Can't get rid of Downloader Virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by Hank101, Aug 16, 2006.

  1. Hank101

    Hank101 Private E-2

    I can't get rid of the downloader virus that shows the infected file as c:\windows\system32\baslug.dll

    I am dunning a Dell computer using Windows XP Home w/ SP2. I am running Symantec Antivirus Corporate Edition and update regularly. This wont clean it as I get the standard message that the file is in use. I have tried in safe mode as well. I have follow the steps outlined in thread 35407 and attached the required files. I not only need help with this issue, but this computer runs sooo slow, even for non internet functions. My guess is there is a lot of crap being loaded that I don't need but need some help figuring how to get rid of it. Thanks, I appreciate your help.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is this the same PC that you never finished working on with Shadow_Puter_Dude in the below thread:

    http://forums.majorgeeks.com/showthread.php?t=98459


    You need to post the other logs requested in the READ & RUN ME (GetRunKey & ShowNew - make sure you download the new version of ShowNew).
     
  3. Hank101

    Hank101 Private E-2

    No, this is another computer we have. I didn't know there was more I needed to do on the first. Let me kow if there is something I need still need to do as the computer has been working great.

    On this computer that I posted the problem today, this does seem to be similar. I have attached the other files you recommended (sorry I didn't catch that with the other stuff).
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First install the current version of Sun Java from: Sun Java Runtime Environment


    Then uninstall the below software using Add/Remove Programs:
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_03
    My Way Search Assistant"
    Viewpoint Media Player

    Now download two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of awvvv.dllonce and then click the kill button. After you have killed all of the awvvv.dllunder winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    BASLUG.dll
    Next double click on explorer.exe and again click once on each instance of awvvv.dlland kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    BASLUG.dll

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
    R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
    O2 - BHO: InfoDocReader Object - {295BA105-3506-4D25-B0DD-54346320BDC5} - C:\WINDOWS\system32\awvvv.dll
    O2 - BHO: (no name) - {d0bb4c88-a9f9-4910-9a48-4b944d3c861f} - C:\WINDOWS\system32\BASLUG.dll
    O20 - Winlogon Notify: awvvv - C:\WINDOWS\system32\awvvv.dll
    O20 - Winlogon Notify: BASLUG - C:\WINDOWS\SYSTEM32\BASLUG.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    Now back on Killbox's main window, Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.

    C:\WINDOWS\SYSTEM32\genjrisy.dll
    C:\WINDOWS\SYSTEM32\jwgodtyr.dll
    C:\WINDOWS\SYSTEM32\lqtdqhqh.dll
    C:\WINDOWS\SYSTEM32\nuvmpuus.dll
    C:\WINDOWS\SYSTEM32\ypsdkvia.dll
    C:\WINDOWS\SYSTEM32\vvvwa.ini
    C:\WINDOWS\system32\awvvv.dll
    C:\WINDOWS\system32\BASLUG.dll

    If Killbox does not reboot or if you get a Pending Operations type error message just click OK to continue and then just reboot your PC yourself.


    Now attach a new HJT log and tell me how the steps went.
    Also attach a new log from ShowNew and a new log from GetRunKey.
    Make sure you tell me how things are working now!
     
  5. Hank101

    Hank101 Private E-2

    Everything seemed to go ok. Too early to tell how pc is running, but the virus does seem to be gone. I have attached the logs you requested. Please let me know if things are ok and if anything else looks strange. I know my daughter has put some stuff on here that probably is not needed that may be taking up resources. Also, not sure if any of these logs display any items that should or should not be checked in the advanced tab of options for IE, but there are probably incorrect settings in here that I dont know what are good or not. Thanks for your help !!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you try uninstalling My Way Search Assistant
    I still see it in your log! Does it appear in Add/Remove programs?


    Do you use FilmLoop Player

    Do you use AOL?
     
  7. Hank101

    Hank101 Private E-2

    The "My Way Search Assistant" was not in the add/remove programs. I do not think the "FilmLoop Player" player is used. The only thing AOL is used for is their AIM (instant messaging). AOL is not our provider and no aol e-mail addresses. Strickly the instant messaging. Not sure if what you see as AOL is related to the instant messaging, but if not it probably should be deleted. Thanks
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you do not use FilmLoop, you should uninstall it. The same goes for anything else that you do not use. There is no sense cluttering up you PC with stuff you do not use.

    Let's get rid of a few more things including an AOL key that you do not need for AIM.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now attach a new log from GetRunKey.

    Also tell me how everything is working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds