Help with Virusbuster and/or Malwarewipe

Discussion in 'Malware Help (A Specialist Will Reply)' started by bleoh, Nov 22, 2006.

  1. bleoh

    bleoh Private E-2

    I think I picked up one or both. I followed the "read me first" although I did run HJT once before changing the name of the file. After I realized it I closed the program, changed the name and ran it again. In addition to what is in the RMF post, I have Kaspersky Internet Security 6.0 on my PC.

    The scans from the RMF steps show I have some infections and that they were not removed. Kaspersky is showing that there is a suspicious action: Keylogger Running Module \Driver\Ps2 but I do not know what it means.

    The only symptom I am seeing now (the steps in RMF help remove that annoying icon in the system tray warning me that I had to buy Virusbusters and Malwarewipe!) is that I get a fake virus warning when I start IE and my homepage has been changed to youriesecure.com

    TIA for your help.
     

    Attached Files:

  2. bleoh

    bleoh Private E-2

    Here are the rest of the files.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.


    Now attach new logs from:
    • GetRunKey
    • ShowNew
    • HJT
    How are things working now?
     
  4. bleoh

    bleoh Private E-2

    Here are the files. I'll post the rapport file in the next post.

    My homepage is working now. Everything seems to be working fine. The Kaspersky software is still giving warnings about suspicious action: Keylogger.

    If these files look good should I toggle my System Restore?

    Thanks a bunch!
     

    Attached Files:

  5. bleoh

    bleoh Private E-2

    Here is the rapport file. BTW, the smitfraudfix instructions say that the program will scan large amounts of files and to be patient. It ran very quickly on my PC, it was done in less then 60 seconds.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Delete the below folder:
    C:\Program Files\SpywareBot

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 5
    J2SE Runtime Environment 5.0 Update 6
    Safety Alert 2006 <--- this is malware

    Now install the current version of Sun Java from: Sun Java Runtime Environment



    Attach a log from Kaspersky that shows what it is finding.

    Not yet!
     
  7. bleoh

    bleoh Private E-2

    I uninstalled J2SE update 5 and 6 and Safety Alert 2006. XP said that Safety Alert had already been removed and it just needed to be removed from the intalled software list.

    I installed Sun Java from your link.

    I have not been able to find where Kaspersky will produce a log. I am using the 6.0 trial version.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have never used it so I cannot tell you but there must be some way to get a report or log. Also can you just tell me EXACTLY what comes up in the message it is giving to you.
     
  9. bleoh

    bleoh Private E-2

    Well, now I am not getting any warnings from Kaspersky. I've looked but can't seem to find any reports I can export or log files.
     
  10. bleoh

    bleoh Private E-2

    The warning popped up. It says "Keylogger detected. Possible driver name is System32\DRIVERS\ELkbd.sys."
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This may be a false positive. I don't have much good info on that file but it may be some kind of driver made by Intel. From the name it sounds like something for a keyboard. One link I had referred to it as Intel(R) Quick Resume Technology

    Can you put a copy of this file into a ZIP and attach it here? It all depends on how large the file is. If the file is too large, even zipping it may not make it small enough to upload. I saw references saying it was 6.7Mb in size. If that is true you probably will not be able to attach it even if compressed into a ZIP file.

    This file often appears in a group with the below files:
    system32\DRIVERS\ELacpi.sys
    System32\DRIVERS\ELhid.sys
    System32\DRIVERS\ELmon.sys
    System32\DRIVERS\ELmou.sys

    You can also do the following if it cannot be uploaded.

    Use Windows Explorer to navigate to c:\windows\System32\DRIVERS\ELkbd.sys. Then right click on it and select Properties. Now see if there is a Version tab in the window. If so, select the Version tab and on the next window select each of the listed Item names (one at a time) to get more info about the file. The most important information is Description and from the Item list is the company name. If there is no Version tab, tell me that too.
     
  12. bleoh

    bleoh Private E-2

    The properties tab says it is an Intel file.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It looks okay to me and I even ran it thru 15 antivirus scanners (one of which is also Kaspersky) and they all came back clean.
     
  14. bleoh

    bleoh Private E-2

    Thanks for doing that!

    So, what are my next steps?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds