Malware Logs

Discussion in 'Malware Help (A Specialist Will Reply)' started by Joe2go, Jan 28, 2013.

  1. Joe2go

    Joe2go Private E-2

    I have some malware or some issue which is causing my internet bandwidth to get eaten alive to the point where I am sending and receiving many billions of bytes and losing internet until I restart it again. It is not a line issue I made sure of that and called my provider many times with 3 technicians sent, it is directly with my pc.

    Cheers.
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks!

    Please re-scan with Hitman Pro and have it delete everything under the headings of
    • Potential Unwanted Programs
    • Malware
    ...ignore any other findings.
    Afterwards, click the Next button.
    HitmanPro may want to reboot the PC in order for the changes to take affect, please do so.

    * If you do NOT use a proxy to connect to the internet - fix this using RogueKiller

    Next, double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button, then select the Registry tab and then select any of the below that exist and then
    click the Delete button.
    • [PROXY IE] HKCU\[...]\Internet Settings : ProxyEnable (1) -> FOUND
    When it is finished there will be a log on your desktop called RKreport[2].txt, attach it to your next reply.
    Then immediately reboot your PC.

    After reboot, run new scans with both RogueKiller and Hitman Pro, attach those new logs to your next reply.

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download

    Junkware Removal Tool
    to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    NOTE: Your MGLogs.zip was very in-complete. Did you receive any error messages when running it? Did you have protection software disabled? Try the below.

    Run the C:\MGtools\ReZip.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). .

    It should take a couple seconds to run. You will see a black command prompt window while it is running and it should tell you that the C:\MGtools\MGlogsR.zip file as been created. Attach this ZIP file.


    Logs to attach:
    • MBAM log.txt
    • updated RKreport[2]
    • updated HitmanPro 2012xxxx.xxxx.log
    • MGLogsR.zip
     
  3. Joe2go

    Joe2go Private E-2

    All done except MGtool was incomplete because it got stuck on the SN64.bat and did nothing for like 30 minutes so I stopped it and got the logs anyway.
     

    Attached Files:

  4. Joe2go

    Joe2go Private E-2

    I got it to fully work now but the zip file hasn't changed, however the log file has so here it is if that makes any difference.
     

    Attached Files:

  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Please perform the steps I give more closely..

    Re-run HitmanPro and fix the detected Potential Unwanted Programs as previously instructed.
    ...ignore any other findings.
    Afterwards, click the Next button.
    HitmanPro may want to reboot the PC in order for the changes to take affect, please do so.

    Run RogueKiller again --> when it opens click the PROXYFIX button
    When it is finished there will be a log on your desktop called RKreport[3].txt, attach it to your next reply.
    Then immediately reboot your PC.

    Now after reboot, run new scans with both RogueKiller and Hitman Pro, and attach those new logs to your next reply.
    The MGLogs.zip is still missing the majority of the expected individual logs normally created.

    *Please boot into safe mode and try running it. If that does not work then please run the below but run OTL from Normal Boot mode.

    Please download OTL by OldTimer.
    • Save it to your desktop.
    • Double click on the OTL icon on your desktop. (If running Vista or Win7 right-click and select Run as Administrator)
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the Customs Scans/Fixes text-field.
      Code:
      activex
      netsvcs
      drives
      %systemdrive%\*.*
      %systemdrive%\MGtools\*.*
      %systemroot%\*. /mp /s
      [/LIST]
      • Now click the Run Scan button.
      • Two reports will be created:
        • OTL.txt <-- Will be opened
        • Extra.txt <-- Will be minimized
      • Attach both OTL.txt and Extras.txt to your next message. (See how to attach)
      Logs to attach in your next reply:
      • updated RKreport[3]
      • updated HitmanPro 2012xxxx.xxxx.log
      • MGLogs.zip - if it ran
      • OTL.txt and Extras.txt
     
  6. Joe2go

    Joe2go Private E-2

    Here you go, it should all be correct now.
     

    Attached Files:

  7. Joe2go

    Joe2go Private E-2

    Sorry here are the OTL files.
     

    Attached Files:

  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    *Please delete C:\Users\Joe\Downloads\Programs\MGtools.exe as this is not where you were instructed to download it and would not be removed in our cleanup steps.

    Uninstall the following-
    Ask Toolbar <-- adware
    Java(TM) 6 Update 30 <-- outdated
    Java(TM) 7 Update 4 <-- outdated
    JavaFX 2.1.0 <-- outdated

    Please download AdwCleaner and save it to your Destop.
    • Double-click AdwCleaner.exe to run it. (Vista & Win7 users should right-click and "Run As Administrator")
    • Click on Delete
    • Your pc should now automatically re-boot
    • AdwCleaner will display a log showing the files, folders, and registry entries that were removed.
    • Attach this log to your next reply.

    Now shut down your protection software (antivirus, antispyware...etc) to avoid possible conflicts.
    Code:
    :OTL
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKU\S-1-5-21-4130007548-3030964992-1365172515-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
    O3 - HKU\S-1-5-21-4130007548-3030964992-1365172515-1000\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
    O4:[b]64bit:[/b] - HKLM..\Run: []  File not found
    O4 - HKLM..\Run: []  File not found
    O15 - HKU\.DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
    O15 - HKU\.DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites)
    O15 - HKU\.DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites)
    O15 - HKU\.DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites)
    O15 - HKU\S-1-5-18\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
    O15 - HKU\S-1-5-18\..Trusted Domains: freerealms.com ([]* in Trusted sites)
    O15 - HKU\S-1-5-18\..Trusted Domains: soe.com ([]* in Trusted sites)
    O15 - HKU\S-1-5-18\..Trusted Domains: sony.com ([]* in Trusted sites)
    O15 - HKU\S-1-5-19\..Trusted Domains: clonewarsadventures.com ([]* in )
    O15 - HKU\S-1-5-19\..Trusted Domains: freerealms.com ([]* in )
    O15 - HKU\S-1-5-19\..Trusted Domains: soe.com ([]* in )
    O15 - HKU\S-1-5-19\..Trusted Domains: sony.com ([]* in )
    O15 - HKU\S-1-5-20\..Trusted Domains: clonewarsadventures.com ([]* in )
    O15 - HKU\S-1-5-20\..Trusted Domains: freerealms.com ([]* in )
    O15 - HKU\S-1-5-20\..Trusted Domains: soe.com ([]* in )
    O15 - HKU\S-1-5-20\..Trusted Domains: sony.com ([]* in )
    O15 - HKU\S-1-5-21-4130007548-3030964992-1365172515-1000\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
    O15 - HKU\S-1-5-21-4130007548-3030964992-1365172515-1000\..Trusted Domains: freerealms.com ([]* in Trusted sites)
    O15 - HKU\S-1-5-21-4130007548-3030964992-1365172515-1000\..Trusted Domains: soe.com ([]* in Trusted sites)
    O15 - HKU\S-1-5-21-4130007548-3030964992-1365172515-1000\..Trusted Domains: sony.com ([]* in Trusted sites)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 10.4.1)
    O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 10.4.1)
    
    :Files
    C:\Users\Joe\AppData\Roaming\Microsoft\Protect\S-1-5-21-4130007548-3030964992-1365172515-1000
    C:\Users\Joe\AppData\Roaming\Microsoft\Protect\S-1-5-21-4130007548-3030964992-1365172515-1000\02b0c6dd-9f8a-4776-8873-46fe98cdcd10
    C:\Users\Joe\AppData\Roaming\Microsoft\Protect\S-1-5-21-4130007548-3030964992-1365172515-1000\4ca6d634-7ca3-43ed-9eba-8ab67c91c964
    C:\Users\Joe\AppData\Roaming\Microsoft\Protect\S-1-5-21-4130007548-3030964992-1365172515-1000\4d189d98-0bf0-48c6-a673-f5473843deb5
    C:\Users\Joe\AppData\Roaming\Microsoft\Protect\S-1-5-21-4130007548-3030964992-1365172515-1000\8aa52685-98a0-408c-a74c-14c017456c7f
    C:\Users\Joe\AppData\Roaming\Microsoft\Protect\S-1-5-21-4130007548-3030964992-1365172515-1000\Preferred
    C:\ProgramData\Norton
    
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Now click the http://img3.imageshack.us/img3/407/otlrunfix.png button.
    • If the fix needed a reboot please do it.
    • Click the OK button (upon reboot).
    • When OTL is finished, Notepad will open. Close Notepad.
    • A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    • Attach this log to your next message. (See: How to attach)

    Now install the latest Sun Java Runtime Environment

    If you also wish to install the latest JavaFX, here is the link:
    JavaFX 2.2.4

    Please attach the below logs to your next reply:
    • the log from OTL
    • AdwCleaner[S1].txt

    How is your machine running?
     
  9. Joe2go

    Joe2go Private E-2

    My issue persists my man. Here is an image of my problem exactly and I know it's not a line issue because I've had 3 technicians come check and the problem only occurs to everyone when my laptop is connected to the network.

    http://i50.tinypic.com/23v4b5.jpg

    It keep increasing to billions of bytes sent and received.
     

    Attached Files:

  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    I'm conferring with my colleagues.
     
  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    We are not finding any remaining malware, Joe2go. I recommend that you post in our Networking forum for further help.

    * If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. It provides no "real-time" protection unless you purchase it and does not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 4 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. If running Vista or Win 7, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. Go to add/remove programs and uninstall HijackThis.
    5. Go to the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and/or deleted.
    7. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work through the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would suggest uninstalling BitComet and uTorrent and see if anything changes. If not then uninstall or if possible, totally shutdown Steam and see if that changes anything.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds