Swizzor.8.BK

Discussion in 'Malware Help (A Specialist Will Reply)' started by Randi, Feb 1, 2007.

  1. Randi

    Randi Private E-2

    I have been trying to get rid of this trojan downloader for quite sometime... I have hijackthis and have saved a log but have not had any responses on it - I am hoping someone will be interested in telling me what this log means and how to deal with it. All other scans, such as Spybot are coming up clean... Any help would be VERY MUCH APPRECIATED - My computer is my only entertainment and it is hurting!!! Thank You all very much.confused

    Edit: Removed inline Hijackthis log for guide below to be run;
     
    Last edited by a moderator: Feb 1, 2007
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Welcome to Majorgeeks!

    Hijackthis is just one part of the malware removal procedure and is one of the last scans to run, it sady cannot pick up on all malware on a pc which is why a few multiple tools are needed,

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.




    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. Randi

    Randi Private E-2

    Swizzor.8.BK - next step of removal? (Part 1)

    I have recently done all scans that were suggested - I feel a little daft as I can't seem to make heads or tails of any of the results! Thanks again for all the help. I have attached two logs here and two more in the following thread. -Randi confused
     

    Attached Files:

  4. Randi

    Randi Private E-2

    Swizzor.8.BK - next step of removal? (Part 2)

    Here are the other two logs from my scanning frenzy! I was also wondering, I renamed hijackthis but it seems to have only changed the name of the icon, is that supposed to be the way it works?confused
    Thank you -R
     

    Attached Files:

    Last edited: Feb 2, 2007
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Swizzor.8.BK - next step of removal? (Part 2)

    This is the third thread you started for the same problem! Please post all messages for this problem in the same thread. I will merge them all together now.

    You are still missing two requested logs:

    - CounterSpy or AVG Antispyware which ever you ran
    - GetRunKey
     
  6. Randi

    Randi Private E-2

    Here are the other two logs I had not included last post - sorry about starting new threads - really new to forums in general - Thank You :)
     

    Attached Files:

    Last edited: Feb 2, 2007
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Swizzor.8.BK - next step of removal? (Part 2)

    Please go back to step 0 of the READ ME and read the information about not using MSconfig. You need to set your PC to Normal Startup mode as requested. And then reboot.

    Then you need to return to the READ ME again and follow the directions in step 2 exactly as written for Windows XP. You did not do all the steps.

    Now you need to get HijackThis installed properly. Where you installed it is a very bad idea. You have it here (and named wrong too, but that's because you had not done step 2 of the READ ME properly).

    C:\Program Files\Analyse.exe.exe

    You need to it installed like the below as requested:

    C:\Program Files\HJT\Analyse.exe <--- only one exe should be in the name, and it should be in its own folder.

    Now delete the C:\Program Files\Analyse.exe.exe file if it still exists and also delete the previous log you made C:\Program Files\hijackthis.log

    After doing the above three items, you now need to attach new logs from GetRunKey and HijackThis.


    Now after attach the two new logs you can get started on your fixes by doing the below while you wait for a response.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 3
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 7
    J2SE Runtime Environment 5.0 Update 9
    Mozilla Firefox (2.0)

    Make sure you reboot after uninstalling the above!

    Then install the current version of FireFox from: Mozilla Firefox
     
  8. Randi

    Randi Private E-2

    Sorry I wasn't reading more thuroughly when I attached these logs the first time. I will pay closer attention next time. Here are the new, accurate logs. Thanks for your patience :wave
    -Randi
     

    Attached Files:

    Last edited: Feb 2, 2007
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still need to correct where you have HijackThis installed and how you named it. It is still here:

    C:\Program Files\Analyse.exe.exe

    Please do what I requested in message # 7
     
  10. Randi

    Randi Private E-2

    Okay I think I renamed it properly this time, sorry about that - I wasn't sure if it had been done right the first time. confused Here is the log.
    -Randi
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now you got it! ;)

    Since you did not install CounterSpy properly in its default folder. You have made cleanup more difficult. You install it like this:
    E:\PC Cleaning Tools (Installs)\sunThreatEngine.exe
    E:\PC Cleaning Tools (Installs)\SunProtectionServer.exe

    which is a very bad idea. Always install tools into their default folder names so they can be recognized as valid programs rather than as a malware imposter. Also if you put other files into the E:\PC Cleaning Tools (Installs) folder that are not part of CounterSpy, they could over write each other's files and cause the programs to not work properly. And now since I want to uninstall CounterSpy, I have a problem. I would normally just say to delete the folder where CounterSpy is installed, but I have no idea what else you may have put in that folder.

    Thus uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below folders left behind by the uninstall:
    C:\Documents and Settings\Randi Janzen\Local Settings\Application Data\Sunbelt Software

    Also delete anything left over in the below folder related to CounterSpy.
    E:\PC Cleaning Tools (Installs)\

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [PLAN JOY WIN FACE] C:\Documents and Settings\All Users\Application Data\Audio Tons Plan Joy\Owns hole.exe
    O4 - HKCU\..\Run: [Ante cool] C:\DOCUME~1\RANDIJ~1\APPLIC~1\COPYHO~1\Kindmetareal.exe

    After clicking Fix, exit HJT.

    Now reboot in normal mode

    Now locate the below folders and delete it if found:
    C:\Documents and Settings\Randi Janzen\Application Data\Copyholdmore
    C:\Documents and Settings\All Users\Application Data\Audio Tons Plan Joy
    C:\Program Files\Copyholdmore

    Now run Ccleaner

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Feb 2, 2007
  12. Randi

    Randi Private E-2

    All of the files you said to delete were there and are now deleted. So far things are going as described. Here are the logs you asked for. Quick side question though. The reboot on my computer is happening at a great speed however I have incredible lag before I can connect or any item can be opened. Anything I can change to fix that?
    -Randi
     

    Attached Files:

  13. Randi

    Randi Private E-2

    Here is the HJT log :)
    -Randi
     

    Attached Files:

  14. Randi

    Randi Private E-2

    The other thing is that I have a system file (Desktop.ini) in a folder that I created on my desktop. The folder is called 'To Be Moved' and is for .txt documents I have written and have not put in their proper spot... just a junk folder really. Now I am not sure how the desktop file ended up there in the first place and don't know where I should be moving it to.:eek:
    -Randi
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please complete ALL steps I give you and complete them in the order given. You never completed all of message number 7. Complete those steps now.

    Then run HJT and fix the below lines which are not malware but you can remove them to help speed things up.
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"

    Now attach new logs from HJT and ShowNew (make sure you did ALL of message # 7 first).

    Are things still slow? It so, it is not malware. You need to get a handle on all the things you are loading at startup and decide whether you need them or not. I cannot decide what you use and do not use and in addition these are not malware problems. You can research your processes at sites like the below:

    www.bleepingcomputer.com/startups
    www.liutilities.com/products/wintaskspro/processlibrary


    As far as the desktop.ini file is concerned, it was always there. You just never saw it because you did not have viewing of hidden and system files enable until running step 2 of the READ ME.
     
  16. Randi

    Randi Private E-2

    I am not sure what step of seven I did not complete. I did do it over again but if it is incorrect can you tell me what part I am missing... (my goodness I am becoming a pain - sorry about that)
    -Randi
     
    Last edited: Feb 2, 2007
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on the ShowNew log you attached in message number 12, you did not do the below from message # 7.
    If you have completed those steps now, attach a new log from ShowNew.

    And if you did what I requested in message # 15, attach a new HJT log.

    Now tell me what problems your are having.
     
  18. Randi

    Randi Private E-2

    The updates have been deleted and I have made a new show new log - any other files that need deleting or logs that you need?
    -Randi
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes the rest of what was requested in message # 17. A new HJT log! And also answer the question posed:
    .
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still did not do all of message # 7. You did not uninstall this:

    J2SE Runtime Environment 5.0 Update 10

    And you did not install the current version of Mozilla Firefox to replace the old one that was uninstalled.

    Also why do I now see the below folder which you did not have before since CounterSpy was never installed properly the first time? Delete the below folder since we uninstalled this!
    C:\Program Files\Sunbelt Software
     
    Last edited: Feb 3, 2007
  21. Randi

    Randi Private E-2

    Other than the lag, which will probably be solved when I have managed what is opening on start up, things seem to be running smoothly. Thank You Very Much! :)
    -Randi
     

    Attached Files:

  22. Randi

    Randi Private E-2

    Oh sorry I forgot to mention that I decided not to continue to run firefox. Thanks
    -Randi
     
  23. Randi

    Randi Private E-2

    I have been attacked by the blue screen of death since we last wrote! Not to sure why - here are the two new logs.
    -Randi
    :wave
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. While a BSOD's could occur due to malware (like maybe a rootkit) they are not typically related to malware. Whenever you get any error messages that you need help with, you should always write down the exact error message with all the number codes and put them in your message. This applies to any forum you post in. If gives the helper alot more info.

    However in the name of being thorough, let's check for a rootkit using two tools.


    Please download Blacklight Beta
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please post contents of the BlackLight log.

    Now run this AVG Anti-Rootkit and attach a log.
     
  25. Randi

    Randi Private E-2

    Thank you... here is the blacklight log. Gone to run the AVG stuff.
    -Randi
     

    Attached Files:

  26. Randi

    Randi Private E-2

    I ran the AVG rootkit scan and nothing was found, I didn't see an option for a log and was wondering if there was not one because of the result ? confused
    thx
    -Randi
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you are all clean as far as malware goes. You will have to create a message in the Software Forum about your BSOD (if you are still getting it) and provide them with the exact details of the error message (give the exact message).


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  28. Randi

    Randi Private E-2

    I can not begin to thank you enough for all of your patience and help. Everything seems to be running wonderfully and again I really appreciate all of your time. Last question: Is there anything specific I am supposed to do to close this thread? Can you tell I am REALLY new to forums! :wave
    Sincerely
    -Randi
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    No! You are done!;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds