Downloader.Swizzor.8.BK issue resolved, I think.

Discussion in 'Malware Help (A Specialist Will Reply)' started by givey, Feb 6, 2007.

  1. givey

    givey Private E-2

    I have follwed to the T the post "Read & Run Me First". And I believe that has taken care of two problems 1) Downloader.Swizzor.8.BK, and 2) bo:heap. I'm not sure what bo:heap is, but it appears to be gone. I am attaching the requested logs because I would like for you all to see if there is anything else I should be aware of. Thanks in advance. Oh, I hope I attached these right.
     

    Attached Files:

  2. givey

    givey Private E-2

    OK, here are the next three attachments. Forgive me if this is incorrect.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You must be getting error messages while running ShowNew and GetRunKey. Or you antivirus program is blocking them from running properly. Neither log shows complete results. See the download links again and make sure your note the possible errors and the fixes.

    Now run this WareOut Removal and make sure to attach the requested log later.


    Did you put in the below Proxy Override settings? If so, why? If not, have HJT fix this line too in the below steps!
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 64.136.29.30;64.136.21.30;64.136.29.34;searchap.untd.com;127.0.0.1;localhost;*microsoft.com;*windowsupdate.com;*wustat.windows.com;*.pogo.com;*.worldwinner.com;*test-speed.com;liveupdate.symantecliveupdate.com;*symantec.com;*.nai.com;*.networkassociates.com;<local>

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: (no name) - {8A418A46-DE0E-A91A-4CD6-EB10E0DE657A} - C:\DOCUME~1\Aaron\APPLIC~1\SPAMFO~1\errorsupport.exe (file missing)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
    O16 - DPF: {11111111-1111-1111-1111-111191113457} -
    O16 - DPF: {11111111-1111-1111-1111-511111193457} -
    O16 - DPF: {11111111-1111-1111-1111-511111193458} -
    O16 - DPF: {23232323-2323-2323-2323-232323291122} -
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{00EC39F3-F7D9-4760-85AB-1EAEAA90033F}: NameServer = 85.255.116.137,85.255.112.23
    O17 - HKLM\System\CCS\Services\Tcpip\..\{7FE639DA-DD05-4228-A90F-0FD854669238}: NameServer = 85.255.116.137,85.255.112.23
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.137 85.255.112.23
    O17 - HKLM\System\CS1\Services\Tcpip\..\{00EC39F3-F7D9-4760-85AB-1EAEAA90033F}: NameServer = 85.255.116.137,85.255.112.23
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.137 85.255.112.23
    O17 - HKLM\System\CS2\Services\Tcpip\..\{00EC39F3-F7D9-4760-85AB-1EAEAA90033F}: NameServer = 85.255.116.137,85.255.112.23
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.137 85.255.112.23
    O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - (no file)
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    c:\documents and settings\all users\application data\mp3 junk sign scr\Wayteam.exe
    c:\windows\switchagreement.txt
    C:\WINDOWS\Downloaded Program Files\ied.inf
    C:\WINDOWS\Downloaded Program Files\start26.inf
    C:\WINDOWS\system32\kdcxk.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!)

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete if found:
    c:\windows\uniq
    c:\documents and settings\all users\application data\mp3 junk sign scr

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. FixWareOut log
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  4. givey

    givey Private E-2

    Thanks for your help thus far.

    I had no error messages the first time with the ShowNew and GetRunKeys, but I removed and re-downloaded the ShowNew and GetRunKey files. I also deactivated my anitvirus. I ran fresh logs, I hope they contain what you are looking for.

    I did not put in the Proxy Override settings. I had HJT fix them as requested.

    As for the Pocket Killbox, I only found one file path:

    C:\WINDOWS\switchagreement.txt

    The below file paths were not found even by a file search:

    c:\documents and settings\all users\application data\mp3 junk sign scr\Wayteam.exe
    C:\WINDOWS\Downloaded Program Files\ied.inf
    C:\WINDOWS\Downloaded Program Files\start26.inf
    C:\WINDOWS\system32\kdcxk.exe

    I did delete the one that was found. And I did not receive a PendingFileRenameOperations prompt.

    After the reboot located both of the following and delted:
    c:\windows\uniq
    c:\documents and settings\all users\application data\mp3 junk sign scr

    Then CCleaner as requested.
     

    Attached Files:

  5. givey

    givey Private E-2

    And the HJT report
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your welcome!

    Your PATH environment variable is not set correctly! That is the problem! This would prevent many kinds of programs (especially batch files like these) from running properly.


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now Reboot ( don't skip the reboot)!

    After reboot, try running GetRunKey and ShowNew and attach new logs!
     
  7. givey

    givey Private E-2

    I think these are better.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that's much better as you already noticed! ;)

    Also delete the below folder left over from the malware program named Torrent101
    C:\Documents and Settings\Aaron\Application Data\Torrent101

    Also do you know what the below folder is for? It was just created on Feb 6th? If not, what is in the folder.
    C:\Documents and Settings\Aaron\Application Data\spam ford
    SPAMFO~1 Feb 6 2007 "spam ford"

    Also delete the below file:
    C:\68.tmp

    Okay now uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software


    I would also suggest that you get your Ad-aware 6 Professional updated. This is way out of date.


    How are things working now?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds