Ad-a-w-a-r-e/vx2 problem here as well

Discussion in 'Malware Help (A Specialist Will Reply)' started by BFLeigh, Dec 23, 2004.

  1. BFLeigh

    BFLeigh Corporal

    THEY ARE GONE!

    Am I 100% clean now? If so, thankyou very much chaslang!

    I'll go do that now.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Yes you are clean! See my post in message #48. I have to get some sleep now.

    Come back tomorrow and let me know if you are still running okay or not.
    And look into doing the stuff I recommend.. You must get you OS update ASAP.
     
  3. BFLeigh

    BFLeigh Corporal

    Good night. Thanks again.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good night! Surf Safely!
     
  5. BFLeigh

    BFLeigh Corporal

    Now chaslang's having his snooze, I'd be grateful to you bjgarrick if you'd be able to show me where I'm vulnerable as apparently my logs show some weak points in my systems.
     
  6. BFLeigh

    BFLeigh Corporal

    Hmmm, running kill2me seems to still bring up My Documents with the search tool open in it.

    Should I be worried?
     
  7. BFLeigh

    BFLeigh Corporal

    Also - when after what things should I turn on System Restore? It's been off since I first found the malware...........
     
  8. BFLeigh

    BFLeigh Corporal

    .............and another thing. Trend Micro Scan's discovered an akrules.dll TROJ AGENT.BT virus in C:\Documents & Settings\Computer\Local Settings\Temp folder - it's uncleanable. Deleting it will take care of it, right?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your biggest problem is not having your OS updated. You will continue to have problems until you get your updates. And you need to do the stuff I gave you in: How to protect yourself from malware!

    It would be a good idea for you to start using FireFox instead of IE now. Especially since you are so out of date.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If your system is now clean, you can turn it back on. But you seem to be indicating you are having problems again.
     
  11. BFLeigh

    BFLeigh Corporal

    Well.........

    The Bin works.

    My home page hasn't been altered.

    No a-d-w-a-r-e site pop-ups when I'm using IE.

    The biggest sign was when I was off-line, Network Connections was constantly telling me that the spyware (the above site) wanted to connect to the web. I couldn't play Age of Mythology because it kept reverting back to the desktop with this bloody connection request.

    This is all after I've had a good night's sleep. Might I be clean? In that case, I'll go about proofing my PC.

    I will later on do another Trend Micro Scan for good measure, but like I said I want to know the My Documents thingo is.
     
  12. BFLeigh

    BFLeigh Corporal

    And another thing - Task Manager reports WINWORD.EXE is again in use in the Processes tab even though I haven't used it in weeks.
     
  13. BFLeigh

    BFLeigh Corporal

    My Documents still pops up with the search tool ready as well after I run kill2me for some reason.
     
  14. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Thats normal for kill2me to open My Documents after being ran.
     
  15. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    If you are on a dialup connection Windows XP Service Pack 2 will take a while to download so if you would like you can go to this website and register to get a free cd from Microsoft with Service Pack 2 on it. It will be sent to you within a week or so. Just go here to register!


    All Windows XP users should have this critical update installed.
     
  16. BFLeigh

    BFLeigh Corporal

    I don't want to get SP2 until I know I'm clean, I'm told I must wait.

    Here is a TDS log:

    Scan Control Dumped @ 14:52:57 28-12-04
    Positive identification (DLL): Adware.Look2Me.u (dll)
    File: c:\!submit\guard.tmp

    Positive identification (DLL): Adware.MPGcom.a (dll)
    File: c:\windows\iempg2.dll

    Positive identification: TrojanDropper.Win32.SurfSide.a
    File: c:\windows\ssk_b5.exe

    Positive identification (DLL): Adware.Coreak (dll)
    File: c:\windows\system32\akcore.dll

    Positive identification (DLL): Adware.VirtuMonde (dll)
    File: c:\windows\system32\aklsp.dll

    Positive identification (DLL): TrojanDownloader.Win32.Agent.br1 (dll)
    File: c:\windows\system32\akupd.dll

    Positive identification (DLL): Adware.Look2Me.u (dll)
    File: c:\windows\system32\aometer.dll

    Positive identification (DLL): Adware.Look2Me.u (dll)
    File: c:\windows\system32\oifox32.dll

    Positive identification (DLL): TrojanDownloader.Win32.Dyfuca.aw (dll)
    File: c:\windows\system32\preload2.ocx

    I had no idea all those were on my PC. They are deleted now.

    Can you tell me if from that log you are able to work out if this spyware is still on my PC?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's why I always tell people to delete files after making fixes. You should have been told back in message # 9 to delete c:\windows\system32\aklsp.dll after doing fixes.

    Delete all the above files after booting in safe mode.
     
  18. BFLeigh

    BFLeigh Corporal

    I can't connect to the web in safe mode so I will then have to re-boot after this.

    Anything else I need to know because of this?

    When you post I'll then go to safe mode.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's better not to be connected to the web anyway (unless we ask you to).

    No! Goto safe mode and delete the files.

    Have you done the stuff here yet: How to protect yourself from malware!
    The longer you keep putting this off, the greater the likelyhood of having more problems.
     
  20. BFLeigh

    BFLeigh Corporal

    They were all gone - TDS got them all it seems. I don't know they mutated/missed one which made them all mutate.

    I will do the malware protection process tonight when I can stay on-line for a while. I read on this forum I think it's risky to download such things as Windows Update SP2 while you still may have spyware on your PC. I also need to know when I should turn System Restore back on.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  22. BFLeigh

    BFLeigh Corporal

    You are a legend. Thankyou so much!
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     
  24. Shabbadoo

    Shabbadoo Private E-2

    Seriously,

    You are awsome. I'm an IT guy by trade, but spyware isn't exactly my field of expertise. Thank you so much. I rarely need to go through this much trouble to fix a problem, and this VX2/ Cool WWW "whatever" it was, was the biggest pain in the #*$& I've had to deal with . You are truly appreciated.
    I didn't have to ask questions, I just followed this thread and used the tools provided. very nice.

    are there any articles on the nature of these "replicating" spyware programs? I could understand how they worked when they were dealing with the registry and hidden files, etc. but when they start registering hidden .DLLs and whatnot it's beyond what I know. has anyone on this forum written anything about it?
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We are too busy helping people fix problems to do any formal writeups. While I could probably write a very large book on this, I don't have the time. So other than procedures we have here (like in the stickies) and the tens of thousands of posts we have made to help fix problems, that is it from us.

    Most of what this malware does is take advantage of built-in features of Windows and also they take advantage of the security holes.
     
  26. BFLeigh

    BFLeigh Corporal

    Google has made itself my home page again. I don't know how or why.

    AboutBuster when ran also opens up My Docs folder.

    I'll wait until I get a post before I post any logs.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Running about:Buster changes your home page to google because it cannot guess at what you want it to be.

    Why are you running it? I thought you were clean!
     
  28. BFLeigh

    BFLeigh Corporal

    I believe I am, I was just doing all the programs I got for this (cwshredder/stinger.exe/kill2me/aboutbuster/vx2finder.exe) just for the sake of it to see if they were picking anything up.

    Thanks for that info though - what are the vx2/look2me/coolwwwsearch finder programs that I don't need anymore and how do I get rid of them?
     
  29. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    If your clean you dont need any of these tools. Just delete them, the only one that creates a program file directory is the older version of CWShredder, the new version does not.(It would be named "Intermute") if it existed. This will remove these files. You can always download these tools again if needed.

    Please see this thread to prevent re-infections.

    How to Protect yourself from malware!

    Browse Safely!
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually, the "older version" by Merijn does not have an install. It was the first couple of new versions by Intermute that went thru and install and added some other items too. And yes you're right, they are in the Intermute folder. But it would be better to look for an uninstall in Add/Remove programs first to make sure.

    Personally I would not remove any of the items. They take up very little space and may come in handy if you run into problems again. Sometimes malware can make it difficult or impossible to connect to the internet which means you would not be able to download anything. If you have all these tools available (even if the versions become outdated), they may get you up and running.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds