Odd Registry Key

Discussion in 'Malware Help (A Specialist Will Reply)' started by ahs, Feb 24, 2009.

  1. ahs

    ahs Private E-2

    First let me thank you for all the great work you are doing voluntarily. Luckily most of the time I just come here to get your great downloads or read the forums. I cleaned up my son's computer using your guide and removed several trojans and bots, etc. I had to go into the registry to find the last little bits of eq2soft (quite an education). Two questions what is the safest way to back up files from it (even though I am fairly certain I found all the bits, I am hesitant to use a flash drive or removable hard drive). If I am only copying Word, Excel and JPEGs would a dvd be safe?
    Then I am going to low level format the drive. I'm not a major geek but I have a little experience and I have never seen anything replicate like the malware or trojans I removed. And even with clean logs I just don't feel comfortable not wiping the drive.

    I also found this key about which I can find nothing on the web

    HKLM\Software\Microsoft\mowurafe with two detail (binary) keys bikodika and hirupapo?
    Any information would be appreciated.

    Thanks again Andy
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!


    Please follow the instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.

    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First.
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide


    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. To avoid addtional delay in getting a response, it is strongly advise that after completing the READ & RUN ME you also read this sticky Don't Bump! It Only Hurts You!!!. Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. ahs

    ahs Private E-2

    Thank you for your prompt reply. I believe I had cleaned out most of the items when I posted. I just found those odd registry keys which I had questioned. By the way. I think a lot of this was related to the problems Auctiva had, due to the fact the computer at issue was on a Java link with them on the 19th and 20th. I also found evidence of the conficker virus. All came at that time. I have some notes of which items were found if it is of interest.

    No log from SAS as it was clean. Here are the other logs.
     

    Attached Files:

  4. ahs

    ahs Private E-2

    The rest of the logs
     

    Attached Files:

  5. ahs

    ahs Private E-2

    Sorry I missed the part of uploading the zip file so here are the rest of the logs. Thanks again!
     

    Attached Files:

  6. ahs

    ahs Private E-2

    Here is the zip file. When I tried to open the files I was unable to do so, however, it is the last scan. Thanks!
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware on your system...what problems are you still having?
     
  8. ahs

    ahs Private E-2

    Tim, let me first thank you and others like you who donate their time here and on other websites. I am not having any problems and was pretty sure I got it all out of the system. By following your guide and removing the last bits from the registry. I do have some info on what loaded and where but it is above my pay grade to post here. It does load on removable drives so caution is recommended transferring files from a clean system to an infected one, unless the drive is set on read only when uploading files to the infected system.

    My original question was about the registry key HKLM\Software\Microsoft\mowurafe with two detail (binary) keys bikodika and hirupapo that is still there. It was there when I was sure the system was clean. I can not find any info on it so wondered if it was old malware or an old key safe to delete. Should I post the question on the software forum? Many thanks again for your time. Andy
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Running CCleaner ...the registry.. should have removed them. If it didn't, then yes, delete the key.
     
  10. ahs

    ahs Private E-2

    Thanks again, had to manually remove. Two last questions is there any benefit or conflict from installing Spyware Blaster if Spybot is already immunizing? Also in the Svchost/ntsvcs key I have some items listed that are not on the MS list. Do other programs which are legitimate show up there?
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Spyware blaster is probably redunant....but no harm.

    And yes, other processes will be seen in the ntsvcs key.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  12. ahs

    ahs Private E-2

    I followed your final instructions. Thanks again!
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome...safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds