Malware Procedure Completed, Logs for review

Discussion in 'Malware Help (A Specialist Will Reply)' started by StiinaQT, Dec 2, 2012.

  1. StiinaQT

    StiinaQT Private First Class

    Found some suspicious things in my email, so I ran the sequence of malware detection/removal. I'm attaching my logs and waiting for instructions on what to do next. Thanks for your help!!

    I have one last file to upload, so I'll comment on this post and add it there. Your procedure gen's 6 logs and we can only attach 5.
     

    Attached Files:

  2. StiinaQT

    StiinaQT Private First Class

    Now for the TDSKiller log, attaching that. Thanks again!
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can have Hitman delete Potential Unwanted Programs. Apart from that your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  4. StiinaQT

    StiinaQT Private First Class

    I'm embarrassed to say that I completely spaced the Defogger and preliminary stuff. I'm having some problems, though. My computer is not acting right.

    Here's what I've done per your direction:

    1. I purchased the license for MBAM and inserted the license codes. I made sure it's turned on and actively monitoring.

    2. I checked and I do not have the ComboFix installed, another oversight. Sorry about that, I was under duress trying to get my computer cleaned plus keep up with other commitments.

    3. I re-enabled the UAC

    4. I ran the MGclean.bat. Does it just go, flash, then finish? I didn't see much when it ran.

    5. I tried to uninstall the Hijack This and I can't find it on my list of programs. I tried to find it in CCleaner and still couldn't. Is it installed under another name? Seems to me that it is, but my brain is not engaging on this one.

    7. I tried to do the system restore and I cannot get the computer properties to come up. I tried to do a snip of the error boxes and my computer says that that feature is gone! I did a screen capture, but it says "Computer Management Snapin Launcher has stopped working. Windows is collecting more information about the problem. This might take several minutes... The bar has no progress. A second box came up and asked if I want to send more info to MS about the problem. Here are the details included:

    Files that help describe the problem:
    C:\Users\Laura\AppData\Local\Temp\WER39F9.tmp.WERInternalMetadata.xml
    C:\Users\Laura\AppData\Local\Temp\WER524B.tmp.appcompat.txt
    C:\Users\Laura\AppData\Local\Temp\WER52D8.tmp.mdmp

    Read our privacy statement online:
    http://go.microsoft.com/fwlink/?linkid=104288&clcid=0x0409

    If the online privacy statement is not available, please read our privacy statement offline:
    C:\Windows\system32\en-US\erofflps.txt

    I can't get to the properties nor can I send you a picture of what it's doing. What happened?

    Thanks for your help!
     
    Last edited: Dec 2, 2012
  5. StiinaQT

    StiinaQT Private First Class

    Something is really wrong. Most of my programs will no longer launch from my task bar, start menu, etc. The only way I could get my browser to launch was via the "CCleaner Home Page" short cut that let me open Chrome. I was able to renavigate back here. I decided to restart my computer, thinking when I restarted the UAC, I hadn't restarted.

    I pulled up CCleaner as the registry scan gives me a feel for how compromised my computer is. I have 14 issues which is not normal.

    4 Missing TypeLib Ref
    6 Invalid Firewall rules
    2 Missing MUI Ref
    2 Invalid file ref

    I don't know if that helps any. Every time I try to open the computer properties, Windows Explorer stops working and has to restart. I'm perplexed.

    Thanks for your help!

    Laura
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    All topic for the software forum by the sounds of it. I did not ask you to install Combofix so do not worry about that.
     
  7. StiinaQT

    StiinaQT Private First Class

    I'm beginning to think that there's something still on my computer. When I opened my email, the broadcast messages were apparently going again as I have another mess load of nondelivery errors.

    I can't boot into safe mode.

    My Windows Explorer shuts down whenever I try to right click on anything.

    Most of my shortcuts are toast, inop.

    Should I start over on the Malware process and this time not skip the beginning?

    Help!

    Thanks, Laura :cry
     
  8. StiinaQT

    StiinaQT Private First Class

    Re: Malware Procedure Completed, Logs for review--2nd run

    I answered my own question and reran the process from the beginning. Logs are attached. I did encounter the following problems:

    1. CCleaner would not run in the other accounts. Good news is they haven't been used so there shouldn't be much junk.

    2. MBAM would not run. I will try to reboot and since it will auto initiate active protection, I'll see if it will run then.

    Everything else went through, but one of the scans wants me to buy it before it will remove anything. I wasn't sure since it marked everything as "no action"

    Thanks for the second look.

    Laura
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem, long as you know I can only remove malware. The software forum exists for non malware related issue. :)

    All I am seeing to do here is to rerun Hitman and have it delete Potential Unwanted Programs. Now run it again (just a scan) and attach the new log so that I can see if it has all gone or not.
     
  10. StiinaQT

    StiinaQT Private First Class

    I understand that this is a malware forum. BTW, as soon as the Hitman removed these items, my software may be ok. I was actually able to right click on a file to delete it and Windows did not stop working!

    Here is the log. Please let me know if there is any additional cleanup I need to do.

    Thanks!

    Laura
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well when you rerun Hitman again, does it find anything or not now?
     
  12. StiinaQT

    StiinaQT Private First Class

    No, it does not. I've attached the log.

    Thanks!

    Is there any clean up now?

    Laura
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can follow final steps in my post #3 if all is well.
     
  14. StiinaQT

    StiinaQT Private First Class

    Re: Malware Procedure Completed, Additional Scans. More Malware

    I honestly do not believe that I'm clean.

    I found RemoveIT Pro in your list of detection / removers and it came up with a long list of suspicious files. I did a check on the files to see if they were actual threats or false detections and there were too many that are considered malware for me to believe that I'm clean.

    The log keeps failing so I can't attach it. Can I get more help with this please??

    Also, you never had me go back and fix anything that Rogue Killer found? Why not?

    I'm still limping along here.

    Laura
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Malware Procedure Completed, Additional Scans. More Malware

    Show me the log file please, or tell me the files it detected as bad.
    Perhaps copy and paste from it's own log and put into a log of your own.

    Because nothing bad shows in there!
     
  16. StiinaQT

    StiinaQT Private First Class

    Okay, I finally figured out where I could find the SnipIt tool and get it to run because I can't cut/paste in that ap. Everything else is so glommed up that Windows keeps shutting down every time I try to open anything using a shortcut.

    I'm attaching the 3 captures of the list. I know that not all of these are actually bad, but when I looked them up, it became obvious that files that were installed since August (I don't remember the exact date) are the suspect ones. From the reading I've done, this malware hides itself using other program names and in the Sys32 folder of Windows. Some are legit, but like I said, if there is a date of 2012, it is probably not. You can't tell here, but when I line them up in the Sys32 folder.

    Thanks!

    Laura
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I seriously warn you against fixing those items with that software. I think you are worrying a bit too much, any issues you have are software related. NOT malware. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds