Ewido

Discussion in 'Malware Help (A Specialist Will Reply)' started by Halbibabe, Jan 4, 2006.

  1. Halbibabe

    Halbibabe Private E-2

    My system runs good,no notable problems. I ran Ewido and it keeps coming up with something I've never seen before.Could someone look at the report and tell me whats up.
     
    Last edited: May 14, 2008
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. Halbibabe

    Halbibabe Private E-2

    Thanks for reply,I was was unable to figure out how to post log so I'll just type out what was found.

    csius.exe
    dmktu.exe
    encodex.exe
    wbemtest.exe
    favset.exe

    I ran the f-secure three times and the same files came up everytime, they were never cleaned for some reason.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is not the full path to the files. Always post complete info. Are they all in C:\windows\system32 Some of these are definitely WareOut related.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  6. Halbibabe

    Halbibabe Private E-2

    Sorry about that. Yes the first four are in c:\windows\system32\
    The fifth one favset.exe is in c:\windows\system32\WBEM

    Yes I had spysheriff on this computer.
    No the second one was for a truck driver friends computer.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't think so. Look again. This wbemtest.exe is probably the one in C:\windows\system32\WBEM
     
  8. Halbibabe

    Halbibabe Private E-2

    A usual you are right.Is there a better way of getting a report off f-secure without running it everytime?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I assume you have HijackThis on your PC but do not post a log. Before we look at HJT logs the READ & RUN ME must be followed.

    Don't worry about it right now. I want to run something.

    Please download FixWareout from one of these sites:
    http://downloads.subratam.org/Fixwareout.exe
    http://swandog46.geekstogo.com/Fixwareout.exe
    • Save it to your desktop and then run it by double clicking on it. It creates a folder named c:\fixwareout.
    • Click Next, then Install.
    • Then make sure Run fixit is checked (this runs C:\fixwareout\fixit.bat). And then click Finish.
    • The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so.
    • Your system may take longer than usual to load; this is normal.
    • When your system reboots, follow the prompts. Afterwards, HijackThis will launch. Please just close HJT.
    • Now reboot into normal mode and please attach the contents of the logfile C:\fixwareout\report.txt
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And just as a double check, continue here.

    Please download Pocket KillBox by Option^Explicit

    Extract the files from it to its own folder someplace you can find it to run.

    Run KillBox.exe. Then on killbox top bar press tools and then "Delete Temp Files" then "OK".

    In the killbox program, select the Delete on Reboot option.
    Copy the file names below to the clipboard by highlighting them and pressing Control-C:

    C:\WINDOWS\system32\csius.exe
    C:\WINDOWS\SYSTEM32\dmktu.exe
    C:\WINDOWS\SYSTEM32\encodex.exe

    C:\WINDOWS\SYSTEM32\favset.exe

    Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
    Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. If you get a Pending Operations message just reboot yourself.

    If your computer does not restart automatically, please restart it manually.

    Let me know how these steps go. Rerun Blacklight and see if it finds anything. Note that wbemtest.exe is okay.
     
  11. Halbibabe

    Halbibabe Private E-2

    I'll do the killbox next//thanks
     
    Last edited: May 14, 2008
  12. Halbibabe

    Halbibabe Private E-2

    I ran the pocket killbox and it deleted the files per post, I then ran blacklight twice and both times it came back no hidden files found.:)
     
  13. Halbibabe

    Halbibabe Private E-2

    I do have HijackThis on my computer.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay as a double check, make sure you have viewing of hidden and system files enable and use Windows Explorer to make sure the below do not exist:
    C:\WINDOWS\SYSTEM32\CSIUS.EXE
    C:\WINDOWS\SYSTEM32\ENCODEX.EXE
    C:\WINDOWS\SYSTEM32\DMKTU.EXE

    How are things working now? Is Ewido still reporting problems?

    If all clean, and you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  15. Halbibabe

    Halbibabe Private E-2

    Thanks for all the help, Ewido is coming back clean, no infective objects.

    I went ahead and did the Read first sticky before asking for help and did everything. Spybot found a windows.ActiveDesktop but cleaned it.

    I was able to run everything in safemode except Pandascan.
    Pandascan found three spywares. Would you mind looking at the log before I mess with system restore?All the other tests were coming back clean.
     
    Last edited: May 14, 2008
  16. Halbibabe

    Halbibabe Private E-2

    Chaslang,

    If you get a chance can you look at last scan so I can clear out restore points// No pressure// Thanks for the help.:)
     
  17. Halbibabe

    Halbibabe Private E-2

    Don't worry about replying I went ahead and cleansed the restore points.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Delete the below files:

    C:\WINDOWS\SYSTEM32\paytime.exe
    C:\WINDOWS\country.exe
    C:\WINDOWS\tool2.exe

    Then you should make sure you have finished working thru the How to protect thread.
     
  19. Halbibabe

    Halbibabe Private E-2

    Thanks, files deleted,I've already worked though the sticky.

    Thank you again for your time I've learned a lot.:)
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds