Kiwee Toolbar Found on Machine That's Been Off for Weeks

Discussion in 'Malware Help (A Specialist Will Reply)' started by AngelsWilliam, Feb 18, 2010.

Thread Status:
Not open for further replies.
  1. AngelsWilliam

    AngelsWilliam Private First Class

    When I booted my desktop computer after it sitting dormant for at least 2 weeks, probably more, PCTools firewall came up with this message asking if some Kiwee Toolbar had permission to do something or other or something or other had permission to do something on behalf of Kiwee Toolbar. (Sorry, can't remember what it said, but I blocked it because I didn't recognize either and wasn't in the process of installing anything new, nor was my computer doing anything that would cause any such thing to ask permission...and what the hell was this Kiwee Toolbar?) After I'd blocked it, I went to Google and did research and, sure enough, found that it was spyware...of the SmileyCentral kind, no less. Goodie.

    Anyway, so I started following the READ ME AND RUN ME FIRST steps. I went to my Add and Remove Programs, and it wasn't even listed there. NOT a good sign. So, I then went to my process list and found some very unfamiliar items listed, not the least of which was bootstrapper.exe. I remembered that to be a bad, bad thing, but I Googled it just to be sure. Ummmm, yeah. Killing processes on my drive one by one when I've just installed a $90 external hard drive? I.DON'T.THINK.SO. So, I killed that process right quick, and then one by one (as I killed each new strange process), new ones started to pop up. And, they did exactly what Google said they would do. Some of the applications I tried to start closed right back down. More on that later.

    So, anyway, I've gone through all the steps and am attaching the logs. A few important notes:

    1. I know damned well that SuperAntispyware didn't get all the database definitions downloaded because I observed as many as 42 in some categories on a verrrrrry long list when downloading the definitions to another computer of mine; but when I downloaded the definitions database to this computer (even after reinstalling the program and trying to download the definitions in Safe Mode with Networking), this list was much shorter and the most in a category was 14.
    2. Whatever this is on my machine shut down MGTools almost immediately every time I started it. It did create the folder and the logs, but the window disappeared instantly. I eventually decided to reboot my machine and try to catch this...thing...off guard and run MGTools before the malware had the chance to get to the shutting-things-down point of its little game. Well, MGT got to a point where it got stuck and my tower was making a LOT of noise (this is something I've never seen MGT do before), so I opened task manager and ended the bootstrapper.exe process. MGT was still stuck, so I thought, "Well, shit, I'll just have to tell them it wouldn't run," and ended that process, too. Then, the tower stopped making all the noise, and I was, like, "OOPS." So, I rebooted my computer so bootstrapper.exe would be running again, and then restarted MGT. Then, I remembered that the folder and logs would've still been there from the last time (and it did seem to run a lot faster until it got to a certain place where it had been stuck before), so I stopped MGT again and deleted the old folder and logs, restarted my computer, and ran MGT again. This time, it ran much like it had before.
    I hope you won't get too angry with me if I did this all wrong! I'm just really nervous because this Kiwee Toolbar thing sounds really nasty, Combofix took over 1/2 hour to run, and MGT--well, let's just say I gave up and went to bed, but was EXTREMELY nervous to leave my infected computer without resident protection or firewall overnight!

    Thanks for your help! This baby remains shut down until I hear from you! Thank God I lost my job--well, not really, but...you know what I mean!
     

    Attached Files:

  2. AngelsWilliam

    AngelsWilliam Private First Class

    Aaaaand, here attacheth mine MGTools log. Thanks again.

    At least this time I know I'm not going to be pissing you off with "clean logs." :-o
     

    Attached Files:

  3. AngelsWilliam

    AngelsWilliam Private First Class

    One more thing: Combofix deleted the autorun from my external HD. Any way to get that back?

    Thanks!
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I could find no traces of the Kiwee toolbar on your system. Was it the Admin. account where you found it?

    You still have some traces of AVG on your system. So let's just do this:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    SecCenter::
    {8decf618-9569-4340-b34a-d78d28969b66}
    
    Driver::
    AvFlt
    Avgfwdx
    
    DeQuarantine::
    C:\Qoobox\Quarantine\G\autorun.inf.vir
    
    Quit::
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    So, what issues are you having? If your issues are on your personal account, you need to do the scans in that user account.
     
  5. AngelsWilliam

    AngelsWilliam Private First Class

    Sorry it took me so long to get back to you. I was checking the wrong e-mail address for responses. OOPS.

    Anyway, I followed your directions, and just as a Windows message came up (for the 2nd time, the 1st being before I ran CF) saying my antivirus software might be out of date, a notepad doc that took up the entire screen came up titled DeQuarantine.txt and CF disappeared from the screen.

    This is what I read this bootstrapper.exe does: It kills processes 1 by 1 on a computer. I left it running so the logs would be accurate. Last time I ran the programs, I started them immediately upon bootup before bootstrapper.exe got the chance to dig its claws in (I hoped), and CF and MGT ran all the way through. This time, tho, with all the other stuff I had to do first, I think CF got stalled by the bootstrapper. DAMMIT.

    Also, when I opened FF to tell you all this, my homepage (Google) said that the connection was lost. I tried other pages, same thing. Also of note, I am being prevented from updating Microsoft Windows and Avast setup is being interrupted in the middle of the update process.

    I don't have separate accounts on this computer like I do on my laptop. I tried to set that up on this computer, but I had trouble for some reason, so I decided not to mess with it. I know, bad me. Anyway, so...this is on the whole computer, not just one account. Kick me in the head.

    Oh, gee. Firefox just popped up that I have updates for 3 of my add-ons. Should I be shocked if they don't install all the way?

    Anyway, I've attached that text document, but all it really says is what you put under DeQuarantine: :
    in your instructions to me. It saved on the C:\ drive, but there was no C:\combofix.txt. I did look.

    *sigh*

    Tell me what to do next. PLEASE.

    Thank you,
     

    Attached Files:

    Last edited: Feb 24, 2010
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to tell me the exact path to that file. In the meantime:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Driver::
    AG Windows Service 
    
    File::
    C:\Program Files\AGI\common\win32\PythonService.exe
    
    Folder::
    C:\Program Files\AGI
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  7. AngelsWilliam

    AngelsWilliam Private First Class

    Okay, first and foremost: YOU.ARE.A.GOD.

    Now that we have that out of the way....

    After watching the end of Combofix go by (the result of your "kill all" script), I doubt I have to tell you this anymore, but...the bootstrapper.exe file was in the

    C:\Program Files\AGI\Common directory.

    Also of interest: When I put my mouse cursor over the file, the description balloon that came up said, "Kiwee Toolbar Installer by AG Interactive." So...every time my machine booted, so did this Kiwee Toolbar Installer, and it kept running as long as I didn't end the process. And if I did end the process, more unfamiliar ones would pop up in task manager. That's what made me nervous and why I contacted you.

    On to the YOU.ARE.A.GOD part of things:
    Absolutely no sign of bootstrapper.exe or any other strange processes in task manager, now. There was an issue with PC Tools Firewall being unable to initialize after CF completed and MGTools ran; but I gave restart the old college try, and everything's fine there.

    So, I'm attaching the logs for your perusal.

    Of note: Combofix restarted my computer before creating the logs; and even though I'd shut down Avast!antivirus and PC Tools Firewall before restart, they came up automatically with reboot. I shut them down as soon as I could when they started themselves. I hope that didn't effect the logs at all.

    One more question: If something on this machine does act up in the near future (like, say, the next week or 2), is that considered close enough for me to reply to this same thread, or should I start a new one? Because the instructions always say to let you know how things are going, but I've gotten in trouble in the past for not starting a new thread. Thanks!
     

    Attached Files:

    Last edited: Mar 4, 2010
  8. AngelsWilliam

    AngelsWilliam Private First Class

    Microsoft and/or Windows updates refused to work until I had a brainstorm to click on the start button on bootup and immediately go to Microsoft update as soon as the start menu popped up. Then, it went through fine. Since then, though, I have had to update Windows Defender manually whenever there is an update. My little yellow shield doesn't come up and tell me. Also, I have set Windows Defender to always show the icon in the tray, and it won't.

    On the bright side, Windows Defender is doing its scans when it's supposed to, and everything is scanning in the background the way it's supposed to.

    So...everything seems to be working except for automatic updates and my Windows Defender prefs.

    Thanks again for your help!
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should address those issues in the software forum. Your logs are clean.

    We have no problem with anyone coming back to a thread it issues arise, but if so, after two weeks, we would expect you to download new versions of all the scanning tools and attach the new logs.

    And, you are most welcome. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  10. AngelsWilliam

    AngelsWilliam Private First Class

    What happens if I did the below steps:

    ...and Windows Defender came up with 4 instances of SafeBoot changes, asking me to permit or deny them? I had absolutely no idea, so I denied them. I am absolutely not going to do the following until you tell me whether or not I did the correct thing. I didn't think this was the kind of thing that warranted a new set of logs, particularly because I haven't had the machine on since the last exchange. Feel free to give me 10 lashes with a wet noodle if I'm wrong.

    Thanks again! :wave
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not sure what your question is. You should just go ahead and do the final clean up steps.
     
  12. AngelsWilliam

    AngelsWilliam Private First Class

    Done! Thanks for all your help. I hope to God this is the last time for a long time I'll have to bother you.
    :innocent
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not a problem.....and good luck. :)
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds