The Elder Geek on Windows: Guidelines For Malware Removal And Log Analysis Forum - The Elder Geek on Windows

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

Guidelines For Malware Removal And Log Analysis Forum Read Before Posting Any Logs

#1 User is offline   Alatar1 

  • Asst. Cook & Bottle Washer (retired TEG Admin)
  • Group: Members
  • Posts: 6,150
  • Joined: 07-May 04
  • Location:Montreal

Posted 28 September 2005 - 04:29 PM

IMPORTANT: If you are browsing through the topics in this forum, please DO NOT follow instructions provided to others. They have been prepared by a forum staff expert to fix that particular members problems, NOT YOURS. Ignoring this warning and using someone else's fix instructions could lead to serious problems with your operating system.

If you are not posting a log for analysis, then please do not post in this forum or reply in another member's topic. Only the Malware Removal Team or Staff members are allowed to assist members in the Malware Removal and Log Analysis Forum. This helps to avoid confusion and ensure the member gets the required expert assistance they need to resolve their problem. While we understand you may be trying to help, please refrain from doing this or the post will be removed. Thanks for your cooperation.

For those who do need assistance, please continue with the instructions provided by our Malware Removal Team: quietman7, daveydoom, Wingman, jmw3, Vino Rosso.


Keep in mind that there are no guarantees or shortcuts when it comes to malware removal, especially when dealing with backdoor Trojans and rootkits. Infections will vary and some will cause more harm to your system then others as a result of it having the ability to download more malicious files. Some infections are difficult to remove completely because of their morphing characteristics which allows the malware to regenerate itself. Sometimes there is hidden piece of malware (i.e. rootkit component) which has not been detected by your security tools that protects malicious files and registry keys so they cannot be permanently deleted. Other types of malware can even terminate your security tools by changing the permissions on targeted programs so that they cannot run or complete scans. Thus, sometimes it takes several efforts with different, the same or more powerful tools to do the job. Even then, with some types of malware infections, the task can be arduous. In some instances an infection may have caused so much damage to your system that it cannot be successfully cleaned or repaired. The malware may leave so many remnants behind that security tools cannot find them. In those cases, starting over by wiping your drive, reformatting, and performing a clean install of the OS or doing a factory restore with a vendor-specific Recovery Disk or Recovery Partition removes everything and is the safest action.

Note for 64-bit system users: Anti-malware scanners and some specialized fix tools have problems enumerating the drivers and services on 64-bit machines so they do not always work properly. Microsoft created a new folder (C:\Windows\SysWOW64) that contains all the 32-bit .dll files required for compatibility which run on top of the 64-bit version of Windows. WOW64 is the x86 emulator that allows 32-bit Windows-based applications to run on 64-bit Windows but x86 applications are re-directed to the x86 \syswow64 when seeking the x64 \system32. For a more detailed explanation, please refer to Making the Move to x64: File System Redirection and WOW64 Implementation Details. Since this is the case, be aware that most of the tools we use for malware removal are designed for 32-bit systems and do not work or can give misleading results on 64-bit machines. For instance, running HijackThis on a 64-bit machine may show log entries which indicate (file missing) when that is NOT always the case. As such, if your system is infected, any assistance we can offer is limited and there is no guarantee all types of infections can be completely removed

Multiple Requests in the Malware Removal and Log Analysis Forum and Note to Repair Techs: TEG is set up to help the home computer user dealing with malware issues and questions relating to their personal computers. We will not provide assistance to multiple requests from the same member if they continue to get reinfected. We cannot provide continued assistance to Repair Techs helping their clients. We try to be as accommodating as possible but unlike larger help sites, that have a larger staff available, we are not equipped to handle as many requests for help. Our forum is an all volunteer forum and malware removal helpers are limited in the amount of time they can contribute. This means for each additional topic opened, someone else has to wait to be helped. This is unfair to other members and the malware removal helpers.

Our goal is to safely disinfect machines used by our members when they become infected. Attempting to clean several machines at the same time could be dangerous, as instructions could be used on different machines that could damage the operating system. As much as we would like to help with as many requests as possible, in order to be fair to all members, we ask that you post only one Malware Removal...Logs forum topic, for one machine, at a time. Home users with more than one computer can open another topic for that machine when the helper has closed the original topic.

Please be aware: Only members of the Malware Removal Team, Moderators or Administrators are allowed to assist members in the Malware Removal and Log Analysis. All others should refrain from posting in this forum. This helps to avoid confusion and ensure the user gets the required expert assistance they need to resolve their problem. Unauthorized replies to another member's thread in this forum will be removed, at any time, by a TEG Moderator or Administrator.

If you do not receive a timely reply: While we understand your frustration at having to wait, please note that TEG deals with numerous requests for assistance such as yours on a daily basis. As a result, our backlog is getting larger, as are other comparable sites that help others with malware issues. Our Malware Removal Team members which include Visiting Security Colleagues from other forums are all volunteers who contribute to helping members as time permits. Visiting Security Colleague are not always available here as they primarily work elsewhere and no one is paid by TEG for their assistance to our members. Please be patient. It may take a while to get a response but your log will be reviewed and answered as soon as possible.

Thank you for understanding and your cooperation.

The TEG Forum Staff

This post has been edited by quietman7: Yesterday, 04:57 PM

"We all know what to do, we just don't know how to win the election afterwards."
Jean-Claude Juncker, prime minister of Luxembourg, talking about politicians making tough decisions for the public good
0

#2 User is offline   quietman7 

  • Elder Janitor & Bug Exterminator
  • Group: Admin
  • Posts: 9,794
  • Joined: 24-December 03
  • Location:Virginia, USA

Posted 26 February 2008 - 02:46 PM

If you are having malware related problems please read the guidelines below and complete the following steps before posting your log. We want to provide help as quickly as possible but if you do not follow these instructions, chances are you may have to repost a log, thus increasing the time it will take for a member of the Malware Response Team to investigate your issues and prepare a fix to clean your system.

Important! If using Vista or Windows 7 be aware that the programs we ask to use, need to be Run As Administrator. Additionally, the built-in User Account Control (UAC) utility, if enabled, may prompt you for permission to run the program. When prompted, please select: Allow.

Before doing anything you should read and print out all the instructions. If you have not already done so, you should back up all your important documents, personal data files and photos to a CD or DVD drive as some infections may render your computer unbootable during or before the disinfection process and reformatting may be the only viable alternative. The safest practice is not to backup any files with the following file extensions: exe, .scr, .ini, .htm, .html, .php, .asp, .xml, .zip, .rar, .cab as they may be infected.
Please download RSIT by random/random from the link provided for your operating system and save it to your desktop.
This tool needs to run while the computer is connected to the Internet so it can download HijackThis if it is not located on your system. If you get a warning from your firewall or other security programs regarding RSIT attempting to contact the Internet, please allow the connection.
  • Close all applications and windows so that you have nothing open and are at your Desktop.
  • Double-click on RSIT.exe to start the program.
  • If using Windows Vista, be sure to Run As Administrator.
  • Read the disclaimer and click Continue.
  • When the scan is complete, a text file named log.txt will automatically open in Notepad.
  • Another text file named info.txt will open minimized.
  • Save the log files to your desktop and copy/paste the contents of log.txt by highlighting everthing and pressing Ctrl+C.
  • After highlighting, right-click, choose Copy and then paste it in your next reply.
  • Copies of both log files are automatically saved in the C:\RSIT folder which the tool creates during the scan.
  • Do not post the info.txt log unless I ask for it.

Post the log along with a brief description of your problem, a summary of any anti-malware tools you have used and a summary of any steps that you have performed on your own. Make sure you post your log in the Malware Removal and Log Analysis forum only. Please DO NOT post the log in any threads where you were advised to read these guidelines or post them in any other forums. When an expert has replied, follow the instructions and reply back in a timely manner.

-- If you are unable to connect to the Internet in order to download and use RSIT, then use another computer to download the program, save to a USB stick or CD and transfer it to the infected Computer.

-- RSIT only works with Windows XP, Vista and Windows 7 (32-bit, 64-bit). In fact many of the tools we use for malware removal only work on Windows XP and above. If you are using an older operating system (i.e. Windows 98/ME/2000), then follow the instructions below for installing and creating a log with HijackThis.

-- If RSIT will not run after installation, then follow these instructions for installing and creating a log with HijackThis. When you have done that, post your HijackThis log in the forum. Be sure to mention that you tried to follow the Prep Guide but were unable to get RSIT to run.

-- Why we no longer ask for HijackThis logs? HijackThis only scans certain areas of your system/registry to help diagnose the presence of undetected malware in known hiding places. Therefore, its log may not always show all the malware on your system. As such, HijackThis has been replaced by other preferred tools like DDS, RSIT and OTL which provide comprehensive logs with specific details about more areas of your computer.

GUIDELINES & RULES:

• Start a new topic, give it a relevant Subject Title and post your log along with a brief description of your problem, a summary of any anti-malware tools you have used and a summary of any steps that you have performed on your own. Please include the top portion of the requested log which lists version information.

• Please start your post by saying that you have already read this announcement and followed the directions or else someone is likely to tell you to come back here. The steps mentioned above are necessary to complete prior to using HijackThis to fix anything. If you already have installed and used some of these tools prior to coming here, then redo them again according to the specific instructions provided.

• Please DO NOT post your log file in a thread started by someone else even if you are having the same problem as the original poster. This helps to avoid confusion.

Please be patient and remember ALL staff on this site are Volunteers. In many cases they have gone through specific training to be able to accurately give you help with your individual computer problems. It takes time to properly investigate your log and prepare the appropriate fix response.

Once you have posted your log and are waiting, please DO NOT "bump" your post or make another reply until it has been responded to by a member of the Malware Response Team. Generally the staff checks the forum for postings that have 0 replies as this makes it easier for them to identify those who have not been helped. If you post another response there will be 1 reply. A team member, looking for a new log to work may assume another Malware Response Team member is already assisting you and not open the thread to respond.

If you performed scans with SUPERAntiSpyware and/or DrWeb-CureIt, please post the scan results along with your RSIT log.

• Please DO NOT post a Spybot or Ad-aware log file unless someone has asked you to do.

• Please DO NOT use ComboFix or other specialized fix tools unless instructed to do so by a member of the Malware Removal Team.

• Please DO NOT PM or Email for personal support - post your question in the forums instead so we all can learn.

Again, only members of the Malware Removal Team, Moderators or Administrators are allowed to assist members in the Malware Removal and Log Analysis Forum. All others should refrain from posting in this forum. This helps to avoid confusion and ensure the user gets the required expert assistance they need to resolve their problem. Unauthorized replies to another member's thread in this forum will be removed, at any time, by a TEG Moderator or Administrator.

------------------------------------------------------------------------------------------------------------------------------------------------
If you would rather try to clean the malware yourself instead of posting a log in the Malware Removal and Log Analysis, we have provided a list of some recommended scanning tools.

Note: Before using these scanning tools, the easiest and first thing you should try is System Restore or System Restore from a command prompt in Safe Mode to return to a previous state before the problems began. This may not always work as it's not uncommon for some types of malware to disable that feature. If your computer is unbootable, other options are:If System Restore works, it is still recommended to perform scans with anti-malware tools as System Restore will back up the good as well as malicious files.

Download and scan with with the following programs. Be sure to check for and download any definition updates prior to performing a scan.
For heavily infected systems:Perform at least one of these free online Virus scans:
(Requires Internet Explorer (or FireFox with IE Tab) to work. Watch the Address bar in IE. You may receive alerts that "This site might require the following ActiveX control...Click here to install...". Click on that alert and then Click Install ActiveX component. If given the option, choose "Quarantine" instead of delete.)
Note: While searching the web or other forums for your particular infection, you may have read about ComboFix and other specialized fix tools. You should not be using Combofix unless instructed to do so by a Malware Removal Expert who can interpret the logs. It is a powerful tool intended by its creator to be "used under the guidance and supervision of an expert", NOT for private use. Combofix was never meant to be used as a general purpose malware scanner like SuperAntispyware or Malwarebytes' Anti-Malware. Using this tool incorrectly could lead to disastrous problems with your operating system such as preventing it from ever starting again. Please read Combofix's Disclaimer. If this tool is needed, we will direct you accordingly.

This post has been edited by quietman7: 16 August 2010 - 09:56 AM

"THE BAD GUYS DON'T NEED A SEARCH WARRANT. ARE YOU PROTECTED?"


Member of UNITE, Unified Network of Instructors and Trusted Eliminators

Microsoft MVP - Windows Security 2007-2010
0

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • This topic is locked