BleepingComputer.com: Win 7 Security Issue

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
  • 8 Pages +
  • 1
  • 2
  • 3
  • 4
  • 5
  • Last »
  • You cannot start a new topic
  • This topic is locked

Win 7 Security Issue

#31 User is offline   m0le 

  • I know the drill!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 29,133
  • Joined: 24-July 08
  • Gender:Male
  • Location:London, UK

Posted 29 January 2012 - 08:37 PM

Good news about the flashdrive. There is some visible malware on the log so let's do a clean up and clear up other stuff too.

Open OTL

Under the Custom Scans/Fixes box at the bottom, paste in the following

:OTL
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
[2011/12/20 06:47:25 | 000,008,280 | -HS- | C] () -- C:\Users\mcunnie\AppData\Local\j6rj08f2li3vlh
[2011/12/20 06:47:25 | 000,008,280 | -HS- | C] () -- C:\ProgramData\j6rj08f2li3vlh
@Alternate Data Stream - 116 bytes -> C:\ProgramData\Temp:502D809E
:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
""=""%1" %*"



Then click the Run Fix button at the top

Let the program run unhindered.

When done it will say "Fix Complete press ok to open the log"
Please post that log in your next reply. Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTL\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
If I have helped you fix your PC then please donate. Thanks

Posted Image
m0le is a proud member of UNITE (Unified Network of Instructors and Trusted Eliminators)

#32 User is offline   mcrugger 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 62
  • Joined: 21-December 11

Posted 30 January 2012 - 01:37 AM

========== OTL ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found.
C:\Users\mcunnie\AppData\Local\j6rj08f2li3vlh moved successfully.
C:\ProgramData\j6rj08f2li3vlh moved successfully.
ADS C:\ProgramData\Temp:502D809E deleted successfully.
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command\\""|""%1" %*" /E : value set successfully!

OTL by OldTimer - Version 3.2.31.0 log created on 01292012_223701



only took about a second to run. What next?

#33 User is offline   m0le 

  • I know the drill!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 29,133
  • Joined: 24-July 08
  • Gender:Male
  • Location:London, UK

Posted 30 January 2012 - 05:36 AM

Now we transfer Combofix using the flashdrive. Drag it onto the desktop and run the program. If the program won't run (and that can happen when the malware detects Combofix) then retransfer the program and run it from the flashdrive folder.
If I have helped you fix your PC then please donate. Thanks

Posted Image
m0le is a proud member of UNITE (Unified Network of Instructors and Trusted Eliminators)

#34 User is offline   mcrugger 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 62
  • Joined: 21-December 11

Posted 31 January 2012 - 02:24 AM

Ok, so I dragged it tot he desktop and ran it, I am attaching the log of the result. When the computer restarted in normal mode, the result was the same, trying to open anything would say it was an illegal operation on a registry key that has been marked for deletion. However, I can choose to run things as administrator and they will work, which is what I am typing this post from right now. When I do, it asks if that program may make changes to the hard drive. Not sure if I shouldnt have done this, but a little late for that... what next?

Attached File(s)



#35 User is offline   m0le 

  • I know the drill!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 29,133
  • Joined: 24-July 08
  • Gender:Male
  • Location:London, UK

Posted 31 January 2012 - 07:25 PM

The Illegal Operation issue can be dealt with by a reboot.

The Combofix log looks fine too. Which means the OTL script removed the blocking files.


Please now continue the clean up by running the online ESET scanner

I'd like us to scan your machine with ESET OnlineScan
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image icon on your desktop.

  • Check Posted Image
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Under scan settings, check Posted Image and check Remove found threats
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology

  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • Copy and paste the resulting log in your next reply

If no log is generated that means nothing was found. Please let me know if this happens.
If I have helped you fix your PC then please donate. Thanks

Posted Image
m0le is a proud member of UNITE (Unified Network of Instructors and Trusted Eliminators)

#36 User is offline   mcrugger 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 62
  • Joined: 21-December 11

Posted 01 February 2012 - 12:21 AM

Bad news: When I rebooted in normal mode, the problem returned. It looks like the fix is only temporary. Any ideas?

#37 User is offline   m0le 

  • I know the drill!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 29,133
  • Joined: 24-July 08
  • Gender:Male
  • Location:London, UK

Posted 01 February 2012 - 02:31 PM

Sometimes the gap between the deletion of the registry items and the reboot causes problems.

Rerun Combofix and if the illegal operation warning comes up then reboot straight away.
If I have helped you fix your PC then please donate. Thanks

Posted Image
m0le is a proud member of UNITE (Unified Network of Instructors and Trusted Eliminators)

#38 User is offline   mcrugger 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 62
  • Joined: 21-December 11

Posted 03 February 2012 - 11:20 AM

So I ran combofix from the flash drive again through safe mode, when it rebooted everything ran okay so i rebooted it again, and the result was the same, the issue is back.

#39 User is offline   m0le 

  • I know the drill!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 29,133
  • Joined: 24-July 08
  • Gender:Male
  • Location:London, UK

Posted 03 February 2012 - 09:37 PM

We're going to go back to xPUD and try and run Dumpit again now we have a flashdrive

Download GETxPUD.exe to the desktop of your clean computer
  • Run GETxPUD.exe
  • A new folder will appear on the desktop.
  • Open the GETxPUD folder and click on the get&burn.bat
  • The program will download xpud_0.9.2.iso, and upon finished will open BurnCDCC ready to burn the image.
  • Click on Start and follow the prompts to burn the image to a CD.
  • Next download dumpit to your USB
  • Remove the USB & CD and insert it in the sick computer
  • Boot the Sick computer with the CD you just burned
  • The computer must be set to boot from the CD
  • Gently tap F12 and choose to boot from the CD
  • Follow the prompts
  • A Welcome to xPUD screen will appear
  • Press File
  • Expand mnt
  • Click on sdb1 (sdb1 represents the USB drive).
  • Double click on the dumpit file.
  • A black window will pop-up and it will dump and zip the MBR to your USB drive.
  • Press Enter to exit the black window.
  • Click on HOME tab and choose Power Off to turn off xPUD.
  • Remove the USB drive and insert it back on your working computer.
  • Locate the mbr.zip file in your USB drive and attach it when you reply.

If I have helped you fix your PC then please donate. Thanks

Posted Image
m0le is a proud member of UNITE (Unified Network of Instructors and Trusted Eliminators)

#40 User is offline   mcrugger 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 62
  • Joined: 21-December 11

Posted 05 February 2012 - 11:57 PM

I will have to do this tomorrow night, the other computer I am using right now can't burn CD's, bleep work laptops

#41 User is offline   m0le 

  • I know the drill!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 29,133
  • Joined: 24-July 08
  • Gender:Male
  • Location:London, UK

Posted 06 February 2012 - 05:56 PM

This can be done without a CD...

Download http://unetbootin.sourceforge.net/unetbootin-xpud-windows-latest.exe & http://noahdfear.net/downloads/bootable/xPUD/xpud-0.9.2.iso to the desktop of your clean computer
  • Insert your USB drive
  • Press Start > My Computer > right click your USB drive > choose Format > Quick format
  • Double click the unetbootin-xpud-windows-387.exe that you just downloaded
  • Press Run then OK
  • Select the DiskImage option then click the browse button located on the right side of the textbox field.
  • Browse to and select the xpud-0.9.2.iso file you downloaded
  • Verify the correct drive letter is selected for your USB device then click OK
  • It will install a little bootable OS on your USB device
  • Once the files have been written to the device you will be prompted to reboot ~ do not reboot and instead just Exit the UNetbootin interface
  • After it has completed do not choose to reboot the clean computer simply close the installer
  • Next download dumpit to your USB
  • Remove the USB and insert it in the sick computer
  • Boot the Sick computer
  • Press F12 and choose to boot from the USB
  • Follow the prompts
  • A Welcome to xPUD screen will appear
  • Press File
  • Expand mnt
  • Click on sdb1 (sdb1 represents the USB drive).
  • Double click on the dumpit file.
  • A black window will pop-up and it will dump and zip the MBR to your USB drive.
  • Press Enter to exit the black window.
  • Click on HOME tab and choose Power Off to turn off xPUD.
  • Remove the USB drive and insert it back on your working computer.
  • Locate the mbr.zip file in your USB drive and attach it when you reply.

If I have helped you fix your PC then please donate. Thanks

Posted Image
m0le is a proud member of UNITE (Unified Network of Instructors and Trusted Eliminators)

#42 User is offline   mcrugger 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 62
  • Joined: 21-December 11

Posted 09 February 2012 - 01:53 PM

The computer didn't recognize my usb to boot from, when i pressed f12 at startup it would only ask me if i wanted to run windows 7. I still have the CD that i burned fromt he sick domputer with xPud, should i just use that?

#43 User is offline   m0le 

  • I know the drill!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 29,133
  • Joined: 24-July 08
  • Gender:Male
  • Location:London, UK

Posted 09 February 2012 - 09:24 PM

Yes, you can use the CD. :)
If I have helped you fix your PC then please donate. Thanks

Posted Image
m0le is a proud member of UNITE (Unified Network of Instructors and Trusted Eliminators)

#44 User is offline   mcrugger 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 62
  • Joined: 21-December 11

Posted 10 February 2012 - 01:59 AM

Here ya go

Attached File(s)

  • Attached File  mbr.zip (2.24K)
    Number of downloads: 1


#45 User is offline   m0le 

  • I know the drill!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 29,133
  • Joined: 24-July 08
  • Gender:Male
  • Location:London, UK

Posted 10 February 2012 - 10:16 AM

The log looks clean. This is a puzzle.

Can you run Junction? This will look for programs which have been disabled

Copy Junction.exe to your desktop
  • Open a new notepad window (Start>All Programs>Accessories>Notepad)
  • Copy & paste the contents of the following codebox into the notepad window
    @ECHO OFF
    junction -s c:\ > log.txt
    start log.txt
    del %0

  • Click File > Save as
  • In the box labelled File name copy and paste look.bat
  • Change Save as type to All Files
  • Save it to your desktop
  • Close the notepad window
  • Double click on look.bat
  • Once it has finished, a notepad window will appear. Copy & Paste the contents of that window as a reply to this topic.

If I have helped you fix your PC then please donate. Thanks

Posted Image
m0le is a proud member of UNITE (Unified Network of Instructors and Trusted Eliminators)

Share this topic:


  • 8 Pages +
  • 1
  • 2
  • 3
  • 4
  • 5
  • Last »
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users