Troubles with malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by stylva, Apr 11, 2007.

  1. stylva

    stylva Private E-2

    I've just gone through the steps 1 to 6B here.
    I've had some troubles during this, and I still have malware problems.

    First of all, CounterSpy could not remove all the troubles it found, one dll was left, and CounterSpy wanted me to reboot. I finished and did so, and now I cannot start up Counterspy again (Error message: The service controller returned No Service. You may be running a scheduled update.) So I cannot access the log from there. I ran counterspy in Safe mode, and restarted in Normal mode.

    I have also tried the AVG Anti Spyware, but it cannot update due to some serverproblem.

    The Bitdefender online scan worked nicely, attaching log.
    The Panda ActiveScan caused troubles, something with the installation and ActiveX did not go through. It might be my avast! antivirus, I'm not sure though. In my eyes I disabled it.

    I've not tried HijackThis, since I have no knowledge about it. If it is needed, I will fix that.

    I hope someone can help.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please run this Virtumonde aka Trojan Vundo Removal - and attach the VundoFix log when you return. Then continue on to the below.

    You don't need any! ;) Just follow the directions exactly as written in step 7 and then attach the log!
     
  3. stylva

    stylva Private E-2

    Thanks alot! Did those two steps now, here are the logs.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program\Sunbelt Software


    Also uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 11

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Now Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {296FCDB7-337D-49A9-B78B-A9F6603F2834} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {A0D47763-1C37-433B-97BB-ED2E3C5EAC66} - C:\WINDOWS\system32\jkhfg.dll (file missing)
    O2 - BHO: (no name) - {A416D604-EAA3-4618-958C-2ECA22414616} - C:\WINDOWS\system32\gebywxy.dll (file missing)
    O20 - Winlogon Notify: geeby - C:\WINDOWS\
    O20 - Winlogon Notify: ssqpq - C:\WINDOWS\system32\ssqpq.dll (file missing)

    After clicking Fix, exit HJT.
    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now! We may have a little more cleanup to do. Once I see the new logs I will know what remains.
     
  5. stylva

    stylva Private E-2

    Ok, I uninstalled those without problems. It even removed the folders you mentioned itself ;) And reinstalled the new Java.

    I ran HijackThis and it fixed the problems without saying anything in particular.

    I rebooted, after startup I get two errors on RUNDLL.
    c:\windows\system32\uuwplwlu.dll and
    c:\windows\system32\kumoxpkr.dll

    These have been appearing since I first got (visible) malware problems. (EDIT Maybe not exactly these .dll's, some others have been appearing too. But these are not new)

    And here are the new logs, I hope I didn't mess something up.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Start by downloading a tool we will need

    - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later.

    Now Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\kumoxpkr.dll",setvm
    O4 - HKLM\..\Run: [PrintDrive] rundll32.exe "C:\WINDOWS\system32\uuwplwlu.dll",setvm

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    C:\WINDOWS\system32\kumoxpkr.dll
    C:\WINDOWS\system32\uuwplwlu.dll
    C:\WINDOWS\system32\ybeeg.bak1
    C:\WINDOWS\system32\rkpxomuk.ini
    C:\WINDOWS\system32\ybeeg.ini
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  7. stylva

    stylva Private E-2

    Here's the new logs.
    All steps went without problems, Pocket KillBox rebooted. Only thing I noticed was a little slower startup than usual. So not much happening..
    No more dll errors popping up at startup.

    Can I uninstall AVG Anti-Spyware btw?
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you can uninstall AVG Antispyware, but you do have to install some other protection software when we finish which is still going to impact your performance, but it is a necessary sacrifice. You will have to install real software firewall. You also need better antispyware protection than the very outdated SpywareGuard offers. This will all be covered in my final directions.

    You can also have HJT fix the below unnecessary update program for Sun Java too which will also save some resources.
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program\Java\jre1.6.0_01\bin\jusched.exe"


    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. stylva

    stylva Private E-2

    Thanks alot for all your help!
    I got PC Tools firewall and SpyWare Blaster, I hope they are ok.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    SpywareBlaster adds some useful protection from bad sites and bad active-x scripts but it is not a replacement for a realtime antispyware blocking application. You need realtime blocking and also keep SpywareBlaster. SpywareGuard did provide some realtime blocking but it is way out of date with todays malware and is just not adequate. It is better than nothing though!
     
  11. stylva

    stylva Private E-2

    Which one would you recommend? I'm not sure how to see if it is a realtime blocker or not, so I would appreciate if you could point them out :)
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First I need you to answer a question! Are you looking for free tools or do you want to purchase a commercial tool.
     
  13. stylva

    stylva Private E-2

    Oh, free ones, thank you :)
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay there aren't too many free realtime blockers so are choices are somewhat limited. Spyware Terminator is one that provides realtime blocking for free. Thus, what you should have installed on your PC are the below applications.

    SpyBot-Search & Destroy (Use the Immunize feature. I don't activate the TeaTimer)
    SpyWare Blaster Install it, click Download Latest Protection Updates, Check for Updates, and then Enable All Protection, then exit. It does a great job of blocking known vulnerabilities as well as known malicious websites.
    Spyware Terminator

    Obviously in addition to the above you still need your antivirus (you have Avast) and a firewall (you said you installed PC Tools Firewall) which you already have.
     
  15. stylva

    stylva Private E-2

    Ok, thanks alot, I have all those installed now. And my computer works like a charm ;)
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds