Dangerous viruses & Helkern worm

Discussion in 'Malware Help (A Specialist Will Reply)' started by Woden20, Mar 13, 2009.

Thread Status:
Not open for further replies.
  1. Woden20

    Woden20 Private E-2

    Hi,

    My Kaspesky scan has detected these 2 files underneath which its says are very dangerous and I can't seem to quarantine them.
    I'd be very grateful if someone could help me get rid of them.

    C\WINDOWS\SoftwareDistribution\Download\79123dd72d0f61d4ed8c7a816ed338d7\ (file name is msxml6.dll)
    C\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.1.0.0_x-ww_b319d8da\ (file name is msxml4.dll)

    This is the details of them per Kaspersky
    http://www.viruslist.com/en/advisories/23655
    I've no idea if I've even got any of these Microsoft XML Core Services installed on my computer that they say would make my computer vunerable

    I tried downloading this patch but I'm not really sure if it was the right one.
    When I installed it my computer saved a system restore point so the virus might be backed up now.
    http://www.microsoft.com/downloads/...3c-5261-4f69-83d0-932c430abd14&displaylang=en

    I've worked my way through your helpsheets and I've attached the 4 logs
    http://forums.majorgeeks.com/showthread.php?t=35407
    http://forums.majorgeeks.com/showthread.php?t=139313

    The other worry I've got is I've been getting a lot of messages lately where Kaspersky says its blocking a worm called Intrusion.Win.MSSLQL.worm.Helkern
    Yesterday though I stupidly turned Kaspersky off by mistake for a minute. Is there a way of checking that this worm hasn't installed itself?

    Many thanks
     

    Attached Files:

  2. Woden20

    Woden20 Private E-2

    Hi,
    Here's the the other file

    Thanks
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean.....please attach the Kaspersky log so I can see what it is referring to.
     
  4. Woden20

    Woden20 Private E-2

    Hi,
    I don't think my Kaspersky 2009 can save a log file. At least I can't see any option to do it. Sorry, I'm maybe being dense but how is it done?

    This is all the details its says -

    Highly dangerous active threats.
    C\WINDOWS\SoftwareDistribution\Download\79123dd72d0f61d4ed8c7a816ed338d7\ (file name is msxml6.dll)
    C\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.1.0.0_x-ww_b319d8da\ (file name is msxml4.dll

    Next to both of them is gives this as details of the vunerability. If you look this up it might help hopefully.
    http://www.viruslist.com/en/advisories/23655

    Thanks
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Using add / remove programs, remove old versions of msxml4 and 6. Do a windows search for any remnants. Then go to microsoft updates and check for needed updates.
     
  6. Woden20

    Woden20 Private E-2

    Hi,
    There wasn't any programs there called msxml4 or 6
    All that was there was the patch I downloaded to see if that would work called MSXML 4.0 SP2 (KB954430) which I've now removed.

    I don't know how to do a windows search for remnants
    How do I know what updates I need?

    Thanks
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to start, search, for files and folders click advanced and check hidden or system files).....and put in one at a time msxml4 and msxml6.

    If no results come back then you can close the search box.

    http://update.microsoft.com it will scan for updates.
     
  8. Woden20

    Woden20 Private E-2

    Hi,
    The msxml6 search detected just 2 files- the one up above and another one with an extra 'R' in the name. I deleted both files OK

    The msxml4 also had a 2nd file with an 'R'.
    I couldn't delete either of them. When I tried it would seem to work but then Kasperky would flash saying ''MSI19.tmp place in restricted''
    Then the pc would close down and reopen and the files were back

    There were also a few other files eg. System 32 files to do with msxml4 that when I tried to delete them seemed to copy themselves as 'Recyler' files.
    They also went back to their original names when the pc rebooted itself.

    I also got a message when the pc logged back on ''WKUfind.exe unable to locate component. The application failed to start because MSVCR70.dll was not found. Reinstalling the application may fix it.''

    Thanks
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Kaspersky is alerting you to vulnerabilities which leave security holes in your system. You need to update all your programs and download SP3.
     
  10. Woden20

    Woden20 Private E-2

    Hi,
    The microsoft website says my updates are upto date apart from SP3, as my pc seems to be set on auto update. I didn't realise that.

    I had a go downloading SP3 it but it failed - error code 0x8024200d.

    What will I try now?

    Thanks
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try downloading here:
    [Click here to Download*]
    *Service Pack 3 does not include all drivers - run this free scan to find which ones need updating.


    Then disable all security software before trying to install.

    This is not a malware issues, so I suggest you follow up with this in the software section. :)

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  12. Woden20

    Woden20 Private E-2

    Thanks for your help, I'll do that
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds