HJT log during cleanup of bro's comp

Discussion in 'Malware Help (A Specialist Will Reply)' started by SWario, Jun 8, 2006.

  1. SWario

    SWario Sergeant

    M'kay, so my older brother (25 years old) brings over two old computers and asks me to build him one good computer by combining the two. Easy enough. Unfortunately, both PCs are OLD. One has a Pentium-II at 350 MHz, and the other has an AMD K6-III at 400 MHz. The AMD is running Win98SE, and the Pentium is running Win98. My brother is extremely computer illiterate, so changing the OS to anything but Windows is a no-no. Unfortunately, the Win98SE machine was custom built, so the original owner doesn't have the Win98SE discs that were used on it, just the Win98 discs from the Win98 machine (a Gateway). My brother said he's willing to dish out some money for the sake of upgrades for his PC, but we both prefer things as cheap as possible. Going by this, and the existing specs of the PCs, I decided to go with the Win98SE machine as the base, and add parts into that. Unfortunately, since we don't have the Win98SE discs, that means I can't format and reinstall, so I have to cleanup the system before giving it to him.

    ...

    :eek: :eek: :eek:
    HOLY CRAP. This machine was the worst case of PEBKAC I have ever seen. The previous owners must not have understood any concepts of PC security or maybe even the notion that their computer could get sick just like people and other appliances. I ran through the READ ME steps before posting, and there was stuff in their Add/Remove list that was on the "You might want to check this list in case there is stuff installed" list. I couldn't believe it! I've never seen a machine with anything from that list in someone's Add/Remove Programs, and not just a few of them, a LOT of them.

    Anyways, Ad-Aware picked up over 400 problems (among them VX2 and some nasty little buggers), SpyBot detected 36 after that, and CWShredder still found an instance of CWS after that. After all this, I ran Kill2Me and About:Buster, and then got me an HJT log. I saved the logs from Ad-Aware and SpyBot, but I'll only attach the HJT log for now. Someone take a look and help me out quick? I want to get this PC finishing in the next few hours if at all possible. Thanks!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We don't need logs from Ad-aware or Spybot but we do need all steps from the READ ME to be followed.

    - You did not run CounterSpy and attach the log.
    - you did not run Bitdefender and attach the log
    - you did not run PandaActiveScan and attach the log

    Please run the above scans and attach those three logs!

    Did you uninstall Web Offer?

    Now download LSP - Fix

    Run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the aklsp.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move aklsp.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.
    If it is already in the Remove section, just click Finish.

    Look for the below file and delete it:
    c:\windows\system\aklsp.dll
     
  3. SWario

    SWario Sergeant

    I've just installed and run CounterSpy from Safe Mode (did not update definitions though, I will explain shortly). Also, I will not be running online scans with this computer at this time. Given the infested state of the machine in question, I will not be connecting it to my home network until after it has been sufficiently cleaned.

    Yes, I did uninstall Web Offer, as well as anything else from the preliminary housecleaning list that was present on the system. When running CounterSpy, 8 items were quarantined and 7 items were removed (always used recommended action, except for "Ignore" which was always changed to "Remove").

    I ran LSPFix, but "aklsp.dll" was not in the list. The file you pointed me to did not exist either, but there were similarly named files:
    • akcore.dll
    • akhost.exe
    • akrules.dll
    • akupd.dll

    Here is an updated HJT Log.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    - You did not attach the CounterSpy log.


    Edit: And yes delete those other 4 files. They are all part of the Trojan downloader.

    How are things working?
     
    Last edited: Jun 9, 2006
  5. SWario

    SWario Sergeant

    I could not find a CounterSpy log feature, so I pulled up the details of the previous scan (the one you're asking for) and copied that into a text file. I hope that it has what you need. I am attaching that with this post. I also deleted those other four files as suggested. As for how things are working, I'm not really sure, I haven't run the computer in Normal Mode since I started this cleaning, it's just been sitting in Safe Mode for a couple days now. Since I am changing the hardware in the machine, I figured that I should clean it up as much as possible before trying to install new hardware.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your last HJT log was free of malware. Only the below minor item can be fixed using HijackThis:

    R3 - Default URLSearchHook is missing

    You should boot normally and see what happens.
     
  7. SWario

    SWario Sergeant

    I booted normally and got the following error message:

    "RUNDLL

    Error loading C:\WINDOWS\SYSTEM\WUAUCLT.DLL

    The system cannot find the file specified."


    Other than that, there seem to be no processes running that really shouldn't be there. I'm attaching an HJT log from Normal Mode.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just have HJT fix the below line:

    O4 - HKLM\..\Run: [autoupdate] rundll32 C:\WINDOWS\SYSTEM\WUAUCLT.DLL,SHStart

    How is everything working now?

    If you are not having any other malware problems, you should work thru the below link:

    How to Protect yourself from malware!
     
  9. SWario

    SWario Sergeant

    I fixed the entries you suggested, haven't noticed any problems yet. Being that this is going to be a Win98SE system running at about 400 MHz, which free AntiVirus and Firewall software do you recommend for this type of system?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Any of the three free ones mentioned should be okay. Give AVG a try an see how it runs.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds