Klone virus help?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Grumbles, Dec 20, 2006.

  1. Grumbles

    Grumbles Bamboozled Geek

    C:\Program Files\HJT\hijackthis\backups\backup-20061001-203246-824.dll - this is the description of path where the Klone virus is. Scan with AVG in Safe Mode to find it. PandaActiveScan and SpyWareBlaster did not find anything.
    I have been getting help on another forum link (software) from Kniht.
    Win XP freezing up on connection to the Internet after installing IE7. CPU would go crazy for 5 mins then I caould carry on as usual!
    Uninstalled IE7 but problem still there with IE6. Switched to Mozilla Firefox and problem still occurring.
    I have deleted all HJT files from PC, but problem still there.
    Any help appreciated.
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi


    Spywareblaster is not a malware scanner, all it does is to add known bad activex and many websites that may infect you into the browsers blocked url listings, only blocks them after you install it and will not block an already present infection, just an FYI :)

    But if a Virus was found best options, especially as your are experiencing issues with multiple browsers is to run the full guide below and the malware guys will tell you if malware is on your PC or not, if it is cleaning it up may help.



    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.




    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. Grumbles

    Grumbles Bamboozled Geek

    Thanks for the reply, I will do these as soon as I can get access to my home PC.
    I have contacted my telephone company so that they can block any Premium numbers just in case there is a dialler involved! Also asked ISP for check on system.
    Will be in touch very soon.
    Steve
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note, if your only problem is with

    C:\Program Files\HJT\hijackthis\backups\backup-20061001-203246-824.dll

    that is just a backup file created by HijackThis when you previously (on Oct 10, 2006) fixed problems with it. You can just delete the backups from withing HijackThis or you can manually delete the folder.

    You should not work issues in multiple forums. That is a very bad thing to do since neither knows about what is going on in the other forum and it can lead to confusion. Also it is discurteous. Choose which forum you wish to work in and attempt to resolve all your problems there. If you hit a point where you are finished fixing your problems or you cannot get them resolved, then it is not a problem if you seek help in another forum.
     
  5. Grumbles

    Grumbles Bamboozled Geek

    I appreciate what you are saying about Multiple Forums. I thought that my problem was a software issue and member Kniht tried to resolve this through various steps. We agreed after doing some tests that this would be better solved in the Malware Forum, as Kniht suggested this would be the best course of action.
    I have contacted my ISP, who suggest un-installing the modem and drivers and try re-installing. I would prefer that Major Geeks try to find out if there is Malware which is causing the 'freezing up' of my connection at start-up. You guys have been brilliant in solving previous issues and I have total faith in this site.
    I will at my earliest convenience follow your procedured for Malware removal and post the relevant logs.
    Thanks
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That would be the best course of action! After doing that we will have a much better feel for whether you have malware problems or not.
     
  7. Grumbles

    Grumbles Bamboozled Geek

    Booted into Safe Mode, but could not run CCleaner there, therefore did CCleaner in Normal Mode.
    I have tried to run Counterspy - would not let me!
    In Safe Mode - AVG Antispyware posted 43 infections that were medium to low risk and I applied action and they were fixed, therefore no log.
    BitDefender - could not run.
    Pandascan - nothing detected.
    Attached GetRunKey,Shownew and HJT log

    I look forward to your thoughts?
    All the best for 2007
     
    Last edited: Jul 7, 2007
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually based on your logs, PandaActive Scan was not run at all. Please run it. It always finds things that other programs do not.

    How far did you get with Bitdefender ? Any error messages?
     
  9. Grumbles

    Grumbles Bamboozled Geek

    PandaActiveScan attached - 3 spyware detected
    BitDefender - No problems report attached
    I could not access BitDefender with Mozilla, had to go with IE.
     
    Last edited: Jul 7, 2007
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Cookies are not spyware nor are they problems! Panda is overstating what cookies are like most applications do.


    That's what the READ ME says to do.

    I'm not seeing any malware. Just a old version ( J2SE Runtime Environment 5.0 Update 9 ) of Sun Java that need to be uninstalled and then you need to install the current version from:

    Sun Java Runtime Environment
     
  11. Grumbles

    Grumbles Bamboozled Geek

    Okay thanks. I have uninstalled J2SE Run 5.0 - 9 and installes JRE 6.
    Problem of Internet freezing up/and PC for 5 mins is still there. Any suggestions?
    I did notice that a file - lucallback.exe was running in task manager while the PC was 'frozen'. After some research I found it was associated with Norton/Symantec, so I have uninstalled NAV. There seem to be a lot of processes running when PC is in this state and the CPU usage is very high!
    Thanks for your time in this matter.
    Oh, and a Happy New Year
     
  12. Grumbles

    Grumbles Bamboozled Geek

    i have connected to the Internet around 6 times just to watch what process is holding things up: WMIPRVSE.EXE network service 7216k : this disappears when access is permitted again! It appears every single time after i dial up (ADSL) and disappears when PC un-freezes. After you not finding any malware etc, could this be the root of the problem?
     
  13. Grumbles

    Grumbles Bamboozled Geek

    The highest user of CPU cycles is explorer.exe at around 40000k all the time, whether connected to the Net or not. I have read that this can be a Trojan and is a problem that Microsoft are aware of?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is not CPU usage. That is how much memory is being used. So exactly what have you been trying to say. Is you CPU usage high or is it the memory use?
     
  15. Grumbles

    Grumbles Bamboozled Geek

    Sorry about that. It is Memory usage that i think is very high. I open Task Manager before I try to connect to the Net, then watch to see if any processes look dodgy.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Explorer can often go that high! It is not unusual and all depends on everything else that you have running. Right now on two PCs I have running explorer is at 6145K on one and 36980k on another.
     
  17. Grumbles

    Grumbles Bamboozled Geek

    So what do I do now regarding the 'freezing up' of my PC? Do I switch forums as there is no malware problem, it might be a network process?? I don't know how to get to the root of this problem :(
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well let's do two more scans just to cover an area we did not check, but I don't expect to find anything.

    Please download Blacklight Beta
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please post contents of the BlackLight log.

    Also let's run a second rootkit detector, sometimes one will find what another does not.
    Run this AVG Anti-Rootkit and attach a log from it too.



    After that, I would say you have to try another forum! Which one is the question! You may have to start in Hardware. Make sure you mention that you PC was already checked for malware.
     
  19. Grumbles

    Grumbles Bamboozled Geek

    ok i will do as above and post back on sunday. thanks
     
  20. Grumbles

    Grumbles Bamboozled Geek

    Ran AVG anti-rootkit, performed in depth scan and found NO problems, unable to save log because of this.
    I am not too keen on downloading Blacklight as there is a warning that it may harm my PC (being the Beta version).
    I shall post to a Hardware forum tonight.
    Thanks
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Blacklight will not harm your PC, especially if all you do is run a scan. Many programs give warnings like that. Even HijackThis is dangerous if used incorrectly.

    I doubt that Blacklight is going to find anything anyway.

    I'm going to give you a link and then a quote from this link that explains WMIPRVSE.EXE could cause problems like this and again I will emphasize that the problems are not malware. I highlighted an important area in bold brown color.

    The below quotes come from: http://www.answersthatwork.com/Tasklist_pages/tasklist_w.htm

    On additional comment I have is this. When you see wmiprvse.exe running, where is it running from. The valid process should be C:\Windows\system32\wbem\wmiprvse.exe

    You will not be able to tell this with Task Manager. You will need to see it using HijackThis's process manager or you can use Process Explorer (see below).

    Please download ProcessExplorer
    • Unzip it to its own folder somewhere you can locate it.
    • Now run procexp.exe by double clicking on it.
    • Let's configure some options first:
      • Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked.
      • Now click on explorer.exe.
      • Now also under the View menu choose "Select columns" and put a check mark on "Image Path".
    • Now when you see the wmiprvse.exe process running. Just run Process Explorer and continue on to do the below which will create a log.
    • Now click on File and then Save As. And save the process list.
    • Post it back here as an attachment.
     
    Last edited: Jan 7, 2007
  22. Grumbles

    Grumbles Bamboozled Geek

    Thanks, I will post back as soon as I can with results. :)
     
  23. Grumbles

    Grumbles Bamboozled Geek

    I have attached Process Explorer text document run today just as I logged on to Internet. Only able to find Explorer.exe. Wmiprvsr.exe did not appear any of the times i logged on. Problem of 'freezing' still persisting.
     
    Last edited: Jul 7, 2007
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still want to see the BlackLight log!

    Unless it shows me something, I recommend you head to the Software Forum because you are not showing any signs of malware.
     
  25. Grumbles

    Grumbles Bamboozled Geek

    Hi,
    Attached Blacklight Log
    Is there any way to transfer all our posts to "Software" Forum, so that whoever is dealing with this problem will get a better understanding of the problem?
     
    Last edited: Jul 7, 2007
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I can move the whole thread there but if we do that, you may not get anyone to read it since it is already 26 messages long! It may be better to start a new thread and clearly state only your remaining problems and also indicate that you have done malware removal already and reference this thread.
     
  27. Grumbles

    Grumbles Bamboozled Geek

    WinXP 'freezing PC' for 10 mins on connection - That is the thread I have started in Software Forum. Thank you Chaslang, you have been a great help.
    You should be promoted!
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  29. Grumbles

    Grumbles Bamboozled Geek

    Any time you are over in Scotland?? A game of Golf and a few beers are waiting!
    Cheers
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're on! ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds