops up if that helps?
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, that would help. :)
     
  6. hutchy74

    hutchy74 Private E-2

    ok.

    I have deleted the file with the space in it.

    My antivirus still displays the (cekar am) which is located at the following location.

    hkey_local_machine \system\currentcontrolset\enum\root\legacy_ndisprot

    I have searched for this file but nothing shows up and i notice theres a space in this line also.

    I do feel the pc is running better now as sometimes in a google search it would re direct me to copy book instead of the site i had typed in.
    This appears to have stopped now.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing it in your logs.....but we can see if it will go away:

    download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Attach that log.
     
  8. hutchy74

    hutchy74 Private E-2

    i got an error after hitting execute but still gave me a log. the error is in the log so i will let you have a look at it.

    Also, the last time i got the cekar message i selected don`t show this again but it came back until i restarted the pc and it seems to have stopped popping up now.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's do this just to be on the safe side:

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Let me know if you have any other problems.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  10. hutchy74

    hutchy74 Private E-2

    okay mate thanks for your help.

    the cekar am message came back but i have added that file to the registry so i will see how that goes now.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If it does come back, I want you to re-run ComboFix and attach the new log.
     
  12. hutchy74

    hutchy74 Private E-2

    ok, heres the new log.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Attach that log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  14. hutchy74

    hutchy74 Private E-2

    still getting cekar am
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Tell me exactly where it is reported.

    In the mean time....

    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the "Input script here:"
    part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Are you still getting the message?
     
  16. hutchy74

    hutchy74 Private E-2

    ok its still there so here goes this is what it says.

    anti-spyware failed to delete cekar AM. To learn more, refer to our spyware centre.
    Spyware item location:
    kkey_local_machine \system\currentcontrolset\enum\root\legacy_ndisprot

    Then it gives me a link to visit the spyware centre which reports "no information available for (cekar am)"

    it also has a check box saying "don`t show again.
    if i check the box it sometimes dissapears for a short time but always seems to return.
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Arrghh...nasty little bugger.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    KILLALL::
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NDISPROT]
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NDISPROT\0000]
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NDISPROT\0000\Control]
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Ndisprot]
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Ndisprot\Security]
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Ndisprot\Enum]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NDISPROT]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NDISPROT\0000]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NDISPROT\0000\Control]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ndisprot]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ndisprot\Security]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ndisprot\Enum]
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Attach the log.
     
    Last edited: Dec 1, 2008
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I had to edit my post....please recheck the fix and in necc., run it again.
     
  19. hutchy74

    hutchy74 Private E-2

    ok here goes.
     

    Attached Files:

    • log.txt
      File size:
      11.5 KB
      Views:
      2
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you still getting the message?
     
  21. hutchy74

    hutchy74 Private E-2

    i have just turned the culprit machine on.
    I will leave it on for the rest of the evening and see what happens.

    Thanks again.

    Ryan
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me give you the final instructions to clean up in anticipation of it not coming back..:)

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  23. hutchy74

    hutchy74 Private E-2

    trhats us sorted mate, i have followed the procedures that you posted.
    no sign of cekar am now.
    well done for persevering with it.

    Thanks.

    Ryan

    :clap
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds