MalwareCrypt
May 25, 2013, 01:48:55 AM *
Welcome, Guest. Please login or register.

Login with username, password and session length
News:
 
   Home   Help Search Login Register  
Pages: 1 2 [3]
  Print  
Author Topic: MY HJT Log!  (Read 3779 times)
Jintan
Administrator
Hero Member
*****
Posts: 3880



WWW
« Reply #30 on: October 25, 2009, 01:56:22 PM »

In checking the research on this issue further, for now it would be good to place emphasis on completing the Daemon Tools uninstall, rebooting and us checking a Gmer result after that. Might be that this effect is part of Daemon's rootkit-like activity.
Logged
tim6918
Newbie
*
Posts: 23


« Reply #31 on: October 25, 2009, 04:01:51 PM »

I will run the Daemon removal tool when I get back home.  I will post the log then.
Logged
Jintan
Administrator
Hero Member
*****
Posts: 3880



WWW
« Reply #32 on: October 25, 2009, 05:45:41 PM »

Good. Run it, reboot and then run the Gmer scan.
Logged
tim6918
Newbie
*
Posts: 23


« Reply #33 on: October 25, 2009, 08:45:04 PM »

Here is the latest gmer log

GMER 1.0.15.15163 - http://www.gmer.net
Rootkit scan 2009-10-25 22:42:32
Windows 5.1.2600 Service Pack 3
Running: vgyb4lnf.exe; Driver: C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\fxloapog.sys


---- Devices - GMER 1.0.15 ----

AttachedDevice  \Driver\Tcpip \Device\Ip                                                                                            avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice  \Driver\Tcpip \Device\Tcp                                                                                           avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice  \Driver\Tcpip \Device\Udp                                                                                           avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice  \Driver\Tcpip \Device\RawIp                                                                                         avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice  \FileSystem\Fastfat \Fat                                                                                            fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- Registry - GMER 1.0.15 ----

Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC                                    
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0                                 C:\Program Files\DAEMON Tools Lite\
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                 0
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                              0xBB 0x2E 0x14 0x41 ...
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001                          
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0                        0x20 0x01 0x00 0x00 ...
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12                     0x5C 0xA4 0x81 0x2B ...
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0                      
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12                0xEC 0x2A 0x95 0xAF ...
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)                
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0                                     C:\Program Files\DAEMON Tools Lite\
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                     0
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                  0xBB 0x2E 0x14 0x41 ...
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)      
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0                            0x20 0x01 0x00 0x00 ...
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12                         0x5C 0xA4 0x81 0x2B ...
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)  
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12                    0xEC 0x2A 0x95 0xAF ...

---- EOF - GMER 1.0.15 ----
Logged
Jintan
Administrator
Hero Member
*****
Posts: 3880



WWW
« Reply #34 on: October 25, 2009, 09:08:50 PM »

Darn Daemon Tools causing false alarms. Daemon has led to so much extra effort in these forum repairs, where rootkit issues are tough enough to assess. But good that it was Daemon, and not malware. Going to need to put that file back now we moved earlier. Let's give it a one-two-three run now.



Be sure to continue to temporarily disable any protective software when running the scan tools we use here.


Open notepad (go to Start, Run, type notepad and press Enter) and copy/paste the text in the codebox below into it:

Code:
DDS::
uStart Page = hxxp://www.ask.com/?o=101760&l=dis
mStart Page = hxxp://www.dell4me.com/myway
uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101757&gct=&gc=1&q=%s
IE: &Search - ?p=ZLfox000
Firefox::
FF - ProfilePath - c:\documents and settings\Christine\Application Data\Mozilla\Firefox\Profiles\32lg7ieh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://yandex.ru/yandsearch?clid=123047&text=
FF - prefs.js: browser.search.selectedEngine - Яндекс
FF - prefs.js: browser.startup.homepage - hxxp://yandex.ru/?clid=123049
FCopy::
c:\WINDOWS\system32\drivers\atapi.sys | c:\WINDOWS\ServicePackFiles\i386\atapi.sys

Save this to your desktop as CFScript.txt


You should now have both ComboFix and that CFScript.txt on the desktop. Just left click/hold on the CFScript.txt file, and drag it into ComboFix to start the scan.

ComboFix will now run as it did before. Allow the scan to run. When completed a text window will appear - please copy/paste the contents back here. This log can also be found at C:\ComboFix.txt.

A caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop.

------------

Download Malwarebytes' Anti-Malware from Here or Here.

Double Click mbam-setup.exe to install the application.

    * Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select "Perform quick scan", then click Scan.
    * The scan may take some time to finish,so please be patient.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Make sure that everything is checked, and click Remove Selected.
    * When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.
    * The log is automatically saved by Malwarebytes and can be viewed by clicking the Logs tab in Malwarebytes.
    * Copy and Paste the entire report in your next reply. If it calls for a reboot to complete the repairs do that as well then.

----------------

Disable your antivirus program and go here and run an online scan using ESET Online Scanner (you will need to use Internet Explorer for this scan, or download the installer to run it in a different browser). If you accept the Terms of Use, check the box and click Start. After the ActiveX Control has loaded, it will take a couple minutes for the scanner to get ready.  Next, check the following boxes:

Remove found threats
Scan unwanted applications


Next to "Current scan targets: Operating memory, Local drives", click the "Change" word. Make sure you place a check next to all disk drives, including any external drives that are attached (no need to check off the floppy or DVD/CD-Rom drives).

Click Start.  This scan may take a while, so please be patient.  A log may open when the scan is complete (if not, go to C:\Program Files\EsetOnlineScanner\ and open the file log.txt). Click Edit - Select All then copy/paste that log back here please.


If you have any problems getting Eset started, one work-around is to have an open Internet connection, and then click here and download the esetsmartinstaller_enu.exe Eset installer. Then click that file, and follow the same previous steps to run the scan.

Post back that log, the Malwarebytes log and the C:\ComboFix.txt log please.
Logged
tim6918
Newbie
*
Posts: 23


« Reply #35 on: October 27, 2009, 09:05:22 PM »

Logged
Jintan
Administrator
Hero Member
*****
Posts: 3880



WWW
« Reply #36 on: October 27, 2009, 09:50:57 PM »

If Eset was the last to run there the results from it look very good. Only infection already removed by SpyBot, or ComboFix to it's Qoobox quarantine folder. Not sure I see a Malwarebytes log though - could you check on that please? Under the Logs tab in Malwarebytes, choosing the one that matches the date/time this last scan was run.
Logged
tim6918
Newbie
*
Posts: 23


« Reply #37 on: October 30, 2009, 03:53:19 PM »

here is the log for malwarebytes

Malwarebytes' Anti-Malware 1.41
Database version: 3044
Windows 5.1.2600 Service Pack 3

10/27/2009 9:57:24 PM
mbam-log-2009-10-27 (21-57-24).txt

Scan type: Quick Scan
Objects scanned: 130637
Time elapsed: 5 minute(s), 36 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 11
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Features\9ee2330ae5f4470cac801baac83818c9 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\568267acfc5644dab06f058006ddbae3 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{bfc08cff-c737-4433-bd5a-0ee7efcfee54} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{4d25f926-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\MyWaySA (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWaySA\SrchAsDe (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Files Infected:
(No malicious items detected)
Logged
Jintan
Administrator
Hero Member
*****
Posts: 3880



WWW
« Reply #38 on: October 30, 2009, 06:00:07 PM »

Good - all really just malware remnants located by that, so looks cleaned up at this point. You have done well there. Just a few other remnants we can remove now left.


Code:
REGEDIT4

[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnli]

[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qomnmll]

[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\d88254b2]

Open Notepad (Start - Run, type Notepad then press OK), and copy the text inside the box above and paste it into the open Notepad textbox.

Save this to your desktop as "remout.reg"

Be sure to include the "" quotes in the name.

Then right click remout.reg, select Merge, and allow it to merge the new information with the Registry.


Before we now just move on to some last cleaning up steps post back how things are running please. Any problems we still need to address there?
Logged
tim6918
Newbie
*
Posts: 23


« Reply #39 on: October 30, 2009, 06:11:28 PM »

Updated my registry.  Everything seems to be running great now as far as I can tell.
Logged
Jintan
Administrator
Hero Member
*****
Posts: 3880



WWW
« Reply #40 on: October 30, 2009, 07:46:08 PM »

Just what we aimed for. Some last changes, and then just need to clean up what we added there to finish now.


Go here and download the latest version of Sun Java Java Runtime Environment (JRE) 6 Update 16. The current file name for that is jre-6u16-windows-i586.exe. I recommend you choose to download the "Windows Offline Installation" by clicking on that file to download it.


Then click here and download JavaRa.zip to your desktop, then unzip that. Close all open programs and browsers, and in the folder created locate and click on JavaRa.exe to start the tool. Select the correct language using the dropdown bar and click Select.

Then click Remove Older Versions, and agree to allow the tool to run. JavaRa will locate and remove all the outdated Java items.

When it completes click okay to allow it to open the logfile. This will also be saved as C:\JavaRa.log. We won't be needing to review that now. You can just use the "X" to close JavaRa.


And click that downloaded jre-6u16-windows-i586.exe to install the latest Java version there, being sure to reboot after.

--------------

To remove what our work added there, installed softwares like Eset and Malwarebytes, if you don't plan to use them again, uninstall through Add/Remove Programs. Though you may opt to keep Malwarebytes for periodic updated scans there.


You can also at this time delete the files/folders of the tools we used. To assist with some of that download OTM.exe by OldTimer to your desktop. This will help by automatically removing some of the tools we used.

Click OTM.exe to run it and click on Cleanup. You'll be asked if you want to begin cleanup process? Select Yes.

OTM will search for and delete/uninstall many of the tools that we have used to fix your problems and all their backup folders and then delete itself when you next reboot. At the end of the run you will receive a prompt to reboot, but save that for the next step resetting Restore.

---------

Then reset the System Restore. To do this, right-click My Computer and select Properties. Click the System Restore tab in the window that appears, and check the box that says "Turn off System Restore on all drives" and click Apply.

You will be asked if you are sure, click Yes. This will delete the restore points. Then click OK in the Properties window and reboot your computer.

When your desktop appears, right-click My Computer and select Properties once more. Uncheck the "Turn off System Restore..." box and click Apply. OK.


In addition, I like to recommend reviewing the information Here to make sure you stay malware free.
Logged
tim6918
Newbie
*
Posts: 23


« Reply #41 on: October 30, 2009, 08:33:56 PM »

I want to thank you for all of your time and your patience in helping me with this matter.  Again, thank you soo much!  I really appreciate it!

Tim
Logged
Jintan
Administrator
Hero Member
*****
Posts: 3880



WWW
« Reply #42 on: October 30, 2009, 09:20:33 PM »

Glad to have helped Tim. :thumbup:
Logged
LoraHup
Newbie
*
Posts: 0


« Reply #43 on: December 01, 2009, 04:03:00 PM »

Вот логи ERROR-ы которые появились сегодня ночью.

Exchange store First Storage GroupMailbox Store MAIL: The logical size of this database the logical size equals the physical size of the .edb file and the .stm file minus the logical free space in each is 20 GB. This database size has exceeded the size limit of 18 GB.

This database will be dismounted immediately.
__

Unexpected error <<0xc1050000 - Unknown Error. The logon to the Microsoft Exchange Server computer failed. Microsoft Exchange Server Information Store ID no: 80040111-03ee-80040111>> occurred.
__

The MAPI call OpenMsgStore failed with the following error: The attempt to log on to the Microsoft Exchange Server computer has failed.The MAPI provider failed.Microsoft Exchange Server Information StoreID no: 8004011d-0512-00000000

Unexpected error <<0xc1050000 - The attempt to log on to the Microsoft Exchange Server computer has failed. The MAPI provider failed. Microsoft Exchange Server Information Store ID no: 8004011d-0512-00000000>> occurred.
Logged
Pages: 1 2 [3]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC
SMFAds for Free Forums
Valid XHTML 1.0! Valid CSS!