Another Downloader Agent 9 BF

Discussion in 'Malware Help (A Specialist Will Reply)' started by Alverez, Mar 15, 2005.

  1. Alverez

    Alverez Private E-2

    Hi, I've been having major probelms with this thing. I know you have seen a million threads on it and are probably getting sick of it, so sorry! I have followed the steps in the "Read me first..." sticky, twice in fact. The first time, the system got a little better, but after a couple reboots, the problem was back as bad as ever. I just finished following the steps again, and wondering if there was anything else I should do. I will not reboot or do anything really until I hear back. Thanks!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. Alverez

    Alverez Private E-2

    Ok, here it is. Thanks!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First quick observation, you have both McAfee and AVG installed. You must only have one AV package installed. So decide which one you want and uninstall the other. Do that now while I look at your HJT log.

    Also what is your expected home page?

    Also look in Add/Remove programs for an uninstall to
    Preview AdService

    or AdService

    Uninstall if found.
     
  5. Alverez

    Alverez Private E-2

    I'll go uninstall AVG now. My homepage is set to Google. In theory, anyways


    I found Preview Ad Service and removed.
    AVG has been removed but is prompting for a reboot. I'll wait on that until you say different for fear of mutations.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    OK! Do you know what this is:
    C:\WINDOWS\System32\Sktempdm.exe

    If not, can you right click on it and Select Properties and Version tab. Find out who owns it.
     
  7. Alverez

    Alverez Private E-2

    C:\WINDOWS\System32\Sktempdm.exe belongs to Silitek Corp.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you know anything about them or this program? Do you have a wireless keyboard? Is that what this is for?
     
  9. Alverez

    Alverez Private E-2

    The keyboard here is not wireless. No, I do not know much about them. It looks to be involved with files from the service provider (similar names, etc) This is actually my girlfriends computer and is usually maintained by someone else.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's ignore the Sktempdm.exe file for the time being!

    You don't seem to show all the typical symptoms of the hijacker so let's try and easier method to fix and see what happens.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\zjupd.dll/sp.html#12345
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\zjupd.dll/sp.html#12345
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\zjupd.dll/sp.html#12345
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {F1A6A9B5-3C41-5DA5-986D-F3935E072EF1} - C:\WINDOWS\winbf32.dll (file missing)
    O4 - HKLM\..\Run: [gah95on6] C:\WINDOWS\System32\gah95on6.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\zjupd.dll
    C:\WINDOWS\System32\gah95on6.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to www.google.ca. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.google.ca. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  11. Alverez

    Alverez Private E-2

    Followed to the letter. Things seem to be alright so far. Just a couple porn sites still listed under favorites, but I never deleted them manually yet.

    Here is the new HJT log
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks good thus far. After a few reboots and some opening and closing of browsers you should know it it is gone or not.

    You should complete the steps in the below thread to help avoid future problems:
    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds