Malware My log files Part 1

Discussion in 'Malware Help (A Specialist Will Reply)' started by Overtaken, Mar 7, 2009.

  1. Overtaken

    Overtaken Private E-2

    My kids are back at it again. I just want to thank you for explaining about setting up restricted password protected accounts for your children rather than giving them full access to my account. I did not read that the last time I went through this. Here we go again, I knew something was wrong when every 10 minutes AVG would detect a new trojan mostly vundo types. I ran SuperAntiSpyware in normal mode and it did not detect anything and then I ran MalwareBytes in Safe mode and it detected 15 trojan. I think most of them were vundo if that makes sense. I thought it was weird that it did not detect it in normal mode, but only found it in safe mode. I thought it was a problem so I uninstalled everything and started over. My computer was really dragging so I followed the procedure and SAS and MBAM didn't find anything. You will see this in the logs. I will have no programs opened and my CPU will be running at 30-60%. It seems that something is going on in the background and I don't know what. It also takes about 15-20 min(10 min to shut down and 10 min to get back to the startup page) to re-boot my machine. It might be that the computer is just dying. I figured i would just check. I now get an error when I boot up saying "Config Parser Error
    Error parsing c:\WINDOWS\system32\URTTemp\config\machine.config
    Parser returned error 0x80070003. Could you please see if there is anything suspicious in the background that would hog up so many system resources and cause my computer to run so slow. The last time it acted the same way it was due to malware. Thanks in advance. I really appreciate all you do.
    Thanks again
     

    Attached Files:

  2. Overtaken

    Overtaken Private E-2

    Malware My log files Part 2

    Here are the next two files. Please let me know if you find anything. I can't thank you enough. You provide an invaluable service to us who know nothing about computers.
    Thank you.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's do this:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\windows\system32\trJ51WgI.exe
    c:\windows\system32\wtP1uim3.exe
    
    AtJob::
    DEL /A/F/Q "%Tasks%\AT*.job"
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combo.
     
  4. Overtaken

    Overtaken Private E-2

    TimW,
    First of all I want to thank you for getting back to me so quickly. I am glad to see that you saw something also. It just seemed like there was something left. I did as you suggested and combofix updated and then restarted the computer before finishing. I hope that was all right. I then had to rerun MGtools.exe since I had deleted the original folder. The two files you wanted me to delete are no longer in C\windows\system32. Hopefully that took care of the problem. Thanks again for all you do to help us computer idiots.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet......If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  6. Overtaken

    Overtaken Private E-2

    TimW,

    Thanks again for all you do. It is great to know the threat is gone. I had already read through "How to protect yourself from malware". I have taken all of your recommendations.

    I don't know if you know that Comodo Internet Security installs malware on your computer. It installs the ASK Toolbar and SAS found Adware.MyWebSearch/FunWebProducts. I don't know if that is a major threat or something you get for downloading a free anti-virus program, but I thought I would let you know. I am sure you already knew this. I am using Avira now and had no problems with malware

    I purchased SAS for my computer so I could get the real time protection. I now have to go through everything on the other computer and make sure it is OK. What a great resource you have online. I am trying to figure out how to set up users for everyone that uses the computer and assign the right privileges.

    Thanks a million,
    Overtaken
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes apparently Comodo Security Suite is installing Ask Toolbar by default now. They do clearly give you the option of not installing it during the installation. This practice of installing by default and also what it is installing are not things we like to see, but in reality Ask Toolbar can simply be uninstalled after the fact if you do not want it. We will add a note to the download page and to the How to protect yourself from malare sticky about the optional toolbar.

    Thanks for bringing this to our attention.

    Note you may want to read the below which may also reduce your concerns about this:

    http://forums.comodo.com/comodo_safesurf_and_comodos_own_toolbar/analysis_of_comodo_toolbar_by_boclean_standards-t24483.0.html
     
    Last edited: Mar 13, 2009

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds