ShadowPuterDude Posted January 29, 2015 Report Share Posted January 29, 2015 Your logs look fine. They show no malware, I cannot fix what I cannot see. Link to comment Share on other sites More sharing options...
pallino Posted January 30, 2015 Author Report Share Posted January 30, 2015 So No reason to worry how these restrictions got on my pc without doing anything,out of the blue ? You still think this device wasn t infected and can be used for transactions? Link to comment Share on other sites More sharing options...
ShadowPuterDude Posted January 30, 2015 Report Share Posted January 30, 2015 I have nothing to go on based what is in your logs to determine what is setting the restrictions. So, I cannot make the call as to whether or not there is anything to be concerned about. Link to comment Share on other sites More sharing options...
pallino Posted January 30, 2015 Author Report Share Posted January 30, 2015 If it was your laptop, what would you do? would you use it i peace, reset it to day 0 and update all, or scan with other tools? Link to comment Share on other sites More sharing options...
ShadowPuterDude Posted January 30, 2015 Report Share Posted January 30, 2015 I would reset the router and reinstall the OS on the Laptop. Especially, when I cannot identify what is causing the problem. Link to comment Share on other sites More sharing options...
pallino Posted February 2, 2015 Author Report Share Posted February 2, 2015 Hello Kevin, thank you for the honest answer! I reinstalled all from the rescue cds I created as soon as I started the laptop the first time. I installed few programs and updated all. When I then tryed to lanch IE to change the settings I got a warning from EMET for a EAF that then closed IE......what can this be? In the FRST under Internet I saw www.amazon.com ..but I didn't visit this site on this laptop... Pls find attached the new reports. How do they look like? I just had a quick look at the additon.txt, what does the error below mean? (Claudio-HP is a laptop that was connected to the same router as I worked on mine.) Error: (02/01/2015 07:42:57 PM) (Source: BROWSER) (EventID: 8009) (User: )Description: The browser was unable to promote itself to master browser. The computer that currentlybelieves it is the master browser is CLAUDIO-HP. thank you Addition.txt FRST.txt virusinfo_syscheck.zip Link to comment Share on other sites More sharing options...
pallino Posted February 2, 2015 Author Report Share Posted February 2, 2015 and Emsi's one.. a2scan_150201-235609.txt Link to comment Share on other sites More sharing options...
pallino Posted February 2, 2015 Author Report Share Posted February 2, 2015 In the meatime I found out what caused EMET to find an EAF mitigation...it was because of Malwarebytes antiexploit..if I stop Malwarebytes AE protetion, EMET stays quite....hope this s "normal". Or I have to uncheck EAF, EAF+ and SiM Exe Flow in EMET. If I uncheck only EAF and EAF+, when I start IE, EMET blocks it for a SiM Exe Flow...hope this helps. Link to comment Share on other sites More sharing options...
ShadowPuterDude Posted February 3, 2015 Report Share Posted February 3, 2015 We run EMET with its defaults. Link to comment Share on other sites More sharing options...
pallino Posted February 3, 2015 Author Report Share Posted February 3, 2015 Same here even if I cannot use IE, but this is not bad since i use firefox...the info above was for info hoping it could help. How do the logs look like and 2. I just had a quick look at the additon.txt, what does the error below mean? (Claudio-HP is a laptop that was connected to the same router as I worked on mine.) Error: (02/01/2015 07:42:57 PM) (Source: BROWSER) (EventID: 8009) (User: ) Description: The browser was unable to promote itself to master browser. The computer that currently believes it is the master browser is CLAUDIO-HP. thks Link to comment Share on other sites More sharing options...
ShadowPuterDude Posted February 3, 2015 Report Share Posted February 3, 2015 The system should be reinstalled. Error: (02/01/2015 07:42:57 PM) (Source: BROWSER) (EventID: 8009) (User: ) Description: The browser was unable to promote itself to master browser. The computer that currently believes it is the master browser is CLAUDIO-HP. See: http://support.microsoft.com/kb/143153 https://msdn.microsoft.com/en-us/library/ms841537.aspx Link to comment Share on other sites More sharing options...
pallino Posted February 3, 2015 Author Report Share Posted February 3, 2015 As suggested I just had reinstalled all! ..and not from recovery partition since it could have been compromised but from resue disks created as soon as the laptop started the first time. How could this have happened? Is this "normal" or a clear sign of malware presence? Is this windows or router related? As info, as I installed windows, the laptop was not connected to internet and I can connect to internet with the laptop. Please help!!! Thank you Link to comment Share on other sites More sharing options...
ShadowPuterDude Posted February 3, 2015 Report Share Posted February 3, 2015 Did you reset you router? If it is infected it can infect any system connected to it. Link to comment Share on other sites More sharing options...
pallino Posted February 4, 2015 Author Report Share Posted February 4, 2015 I reset it twice in the past, one when you suggested me and one another time but not immediately before reconnecting te laptop after reinstalling al. If it's the outer, than it gets reinfected easily after resetting it...or resetting doesn 't delete the malware (if the router got haked) or the problem is elsewhere...before resetting I didn't have this roblem...... What do you think and what can I do now? What would you do if it was your laptop? Link to comment Share on other sites More sharing options...
ShadowPuterDude Posted February 4, 2015 Report Share Posted February 4, 2015 Doing a hard reset, resets the router to factory settings. If you do not change the default password or set a difficult to guess password on the router, then it is going to get infected again. If the reset does not work then a firmware update should. Link to comment Share on other sites More sharing options...
pallino Posted February 5, 2015 Author Report Share Posted February 5, 2015 I reinstalled all, then reset the router and immediately changed username and psw. No firmware updates are available. How do the logs look like now? All fine and safe? Thank you Addition.txt FRST.txt virusinfo_syscheck.zip Link to comment Share on other sites More sharing options...
ShadowPuterDude Posted February 5, 2015 Report Share Posted February 5, 2015 Your logs look fine. Link to comment Share on other sites More sharing options...
pallino Posted February 6, 2015 Author Report Share Posted February 6, 2015 After all what happened on this laptop and othe the other one I run also Roguekiller and NPE. They both found a oonqp.sys file (I managed to cut&paste it, then it disappeared from /system/32/drivers)...apparently is a malwarebytes file but I cannot find it on any other devices I have. Attached the new logs. I also keep getting warnings from Emsi that HP Hpsa (helpsupport) is being modified or the youcam program, most when I scan with AV (always with a blank page if I want additional informations) ...is it normal or is it suspect? What do you think? Thank you! virusinfo_syscheck.zip Addition.txt FRST.txt RKreport_SCN_02052015_184543.log oonqp.zip Link to comment Share on other sites More sharing options...
ShadowPuterDude Posted February 6, 2015 Report Share Posted February 6, 2015 oonqp.sys is a Malwarebytes file. Norton is wrong. Copy the below code to Notepad; Save As fixlist.txt to your Desktop. 2015-02-05 11:47 - 2015-02-05 11:47 - 00000000 ____D () C:\ProgramData\{65AB91D4-DDD0-48D4-804D-C24E1FC90D44} 2015-02-04 14:46 - 2015-02-04 14:46 - 00000000 ____D () C:\Users\Default\AppData\Local\Pokki 2015-02-04 14:46 - 2015-02-04 14:46 - 00000000 ____D () C:\Users\Default User\AppData\Local\PokkiClose Notepad.NOTE: It's important that both files, FRST64 and fixlist.txt are in the same location or the fix will not work. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system Run FRST64 and press the Fix button just once and wait. If the tool needed a restart please make sure you let the system to restart normally and let the tool complete its run after restart. The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply. Note: If the tool warns you about an outdated version please download and run the updated version. Link to comment Share on other sites More sharing options...
pallino Posted February 9, 2015 Author Report Share Posted February 9, 2015 Hi Kevin, please find attached the new logs. - What can the utizmzqw.sys error be about? - What is this error blow? Error: (02/05/2015 09:06:03 PM) (Source: NetBT) (EventID: 4311) (User: )Description: Initialization failed because the driver device could not be created.Use the string "9CAD979D61B4" to identify the interface for which initializationfailed. It represents the MAC address of the failed interface or theGlobally Unique Interface Identifier (GUID) if NetBT was unable tomap from GUID to MAC address. If neither the MAC address nor the GUID wereavailable, the string represents a cluster device name. - Why do i keep getting warnings from EMSI that HPSA.exe or youcam.exe got modified every time I scan the pc? If I ask Emsi to update the rule, the scan get closed. If I say remove rule, I might get another warning but I can completee the scan....I have then the same warning the next time I rescan... What do you think? thank you! Addition.txt FRST.txt Fixlog.txt virusinfo_syscheck.zip Link to comment Share on other sites More sharing options...
ShadowPuterDude Posted February 9, 2015 Report Share Posted February 9, 2015 The Event log is full of cryptic error reports, for the most part they should be ignored. utizmzqw.sys is the AVZ driver. Your logs look fine. I have no idea why you are get warnings that HPSA.exe or youcam.exe have been modified. Link to comment Share on other sites More sharing options...
pallino Posted February 11, 2015 Author Report Share Posted February 11, 2015 Hi Kevin, thank you! Since this laptop is new and will be used for online/safe stuff only it should be clean and "doudt free". This was my 2nd fresh reinstall and we still have strange/unaxplainable things...I decided to reinstall all again. I'll update all logs as soon as ready, probably tomorrow (I m working on the other laptop right now. If that one is safe, I'll connect this one to internet and update all programs). Thank you Link to comment Share on other sites More sharing options...
ShadowPuterDude Posted February 11, 2015 Report Share Posted February 11, 2015 I'll take a look at the logs once I get them. Link to comment Share on other sites More sharing options...
pallino Posted February 13, 2015 Author Report Share Posted February 13, 2015 I ll work on this laptop over the weekend, pls keep the tread open. thank you and nice weekend Link to comment Share on other sites More sharing options...
ShadowPuterDude Posted February 16, 2015 Report Share Posted February 16, 2015 When ever you have the logs, I'll look at them. Link to comment Share on other sites More sharing options...
pallino Posted February 17, 2015 Author Report Share Posted February 17, 2015 Hi Kevin, please find attached the new logs. Why are windows and Fbar telling me that Emsi is not active/off? According to Emsi IS, my computer is protected..... who is right? According to NPE (and 2 scanners on virustotal), the attached zip temp file that was in c:/windows/temp is infected too... What do you think? thank you P.S. Since I didn't like the findings till now as the problem with Emsi above I also run rogue killer and attached the log.... Addition.txt FRST.txt virusinfo_syscheck.zip Addition.txt WAXB928.zip RKreport_SCN_02162015_222627.log Link to comment Share on other sites More sharing options...
ShadowPuterDude Posted February 17, 2015 Report Share Posted February 17, 2015 Did you reboot? Your logs show no malware. Link to comment Share on other sites More sharing options...
pallino Posted February 17, 2015 Author Report Share Posted February 17, 2015 Hp updated ciberlink and few hp programs..I didn t reboot, you are right, but why should Emsi disactivate? Was is still protecting the pc or was it off? The temp file and rogue killer logs were o.k too? Thank you Link to comment Share on other sites More sharing options...
ShadowPuterDude Posted February 17, 2015 Report Share Posted February 17, 2015 The security center sometimes does not register Emsisoft. Link to comment Share on other sites More sharing options...
pallino Posted February 18, 2015 Author Report Share Posted February 18, 2015 -The scary part is that also Fbar found Emsi off...did it get turned off/bypassed by malware or were fbar and wundiws wrong? -Is the temp file infected or a false alarm? Thank you Link to comment Share on other sites More sharing options...
ShadowPuterDude Posted February 18, 2015 Report Share Posted February 18, 2015 FBAR queries WMI for the status, which is the same place the Security stores the info. So, if the Security Center thinks it is disabled; so, will fbar. Link to comment Share on other sites More sharing options...
pallino Posted February 18, 2015 Author Report Share Posted February 18, 2015 Could you check the temp file? What about roguekillers pum? Link to comment Share on other sites More sharing options...
ShadowPuterDude Posted February 18, 2015 Report Share Posted February 18, 2015 It is a C library from Dinkumware used for encryption and decryption. Most likely used by PGP. Link to comment Share on other sites More sharing options...
pallino Posted February 20, 2015 Author Report Share Posted February 20, 2015 Hi Kevin, thank you! What about roguekiller 's PUM ? Can you please check this too? I attached new logs since today I had to go online and accessed all my accounts. If all is clean and safe I'll be super happy.....and the thread could be closed. :) thank you!!! Addition.txt FRST.txt virusinfo_syscheck.zip RKreport_SCN_02202015_115829.log Link to comment Share on other sites More sharing options...
ShadowPuterDude Posted February 20, 2015 Report Share Posted February 20, 2015 Stop with the constant logs. Just because RogueKiller finds something, does not means that it is dangerous. Link to comment Share on other sites More sharing options...
pallino Posted February 21, 2015 Author Report Share Posted February 21, 2015 again, I uploaded new logs not because I like it but because I had something that till today wasn't found/ recognised but that infected the router and 2 pcs at least and forced me to reinstall all many times and on different pcs. Since I use this laptop for online banking I think it s normal to ask to double check if all is still safe after all what happened and 3 reinstalls and 3 router resets...and roguekiller pum (that in the past you asked me to fix) didn t help as the tmp file! Thank you for your help, time and patience till now! Link to comment Share on other sites More sharing options...
ShadowPuterDude Posted February 23, 2015 Report Share Posted February 23, 2015 Your logs have not showed any malware for sometime. Sending me new logs from the same tools is not going to change what they are showing. Your logs look fine. Link to comment Share on other sites More sharing options...
Recommended Posts