help please

Discussion in 'Malware Help (A Specialist Will Reply)' started by haywood, Jan 17, 2007.

  1. haywood

    haywood Private E-2

    been battling for weeks and I can't get my computer disinfected.
     

    Attached Files:

  2. haywood

    haywood Private E-2

    the rest:
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You show signs of having a Rustok rootkit infection! CounterSpy may or may not have fixed it. Let's be sure!

    Please run this first AVG Anti-Rootkit and attach the log!
     
  4. haywood

    haywood Private E-2

    Thanks for the reply. The AVG anti-rootkit doesn't allow for saving a log file so
    I have attached a screen shot instead. It says I have 17,499 items found after the scan. Can this be right?

    (had to zip the screen shot because file size was too big, sorry)
     

    Attached Files:

  5. haywood

    haywood Private E-2

    about the avgscan, looks like kaspersky marks files with the kavichs tag?

    counterspy ran again and found SpamTool.Win32.Mailbot.az on my system so
    i'm still not in the clear.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes as you discovered this is due to the fact that you use Kaspersky and they add an ADS (Alternate Data Stream) to each file scanned. This is annoying when trying to find bad data due to malware.

    Please download and run this tool from Kaspersky to remove the ADS: klstreamremover

    Then get a new scan from AVG Antirootkit. If you find a line showing something like c:\windows\system32\lzx32.sys or c:\windows\system32:lzx32.sys fix it!!!!
     
    Last edited: Jan 19, 2007
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I know that already. See the runkeys.txt log you posted in message # 2. My GetRunKey application already found that. And that is why I had you run the rootkit scan.
     
  8. haywood

    haywood Private E-2

    after running KLStreamRemover.exe -r, AVG anti rootkit shows no problems.
    F-secure blacklight (slower) shows no problems either.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Kazaa Lite Resurrection 0.0.8 <-- it is highly recommended that you do not use anything related to Kazaa nor connect to their servers.

    Make sure you reboot after uninstalling the above!


    Attach new logs from GetRunKey and ShowNew.

    Are you having any malware problems?
     
  10. haywood

    haywood Private E-2

    done, done and done. Haven't had any malware problems since CounterSpy
    found spamtool.win32.mailbot.az the other day.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay your logs are clean!


    You should uninstall the CounterSpy trial now since it will expire and will be of no use after that! After uninstalling it, delete the below two leftover folders
    C:\Documents and Settings\joe blow.VF1\Local Settings\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds