Can't run some of the programs, still there.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Waelfwulf, Aug 25, 2009.

  1. Waelfwulf

    Waelfwulf Private E-2

    Sorry if I don't use the proper terminology-
    Problem started about 2 hours ago (5:00 pm EST 25 Aug, 2009)

    So when trying to download a torrent file (can't remember which site it was from and computer has been restarted since then, losing the history) it turned out not to be a torrent file, but some sort of malware. The only symptoms (so far) are little icons in the bottom right of the toolbar (two actually) proclaiming that "your computer is infected!". I immediately ran through the windows XP cleaning procedure, but not all of the programs will run.
    SuperAntiSpyware won't run.
    Malwarebytes won't run.
    Combofix won't run.
    RootRepeal DID run.
    MGTools DID run, but ends with an error saying that sort utility encountered a problem and needed to close.

    I've also tried Spybot Search and Destroy, it won't run.
    I've tried registry mechanic, it DID run.
    and finally, CCCleaner, which DID run.

    After running the ones that will actually run, the malware is still present.

    Oh, and I tried running the programs in safe mode, same results.
     

    Attached Files:

  2. Waelfwulf

    Waelfwulf Private E-2

    Not a bump, I swear!

    New symptom- a shortcut has appeared on my desktop for a program called "PC Antispyware 2010". Hopefully this can help identify the malware?
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do this first:

    Please double-click the RootRepeal.exe previously downloaded.

    * Select File then Scan
    * On the Select Drives form select drive [ insert drive infected here ] by "ticking" the box for drive [insert drive here] and click OK
    * When the scan is complete - highlight each of the following file(s) (one at a time if more then one is listed) by left clicking it. Then use right mouse click and select the Wipe File option only for each file.
    C:\WINDOWS\Temp\UACde64.tmp
    C:\WINDOWS\system32\kbiwkmjxujoyqm.dll
    C:\WINDOWS\system32\kbiwkmklyrvomo.dat
    C:\WINDOWS\system32\kbiwkmltenqodq.dat
    C:\WINDOWS\system32\kbiwkmvdhmvioy.dll
    C:\WINDOWS\system32\UACfiwtckkjjx.dat
    C:\WINDOWS\system32\uacinit.dll
    C:\WINDOWS\system32\UACktesublgul.dll
    C:\WINDOWS\system32\UACnayijgenkl.dll
    C:\WINDOWS\system32\UACthcqthcmqo.dll
    C:\WINDOWS\system32\UACthektauxds.dll
    C:\WINDOWS\system32\UACxxpgvpkmla.db
    C:\WINDOWS\system32\drivers\kbiwkmgilkrsap.sys
    C:\WINDOWS\system32\drivers\UACimpeqmbhct.sys
    C:\Documents and Settings\Dan\Local Settings\Temp\UACb053.tmp
    * After Wiping all files, immediately reboot your pc!

    After reboot, download/install/update and run the scanning tools you couldn't run!

    Attach those logs.

    Now lets get a new MGLogs. run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * RootRepeal log
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  4. Waelfwulf

    Waelfwulf Private E-2

    Ran the scans as you said, found the items mentioned, deleted them successfully, ran the other scans successfully, posting the logs. (I seem to have misfiled my logs for SAS and MBAM... grr) I'm rescanning with those, and will post the new logs.

    Things are working much better, except for some reason firefox will randomly crash occasionally. However, it hasn't happened in the five minutes since I ran the last scan, so we'll see.

    Thanks for the help. I really appreciate that you folks do this stuff for free. You guys are lifesavers.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You didnt attach any logs.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds