UKASH infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by alanhacksaw, Oct 17, 2013.

  1. alanhacksaw

    alanhacksaw Private E-2

    Hi and thanks in advance for any help you can offer. my son came home from Uni for the weekend and has clicked on some link which has brought me a Ukash infection. I have previously removed another infection with the procedures on MG, but with this one I cannot gain access to the computer to start the process. On startup I get the blue screen of death and the PC immediately reboots so that I cannot read the dump message. I have tried "Del at Startup" but in the Boot section I cannot find an auto restart to disable. Pressing F8 at startup only gives me a menu of drives to boot from.
    The PC is Fujitsu Siemens running Windows XP home and its genuine (I know it's old, but it works, well it did:( )

    Any help to get into it and clear teh virus gratefully received.
    Alan
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. alanhacksaw

    alanhacksaw Private E-2

    Thanks. Downloaded the files to the USB and booted the infected PC from it - waiting with bated breath to see what happens.
    I'll let you now how it goes.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes please.
     
  5. alanhacksaw

    alanhacksaw Private E-2

    Not too well so far, actually. Got the Kaspersky menu screen and selected the Graphic rescue mode, but then the screen goes black and it just sits there, hard drive running, but noithing appearing to happen. I left it for a couple of hours like that, but nothing ever seemed to happen.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Damn. Does this machine work in safe mode?
     
  7. alanhacksaw

    alanhacksaw Private E-2

    No. Just constantly reboots like normal mode. I just tried malwarebytes hitmanpro kickstart which also loads up and presents a menu, but the keyboard won't type so I can choose an option.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So just to be absolutely clear, your keyboard does not work, your mouse does; are you able to run ANY of these procedures?

    READ & RUN ME FIRST - Malware Removal Guide

    You mentioned you could run Malware Bytes. Did it ever get to finish its scan? Do you have a log from it? I am hoping you can at least get RogueKiller & MGTools to run.
     
  9. alanhacksaw

    alanhacksaw Private E-2

    The keyboard works as the PC boots so that it accepts the F8 command to select the boot from USB option. Once it boots up and the hitmanpro menu appears, the PC won't recognise the fact that I press 1 to select that option from the menu, or the Enter key to run the default option. Until I get to a GUI screen, I don't know if the mouse works or not. When I booted form the Kaspersky, the keyboard worked so that I could move up and down the menu and select the option, but the PC just sat there after that.
    I can't run anything except whe the PC boots from the USB or CD. I have just managed to boot from the recovery CD which came with the PC and the keyboard allows me to select R for the recovery console, but I don't know if that will help. I just did a DIR command in DOS and got "An error occurred during directory enumeration" Can I run any of the programs you mentioned from the recovery console?
    Thanks for trying to help.
    Alan
     
  10. alanhacksaw

    alanhacksaw Private E-2

    A little more progress. The keyboard not working seems to be not always the case. After running the recovery console, although I couldn't find anything useful to do with it, the keyboard would let me select option 1 "Bypass master boot record". Unfortunately, this did not appear to work and the PC went back to continuous rebooting after a few seconds. During these reboots I press F8 and boot from the USB to try again, but the keyboard again doesn't work until I cycle power to the PC, then, after a rest, it will work again. (It's a USB keyboard, by the way - I can't see a conventional socket to replace it).
    When I select option 1, I get 2 message lines - "hitman pro kickstart booting" and "MBR read" then it reboots as before. Trying option 2 adds "starting bootcode" then PC restarts goes back into constant reboots. option 3 displays as per option 1 and then system reboots before going bac into the constant rebooting.
    Going back to try the Kaspersky again.
    Alan
     
  11. alanhacksaw

    alanhacksaw Private E-2

    Aha - now the Kaspersky gets to the menu screens and I have selected the "risk of file damage" options. Completed first stage and now scanning files, although I can't connect to teh wireless so haven't updated the database yet. Will try to find the cable and connect that way. But at least it's progress!
     
  12. alanhacksaw

    alanhacksaw Private E-2

    Wireless network now reconnected and database updated. Virus scan completed and nothing found with bootsector and hidden startups checked. Now rerunning adding C; to the list.
    53 minutes to go - will let you know what happens.
    Alan
     
  13. alanhacksaw

    alanhacksaw Private E-2

    Scan complete. Nothing found!
    Restarted and got same flash of BSOD followed by rebooting.:(
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you try the avg rescue CD and let me know how you get on?

    I have something else we can try if that does not help.
     
  15. alanhacksaw

    alanhacksaw Private E-2

    Hi, and thanks for your continuing help.
    OK,I got the AVG rescue USB and have booted form it and run the scan option. There are two volumes, apparently, scanning one...
    After a few minutes,it reaches 14% and then in the grey square it displays,
    /mnt/sdc1/documents and settings/all users/application data/avg2013/ids/quarantine/c97437e8-02a3-47d0-8736-d15caf6185b1.zip Passsword-protected.

    Shortly thereafter, text appears in a black bakground badly wrapped across the screen which says
    Processing Command line...successfully; the faulting process should now crash
    Cfg file not specified using opt/avg/av/cfg/diagcfg.xml.
    Preparing output directory....
    Failed to create diag temp/tmp/897819f4-06b3-4a33-8354-97af699b5369. Error code: 0xe00

    Pressing return shows "Info: There are no infected files"

    Scanning the other has much the same effect except that the text displays "

    Processing command line...all transactions have been performed successfully; failed with error (e001930e)
    Cfg file not specified using opt/avg/av/cfg/diagcfg.xml.
    Preparing output directory....
    Failed to create diag temp/tmp/3a980fad-2dc4-4082-b726-44ba9a022453. Error code:0xe002001c"
    and then
    "There are no infected files"
    only gets to 14% in either volume. Different scan option selections appear to produce different error messages, but they always crash at 14%.
    I'll be out for a coule of days so it will be Thursday before I can try anything else.
    Regards
    Alan
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download OTLPE and save it to your desktop:

    OTLPE

    Double click the OTLPENet icon on your desktop
    "Do you want to burn the CD?" choose Yes
    ImgBurn will automatically extract and load the OTLPE Iso to be burned to CD
    Place a blank CD in your CD-Rom.
    Click http://i198.photobucket.com/albums/aa263/Merlin10101/ximgbrn.jpg?t=1382444390 to start the burn process.

    You will see a dialog "Operation successfully completed"
    Boot the non-working computer using the boot CD you just created
    In order to do so, the computer must be set to boot from the CD first.
    Note : For information click here.

    Your system should now display a REATOGO-X-PE desktop.
    Double-click on the OTLPE icon.
    Select the Windows folder of the infected drive if it asks for a location
    When asked "Do you wish to load the remote registry", select Yes
    When asked "Do you wish to load remote user profile(s) for scanning", select Yes
    Ensure the box "Automatically Load All Remaining Users" is checked and press "OK"
    OTL should now start.
    Push the RUN SCAN button.
    When finished, the file will be saved in drive C:\OTL.txt
    Copy this file to your USB drive.
    Please attach the C:\OTL.txt file in your next reply.
     
  17. alanhacksaw

    alanhacksaw Private E-2

    Thanks, been away for a couple of days. I'll have a go at that tomorrow.
    Alan
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, I'll be floating around at some point. :)
     
  19. alanhacksaw

    alanhacksaw Private E-2

    OK, that took a bit longer than planned. I thought it prudent, with all this going on, to take the AVG2014 update, which promptly locked out the wifi on the rescue computer! So I had to dig out an old laptop to investigate that - not easy as the "g" and "delete" keys don't work! Anyway, I finally managed to uninstall, delete and rid myself of enough traces of it to do a System Restore. That got me back online so that I could download your programme and burn the CD. It's just booting up on the infected PC now.
    More news in a minute.
     
  20. alanhacksaw

    alanhacksaw Private E-2

    Clicked on the OTLPE icon, selected the C: drive.

    "RunScanner Error - Target is not windows 2000 or later"

    It is, it's XP Home SP2.
    Tried using the explorer and selecting c: I get "C:\ is not accessible. The file or directory is corrupted and unreadable."

    Repeated OLTPE icon - same result:(:(:(
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am seeking advice. Hang in there. :)
     
  22. alanhacksaw

    alanhacksaw Private E-2

    Thanks! I'll be out for most of the day, but tomorrow I'll try and save data from it using the linux boot USB.
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  24. alanhacksaw

    alanhacksaw Private E-2

    Woo Hoo! Progress. PC now boots windows normally until the virus kicks in and locks the screen.
    Back to your first suggestion now, I'm guessing?

    Many thanks for your help so far.
    Alan
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  26. alanhacksaw

    alanhacksaw Private E-2

    Thanks to chaslang.
    When the PC rebooted it went straight to the hijaack screen, so I could do nothing with it.
    I had the hitmanpro kickstart still on the USB so I thought I'd try that first. I've selected option 1 and it's just rebooting in Windows - we'll see what happens.
    If that doesn't work then I'll try the kaspersky again.
    Will keep you informed of progress.
    Thanks again.
     
  27. alanhacksaw

    alanhacksaw Private E-2

    Ah well, so much for hitmanpro! It said it would take over from the virus after a few minutes, but that's 45 now and still nothing has happened. I'll reload the USB with kaspersky and see what happens there.
     
  28. alanhacksaw

    alanhacksaw Private E-2

    Kaspersky got as far as selecting "Rescue disk in Graphics mode", then just sat there with a black screen as it did previously. I can't seem to find th esequence of events which let it run after that before. In the meantime, I still have the OLTPE CD, so I'm giving that a go.
    It has produced a logfile which I shall try to attach.
     
  29. alanhacksaw

    alanhacksaw Private E-2

    OLT.txt should be attached to this post.
     

    Attached Files:

    • OTL.txt
      File size:
      80.3 KB
      Views:
      3
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We need to run an OTL Fix

    • Open up OTL to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code
    Code:
    Code:
    :otl
    SRV - [2013/10/17 09:58:03 | 000,229,376 | ---- | M] (Eggenberg Corporation) [Auto] -- C:\Documents and Settings\All Users\Application Data\8wfl3lb.plz -- (winmgmt)
    O4 - Startup: C:\Documents and Settings\User\Start Menu\Programs\Startup\bl3lfw8.lnk = X:\I386\SYSTEM32\RUNDLL32.EXE (Microsoft Corporation)
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ClickPotatoLite@ClickPotatoLite.com: C:\Program Files\ClickPotatoLite\bin\10.0.631.0\firefox\extensions [2010/12/29 17:40:31 | 000,000,000 | ---D | M]
    [2013/10/17 10:06:24 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\AppData
    [2013/10/17 09:58:03 | 000,229,376 | ---- | C] (Eggenberg Corporation) -- C:\Documents and Settings\All Users\Application Data\8wfl3lb.plz
    [2013/10/27 18:49:20 | 095,025,368 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\bl3lfw8.pff
    [2013/10/17 09:58:20 | 000,000,800 | ---- | M] () -- C:\Documents and Settings\User\Start Menu\Programs\Startup\bl3lfw8.lnk
    [2013/10/17 09:58:03 | 000,229,376 | ---- | M] (Eggenberg Corporation) -- C:\Documents and Settings\All Users\Application Data\8wfl3lb.plz
    [2013/10/17 09:58:19 | 000,000,800 | ---- | C] () -- C:\Documents and Settings\User\Start Menu\Programs\Startup\bl3lfw8.lnk
    [2013/10/17 09:58:18 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\bl3lfw8.ctrl
    [2013/10/17 09:58:05 | 095,025,368 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\bl3lfw8.pff
    [2010/12/29 17:40:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\ClickPotatoLite
    [2010/12/29 17:54:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ClickPotatoLiteSA
    @Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9638A27E
      
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.


    Are you now able to run any of the read and run me first in either normal or safe mode?
     
  31. alanhacksaw

    alanhacksaw Private E-2

    the storm has knocked out my internet. I will do it when i can reconnect. Hopeful won.t be too long. From my phone
     
  32. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hope everything is okay for you! :)
     
  33. alanhacksaw

    alanhacksaw Private E-2

    Thanks. No damage done, but the phone lines are still out. I've borrowed some wifi and have copied your code to a text file. I'll get it into OLT tonight and let you know what happens.
    Thanks again.
     
  34. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I'm glad to hear that!

    Yes, let me know what happens after you run the script.
     
  35. alanhacksaw

    alanhacksaw Private E-2

    Fantastic! Thank you so much.
    PC rebooted after running your script and seems back to normal. I ran AVG2014 and it found the screenlock in the OLT moved files. Once the phone lines are back up I'll download and run the stuff in the Run & Read Me section.

    The log file is attached.

    Again very many thanks, I'd have been lost without you.

    Now, just have to sort out the AVG2014 that screwed up the netbook!

    Thannks and Best wishes.
    Alan:)
     

    Attached Files:

    Last edited: Oct 31, 2013
  36. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Very pleased we're making good progress. :)

    Yes, it's best to.
     
  37. alanhacksaw

    alanhacksaw Private E-2

    Thanks once again. Th ephone lines are now restored and I've run the Run & Read Me section stuff. I've attached the logs in case they are of any use/interest.
     

    Attached Files:

  38. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Nice!

    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate this detection:

    • [HJ DLL][Rans.Gendarm] HKLM\[...]\CS001\[...]\Parameters : ServiceDll (C:\DOCUME~1\ALLUSE~1\APPLIC~1\8wfl3lb.plz [x]) -> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.


    Delete this:
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\8wfl3lb.plz

    Now re run Hitman and have it delete Potential Unwanted Programs. Also have it address what needs fixing on the "repairs" tab.

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    After reboot, check to see if your firewall is working.



    Re run RK one more time, just a scan, and attach log.
     
  39. alanhacksaw

    alanhacksaw Private E-2

    Thanks agai. I've run roguliller and attached are the two logs generated.
    As I need to reboot, I thought I'd post them now.
    More shortly!
     

    Attached Files:

  40. alanhacksaw

    alanhacksaw Private E-2

    Rebooted PC.
    Couldn't find any file called .plz
    Have rerun Hitman and it reports "No Threats Found" but 11 traces, all of which were deleted. Couldn't see a 'repairs' tab, but the log is attached.
    Now about to run Windows repair.
     

    Attached Files:

  41. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Forgot this part, sorry.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  42. alanhacksaw

    alanhacksaw Private E-2

    OK, thanks.
    Windows repair finished and PC rebooted OK, firewall appears to be working OK.
    Have run RogueKiller again, scan only and log is attached. Should I not do anything about the 'susp path' and the 2 'PUM' it found?
    MGtools now run and log attached.

    Thanks agan.
     

    Attached Files:

  43. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    These entries are benign, nothing to be concerned about. :)

    So the firewall's running again, how is everything else, Alan? Ready for final steps?
     
  44. alanhacksaw

    alanhacksaw Private E-2

    There's more? Only surprised because everything seems to be back to normal.
    Yes, AVG firewall said it was working. Free period expires today so I'll reinstate the Windows one before I downloaded a new one.
    Next steps? Bring it on! (Feeling confident now:-D)

    Thanks again,
    Alan
     
  45. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    :-D

    Ahh, you're most welcome!




    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    9. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  46. alanhacksaw

    alanhacksaw Private E-2

    OK. All done.
    Got rid of AVG and replacing it with avast. Downloading another firewall as I type.
    Thanks once more for your help. I do hope I won't need to trouble you again, but as long as I have a student in the house...who knows what they'll be up to.
     
  47. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem, you're most welcome. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds