RogueKiller Log

Discussion in 'Malware Help (A Specialist Will Reply)' started by BreezeBrat, Sep 14, 2012.

  1. BreezeBrat

    BreezeBrat Private E-2

    I think I am doing this right.



    RogueKiller V8.0.3 [09/13/2012] by Tigzy
    mail: tigzyRK<at>gmail<dot>com
    Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
    Blog: http://tigzyrk.blogspot.com

    Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
    Started in : Normal mode
    User : Compaq_Owner [Admin rights]
    Mode : Scan -- Date : 09/14/2012 15:04:12

    ¤¤¤ Bad processes : 0 ¤¤¤

    ¤¤¤ Registry Entries : 4 ¤¤¤
    [TASK][SUSP PATH] GoogleUpdateTaskUserS-1-5-21-37831335-1886233326-2625279817-1009UA.job : C:\Documents and Settings\Compaq_Owner.SASSY\Local Settings\Application Data\Google\Update\GoogleUpdate.exe -> FOUND
    [TASK][SUSP PATH] GoogleUpdateTaskUserS-1-5-21-37831335-1886233326-2625279817-1009Core.job : C:\Documents and Settings\Compaq_Owner.SASSY\Local Settings\Application Data\Google\Update\GoogleUpdate.exe -> FOUND
    [HJ] HKLM\[...]\SystemRestore : DisableSR (1) -> FOUND
    [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

    ¤¤¤ Particular Files / Folders: ¤¤¤

    ¤¤¤ Driver : [LOADED] ¤¤¤

    ¤¤¤ Infection : ¤¤¤

    ¤¤¤ HOSTS File: ¤¤¤
    --> C:\WINDOWS\system32\drivers\etc\hosts

    127.0.0.1 localhost


    ¤¤¤ MBR Check: ¤¤¤

    +++++ PhysicalDrive0: ST3160021A +++++
    --- User ---
    [MBR] 7f58dffdf10563011afeefb8613f874e
    [BSP] 8a7884da59e414827f91c43dcf324e78 : Toshiba tatooed MBR Code
    Partition table:
    0 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 63 | Size: 7138 Mo
    1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 14619150 | Size: 145487 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    Finished : << RKreport[1].txt >>
    RKreport[1].txt
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please explain the purpose of your post. You did not tell us what problems you are having. If you are having malware problems then you need to complete ALL of the instructions in the below and then attach the logs along with an explanation of your remaining problems.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. BreezeBrat

    BreezeBrat Private E-2

    Code:
    HitmanPro 3.6.1.164
    www.hitmanpro.com
    
       Computer name . . . . : SASSY
       Windows . . . . . . . : 5.1.3.2600.X86/1
       User name . . . . . . : SASSY\Compaq_Owner
       License . . . . . . . : Trial (29 days left)
    
       Scan date . . . . . . : 2012-09-15 13:03:58
       Scan mode . . . . . . : Normal
       Scan duration . . . . : 12m 42s
       Disk access mode  . . : Direct disk access (SRB)
       Cloud . . . . . . . . : Internet
       Reboot  . . . . . . . : No
    
       Threats . . . . . . . : 0
       Traces  . . . . . . . : 0
    
       Objects scanned . . . : 1,272,558
       Files scanned . . . . : 205,858
       Remnants scanned  . . : 398,717 files / 667,983 keys
    
    
    
     
  4. LauraR

    LauraR MajorGeeks Super-Duper Administrator Staff Member

  5. BreezeBrat

    BreezeBrat Private E-2

    I'm not sure how to add the MGTools since it's a zip file with several logs inside. I didn't do a scan with Malwarebytes because that takes over 9 hours to scan. I'm not sure how your site works as most places only want one thing at a time but was told by someone in here that it probably would be best to post the others.

    I was surfing the internet a couple days ago and sites I visit regularly for my graphics came up saying this site is malicious and my antivirus popped up saying it blocked malware. I went to one site and they helped and I had a trojan that got in the back door. I wanted to save things on my computer like my photos and graphics to some flashdrives but was told my files could be infected and if they are and I put the flashdrives into another system that I would infect that computer too. It was recommended to me to come here and see if I could clean up my computer. Sorry I didn't explain things but as I said I didn't know how this site worked.

    I am running Windows XP, Avast antivirus
     

    Attached Files:

    Last edited: Sep 15, 2012
  6. BreezeBrat

    BreezeBrat Private E-2

    Looks like I am messing up all over the place and for that I am sorry. I didn't know you didn't allow actual logs to be posted.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like you may not have followed the instructions we gave that said
    But even so, running a full scan is still worth the time and it would have been finished now too.

    We want all the logs at once. Everything is in the instructions and in the sticky/pinned threads in the forum. ;)

    Not impossible that they would get infected, but it is very rarely the case. And based on your logs, I don't think it is an issue. What you do have to be careful of is that your USB drive itself is not infected with any .exe files like we are removing below from your C:\ root folder.

    There are a few more things to cleanup on your PC.

    Uninstall the below two programs:
    Coupon Printer for Windows
    Search.com Bar


    Please download OTM by Old Timer and save it to your Desktop.
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    winpatrol.exe
     
    :Files
    C:\bswyvdxk.exe
    C:\dror.exe
    C:\kkqkm.exe
    C:\tdndhuv.exe
    C:\wggam.exe
    C:\Documents and Settings\Compaq_Owner.SASSY\Local Settings\temp\0033043E.vbs"
    C:\Documents and Settings\Compaq_Owner.SASSY\Local Settings\temp\CRX_75DAF8CB7768"
    C:\Documents and Settings\Compaq_Owner.SASSY\Local Settings\temp\dump.dat"
    C:\Documents and Settings\Compaq_Owner.SASSY\Local Settings\temp\kavremvr 2012-09-13 16-23-38 (pid 3732).log"
    C:\Documents and Settings\Compaq_Owner.SASSY\Local Settings\temp\svbek.tmp"
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InstallWIX_{8CB14A64-CEF4-4C8F-B1C8-1C3B8752CB55}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0290BF93-2A4D-4B1A-B43D-0789441B7F67}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    After reboot, run a new scan with RogueKiller and save a log as in original instructions and attach the new log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    How are things working?
     
  8. BreezeBrat

    BreezeBrat Private E-2

    I did a quick scan with malwarebytes. Sorry I misread when I was looking that over and reading the instructions. I think I have attached all you asked for now.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  10. BreezeBrat

    BreezeBrat Private E-2

    Thank you so much! Now does that mean my files are clean and I can save my stuff to my flashdrives?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Yes but did you take note of what I said back in message # 7
     
  12. BreezeBrat

    BreezeBrat Private E-2

    Yes and I removed those like you said. How can I tell for sure the drive isn't infected?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes we renoved them from drive C but did you find any similar to these on your USB drives? If so, those need to be removed.

    You can run scans with your USB drives plugged in and make sure you choose to scan them.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds