Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - CK111

Pages: [1]
1
RogueKiller / Re: Help with Report Please
« on: February 21, 2015, 01:14:15 PM »
Thanks for letting me know, Curson!!

-I'm going to monitor the computer for a few days before I weigh in on how the computer is running, to tax it et al.  I will let you know.

THANK YOU (I really can not express how much I appreciate your help!) :)
 

2
RogueKiller / Re: Help with Report Please
« on: February 19, 2015, 11:59:49 PM »
Curson,
-Norton did not immediately delete FRST or Fixlog.txt -like it did before - when I re-enabled Norton Antivirus Auto-Protect even though it deleted FRST mid-download when I was trying to download it earlier today before I disabled the auto-protect. 
(usually, Norton does not require a restart to update virus definitions and will tell you when it does  So, I don't know whether or not Norton has whitelisted it or not or if Norton will delete FRST later on).

-So, I will let you know if Norton does anything with FRST and/or Fixlist.exe.

-Also, in serveral days and after several Norton updates, I'll try to download FRST again and see if Norton blocks it. I imagine y'all don't want FRST blacklisted and want to know that Norton has actually completed the whitelisting process.

I look forward to your telling me what else we need to do.

THANK YOU SO MUCH!!

3
RogueKiller / Re: Help with Report Please
« on: February 19, 2015, 11:48:30 PM »
Hi Curson yet again,
-Apparently, Norton had not yet included the FRST whitelist in it's virus definitions.  I updated my security settings (using steps that the Norton folks showed me that goes beyond just doing it once (multiple updates until you get a certain result) - which completely insures the program is fully updated - something they do before they do any analysis).  So, if they had released the virus definitions with FRST whitelisted, it should have allowed me to download FRST instead of blocking it.
So, to follow your instructions, I have had to disable the Anti-Virus Portion of Norton to do this.
Here is what I did (I hope that I did it right).
1. I downloaded the new fixlist.txt file into the same directory I would be downloading FRST.
(I don't like to use desktop - it's easier to track things if I create a separate folder under my download directory)
2. I (finally with Norton Antivirus Auto-Protect disabled) downloaded FRST to the same directory as the new fixlist.txt file - successfully only after disabling Norton.
3. I clicked on FRST and the Recover Tool Opened.
4. I did NOT run a another full scan using FRST - I hope that did not mess things up.  I should have asked you first if you meant by saying 'run FRST' running another scan or just a fix.
5. When FRST opened, I clicked on Fix once.
6. FRST ran some processes and deleted a number of temporay files per the progress bar.
(I did look at, without modifying it, the new fixlist.txt file.  While I did not see FRST on the progress bar making the registry changes that appear to have been in the new fixlist.txt file, I have not gone into the registry to look to see if those changes were made.  FRST removed the new fixlist.exe file from the directory/folder where I placed it and FRST during the mandatory restart.  FRST remains there for now.
Also, as I write this response, I don't see the new fixlist.txt attached to your response - perhaps because, when I logged into the forum it changes, the view.)
Nonetheless:
7. FRST restarted the computer (no apparent problems there).
8. Norton Antivirus Auto-Protect did not restart when I restarted the computer.
(I will restart it in a minute)
9. As of now, I am going to submit this reply with the Fixlog.txt before re-enabling Norton Antivirus Auto-Protect.
10.  Then, I will re-enable Norton Antivirus Auto-Protect and see what happens.
-I have copied the Fixlog.txt to a newly created folder that does not have FRST in it - so, we'll see what happens when I re-enable Norton.
-I'll let you know what Norton does in a separate post.

Also, please let me know if I did the steps properly and what we need to do next.

THANK YOU AGAIN!!!!

4
RogueKiller / Re: Help with Report Please
« on: February 18, 2015, 06:26:56 PM »
Hi Curson,
-I have some good news from Norton; but, first a couple of things:
1. In all of the lengthy answer about Coupon Printer et al, I forgot to tell you that, per your instructions, I did not run the script you sent since I did download those programs deliberately.
2.  If you need it: Next time one of the the svchost.exe processes running hogs memory (like one did today spiking to 500,000 KB plus), I can send you the services that one is accessing.

THANKS AGAIN - I look forward to the next steps as we track down the hooks and other things that may not supposed to be on my computer.

NOW to Norton -
-The good news is that they have approved the exception - whitelisted Fabar Recovery Scan Tool (FRST.exe) and it will be released in the next virus definitions updates.
-Here is their e-mail received overnight my time.

In relation to submission [3729629].

Upon further analysis and investigation we have verified your submission and, as such, the detection(s) for the following file(s) will be removed from our products:

   B77374098AFC4AAB9AB17E5A9FAD8BC7 - FRST.exe


The updated detection(s) will be distributed in the next set of virus definitions, available via LiveUpdate or from our website at http://securityresponse.symantec.com/avcenter/defs.download.html

Decisions made by Symantec are subject to change if alterations to the Software are made over time or as classification criteria and/or the policy employed by Symantec changes over time to address the evolving landscape.

If you are a software vendor, why not take part in our whitelisting program?
To participate in this program, please complete the following form: https://submit.symantec.com/whitelist


AGAIN, thanks Curson!

5
RogueKiller / Re: Help with Report Please
« on: February 18, 2015, 01:11:00 AM »
Well Curson - First of all, thank you for your personal remarks - concerns about the temperatures.  You are a good person for sure.

Now, on the the problem at hand and your questions/information you requested:
-The computer is still running slowly at times and at other times faster/ok.  The problem with svchost.exe hogging memory still recurs from time to time - yet, when I end the process using Task Manager, it does the weird things it should and then the computer runs faster (however, that does not 'feel' like the only problem or maybe not the root problem.  I have some experience in diagnosing problems but not always the skills to fix them or the knowledge to know about the great tools out there now that work best.  Thurs my statement about 'feeling' like the problem).
In fact, when I first used Rogue Killer, the hooks et al made too much sense as a possible core source of the problems - especially since it also 'feels' like I have something dragging down performance (like malware that can track) and I've even suspected a keylogger or other way to see/watch what I am doing).

Re Norton and reporting the issue and requesting white listing
-Done - I'll let you know when I hear from them (right now, I've only posted it and received an acknowledgement)
-If I have room, I paste their response since it includes what I sent Norton at the bottom of this. 
-If not enough room, then I'll put it in a subsequent reply.

Re Coupon Printer, Hopster or Catalina Marketing on purpose:
-Yes, I installed them on purpose.  I use coupons extensively and, as you know, those are required files to print coupons.  (Although, if memory service, Hopster is what Red Plum uses and it is not working properly.)
-If they weren't required files by various sites (Coupon Printer becoming more and more necessary), then I would not use them.
-For a long time, I would (and still do) disable the Coupon Printer service in the services window.  I also make it a manual (not automatic) service. Then, right before I plan to print coupons, I would enable the service manually.
That tended to make Coupon Printer not working (and appeared to keep it's background 'mess' to a minimum.)
-Recently, the Coupon Printer service can be totally off and also on manual start - and, the Coupon Printer will still print (oddly).  Also, sometimes, I uninstall Coupon Printer from the Programs anyway and then reinstall when I want to print coupons that require Coupon Printer.  One additional oddity is that sometimes installing Coupon Printer will not install a corresponding service (i.e. - none there at all). 
-Seems like the Coupons.com/Coupons Printer folks are getting sneakier and sneakier to make sure they can get the information the Coupon Printer feeds them without us being able to block it..
-In fact, one time (has only happened once), I uninstalled Coupon Printer and then sometime later needed to print some coupons requiring Coupon Printer.  Instead of prompting me to install Coupon Printer (it having been uninstalled), the coupons simply printed.  So, somewhere, Coupon printer had to still be working despite it not showing in Services or even in Programs under Control Panel.

-Currently, I see no service for Hopster or Catalina Marketing.  I do see the Coupon Printer Service (which was on manual and not started when I've run the scans.)
-Under the Programs area of the Control Panel
-Catalina Savings Printer - Publisher:  Catalina Marketing Corp - Installed on:  9/30/2013 - Size:  1.94 MB - Version:  1.0.0
-Coupon Printer for Windows - Publisher:  Coupons.com Incorporated - Installed on:  1/6/2015 - Size: (nothing listed) - Version:  5.0.1.3
(A reinstall after an earlier deletion.  This time, it did show install a service.  But, it has printed even when the service was disabled/not started)
-CouponPrinterPlugin - Publisher:  Hopster - Installed on:  1/6/2015 - Size:  2.82 MG - Version:  2.0.2.0
(There is not a listing for a program named Hopster; so, apparently, Hopster names itself upon install as CouponPrinterPlugin.  Also, when I installed it on 1/6/2015, it did not work properly and never printed a coupon for me.  I have not had a chance to troubleshoot and have not needed it to print any coupons since then).


Thank you for contacting Symantec.

Your submission has been received and will be reviewed. We endeavor to respond to all submissions within 2 working days.

The tracking number for your submission is: 3729629, please reference this tracking number in any further correspondence on this issue.

Your submission:
-----
  When did the detection you are reporting occur? = APPLICATION
  Which product were you using when you saw this? = N360
  Which of the following types of detection are you reporting? = AUTO-PROTECT
 
  Name (person to contact) = Clif Kelley
  Email address = clifkelley@earthlink.net
  Are you the creator or distributor of the software in question? = no
 
  File being uploaded =
  Download (or blocking) URL = http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/
 
  Name of the software being detected = Fabar Recovery Software Tool - FTST.exe and FRST(1).exe
  Name of detection given by Symantec product = Suspicious.Cloud.7.EP
  File hash or clipboard paste from product = FIRST PROBLEM:
Filename: frst.exe
Threat name: Suspicious.Cloud.7.EP
Full Path: c:\users\clif\downloads\fabar recovery scan tool\frst.exe

____________________________



Details
Unknown Community Usage  Unknown Age  Risk High





Origin
Downloaded from
 Unknown





Activity
Actions performed: 14



____________________________



On computers as ofÂ
Not Available


Last UsedÂ
2/17/2015 at 11:47:29 AM


Startup ItemÂ
No


LaunchedÂ
No


____________________________


Unknown
It is unknown how many users in the Norton Community have used this file.

Unknown
This file release is currently not known.

High
This file risk is high.

Threat type: Heuristic Virus. Detection of a threat based on malware heuristics.



____________________________



Source: External Media



____________________________

File Actions

File: c:\users\clif\downloads\fabar recovery scan tool\ frst.exe Removed
File: c:\users\clif\downloads\fabar recovery scan tool\ addition.txt Removed
File: c:\users\clif\downloads\fabar recovery scan tool\ frst.txt Removed
File: c:\frst\logs\ frst_17-02-2015_11-34-52.txt Removed
Directory: c:\ frst Removed
Directory: c:\frst\ logs Removed
Directory: c:\frst\ quarantine Removed
Directory: c:\frst\ hives Removed
____________________________

Registry Actions

Registry change: HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ FRST_RASAPI32 Removed
Registry change: HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ FRST_RASMANCS Removed
Registry change: HKEY_USERS\S-1-5-21-3395011634-4035225922-1332991411-1003\Software\Microsoft\Windows\CurrentVersion\ Internet Settings-ProxyEnable:0 Repaired
Registry change: HKEY_USERS\S-1-5-21-3395011634-4035225922-1332991411-1003\Software\Microsoft\Windows\CurrentVersion\ Internet Settings-ProxyOverride:.local Repaired
Registry change: HKEY_USERS\S-1-5-21-3395011634-4035225922-1332991411-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ Connections-SavedLegacySettings:... Repaired
Registry change: HKEY_USERS\S-1-5-21-3395011634-4035225922-1332991411-1003_CLASSES\Local Settings\MuiCache\67C\ 52C64B7E-LanguageList:... Repaired
____________________________


File Thumbprint - SHA:
0b7923a063eadd4b8e45b1aaa676afb8922e6638967ff40588e830ecf8d2f3e5
File Thumbprint - MD5:
Not available

SECOND PROBLEM WHEN SUBMITTING THIS REPORT
Filename: FRST[1].exe
Threat name: Suspicious.Cloud.7.EP
Full Path: c:\users\clif\appdata\local\microsoft\windows\temporary internet files\low\content.ie5\epf7tqcv\frst[1].exe

____________________________



Details
Unknown Community Usage  Unknown Age  Risk High





Origin
Downloaded from
 http://download.bleepingcomputer.com/farbar/FRST.exe





Activity
Actions performed: Actions performed: 1



____________________________



On computers as ofÂ
2/17/2015 at 6:22:41 PM


Last UsedÂ
2/17/2015 at 6:24:15 PM


Startup ItemÂ
No


LaunchedÂ
No


____________________________


Unknown
It is unknown how many users in the Norton Community have used this file.

Unknown
This file release is currently not known.

High
This file risk is high.

Threat type: Heuristic Virus. Detection of a threat based on malware heuristics.



____________________________


http://download.bleepingcomputer.com/farbar/FRST.exe

Downloaded File FRST[1].exe Threat name: Suspicious.Cloud.7.EP
from bleepingcomputer.com

Source: External Media




frst[1].exe




____________________________

File Actions

File: c:\Users\Clif\AppData\Local\microsoft\Windows\temporary internet files\Low\Content.IE5\EPF7TQCV\ FRST[1].exe Removed
____________________________


File Thumbprint - SHA:
0b7923a063eadd4b8e45b1aaa676afb8922e6638967ff40588e830ecf8d2f3e5
File Thumbprint - MD5:
Not available
 
  Additional notes or steps to reproduce the detection = -Initially Norton blocked the download of the file (like the second occurrence above.  I had a link on both occasions to directly begin the download and Norton Blocked it.

So I disabled the Norton Antivirus portion of Norton 360 and successfully downloaded ran the tool (Fabar Recovery Scan Tool aka FRST.exe) so I could get the two log files/reports it generates.  With Norton Anti-virus disabled I forwarded one log file/report generated by the successful scan to someone and then enabled Norton the Norton Antivirus.  Norton then automatically removed both the FRST.exe file and the other log file (SECOND PROBLEM Above.)

This is probably a false positive and the Fabar Recovery Scan Tool needs to be white listed.

-----

Sincerely,
Symantec Security Response
http://securityresponse.symantec.com

This message (including any attachments) is intended only for the use of the individual or entity to which it is addressed and may contain information that is non-public, proprietary, privileged, confidential, and exempt from disclosure under applicable law or may constitute as attorney work product. If you are not the intended recipient, you are hereby notified that any use, dissemination, distribution, or copying of this communication is strictly prohibited. If you have received this communication in error, notify us immediately by telephone and (i) destroy this message if a facsimile or (ii) delete this message immediately if this is an electronic communication. Thank you.

6
RogueKiller / Re: Help with Report Please
« on: February 17, 2015, 06:07:06 PM »
Hi Curson again,
Norton removed the Additions.txt before I could send it.  Here are the details:

-FYI - when I re-enabled Norton's Antivirus Protections - Norton Initially told me that it was investigating a Suspicious Cloud. 
-Then, when I went to the directory to attach the Additions.txt, the FRST.exe file was removed (by Norton).
-After that, Norton informed me of having done that removal and added the following Information:
Severity:  High;  Activity:  frst.exe (Suspicious.Cloud.7.EP) detected by Auto-Protect;  Status:  Restart Required; Date/Time:  2/17/2015 11:47:29 AM.
frst.exe contained threat Suspicous.Cloud.7.EP; Risk: High; Origin: Not Available; Activity:  Threat Actions performed:  14

Filename: frst.exe
Threat name: Suspicious.Cloud.7.EP
Full Path: c:\users\clif\downloads\fabar recovery scan tool\frst.exe

____________________________



Details
Unknown Community Usage,  Unknown Age,  Risk High





Origin
Downloaded from
 Unknown





Activity
Actions performed: 14



____________________________



On computers as of 
Not Available


Last Used 
2/17/2015 at 11:47:29 AM


Startup Item 
No


Launched 
No


____________________________


Unknown
It is unknown how many users in the Norton Community have used this file.

Unknown
This file release is currently not known.

High
This file risk is high.

Threat type: Heuristic Virus. Detection of a threat based on malware heuristics.



____________________________



Source: External Media



____________________________

File Actions

File: c:\users\clif\downloads\fabar recovery scan tool\ frst.exe Removed
File: c:\users\clif\downloads\fabar recovery scan tool\ addition.txt Removed
File: c:\users\clif\downloads\fabar recovery scan tool\ frst.txt Removed
File: c:\frst\logs\ frst_17-02-2015_11-34-52.txt Removed
Directory: c:\ FRST Restart Required
Directory: c:\FRST\ Logs Restart Required
Directory: c:\frst\ quarantine Removed
Directory: c:\FRST\ Hives Restart Required
____________________________

Registry Actions

Registry change: HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ FRST_RASAPI32 Removed
Registry change: HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ FRST_RASMANCS Removed
Registry change: HKEY_USERS\S-1-5-21-3395011634-4035225922-1332991411-1003\Software\Microsoft\Windows\CurrentVersion\ Internet Settings->ProxyEnable:0 Repaired
Registry change: HKEY_USERS\S-1-5-21-3395011634-4035225922-1332991411-1003\Software\Microsoft\Windows\CurrentVersion\ Internet Settings->ProxyOverride:*.local Repaired
Registry change: HKEY_USERS\S-1-5-21-3395011634-4035225922-1332991411-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ Connections->SavedLegacySettings:... Repaired
Registry change: HKEY_USERS\S-1-5-21-3395011634-4035225922-1332991411-1003_CLASSES\Local Settings\MuiCache\67C\ 52C64B7E->LanguageList:... Repaired
____________________________


File Thumbprint - SHA:
0b7923a063eadd4b8e45b1aaa676afb8922e6638967ff40588e830ecf8d2f3e5
File Thumbprint - MD5:
Not available


YOUR ADVICE/Thoughts? - I can temporarily disable Norton Anti-Virus again, download and then run Fabar again and move the logs - if it generates both logs since that would not be technically the first time I will have run Fabar (I can may sure to check the box next to Additions if that will generate another Additions.txt) - to another directory before re-engaging Norton Anti-Virus (since I really don't like to be on-line with no Anti-Virus operating).  While, I would anticipate Norton again deleting both FTST.exe and the two logs from the directory I download FRST.ext into, I would have copies elsewhere we can work from.


7
RogueKiller / Re: Help with Report Please
« on: February 17, 2015, 05:43:58 PM »
Hi Curson,
-Thanks for keeping the thread open.
-Well, I'm feeling well enough to re-start this diagnosis process (now, since we are expecting temps near or below zero which have never happend where I live and we have just had a sleet storm, let's hope the power stays on and my heat can keep up since the heat pump portion which is waiting a part to repair it is not a working part of the system so I only have supplemental heat there . . . in other words, when I can replay after you review the logs from the Fabar Recovery Scan Tool will depend upon how things work out with the weather/heat.)

-Re the Fabar Scan:  Norton hates it.  It deleted it each time I tried to download it with Norton Running.  Then, after disabling Norton's Anti-Virus protection to get it downloaded. when I re-enabled Norton and tried to run Fabar, Norton still deleted it.
-HOWEVER, I did get it to run by disabling Norton's Anti-Virus while running it.
(Did not know if that would be of importance.)

Attached is the first log (FRST.txt from 2-17-15).
-I will send the second file (Addition.txt from 2-17-15) in an additional reply post.

I did not do any fixes using Fabar.

THANKS AGAIN, Curson!!!

8
RogueKiller / Re: Help with Report Please
« on: February 08, 2015, 03:41:39 AM »
Curson,
-Please do not close this thread.  I've been quite under the weather and probably will not feel like doing the Fabar Recover Tool activities until mid week next week at the earliest.
-I did however, want to respond just to let you know that i am still interested in and appreciative of your help and will follow through. 

9
RogueKiller / Re: Help with Report Please
« on: February 03, 2015, 11:09:32 PM »
The computer is slower than it should be (in my opinion), Curson - like I have something draggin it down.  I've wondered (due to some things that have happened) if I have a keylogger; but, I hope Rogue Killer debunked that concern.
-For example, it hangs when opening files, emails, etc. (get 'Not Responding') way too often.  Also, one of the svchost.exe processes running seems to hog memory from time to time. That's what led me to find Rogue Killer

The computer is a Compaq CQ60-615DX Intel Celeron with 2GB Ram.

So, unfortunately, to answer your question - I can't tell if the computer is running normally. 
-I have Norton One which, as you know, allows unlimited technical support.  The computer has run slowly in the past when Norton found something.  The first time I purchased/used Norton One, they found a boot sector virus.  Then, two weeks later, they found some other thing apparently concealed by the boot sector virus. That was a couple of years ago.  Also, recently, I found my computer running slowly and they found Trojan.Poweliks was infecting my computer and removed it.
-Bottom line - sometimes the Norton One folks have found problems such as the examples listed above; and, at other times, I've called and they've found nothing when I've called.
(FYI - I use Norton 360 as the 'live' antivirus/firewall/etc. program - my main one.  I also use the free versions of Super AntiSpyware, Spybot, and Malwarebytes Anti-Malware bytes to check my computer from time to time.  None run actively so as not to conflict with Norton nor do they run in the background.  I manually kick off checks periodically using each of them.)

THANKS SO MUCH CURSON!!!!

10
RogueKiller / Re: Help with Report Please
« on: February 02, 2015, 08:47:49 PM »
And, Curson - Here is the log from the first (ABORTED) Scan that I had started without the TDSS Killer checkbox for the Loaded Modules checked - just in case you need it.
-As stated, the log from the full scan is attached to my other post today.

Once again, I appreciate your help!

11
RogueKiller / Re: Help with Report Please
« on: February 02, 2015, 08:44:22 PM »
Thank you for responding Curson!
-Thank you too for the excellent and clear directions.

Downloaded and ran TDSS Killer as you asked.
-Initially, I started it without having checked the Loaded Modules checkbox checked (my bad) and interrupted that scan almost immediately after starting it.
-Then, I clicked the Loaded Modules checkbox; and, as you predicted, a reboot was required.
No Threats were found.

-I tried to attach the log from the aborted scan (TDSSKiller.3.0.0.44_02.02.2015_14.14.11_log.txt)
and the log from the complete TDSS Killer scan (TDSSKiller.3.0.0.44_02.02.2015_14.22.47_log.txt);l however, since I could only attach one lo as an attachment - So, the full scan log is attached.
(TDSSKiller.3.0.0.44_02.02.2015_14.22.47_log.txt).

I will create another response and attach the aborted scan log - just in case you need it.

THANKS again!


12
RogueKiller / Help with Report Please
« on: January 30, 2015, 06:15:40 PM »
Ran Rogue Killer once and fixed the registry entries.  Saw the Antirootkit listings on the tab and in the report.  Also, the Hosts File was too large; so, I let Rogue Killer rest it.

Ran a second Rogue Killer Scanner and still found Antirootkit entries Hooks in orange in the GUI interface.  Also, they (of course) showed up in the log.
-tried searching for a couple in the registry to see if they needed fixing/I could interpret; and, the registry search said it could not find them (nothing found at all on search results).

Here is the log from the second scan.
-Please let me know if you see problems - particularly with the unknown location hoooks - and, if there are problems, some guidance as to how to begin to fix.

THANKS!

FYI - log file had too many characters in and of itself for me to include in the narrative; so, I have included as an attachment.  Thanks!

Pages: [1]