Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Help with Wacatac.B!ml on Server 2016 Standard


  • Please log in to reply
44 replies to this topic

#31 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 55,541 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:06:24 PM

Posted 03 September 2023 - 08:56 PM

Let's see how we do. I am now not as confident Post #21 will work. If not, I have another process that will. We would boot into a Linux environment to completely bypass Windows then access and remove the offending entries.

Gary 

“Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.”

Where to Start


BC AdBot (Login to Remove)

 


#32 mlonabaugh

mlonabaugh
  • Topic Starter

  •  Avatar image
  • Members
  • 188 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:24 PM

Posted 04 September 2023 - 10:06 AM

Hi Gary,

Thanks for the update.

I will go into work now and try to hammer this out...   :smash:



#33 mlonabaugh

mlonabaugh
  • Topic Starter

  •  Avatar image
  • Members
  • 188 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:24 PM

Posted 04 September 2023 - 11:23 AM

So that was much easier than I expected as well :)

I hope this is good news...

Thank you sir.

*****************************************************************

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 28-08-2023
Ran by SYSTEM (04-09-2023 12:11:43) Run:25
Running from F:\
Boot Mode: Recovery
==============================================
 
fixlist content:
*****************
C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db
C:\Windows\Temp
*****************
 
C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db => moved successfully
C:\Windows\Temp => Could not move
 
==== End of Fixlog 12:11:44 ====


#34 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 55,541 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:06:24 PM

Posted 04 September 2023 - 03:17 PM

Hi Mark.

The Windows Defender file was removed but the C:\Windows\Temp folder was not. I was concerned this might happen.

I am not real familiar with Server 2016 and you may find Ubuntu is prohibited from booting because of BIOS (Secure boot) type settings. Just a heads up regarding a possible hiccup. Please attempt this.

===================================================

Deleting File/Folder Running Ubuntu From a USB Device

--------------

Note: This is an older version of Ubuntu which I have tested and is sufficient for our purposes.
  • You will need a USB device with at least 2 GB of space
  • If necessary insert your USB drive into a clean computer. Caution: The next step will remove all information from your USB device.
  • Press Start, My Computer, right click your USB drive, click Format, then select Quick format
  • Download Ubuntu Live Ubuntu 12.04.4. This is a large file so allow it some time to download
  • Download UNetbootin and save it to your Desktop as well
  • Double click the UNetbootin icon, select Run, then I Agree
  • Select the Diskimage Option then click the Browse Button located on the right side of the textbox field.
  • Browse to and double click the Ubuntu 12.04.4 file you downloaded
  • Verify the correct drive letter is selected for your USB device then click OK
  • It will install a little bootable OS on your USB device
  • Once the files have been written to the device you will be prompted to reboot ~ do not reboot and instead just Exit the UNetbootin interface
  • With the USB device inserted into the infected computer restart your computer
  • If your computer does not automatically boot from the USB device please see here
  • Select Try Ubuntu without installing
  • Click the Home Folder (3rd one from the top)
  • Under Devices you will see a System entry along with one or more additional entries indicating a GB size, i.e. 250GB)
  • Click on a GB entry until you see the Windows folder on the right side
  • By means of double clicking folders, individually navigate to the following location:

C:\Windows\Temp

  • Right click on the entry and select Move to Trash
  • In the upper right hand corner of your screen select the icon just to the right of the time
  • Click Shut down... then click Shut down... again in the pop up window
  • Reboot your computer into Windows
  • Click the Windows key + E at the same time
  • Navigate to the listed location and confirm the entry has been removed
  • Post back with the results
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
  • Results?

Gary 

“Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.”

Where to Start


#35 mlonabaugh

mlonabaugh
  • Topic Starter

  •  Avatar image
  • Members
  • 188 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:24 PM

Posted 05 September 2023 - 07:35 AM

Good morning sir,

Like usual this may take a while to accomplish. 

 

I want to be clear, the end game is to delete the entire Windows Temp "Folder", not the contents? 

 

Thank you!



#36 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 55,541 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:06:24 PM

Posted 05 September 2023 - 08:51 AM

No problem on the delay, I understand the availability issue.

 

Yes sir, delete the entire folder and it should be automatically recreated upon reboot.


Gary 

“Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.”

Where to Start


#37 mlonabaugh

mlonabaugh
  • Topic Starter

  •  Avatar image
  • Members
  • 188 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:24 PM

Posted 10 September 2023 - 09:04 AM

Good morning,

I finally completed the task and the temp folder seemed to be successfully deleted.

There is now a Windows\Temp folder that was created after reboot.

 

Is that what you expected my friend?

 

Thank you!!!!



#38 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 55,541 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:06:24 PM

Posted 10 September 2023 - 09:32 AM

Welcome back sir.

Yes, that is exactly what I expected. Run a Windows Defender scan and see how we do.

Gary 

“Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.”

Where to Start


#39 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 55,541 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:06:24 PM

Posted 13 September 2023 - 04:00 PM

Greetings,

===================================================

Do You Still Need Help?

It has been 3 days since my last post.
  • Do you still need help with this?
  • If you have not replied within 48 hours I will assume you have abandoned the Topic and it will be closed.

Gary 

“Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.”

Where to Start


#40 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 55,541 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:06:24 PM

Posted 15 September 2023 - 10:55 AM

Are you with me Mark?

Gary 

“Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.”

Where to Start


#41 mlonabaugh

mlonabaugh
  • Topic Starter

  •  Avatar image
  • Members
  • 188 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:24 PM

Posted 17 September 2023 - 02:59 PM

Hi Gary,

I'm so sorry, I've been swamped I missed your last 3 messages. 

I followed your last instruction and so far there have not been any more Virus found messages from Defender.

 

I think your suggestion did the trick my friend...

 

Thank you so very much for your help and your patience!!!!



#42 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 55,541 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:06:24 PM

Posted 17 September 2023 - 03:56 PM

You are quite welcome Mark.

It sounds like we are all set unless you have any other issues or questions.

Gary 

“Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.”

Where to Start


#43 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 55,541 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:06:24 PM

Posted 19 September 2023 - 08:05 AM

Hi Mark.

I know you are quite busy, and it seems like we are all set, so......

Here is our final step and some additional information to consider.

===================================================

KpRm by Kernel-panik

--------------
  • Download KpRm and save it to your Desktop (see here if you must use Chrome)
  • Note: If the file is detected as malware it is not and it is safe to download. The detection is a false positive.
  • Right click on the icon and select Run as administrator
  • Click Yes on the Disclaimer
  • Place a check mark in Delete Tools, Create Restore Point, and Delete in 7 days
  • Click Run
  • Click OK on All operations are completed
  • KpRm will delete itself from you Desktop and you can either save or remove the report that is generated
  • You are free to remove any other tools/reports still remaining
===================================================

All Clean!

--------------

Your computer is now clean. Please consider this going forward.

===================================================

Please take the time to read below on how to secure the machine and take the necessary steps to keep it clean.

Lawrence Abrams, the founder of BleepingComputer.com, has developed an excellent tutorial which will provide you with the information you need to know about how to keep your computer secure and clean. Please take the time to read: Simple and easy ways to keep your computer safe and secure on the Internet.

In addition, here are some more links you might find of interest:Thank you for placing your trust in BleepingComputer. It was a pleasure serving you. ohmy_done.gif

Gary 

“Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.”

Where to Start


#44 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 55,541 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:06:24 PM

Posted 21 September 2023 - 01:49 PM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.

Gary 

“Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.”

Where to Start


#45 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 55,541 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:06:24 PM

Posted Today, 09:23 AM

This topic has been re-opened at the request of the person who originally posted.

Gary 

“Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.”

Where to Start





2 user(s) are reading this topic

0 members, 2 guests, 0 anonymous users