possible malware, cannot detect

Discussion in 'Malware Help (A Specialist Will Reply)' started by rkgtech, Apr 19, 2008.

  1. rkgtech

    rkgtech Private E-2

    I first got wind of this when my network admin told me that my machine is going to some weird sites (e.g. bloodwych.org) - connecting and disconnecting very fast. I looked at aports and found bloodwych.org (svchost.exe) and even if i am not connected to any site the network monitor keeps showing MBs being transferred. I stopped the mail server (which had tons of logs of programs trying to connect - from denmark) but i still see a LOT of traffic on the network card.

    I tried the read and run me and have all the logs. could someone please help?

    Thanks!
    Ron
     

    Attached Files:

  2. rkgtech

    rkgtech Private E-2

    the malware log..

    thanks for all your help!
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I'm not seeing any real signs of malware. I do have a question on whether the below are related to all the networking/Cisco software you have running. Do you recognize the below? I'm pretty sure the second is for Cisco but the first one seems suspicious.

    O20 - Winlogon Notify: gpkcsp32 - C:\WINDOWS\SYSTEM32\gpkcsp32.dll
    O20 - Winlogon Notify: PAStates - C:\WINDOWS\SYSTEM32\PAStates.dll

    SuperAntiSpyware appears to have removed something for Cisco that you may need. You should restore that and report the false positive.


    You do however have security risks due to having about 13 old (some very outdated) versions of Sun Java installed.

    Uninstall the below old versions of software:
    J2SE Development Kit 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 5
    Java 2 Runtime Environment Standard Edition v1.3.1_01
    Java 2 Runtime Environment Standard Edition v1.3.1_18
    Java 2 Runtime Environment, SE v1.4.2_06
    Java 2 Runtime Environment, SE v1.4.2_12
    Java 2 Runtime Environment, SE v1.4.2_14
    Java 2 SDK Enterprise Edition v1.2.1
    Java 2 SDK, SE v1.4.2_06
    Java 2 SDK, SE v1.4.2_12
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    If you need the Sun Java Development kit you can get it here: http://java.sun.com/javase/downloads/index.jsp


    To be on the safe side you can run the below to look for rootkits, but I don't think we will find any:

    Using Sophos Anti-Rootkit
     
  4. rkgtech

    rkgtech Private E-2

    Thanks so much for pointing those two lines out..
    O20 - Winlogon Notify: gpkcsp32 - C:\WINDOWS\SYSTEM32\gpkcsp32.dll
    O20 - Winlogon Notify: PAStates - C:\WINDOWS\SYSTEM32\PAStates.dll

    PAstates is cisco related and gpk.. was the culprit (I think) - i deleted all the previous versions of java, rebooted, used killbox to delete gpkcsp32.. now at least on tcpview i dont see the MB transfers to weird websites anymroe.. hopefully that was it.

    THANKS SO MUCH!
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are sure that the gpkcsp32.dll file was not valid, then also do the below.
    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O20 - Winlogon Notify: gpkcsp32 - C:\WINDOWS\SYSTEM32\gpkcsp32.dll

    After clicking Fix, exit HJT.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  6. rkgtech

    rkgtech Private E-2


    Thanks, but the way i got rid of it was by using killbox.exe.. so far so good.. the network admin has not complained yet. thanks much for the support!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I know but you still need fix that line withe HijackThis since Pocket Killbox would not have removed the registry entry. And you need to cleanup from what you did in the READ ME.;)
     
  8. rkgtech

    rkgtech Private E-2

    kewl - u were right. i used hijackthis to fix it and did the rest of the cleanup. thanks !!!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds