Wanso - Nothing can remove it

Discussion in 'Malware Help (A Specialist Will Reply)' started by skokeh, Mar 9, 2007.

  1. skokeh

    skokeh Private E-2

    All

    I have followed the steps and used every programmed advised, but Wanso remians on my conputer in C:prog Files/Common files
    sobar.dll
    player.dll

    They return after every files detects and attempts to delete them, even in safe mode. Even when i modify msconfig and close to delete wanso, it just checks itself again instantly

    I attach all 6 logs below from each of the tools suggested



    Any help??

    Thanks in advance
     

    Attached Files:

  2. skokeh

    skokeh Private E-2

    futher logs attached
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Let's first take care of some house keeping!

    Uninstall the below old versions of software:
    Ad-aware 6 Personal <-- this is more than two years out of date
    J2SE Runtime Environment 5.0 Update 11
    Mozilla Firefox (1.5.0.10)
    Sunbelt CounterSpy <-- Uninstall this trial since we are finished with it now!

    Make sure you reboot after uninstalling the above!

    Then install the current version of FireFox from: Mozilla Firefox

    Then install the current version of Ad-Aware from: Ad-Aware SE Personal

    Now download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: WanSo.lnk = ?
    O18 - Protocol: bw+0 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw+0s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw-0 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw-0s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw00 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw00s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw10 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw10s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw20 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw20s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw30 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw30s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw40 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw40s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw50 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw50s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw60 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw60s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw70 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw70s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw80 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw80s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw90 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw90s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwa0 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwa0s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwb0 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwb0s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwc0 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwc0s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwd0 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwd0s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwe0 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwe0s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwf0 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwf0s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: bwg0 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwg0s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwh0 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwh0s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwi0 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwi0s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwj0 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwj0s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwk0 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwk0s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwl0 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwl0s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwm0 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwm0s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwn0 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwn0s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwo0 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwo0s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwp0 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwp0s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwq0 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwq0s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwr0 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwr0s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bws0 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bws0s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwt0 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwt0s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwu0 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwu0s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwv0 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwv0s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bww0 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bww0s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwx0 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwx0s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwy0 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwy0s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwz0 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwz0s - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: offline-8876480 - {A7402CE7-260F-40E4-B004-3A870BC9B456} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Program Files\Common Files\WANSO\Player.dll
    C:\Program Files\Common Files\WANSO\SoBar.dll
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WanSo.lnk
    C:\WINDOWS\pss\WanSo.lnk
    C:\WINDOWS\system32\1k1sa7wgu.dll
    C:\WINDOWS\system32\adou2a.dll
    C:\WINDOWS\system32\duo23sdd.dll
    C:\WINDOWS\system32\HOTAG.DLL
    C:\WINDOWS\system32\JPVBHM.DLL
    C:\WINDOWS\system32\peer.ini
    C:\WINDOWS\system32\drivers\32897dsd.dat
    C:\WINDOWS\system32\drivers\AGMRYEJPVAGNS.DAT
    C:\WINDOWS\system32\drivers\BHMTYEJPUAFLQ.DLL
    C:\WINDOWS\system32\drivers\doakodjd.dll
    C:\WINDOWS\system32\drivers\ncio.sys
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folders and delete if found:
    C:\Program Files\Common Files\WANSO
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  4. skokeh

    skokeh Private E-2

    Hey thanks for your swift and detailed reply

    I have done all of these changes, and posted the new logs below

    I did not receive the error - PendingFileRenameOperations

    But Wanso remains, and cannot be delete - it replaces itself again still

    This one is stuborn :)

    Thanks
     
  5. skokeh

    skokeh Private E-2

    As per below
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We need to dig a little deeper to find potentially find some other hidden files.
    • First manually (use Windows Explorer), delete the below files:
      • C:\rundll32.txt
      • C:\tasklist.txt
      • C:\WINDOWS\system32\SBFC.dat
      • C:\WINDOWS\system32\SBRC.dat
    • Now Run Pocket Killbox and select File, Cleanup, Delete All Backups
    • Now exit Killbox
    • Now run Ccleaner
    • Now download the new version of ShowNew from Using ShowNew and use it to get me a new log. This will locate more of the files related to WANSO.
    Also tell me does the below folder exist:

    C:\Documents and Settings\All Users\Application Data\startup\Cast

    If so, what files do you see in this folder?


    Please download Blacklight Beta
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Now let's run another tool named ComboFix
    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.



    Please attach the below two requested logs
    • ShowNew
    • BlackLight log
    • ComboFix
     
    Last edited: Mar 10, 2007
  7. skokeh

    skokeh Private E-2

    Files deleted, killbox used

    Cannot find startup folder, in this location , and thus no cast folder

    BBlbeta found no problems, and therefore generated no report

    show new & Combofix files attached

    Thanks again for your patience & support with this one ;)

    S
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you follow the steps below in the exact order written!

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download the attach FixWS.Zip file to your Desktop and extract the FixWS.bat file from it to your Desktop too.
    Double click on the FixWS.bat file to run it.


    Now please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.


    Okay now run ComboFix again and attach this new log later when I ask for it.

    Then immediately after running the ComboFix procedure, run CounterSpy and attach this new log later when I ask for it.



    Make sure that you follow the below instructions exactly. You must make sure you use Delete on Reboot and not Standard File Kill.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
    • Note: if the Unregister .dll Before Deleting check box becomes active, make sure you check it.
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WanSo.lnk
    C:\Documents and Settings\All Users\Templates\temp.exe
    C:\WINDOWS\system32\ntfis.exe
    C:\WINDOWS\system32\DRIVERS\ncio.sys
    C:\WINDOWS\system32\drivers\front.sys
    C:\WINDOWS\system32\drivers\roreg.sys
    C:\WINDOWS\system32\drivers\fkwld.sys
    C:\Program Files\Common Files\WANSO\Player.dll
    C:\Program Files\Common Files\WANSO\SoBar.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But if you do get this message, make sure you tell me!)

    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. ComboFix
    2. CounterSpy
    3. GetRunKey
    4. ShowNew
    5. HJT


    Make sure you tell me how things are working now!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As an additional backup step (after completing the steps in message # 8), also please run the below and attach a log from it:

    GMER
     
  10. skokeh

    skokeh Private E-2

    Thanks

    In concern, i cannot find fixws.zip anywhere? I searched MG but could not find anywhere
    Any pointers?

    I will begin these steps when i have all the files i need

    Thanks

    S
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is attached to the bottom of the message with the instructions.
     
  12. skokeh

    skokeh Private E-2

    Counterspy - couldnt create a log - but it found the trojan.sobar.a as before, but could not delete it

    rest of the actions completed exactly per instructions, new logs attached
     

    Attached Files:

  13. skokeh

    skokeh Private E-2

    Rest of files
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not run GMER as requested.

    The base of the infection may be due to the fkwld.sys which is not getting properly deleted. There could be other hidden files and registry keys. I need the log from GMER. Run it now! Please be sure to always follow all instructions.

    Do you access Chinese websites and do you have any Chinese related software installed? This infection seems to be related to things eminating from Chinese sites. Do you have any cracked/illegal software download installed? If so, uninstall them!


    What are the below installed programs (especially the PPMateIoA.... item which appears to have strange characters in the file proagram name - I have a feeling this is some kind of P2P TV program and is from China).
    "DisplayName"="DynDNS Updater 3.1"
    "DisplayName"="FMS"
    "DisplayName"="Indeor Software"
    "DisplayName"="Joost (tm) 0.8.1"
    "DisplayName"="KhalSetup"
    "DisplayName"="MagicTune3.6_Client_pivot"
    "DisplayName"="Natural Color"
    "DisplayName"="PPMateIoA‡æ‡EO 1.7.3.33"
    "DisplayName"="TrackMania Nations ESWC - Update 2"

    And what is the below that I see:
    The Venice Project (Baaima N.V.)
    • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    • Now exit Pocket Killbox!
    • Now download The Avenger ( http://swandog46.geekstogo.com/avenger.zip ) by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy the quoted bold print below and paste it in the box that opens from Avenger:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it.
    • A log file from Avenger will be produced at C:\avenger.txt, please post that log here in your next reply.
    Now attach the below logs
    1. GMER
    2. Avenger
    3. ShowNew
    4. HJT
     
  15. skokeh

    skokeh Private E-2

    Ok apologies for missing GMER 1st time

    PPmate was a chinese P2P tv stream which my friend installed - now it has been uninstalled

    From my searching ic an see that the Venice project is related to the Joost TV streaming programme - which is also on my PC, but i am told it is 100% ok?

    all logs attached
     

    Attached Files:

  16. skokeh

    skokeh Private E-2

    ps - c:/programme files/common files/wanso folder seems to have dissapeared, progress :)
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that looks much better! Is everything working okay now?

    I do see one new file that showed up. I'm not sure if it is related to GMER or not. I don't recall it installing or creating any files with such strange names. Delete the below file:

    C:\WINDOWS\system32\drivers\^eftakql.sys

    Also uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
    Last edited: Mar 16, 2007
  18. skokeh

    skokeh Private E-2

    A quick note just to say thanks to you for all your help and patience on this one

    I will certainly be reccomending this site and all to my friends, its is rare to find such a good community!

    Thanks again, all is well, i have you to thank

    Skokeh
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Thanks for the recommendation! :)

    Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds