Questions about malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by rent143, Jun 20, 2007.

  1. rent143

    rent143 Private E-2

    Hello! I had a couple questions concerning malware..

    1. Is there anyway to tell if malware installed on a system successfully gathered keylogs, or took screenshots, etc? If so, is there anyway to tell what specific type of things it was able to gather?

    2. Is it possible to tell if a firewall or spyware monitor blocked the malware from actually sending the information/screenshots it gathered?

    3. Lastly, would it be possible to tell if installed malware was able to gather any information based on the filenames that show up when it is detected?


    Any insight would be greatly appreciated. I'm trying to find out if there's any possible way I can tell if any screenshots were successfully taken of my computer desktop and were also successfully sent out.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    No not really! There is no way to tell what may have been stolen. However you need to first determine if you even have to worry about any of this by determining if you have any malware infections.

    Not 100%, but look at your firewall logs and any other logs from tools you have installed to see if they have captured any information. Most firewalls have logs and most will normally popup notices about strange activities and so will any good antispyware or antivirus program.

    No! If you have malware (yet to be determined) you have to determine what the malware is and what it is capable of doing; however that does not mean that it actually did steal any information. On the otherhand, just because you don't notice any problems, it does not mean that you have no malware or that it did not stall anything.


    You need to run the READ & RUN ME sticky thread procedure to determine if you have any malware problems.
     
  3. rent143

    rent143 Private E-2

    Hi, thank you for your response, I appreciate you taking your free time to do this.

    As for the malware on my computer, I had it removed last Sunday and was told it was "Spectre" spyware, which is capable of taking secret screenshots. I really need to know if it was successful in getting screenshots of certain things on my computer. I was even going to call somebody in person and ask them if they could look at my computer, but I wouldn't even know who to call. But it's really important that I know..
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Never heard of it but everyone calls things different names. Well actually let me amend this, I have heard of this. I believe it is this: http://www.symantec.com/security_response/writeup.jsp?docid=2006-031513-4219-99&tabid=1

    It is something that you or someone else installed.

    You will not be able to find out that information by looking at your PC. If you have no malware (are you really sure) then the only thing you can do is the below if you are worried about security of what may have been stolen.

    http://www.dslreports.com/faq/10451
     
  5. rent143

    rent143 Private E-2

    Well I ran CCleaner, AVG-antispyware, AVG Anti-rootkit, Spybot S&D, VundoFix, my anti-virus software, ComboFix, and Hijack-This. I still have the logs from them that show that I (apparently) have malware installed. Do you want me to post any of those logs and see what you think?

    Thank you for that link!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you want to know if you have malware, the READ & RUN ME FIRST Before Asking for Support sticky thread procedure must be followed and then the below logs (from the procedure) must be attached.

    • CounterSpy - only for Windows XP, 2K, & NT users
    • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
    • Bitdefender - from step 6
    • Panda Scan - from step 6
    • runkeys.txt - the log from GetRunKey.bat
    • newfiles.txt - the log from ShowNew.bat
    • HijackThis
     
  7. rent143

    rent143 Private E-2

    So you'll still be able to tell if I had that malware last Saturday even after I've run all those programs since then, and have deleted specific files with ComboFix? Wouldn't you need to see the logs that I have saved from before I deleted those files?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That procedure will tell what remains which is really most important at this time.

    If you want to attach the old logs from things you have already run, you can do that too and I will then see what they already may have removed.
     
  9. rent143

    rent143 Private E-2

    Alright.. I'll start with posting the old logs from before anything was fixed/deleted. I need to know if any malware that is capable of taking screenshots was installed on my computer..

    In addition to the logs posted I also ran the AVG Anti-rootkit scan, and that came up with no infections. Spybot S&D also came up with no infections, and no infections were found with my antivirus software run in safe mode.

    Thanks for helping me out with this.
     

    Attached Files:

  10. rent143

    rent143 Private E-2

    Here are more logs... the "ComboFix2" log is from after I deleted files through ComboFix but those 2 "rapport" logs are from before I did anything.
     

    Attached Files:

  11. rent143

    rent143 Private E-2

    And here's the ComboFix quarantine log just in case you wanted to see it. I don't get why the dates for the files in the quarantine are from 2003 and 2004?
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Part of your ComboFix log shows the below:
    C:\WINDOWS\system32\CRDE2003.dll
    C:\WINDOWS\system32\ILRawRead.dll
    C:\WINDOWS\system32\ISP2003.dll

    These files may or may not be part of the Spectre item. If you look at the Symantec link you will see the Spectre installs them but puts them into its own folder in C:\Progam Files. Thus while these could be problems, they could also be used by some other program that uses the libraries. They may have functions with in them that are used by any program that does screen snapshots. Do you have anything installed like that. You can even see a couple of these are used in software like the below:

    http://www.compulink-support.com/technotes/wantwain.htm

    Other places they are used are in PDF Readers or conversion programs. Even Optical Character Recognition (scanners). Do you have a scanner? For example search the below file and you will see two of the above file names mentioned:

    http://www.library.okstate.edu/access/ils/illiad/OCLCILLiadVersion7.pdf



    I have no idea what the other two files ComboFix removed are:
    C:\WINDOWS\system32\MRARM.dll
    C:\WINDOWS\system32\MRCE2.dll
     
  13. rent143

    rent143 Private E-2

    Hello,

    I do have both a scanner and Adobe Acrobat. Actually, I use my scanner to scan papers and convert them into PDF files through Acrobat. I also use the scanner to make copies of papers.

    How do I check to see if those files are used for my scanner and Adobe Acrobat instead of for malware?

    I haven't knowingly installed Spectre, the only time it could have been installed was when I installed different programs that read digital camera memory cards to recover deleted photos. Those were all installed (and then un-installed) on Saturday, June 16th. Were those files that were removed by ComboFix created on June 16th? Maybe that would explain if they are or aren't spyware?

    Thanks for your assistance.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The odds are very high that these are not problems. You can right click on the files and select Properties, Version and take a look at who they belong to (assuming the files give you a version tab) but since they appear to be common DLLs use by a variety of programs that still does not tell you anything.

    Since you do not have the Spectre software installed on your PC and the folders for it do not show, I still stand by my assertion that these are not problems.

    In message # 3 you said:
    If by this you mean that ComboFix removed them, then you will at some point find that some aspect of your scanner or Adobe software no longer works. That will answer your question as to whether the files are used by you. The other way is to reinstall your software and if the files show up again then you know where they came from (that is assuming they are really gone right now).
     
  15. rent143

    rent143 Private E-2

    Well I tried using both Adobe Acrobat and my scanner and they both worked fine.


    I went to the quarantine folder and clicked on properties, and here's what the 5 files that ComboFix removed said:

    ILRawRead.dll (120 kb)
    Created: Saturday, June 16th, 2007. 7:23 PM
    Copyright ImageLib Skyline Tools 2003
    Developed by Dave Co ffin and Jan De kkers ImageLib Skyline Tools. Based on Dave's Revision: 1.97

    CRDE2003.dll (1.06 MB)
    Created: Saturday, June 16, 2007, 7:23 PM
    Description: ImageLib Core DLL
    Copyright: Creative Development LTD

    ISP2003.dll (237 KB)
    Created: Saturday, June 16, 2007, 7:23 PM
    Description: Special Effects Library Suite 7.0
    Copyright: Creative Development LTD 95, 96

    MRCE2.dll (362 kb)
    Created: Saturday, June 16, 2007, 8:05 PM
    Copyright: MediaRECOVER, Inc
    No description

    MRARM.dll (48 kb)
    Created: Saturday, June 16, 2007, 8:05 PM
    No copyright
    No description


    So all of these were created on the day that I installed those digital camera memory card reader programs. The question then would be if these are part of spyware program(s) that take screenshots, or if they are just legitimately part of those programs that I installed?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I stated earlier they could be use for valid purposes and that is what they were. Whoever told you that you had Spectre was wrong.

    You need to reinstall your Camera software or just move those files out of ComboFix's quarantine back to their original folders. That is assumig you need it.
     
  17. rent143

    rent143 Private E-2

    So you're positive that these files have nothing to do with any sort of malware?

    Is spectre the only malware capable of taking screenshots?

    The only thing I've been worried about this whole time is if these files could have been taking screenshots of my pictures, so I want to be 100% sure that these aren't malware that can do that.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since you never follow my instructions from step # 6, I cannot say that you do not have any malware at all. I can just say that based on whaty you posted, you did not have any. And in addition you do not and did not have Spectre. You are worrying about nothing. Whatever told you you had Spectre was a false positive.

    If you want to confirm this for yourself then do what I stated in my previous message and reinstall all of your camera software. You will more than likely see the files reappear in the system32 folder.
     
  19. rent143

    rent143 Private E-2

    I re-installed a total of 11 programs and one of them also re-installed the MRARM.dll and MRCE2.dll files in the system32 folder. None of the other ones installed those other 3 files, but I'm not sure if I was able to remember all of the programs that I had installed last week. Is there any way to check what programs have been recent installed/un-installed on your computer?

    I've also downloaded and prepared everything I need to so that I can complete the complete malware scan and post the 6 logs. I want to wait yo start that until after I'm donw installing all these programs though.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not really, but you could check the file and folder dates in c:\Program Files to see what is new. That however assumes that this is where you installed everything.
     
  21. rent143

    rent143 Private E-2

    Alright, I finally found the 2 programs... MRARM.dll and MRCE2.dll were both installed when I installed the "MediaRecover" program. Those 2 files remained even after I un-installed the program.

    CRDE2003.dll, ILRawRead.dll, and ISP.2003.dll were all installed when I installed the "Digital Picture Recovery" program. The files remained even after I un-installed the program. I also found this site: http://www.siteadvisor.com/sites/dtidata.co.nz/downloads/3633139/ It lists the changes the program makes to your computer. I found it through a search engine.

    I know the files aren't related to Spectre obviously, but is there still a chance they could be spyware related?

    I'm starting the malware scanning steps you gave in Post 6 now. I'll post the 6 logs when I complete it. Thanks for all your help so far!
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are overly paranoid for no reason at all. As I said before there are many processes/files that can be used for valid as well as malware purposes. You installed the software that put these files on your PC, if you don't trust them or are going to continue to be worried about them then uninstall the software and delete the those files if they are left behind. Then do not use the this software anymore.
     
  23. rent143

    rent143 Private E-2

    Well that Norton SiteAdvisor said that that program that installed those 3 files isn't spyware, so you were right about the files being legit.

    Anyways, I completed the malware scanning process, I will attach the logs. On one of the files there's a list of quarantined Norton System Works files.. I'm sorry I didn't clear out those quarantine folders before scanning, but I thought those would be deleted when I un-installed the program. I last used it September 21st, 2004!
     

    Attached Files:

  24. rent143

    rent143 Private E-2

    Other 3 logs:
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have infected file in other user accounts. You ran the scans on TONY.TONY-SBWG4ZNZOA but the user account named tony has some malware in its temp folder. Delete all files in the below folder:
    C:\Documents and Settings\tony\Local Settings\Temp

    Also delete this folder: C:\Program Files\Norton SystemWorks

    Now uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users.WINDOWS\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Mozilla Firefox (1.5.0.12)
    SpywareBlaster v3.4 <-- this is more than 2 years out of date.
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    Also install the current version of SpywareBlaster from: SpyWare Blaster


    Now attach a new log from ShowNew.
     
  26. rent143

    rent143 Private E-2

    Alright, I followed all of those instructions. I also re-deleted those 5 files, since I have no use for either of those programs anymore anyways. So I'm also attaching the ComboFix from after I did that.

    When I restarted my computer a McAfee Virus Shield warning came up that said "McAfee has found a suspect file on your computer and recommends you scan now." Is that just a false positive of ComboFix or one of those other programs?

    Thanks!
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean!

    I cannot answer that unless you tell me exactly what is being found and where it is finding it. All I can suggest is that you remove quarantines and backups from the tools (which the below steps should do) and see what happens.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  28. rent143

    rent143 Private E-2

    Alright I did the system restore steps.

    If there is a laptop that uses the same wireless internet as this computer, is there a chance it can't infect the computer if they're both connected to the internet at the same time?
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since you did not have any infections to begin with, the answer is no.
     
  30. rent143

    rent143 Private E-2

    A bunch of error messages popped up today when I started up the computer. One said something about memory not being able to be written at "0x0000008" or some number like that. And it gave me an option to terminate the program or debug it.

    Another error popped up that said "To help protect your computer, Windows has closed this program: NAME: Generic Host Process for Win32 Services
    Publisher: Microsoft Corporation.

    And finally an AOL error appeared that said "The main.idx database file is damaged" and it says I have to re-install the software.

    What do I need to do about these? I haven't used the computer since I followed the spyware removal steps and toggled the system restore, so I don't think it's some new spyware or anything..
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to post in the Software Forum. These are not malware issues.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds