urlap.exe

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by revets2, Oct 28, 2004.

  1. revets2

    revets2 Private E-2

    does anyone know what "urlap.exe" is? i've searched and searched and i'm only getting hungarian...which is a little scary. appreciate the help!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't know! Where are you seeing this file? In a process list, in HijackThis?
    Do you have some kind of problem on your PC?
     
  3. revets2

    revets2 Private E-2

    thanks for your reply.

    my cpu was whirring and couldn't get anything done, so i followed the most excellent instructions in "READ ME FIRST...". although i was not able to run the online scanners in safe mode with networking the situation is much improved and stuff like logs.exe, bkinst.exe, and others are gone.

    except for one...urlap.exe (not to be confused with urlmap.exe).

    according to the "processes" tab in task manager it consistently takes over 20,000k of memory, won't go away when asked to end the process.

    the mcaffee firewall i installed yesterday announced that "urlap.exe is trying to access the internet." i've blocked it, but am not sure how much good that's doing.

    microsoft doesn't know what it is, http://www.2-spyware.com (which has been helpful in identifying the good, bad, normal, and not so normal) don't identify it. when i google it, it only gives me references to hungarian websites.

    can you help?

    thanks very much for helping me and so many others. you have positively impacted so many lives.
     
  4. PhilliePhan

    PhilliePhan Guest

  5. revets2

    revets2 Private E-2

    thanks for your response. fortunately, bkinst.exe is gone! but if you have any info on urlap.exe let me know!
     
  6. PhilliePhan

    PhilliePhan Guest

    Hi revets2,

    What I am saying is that bkinst.exe is a sign of bigger problems, such as a Stopguard infection. Just getting rid of it does not always solve your problem.
    Take a look at these threads:

    Morphing malware

    Could use some help.

    urlap.exe is probably one of a few randomly generated .exes as a result of a Stopguard mutation. Of course, I could be wrong - But we cannot know that without a HJT log. I'm just speaking from what I've seen before ;)

    If you decide to attach a log, I'd be happy to look at it - I usually check back in the wee hours of the night.

    Best,
    PP
     
  7. revets2

    revets2 Private E-2

    hi phillie phan...

    thanks for your patience and advice.

    can you tell me how to access the "hjt" log?

    sorry for my ignorance.

    thanks!
     
  8. PhilliePhan

    PhilliePhan Guest

    Hi revets2,

    You caught me right as I was calling it a night! ;) Did you see any similarities in the links I gave you?

    For HijackThis, please read this:
    NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Note that your HijackThis should be up-to-date (v1.98.2) and MUST be extracted to its own safe folder - C:\Program Files\HijackThis

    If you need a Fresh Download of HJT, get it HERE: HijackThis 1.98.2

    Also note that, before you scan, you MUST close all running programs including your web browser, e-mail and items in the system tray.

    Please save your HJT Log as a .txt file and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    Send us a log & I'll check back when I get a chance - probably the wee hours tomorrow.

    Best :)
    PP
     
  9. revets2

    revets2 Private E-2

    hey pp...

    here's the log and once again, thanks again.

    revets
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    PP, Since I was here I figure I would get Revets2 going on this.

    Revets2,
    First you should follow our directions on using HijackThis and get it into its own directory that is not a sub-folder of C:\Documents and Settings. You have it here:
    C:\Documents and Settings\Administrator\Local Settings\Temp\HijackThis.exe

    Try using C:\Program Files\HJT or similar.

    Make sure you have viewing of hidden files enabled.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    O2 - BHO: (no name) - SOFTWARE - (no file)
    O2 - BHO: IE Agent - {00000000-0000-0000-0000-000000002230} - C:\PROGRA~1\Lycos\IEagent\CSBB.DLL (file missing)
    O2 - BHO: CATLEvents Object - {55E301E5-BA44-4095-BB0B-14E0123CCF71} - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\palru.dat
    O2 - BHO: (no name) - {DF57FEB6-9BCE-45E3-AA65-BE327B8CCE7F} - (no file)
    O4 - HKLM\..\Run: [*urlap] C:\WINNT\inf\urlap.exe
    O4 - HKLM\..\RunOnce: [*urlap] C:\WINNT\inf\urlap.exe rerun
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)

    Click FIX and then while still in HijackThis, look in the lower right-hand box where it says “Other stuff,” and select CONFIG > MISC TOOLS > select DELETE A FILE ON REBOOT and where it says File Name, enter (or navigate to the file in the HijackThis pane)C:\WINNT\inf\urlap.exe and click OPEN. A message will ask you if you want to reboot now. Click YES and reboot into SAFE MODE by tapping F8.
    You may receive an error message after rebooting into Safe Mode that says Windows could not find the file you told it to delete. Just click okay and DO NOT REBOOT AGAIN.


    While in Safe Mode, find and DELETE:

    C:\WINNT\inf\urlap.exe
    C:\WINDOWS\System32\bkinst.exe (look for this file too and delete if found).

    Use Windows Explorer to run a search of your computer for:
    bkinst
    palru
    urlap

    and DELETE the related files. (We neet to get rid of urlap.ini & urlap.dat and palru.ini & palru.dat + any other related crap.)

    Run CCleaner and Spybot S&D

    Then, go to C:\Documents and Settings\Administrator\Local Settings\Temp and delete any files or folders that remain.


    Reboot Normal and Attach a fresh HJT log. Give detail as to any problems that you may have encountered with the above instructions.

    If you have since rebooted, these may be different. Note the BHOs with the file names reversed and those 04 entries with the "*" and "run once" "rerun."

    If the files are indeed different and you do not feel confident in finding them yourself, please attach a fresh HJT log and then Do Not Reboot until PP or myself can check back.
     
  11. revets2

    revets2 Private E-2

    thanks for your reply. attached is the log, and, yes, i don't feel confident...i hope you don't mind lending a hand.

    only problem experienced was it didn't initially find urlap and bkinst. i had to really, really dig.

    thanks so much, and btw, i'm one of the ones that "don't"! couldn't you tell?!?
     
  12. PhilliePhan

    PhilliePhan Guest

    Hi revets2,

    Looks like my suspicions were on target ;)

    It looks like your new log didn't attach - please try again.
    I'm just popping in and out so I won't be able to look at it until later. Chas will probably beat me to it.

    We are happy to talk you through all of the steps - StopGuard can be a real pain! :)
    After we get you all fixed up, we'll give you some pointers on how to better protect your computer from Malware.

    Best,
    PP
     
  13. revets2

    revets2 Private E-2

    oops! sorry, here's the log!
     

    Attached Files:

    Last edited: Oct 29, 2004
  14. PhilliePhan

    PhilliePhan Guest

    Hi Revets2,

    Your HJT Log looks good! It looks like you and Chas got it all :) How are things running now??

    Did you have any trouble running my removal steps? What sort of difficulties did you have finding urlap & bkinst? I could really use any feedback you might have - It'll help us help the next person down the line with the same problem.

    You should also take a look at Chas' recommendations HERE:How to protect yourself from malware!

    I definitely recommend that you use the following tools:
    Ad-Aware SE Personal

    SpyBot-Search & Destroy - Remember to use the "Immunize" feature

    SpywareBlaster

    These are all FREE! Just remember to Internet Update them regurlarly! They, along with a good Anti-Virus and Firewall & keeping your Windows up-to-date will do wonders in helping to keep Malware off your computer!

    Best :)
    PP
     
  15. PhilliePhan

    PhilliePhan Guest

    I finally realized that you were referring to Chaslang's signature - - - All that really means is that he is a fan of the 11 Stooges and his favorite movie is Disney's Five Dalmatians. :p ;)
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, I could! And I understood your comment. PP is just a little slow! :p He just can't get use to working on all these HJT logs all night long! :eek:

    How about:
    10 Fast 10 Furious

    Revets, if you really don't understand, we are referring to binary numbers. 10 is binary for 2.
    11 = 3
    101 = 5

    Oh! And by the way. I agree with PP, your log is clean now!
     
  17. revets2

    revets2 Private E-2

    pp & chaslang...

    how can i thank you both for saving my computer, our not-for-profit work and lots of disadvantaged children? i hope you know what an impact you've had on so many lives this last week and into the future.

    you both are the greatest!

    thanks a million!!!! :)
     
  18. PhilliePhan

    PhilliePhan Guest

    You're welcome! A nice message like that is thanks enough! I can probably speak for Chas when I say that we are happy to help :)

    Best Regards,
    PP
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You bet PP! It's great to help. And when we find out who we have just help out like this, it is even more rewarding.

    Thanks for the compliments Revets2!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds