help with UKash - ?win32generic_bt?

Discussion in 'Malware Help (A Specialist Will Reply)' started by autogeekdidact, Mar 1, 2013.

  1. autogeekdidact

    autogeekdidact Private E-2

    Hello, and advTHANKSance,

    I am helping my neighbour rid his system of this ransomware. I have done everything in chaslang's malware removal guide and am attaching logs. Sorry about the mbam log as it is in french, anyhow. None of it turned up anything blatant. The problem has only just occurred, and the computer seems unlocked and functional (for now,) but the problem isn't solved, as I have done nothing else. It seems to be letting me use the desktop and start menu although I did not need to boot in safe mode. Hope it lasts.
    System is windows 7 64bit on an Asus notebook.
    _ps The first CCleaner link on your download page was 'Not Found'.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. However, this file and folder look suspicious to me:
    C:\ProgramData\wrguqrghlhsyzcb
    C:\ProgramData\zhirzqekdobrmdn

    Use windows explorer to find and delete them. Also, run CCleaner to clean out your temp folders.

    What malware issues are you having, if any?
     
  3. autogeekdidact

    autogeekdidact Private E-2

    First, thank you for your prompt attention.
    My system is definately compromised by ransomware. I got the UKash splash screen on several occasions. I have done NO cleaning yet. It must still be in there somewhere. Perhaps it has not yet had time to spread. I suspect win32 generic!bt because it is the same splash screen as I have seen on another system which was infected with that particular form of ransomware. The computer was locked, but I used a workaround to get into cmd and onto the internet in order to download and run the programs from chaslangs proceedure.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  5. autogeekdidact

    autogeekdidact Private E-2

    Yahoo! Threats found! I'm not imagining things.
    A buggy scan even without touching anything, anyhow...
    It seems that Windows started cleaning the files even as the scan was progressing. (progress bar doesn't work, btw)
    After an hour-long scan for 130,000 files it turned up five threats. They were quarantined but not deleted. The threats were fixed, though.
    (log attached)
    CCleaner was installed and run for temps.
    _ps can a virus hide in an .iso and go unnoticed? There are 4 backup files in this puter which are .iso.
    Thanks so much, these tools are excellent, so what next?
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download ComboFix to your desktop. Turn off any AV software you have before you run it. Attach the log when finished. Do not do anything while it is running or it may stall the program.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  7. autogeekdidact

    autogeekdidact Private E-2

    Well, I never saw the license agreement for Hijack this, but the logs are attached.
     
  8. autogeekdidact

    autogeekdidact Private E-2

    I seem to be having trouble uploading files. Had to do it twice, for the second time. Anyhow, here are the logs.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You didn't put Combo directly on your desktop as directed.

    I am not finding any traces of Ukash. Are you still having issues?
     
  10. autogeekdidact

    autogeekdidact Private E-2

    Oops, it's in a folder on my desktop. My bad.
    No, I'm not getting the splash screen anymore and the computer is responding well. I think we might be done.
    Thanks a ton for your help, Tim.
    As helpful as you've been, I sincerely hope never to have to speak with you again. But that's probably wishful thinking.
    Phil...
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. And you are most welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:



    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds