Inqwire Trojan.Win32.Kolweb.f

Discussion in 'Malware Help (A Specialist Will Reply)' started by wannabetechie, Dec 8, 2005.

  1. wannabetechie

    wannabetechie Private E-2

    I just wanted to thank the folks here for the "read me and run first..." instructions in this forum. After over a week of frustration, countless downloads, and scans that found nothing, the Kaspersky online scan found two infections (see attached). It found the Trojan.Win32.Kolweb.f and Trojan.Win32.Kolweb.g infections online, but none of the tools I used identified them, so I couldn't remove them. Finally I decided to manually remove all the objects with the McAfee shredder and then used Microsoft's Anti-Spyware to clean up registry info, and unknown BHO's. So far it seems to be working.

    I wanted to post this also because my google searches found nothing on removing these two. I think they're fairly new. Thanks again and happy hunting.
     

    Attached Files:

  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Please post a HijackThis log also.
     
  3. wannabetechie

    wannabetechie Private E-2

    Thanks for the reply. Here's a log from 12/6 and one from a few moments ago. Please let me know if you see anything that still looks suspicious in the current one.
     

    Attached Files:

  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Disable Spybots Teatimer. This was requested in our READ ME.

    Now scan and have HJT Fix the following:
    Download
    - Pocket Killbox
    - ExplorerXP

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open ExplorerXP navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Follow the directions for Running Spy Sweeper

    Post a fresh HijackThis log along with the Spy Sweeper log.
     
  5. wannabetechie

    wannabetechie Private E-2

    Thanks for all your help, Shadow_Puter_Dude! With Teatimer, I enabled it only after I believed I was clean. It's off now.

    I've done everything you suggested, and attached the HJT & Spysweeper logs. It looks pretty clean to me, but I'm just a "wannabe." Your expert analysis is appreciated. Please let me know if you see any other issues.

    Also, with all the spyware downloads I've done and their autorun/autoupdate functions, it now takes me about 10 minutes to reboot (it used to take just a minute or two.) Can you tell me what at a minimum I should leave running on a daily basis to help protect me from future infections? I'm thinking McAfee Security and Spybot S&D Resident & Teatimer would do it. What do you think?
     

    Attached Files:

  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Your system appears to be clean.

    You can uninstall everything. I would keep Spybot, but don't run Teatimer, it can be a resource hog; and often blocks legit system changes. I would also use Spyware Blaster in addition to Spybot. I also recommend using either MS Antispyware or SpywareGuard.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds