Just getting started

Discussion in 'Malware Help (A Specialist Will Reply)' started by kzook, Jul 5, 2006.

  1. kzook

    kzook Private E-2

    Hi,
    I have used your site before with great success but it has been awhile. Just printed out all of the preliminary procedure stuff and will start through that tomorrow evening. In the meantime, I would simply like to know if I am in the right place to solve the following problems (may be related?):
    1. virus "W32/Downloader.ABKP", infected file is c:\windows\system32\kbdopy.dll, which could not be deleted.
    2. constant popups for WinAntiVirus
    Please let me know if this is the place to get this stuff resolved and I will start in on the cleanup procedure. Thanks very much.
    Keith
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Magorgeeks!

    Yes! You are in the right place. Run the READ & RUN Me and attach the 3 requested logs. To avoid any delay in getting help, follow ALL steps completely. Make sure you install HijackThis exactly as requested in the procedure and make sure you attach the two logs from the online scanners and that they are run BEFORE HijackThis.
     
  3. kzook

    kzook Private E-2

    Ok, I just performed every step of the READ & RUN ME FIRST chronicles. With every scan there were viruses and spyware detected and removed. Do not appear now to be having the problem with the WinAntiVirus popups and just ran a virus scan and nothing is showing up. SO I think the problems that I was seeing have been rectified; HOWEVER, according to one/some of the attached logs there was some spyware or malware that was identified but was not deleted. So the log files are attached. Let me know what I should do from here. Also, exactly when do I do the STEP 1 Disable System Restore? Now, or wait to see if there will be further cleanup? Thanks for all of the help.
    Keith
     

    Attached Files:

  4. kzook

    kzook Private E-2

    And here is one more log file.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I will tell you when to toggle System Restore!

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {b3012e70-de44-48a5-a382-3f03bdb140bf} - C:\WINDOWS\system32\IGFvaa.dll (file missing)
    O4 - HKLM\..\Run: [lich] lich.exe
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
    O20 - Winlogon Notify: IGFvaa - IGFvaa.dll (file missing)
    O20 - Winlogon Notify: kbdopy - kbdopy.dll (file missing)


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete (they may be gone already but we must check):
    c:\windows\warnhp.html
    C:\WINDOWS\system32\IGFvaa.dll

    Now empty your Recycle Bin.

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.
     
  6. kzook

    kzook Private E-2

    I will do exactly as you say when I get home tonight. Reading this at work right now. Thank you.
     
  7. kzook

    kzook Private E-2

    Did everything tonight per the instructions. The latest HJT log file is attached. Things seem to be operating ok. Did a virus scan and nothing showed up. There are a few things, however, that bother me. Don't know if these are related or not.

    1. Last night several times when I shut down the PC to restart it a message came up that said "end program explorer.exe". I didnt think too much of it because it looked windows related. Tonight when I shut down to reboot a message came up saying "end program freedom.exe". That worries me. What would be running called freedom.exe that needs to be ended before shutting down?

    2. My company uses a web based time collection system that employees use to enter their time charges. When I accessed this last night, and also now this evening I immediately get an error message and the application does not run. The error message that comes up is in the attached file "error message.txt". Behind the error message box is a "500 Internal Server Error" and a "404 Not Found" and associated text. I have copied and pasted all of that as well into the attached "error message.txt". Today I was able to access this web based application from my work pc with no problems.

    Thanks for anything further you can do for me.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is related to your ISP (BellSouth)

    C:\Program Files\BellSouth\BellSouth Internet Security\Freedom.exe
    O4 - HKLM\..\Run: [BellSouth Internet Security] "C:\Program Files\BellSouth\BellSouth Internet Security\Freedom.exe"

    You will have to speak with your company about this. Perhaps there is something missing from your PC that they require.

    You log is clean so I do not think you are having malware problems.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  9. kzook

    kzook Private E-2

    Ok. Will do. Thanks for all of your help.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  11. kzook

    kzook Private E-2

    I'm sorry, I just have one more question about something that looks suspicious. We just noticed yesterday this file "thumbs.db" that appears to be floating around. We delete it and then it appears somewhere else. I just did a search on it and it appears in two places:

    c:/documents and settings/keith/.housecall/resource/images/hackercheck

    and

    c:/documents and settings/keith/.housecall/resource/images/infection-finding

    WHAT IS THIS?????? It looks suspicious.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  13. kzook

    kzook Private E-2

    Cool. Thanks!!!!!!!!!!!!!!!
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds