upapp - what is it

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Morlo, Dec 29, 2005.

  1. Morlo

    Morlo Private E-2

    Hello. My first venture into trouble shooting through a forum but, having followed the instructions in one thread and the <READ & RUN ME FIRST Before Asking for Support> page - seemingly resulting in successfully getting rid of whatever was causing my PC to search for a spyware associated file "ibm00003.exe" (for which, many thanks), Major Geeks looks like he is the man to help. So, I thought I'd repeat a question that I have seen asked elsewhere and to which two very diiferent answers seem to be posted in various places on the web.

    Whilst checking for Malware programs to delete in Control Panel \ Add or Remove programs, I noticed "upapp" listed. I cannot find it anywhere else on my PC, I know I didn't install it knowingly and I have no idea what it does or where is came from. As I cannot find it anywhere and at 45 Mb I am suspicious of it. One posting I have read says it is something nasty left behind by Spyware; two others say it is associate with an HP printer (checks for updates). I cannot find any sign of it within any HP directory and so believe it must be nasty - but would like to be sure before I hit the delete key.

    Any confirmation one way or the other?

    Many thanks

    Morlo
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should have attached the three logs from the READ ME. BitDefender, PandaActiveScan, and HJT.

    Note, if you had ibm00003.exe, consider changing all your passwords and login info especially for financial institutions. See: Malware - Bancos.LU

    You should search your registry for upapp and see if there are any hits. Names used in the registry for programs do not always match the application names (developers can be pretty stupid sometimes. ;) ) You could use the below to do the search if you do not know how.

    Download the Registry Search Tool from here:

    http://www.billsway.com/vbspage/vbsfiles/RegSrch.zip

    Unzip to your Desktop and double click on regsrch.vbs
    (if you have script protection, please allow this to run)

    In the dialog that opens enter the following:

    upapp

    Press 'OK'

    The search will run for a while then alert you when it is finished.

    Press 'OK' and copy the contents of the WordPad window and post in this thread.
     
  3. Morlo

    Morlo Private E-2

    Many thanks for reply.

    One of my on-line access bank accounts had been accessed without authorisation and I just changed the passwords etc a couple of days ago - at least now I might know how it happened - so thanks for this.

    Anyway, logs from BitDefender, Panda and HJT are attached, as is also the log from the RegEdit search (file name: sOutTmp162210 - upapp Reg Edit search.txt)

    Hope some of this makes sense to you - it doesn't to me

    Regards

    Morlo
     

    Attached Files:

    Last edited: Dec 30, 2005
  4. Morlo

    Morlo Private E-2

    The log files don't seem to have attached - try again

    Morlo
     
  5. Morlo

    Morlo Private E-2

    I am clearly having troubvle attaching these files ... here goes again

    Morlo
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    upapp appears to be something for Hewlett Packard. Is you PC an HP or do you use something else from HP (a printer etc)?
    Somemore of that keylogger that is stealing passwords still exists. Make sure you do not use this PC for any thing that must be secure. Either change your passwords on the phone or use another PC that you know is not infected.

    Please run this: Running Ewido Security Suite it will help remove some more of this keylogger. Attach the Ewido log.

    Also download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    Make sure you empty:
    - C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine
    - your recycle bin
    - if you use Norton N-protect to guard the recycle bin, make sure you empty the N-Protect stuff too.

    I would then suggest you do another BitDefender scan and post the new log. It found a bunch of things and we must make sure you get this system cleaned up and trust worthy.
     
    Last edited: Dec 30, 2005
  7. Morlo

    Morlo Private E-2

    Many thanks

    Yes, I do have an HP printer. I will leave upapp alone then.

    As for the rest, I'll do as recommended and post results on completion.

    Regards

    Morlo :)
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you get that Norton stuff I mentioned cleaned up!
     
  9. Morlo

    Morlo Private E-2

    Hi again

    Norton quarantine and trash can emptied

    Ewido run and log attached

    Hoster run as instructed

    HJT re-run and new log attached

    Thanks again

    Morlo
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is still (or at least was) stuff in the NProtect folder from Norton. Did you forget to empty it? It takes special steps. Just empty the Recycle Bin is not sufficient. The below link explains how to empty this.

    Emptying the Norton Protected Recycle Bin

    The person (looks like Ross) downloading the below type programs should be show the Ewido log and should avoid downloading illegal cracks for software:
    C:\Documents and Settings\Ross\Local Settings\Temp\Temporary Directory 1 for Sibelius v1.4 crack.zip\crackmasters.exe/loadadv458.exe -> Downloader.Agent.xq : Cleaned with backup
    C:\Documents and Settings\Ross\Local Settings\Temp\Temporary Directory 1 for Sibelius v1.4 crack.zip\crackmasters.exe/loadadv458.exe -> Downloader.Agent.xq : Cleaned with backup

    When you try to get something for free, you may got a lot more than you think.

    Are you sure you ran Hoster properly? Also the O1 - Hosts line are still in your HJT log. If you are sure then disable all realtime protection of MS Antispyware and run Hoster again. Then get a new HJT log to attach but look at it first. If the O1 - Hosts lines are still there uninstall MS Antispware and disable Ewido (or uninstall) and try again.
     
    Last edited: Dec 31, 2005
  11. Morlo

    Morlo Private E-2

    Good morning

    Thanks for the message to Ross - my dear 16 year old son who, like most teenagers, is sure he knows best and cannot be told otherwise. I think this exercise is actually teaching him something about internet security and perhaps the risks of getting something nasty through the wires are not just fairy tales told him by his elders!

    I had indeed goofed on emptying the Norton recycle bin (I had uninstalled my old N utilities when I got NIS 2006 as they were incompatible - and the Norton recyled bin icon disappeared at that time - so I had to empty manually).

    Hoster - I'd overlooked that it was set as Read Only. So I set to Writable and re-ran. No O1 lines now in HJT log. Does this mean we're getting there? I hope so as my wife is twitching about internet banking.

    Should I have done another BitDefender scan?

    Regards

    Morlo
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes looks like we are almost there.

    The below items that were in the previous Bitdefender log is a minor issue but it would be nice to fix it.:
    C:\Documents and Settings\Blaise\Local Settings\Application Data\Microsoft\Outlook\archive.pst=>[Subject: Re: Hello again][From: Mary Mellor]>(body)Suspected of: Exploit.Iframe.Vulnerability

    See if you can locate this Outlook message from Mary Mellor and delete it!

    After that I would like to do two more things to make sure you are clean:
    1) Run BitDefender one more time and post a final (hopefully) log.
    2) Download, install and run BlackLight by F-Secure. Post the log once finished.

    Questions:
    1) Are you sure you took care of changing all passwords so that your financial info is safe?
    2) Does your Norton app include a firewall and are you using it? A real firewall is a must have.
     
  13. Morlo

    Morlo Private E-2

    Hi

    I deleted the offending archive file but it has appeared again in C:\ recycler - as seen in attached BitDefender log. Before I go ahead and delete this and four other files / folders in recycler dated today and two days ago, am I right in assuming they can be deleted?

    I am confused by the other log reults -
    C:\System Volume
    Information\_restore{FAD31253-1C6F-4667-9D3B-0B60ECC5D88D}\RP1\A0000227.MSI=>(Quarantine-2)=>(Embedded
    CAB)=>loadadv458.exe

    This looks like something in quarantine - can I just delete this and items like it?

    Lastly, I tried to download & install F-Secure's Backlight. I had to disable all the anti-Spyware programs I have installed over the last few days (SpyCatcher - recommended by SpyWare Warrior who I linked to from Major Geeks - in particular, would not let it download). And once I had downloaded it would not install without my uninstalling Norton Internet security 2006 and Ad-Aware. Since both of these are known to me I was unhappy about doing so and so have been unable to run Backlight. Will this be a serious shortcoming?

    Morlo
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just empty the Recycle Bin and also Norton NProtect like earlier.

    Also since we are close to being cleaned up, goto the READ & RUN ME sticky and complete step 1 to remove all the Restore points that could be infected with the baddies.

    Then do what I gave you in my previous post again (don't forget to answer questions). I'll repeat the steps:
     
  15. Morlo

    Morlo Private E-2

    Thanls again

    Will get on it. Lots of unistalling and installing - and work to interfere! - so will take a little time. Will post results a.s.a.p.

    Morlo
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but don't forget to answer my questions.
     
  17. Morlo

    Morlo Private E-2

    Big troubles.

    I uninstalled NIS and AdAware, disabled Anit SpyWare and installed F-Secure and then trouble began. PC failed to boot properly - got stuck in constant reboot loop showing error screen in attached jpeg. Error screen only appeared long enough for me to take digital photo, not even enough time to write down any of the detail. It took over an hour to manage to interupt the re-boot loop enough to get into safe mode and uninstall F-secure. I think machine has rebooted correctly now but am sending this from a different machine.

    Having looked again at the F-secure site, I think I downloaded the Internet Security Suite not the Blacklight Beta version - can you confirm that it is Blacklight Beta I need? Thanks

    Morlo
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that is what I said. Blacklight is what you want.
     
    Last edited: Jan 3, 2006
  19. Morlo

    Morlo Private E-2

    Hello again

    Success! Sorry for being an idiot getting mixed up between Backlight and the full blown F-secure internet security. Backlight was no problem at all. So, I have:
    - empitied recycle and N-protect bins

    - run backlight - log attached (it showed results from Spy Catcher which I installed on recommendation from spyWare Warrior which I linked to from Major Geeks at http://www.spywarewarrior.com/rogue_anti-spyware.htm#rec - which I assume is OK

    - re-run BitDefender - log attached which I assume means clean

    Yes, have sorted passwords with banks via phone. The fraud team from the bank I said appeared to have had unauthorised access on my sign-in confirmed that there had been several attempts including a successful one which came just a few days after they had upgraded their security - which prevented money transfer. A lucky break. It was traced to a town in the north of England.

    And yes, Norton Internet Security does indeed have a firewall. (My wireless network router also has a firewall). However, What NIS 2004 did not have - which I did not realise until I upraded to NIS 2006 in November - was any Anti-Spyware. So I suspect that most or all of the infections have been around for a while and it was only after upgrading to NIS 2006 and installing MS AntiSpyware at roughly the same time that I began to detect and delete - leading to the error message about ibm00003.exe which started me on this road.

    Hope all is now clean and well?

    Regards

    Morlo
     

    Attached Files:

    Last edited: Jan 3, 2006
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it looks like you are clean now! If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link (some of which you already have done):

    How to Protect yourself from malware!
     
  21. Morlo

    Morlo Private E-2

    Hurray :)

    Very many thanks for all your help. I am way ahead of you with your last post - already done the System Restore action and I have followed the "How to protect from malware" advice page - including shifting to Firefox (which I find I prefer to IE anyway). My son - remember him? the probable source of most of the spyware - is now urging me to throw the PC out the window and buy a Mac. He could be right!

    I have also just completed a long e-mail to a bunch of friends telling them of my recent trials and troubles and giving them the links to enable them to check out their own computer sucurity.

    Once again, many thanks - and believe me, we'll be trying hard to keep the machine nice and clean.

    Best wishes,

    Morlo
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Well MACs will give you less problems than in the PC world. At least right now. If they were as dominant as PC, more people would be attacking them (but probably not as much as they love to attach MS).

    With the proper tools installed and more educated surfing habits and reading what popups before clicking, you should not have very many problems. I surf more than most and I do not get any malware problems. Is it impossible for me to get them? No but the odds are low compared to others, due to the tools I have installed and keep updated and smarter surfing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds