Cowabanga won't die

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ChudWick, Jul 13, 2006.

  1. ChudWick

    ChudWick Private E-2

    Greetings! This is my first post on a forum, so I apologize for newbie-ness!
    I have a recurring problem with Cowabanga and it's endless spawn. I have tried many different methods, first being formatting my hard drive and starting with a fresh OS ... no good. Then I found Major Geeks! So here I am. I have gone through steps 1-7, and attached are logs from AdAware, SpybotS&D, and Panda.
    This computer is using WinME, if that helps.
    I have installed a firewall (Sygate) and it's still finding wuauclt.exe after all the fixes so far. That, among others, are by-products of the Cowabanga. Many of these have been removed by your processes, but I fear there's more lurking.
    Please help!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    I know you said you went thru steps 1 thru 7 but you did not follow the directions in there. We don't ask for Ad-Aware or Spybot logs. They are not typically needed. But we did ask for:

    - CounterSpy log
    - Bitdefender log (which must be run before PandaActiveScan)
    - and a HijackThis log in step 7.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    And since you have WinMe, you need to also attach the log from CounterSpy!
     
  3. ChudWick

    ChudWick Private E-2

    Sorry for the extra info! I did run Bitdefender before Panda however, and have included that log here. I also have included the CounterSpy log and a HijackThis log as well.
    I did follow the tutorial, and many little goblins were found along the way. Even just now, something was wrong with my SysTray. I tried to open the volume control, it shut down. Tried to open Explorer, got an error saying the current version was not compatible.
    I have found RegCleaner very effective. I ran that just now, and there was a new entry, VDO. I deleted it, restarted, and I'm back up. However, that says to me that I still have problems. So I ran another HijackThis. Only 3 attachments are allowed, so with this post I have the 1st Hijack this. I will also post another with the second try shortly.
    Sorry, I did try to follow the tutorial, I know it's frustrating for you when that doesn't happen!
    Thanks for your help!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The only thing remaining to delete was in your Panda log. Delete the below folder:


    C:\WINDOWS\SYSTEM\SBUtils

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  5. ChudWick

    ChudWick Private E-2

    Got rid of that folder (in dos mode), thanks.
    Not done yet, tho. Computer is still acting funny, so I ran another BidDefender scan, and it found a trojan. I attached the log.
    I want to format the harddrive and start over, but that doesn't seem to help with this thing. Any other advice?
    Thanks
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All Bitdefender found is something in System Restore which we have not emptied yet per step 1 of the READ ME. You have no other malware based on the logs you have posted. You follow the directions in step 1 for disabling System Restore, then reboot, run a new Bitdefender scan if you want to, and then reenable System Restore.

    Are you actually having malware problems? Give specifics!! "acting funny" does not mean anything to me!
     
  7. ChudWick

    ChudWick Private E-2

    Sorry, I'll be more specific!
    I did get rid of that restore program BitDefender found, and I reset the restore points per step 1 as you advised. My concern is that BD labeled that guy as a trojan. Between google and your site, the research I did on Cowabanga says that it manifests itself in different folders and different names, and when you try to get rid of it, it knows and spawns somewhere else. That was proved when the first thing I did, before I found you guys, was format my drive. When I did that, the report said I had like 8mb in "bad sectors". And when I had all my OS back up, the baddies were still there. Folders and progs like uthm, acst, nslookup, wuaog, etc. All things related to Cowabanga per google searches, and that's what led me here.
    So anyway, the specifics. Right now, as I'm typing, I'm watching the hourglass flickering next to my pointer, as if it's trying to load something. As I type, it takes a second to catch up putting the letters on the screen. When I move my mouse, it jerks and stops and catches up. When I ctrlaltdel, task mgr shows pretty much normal stuff running, but next to smc (sygate firewall), it says not responding. The other questionable stuff running is Winmgmt and Wuauboot. Apparently those are actual windows updaters, but also known to be malware in some cases. I'm thinking I still have something going on, and it's hiding from the methods we've done ... Here's a good one, as I was typing, the window just froze up and I couldn't type in it. I'm typing in notepad now to cutpaste later because it's usually only a matter of time before explorer freezes up on me.
    Also, something is weird with my systray. Don't know if it's malware related or not, but when I click on the volume control, it says "Systray has caused an error in <unknown>. Systray will now close." And sometimes when I click the 'e' in the taskbar, it tells me I have a bad version. So I restart, and then it's fine. But the hourglass doesn't stop flickering next to my pointer unless I 'end task' on Winmgmt, which usually takes three times to actually turn off. Then wuauboot shows up, takes a couple 'end task's to shut down, then <unknown> shows up (these are all in the ctrlaltdel task mgr window). Only then, only sometimes, does the hourglass go away.
    Also, when I log out of your site, it turns black&white as it should, but then it takes literally 2 mins for the 'are you sure' prompt to come up.
    Everything is sporadic. As I've been writing this, I've had to restart because it wouldn't let me continue typing, even in notepad! When I restarted, I did it correctly, from start menu, and it still ran scandisk. However, this time the hourglass is not going. I just looked at my firewall log, and it says "Somebody is scanning your computer. Your computer's UDP ports: 1028, 1029, 1030, and 1032 have been scanned from remote host 61.156.42.103". I have no idea what that means, except it sounds like I still have a problem. Oh, and the hourglass just started flickering again.
    Sorry, I know this is wordy, but you asked for specifics :)
    Thanks again!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What guy?? Cowabanga???? You show no signs of this.

    I have no idea what procedures you are following to reinstall nor where you got the CD's you are reinstalling from. If they are not original CDs from Microsoft (i.e., they are copies you made or someone else made for you) they could easily be infected. Thus a reinstall from them will just infect you each time. Also the proper way to reinstall would be to delete your partitions then re-partition and format and reinstall.


    Both are normal valid processes. Wuauboot.exe does not show in your HJT log anyway.


    Sounds more like your install of Windows ME has just become unstable.

    Normal! Malware is always looking for PCs with open ports. As long as your firewall is blocking them, it is not a problem. Someone in China knows about your PC and is looking for a way in. This happens all the time and is the reason for having firewalls and other protection installed.
     
    Last edited: Aug 16, 2006
  9. ChudWick

    ChudWick Private E-2

    My apologies for the delayed response!
    I thank you for your help. I did resolve my problem, but I took the one piece of advice that you (tactfully) omitted ... I joined this century and got a whole new system! No more WinME!
    I have used your advice and your site extensively in the new setup, however. I am more protected and more aware than ever!
    Thanks for everything!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds