Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Exchange 2013 infected by Backdoor:MSIL/Chopper & other variants


  • Please log in to reply
65 replies to this topic

#61 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 57,028 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:58 PM

Posted 19 February 2024 - 03:12 PM

Thank you.

I would like to install a system monitoring program and obtain another configuration file.

Please do this.

===================================================

Sysmon Install

--------------------
  • Download Sysmon and note where the folder is saved >>>>Important<<<<
  • If the folder is saved someplace other than the Desktop, copy and paste the folder onto the Desktop >>>>Important<<<<
  • Right click on Sysmon.zip and select Extract All...
  • Place a check mark in Show extracted files when complete then click Extract
  • Confirm the extracted folder is on the Desktop
  • Click Start, type cmd, then select Run as administrator
  • Individually copy and paste each line below after the command prompt, hitting Enter after each line. Confirm each command is successful

cd %userprofile%\Desktop\Sysmon
Sysmon64.exe -i -n -accepteula

  • Close the command prompt window
===================================================

Farbar Recovery Scan Tool Fix

--------------------
  • Right click on the FRST64 icon and select Run as administrator
  • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
  • There is no need to paste the information anywhere, FRST64 will do it for you
Start::
Zip: C:\inetpub\temp\apppools\MSExchangeECPAppPool\MSExchangeECPAppPool.config
End::
  • Click Fix
  • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
  • The tool will create a zipped folder in the same location from where FRST was run with today's date, example: 07.30.2023_13.24.50.zip. Please upload the file here.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
  • Sysmon install properly?
  • Fixlog
  • Uploaded zip file

Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

BC AdBot (Login to Remove)

 


#62 kpatel45

kpatel45
  • Topic Starter

  •  Avatar image
  • Members
  • 35 posts
  • OFFLINE
  •  
  • Local time:07:58 AM

Posted 27 February 2024 - 01:17 AM

Fix result of Farbar Recovery Scan Tool (x64) Version: 03.02.2024 01
Ran by ex-super_user (27-02-2024 10:16:20) Run:14
Running from C:\Users\ex-super_user\Desktop
Loaded Profiles: ex-super_user
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start::
Zip: C:\inetpub\temp\apppools\MSExchangeECPAppPool\MSExchangeECPAppPool.config
End::
*****************

================== Zip: ===================
C:\inetpub\temp\apppools\MSExchangeECPAppPool\MSExchangeECPAppPool.config -> copied successfully to C:\Users\ex-super_user\Desktop\27.02.2024_10.16.20.zip
=========== Zip: End ===========

==== End of Fixlog 10:16:21 ====



#63 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 57,028 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:58 PM

Posted 28 February 2024 - 10:26 AM

Thank you.

When you get a chance please do this.

===================================================

Event Viewer Sysmon Operational Log

--------------------
  • Press Windows Key + R at the same time
  • Type eventvwr.msc and press Enter
  • Click on the arrow to the left of the below listed entries to expand the categories

Application and Services Logs
Microsoft
Windows
Sysmon

  • Right click on Operational then select Save All Events As...
  • Save the file onto your Desktop (or note where the file is saved) as SysmonOperational, leaving the default Save as type: entry
  • Zip the file and upload it here
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
  • Uploaded file

Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

#64 kpatel45

kpatel45
  • Topic Starter

  •  Avatar image
  • Members
  • 35 posts
  • OFFLINE
  •  
  • Local time:07:58 AM

Posted 29 February 2024 - 04:44 AM

Hi there,

 

file has been uploaded.



#65 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 57,028 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:58 PM

Posted 29 February 2024 - 09:11 PM

What was uploaded was the Sysmon program rather than the SysmonOperational log.
Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

#66 kpatel45

kpatel45
  • Topic Starter

  •  Avatar image
  • Members
  • 35 posts
  • OFFLINE
  •  
  • Local time:07:58 AM

Posted Today, 05:42 AM

Hi Gary,

 

apology for uploading wrong file. The correct one  has been uploaded.






1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users