When I boot gives me a strange(fake?) warning message about too many secrets

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Arathron42, Dec 2, 2011.

  1. Arathron42

    Arathron42 Private E-2

    Hi, I'm not sure what is going on. Our office computer has started to rapidly display a warning message when we turn in on and sporadically while doing other tasks.

    It says "The maximum number of secrets that may be stored in a single system has exceeded. The length and number of secrets is limited to satisfy United States State Department export restriction."

    It pops up and as soon as you click to close or acknowledge it another springs up. Also the console (not sure if that is what it's called these days the thing that pops up with a c:\ if you typed cmd into run back in the day) it springs up and down so fast it's like a flash I can't see what is written or executing.

    As I said it's our work computer and given our office layout it's highly unlikely anyone was cruising for porn or any of that nonsense.

    I don't think it's a real windows warning. I've included all the logs from the read and run win 7 62bit version.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You had/have a form of Zero Access infection.



    Uninstall the below old versions of software:
    Java(TM) 6 Update 21


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After you finish my first set of instructions with ComboFix, continue with the below.


    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    • Be sure to attach your log from TDSSKiller
    Now please also download MBRCheck to your desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  4. Arathron42

    Arathron42 Private E-2

    Wow thanks for getting back to me so quick. I'll run this first thing Monday (office isn't open weekends)
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay and since you have now informed us that this is a company PC, you may want to consider backing up important data first.
     
  6. Arathron42

    Arathron42 Private E-2

    Alright, I've done the first post and have attached the logs. The first time I ran combofix it bluescreened while it was doing the log after the reboot. I it may have been because I forgot to uninstall the java. So I did then tried again and after reboot it blue screened. Then I noticed that the Mbam active scanner was loading on the reboot so I told it not to start on reboot and it worked fine.

    The too many secrets message didn't pop up at all during this latest reboot. Moving on to the second post thanks for all the help.
     

    Attached Files:

  7. Arathron42

    Arathron42 Private E-2

    Here are the TDSS and MBRC logs. The secrets pop up hasn't been seen during the last few reboots. I haven't done much on the computer though other than run the procedures described in your posts.

    Thanks for all your help
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Okay that looks much better.

    Now delete the below folder:
    C:\Users\owner\AppData\Local\4740edfd

    Then reboot this PC and run TDSSkiller one more time and attach the new log so we can make sure it comes up clean this time.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds