well I'll apologize before hand

Discussion in 'Malware Help (A Specialist Will Reply)' started by Deechou, Dec 5, 2006.

  1. Deechou

    Deechou Private E-2

    Hey guys, I'm really sorry about this one. I used your advice before to clear up some bad chinese viruses but now my girlfriend downloaded something really heavy on her computer... I was lucky enough to escape with my life... Oh yeah, the whole sorry part, about that, I couldn't follow those first steps because I couldnt really do anything without the computer freezing and starting from ground zero. But I was able to sneak hijack this on there through the usb to pull a list thingy.(I cleared up the last problem with that)
    So again I apologize for the inconvinience
    Oh yeah a few things you might need know
    Its a japanese comp
    It's most likey a chinese virus or many chinese viruses
    It's virus definitions havent been updated in years and I don't think she has ever run a scan before
    So any help would be appreciated
     

    Attached Files:

  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Can you boot into Safe Mode to run some of the cleaning routines mentioned in our Read Me ?


    as you managed to get Hijackthis on that PC, could you not do the same with ShowNew or GetRunkeys etc?

    To get a sucessful hijackthis log you need to not use MSCONFIG to control startups as all of them will need to be seen to assess the extent of malware infection, plus also install it and rename it as listed in the guide, many new varients of malware hide themselfs unless this has been done.


    just a recap of the guide as it may have changed since you last needed to use it,

    Our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.




    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. Deechou

    Deechou Private E-2

    Hey thanks for the quick reply.
    I was able to sneak getrunkey shownet and a new hijackthis scan.
    I made some progress with installing spybot and avg but I was unable to update the badboys. it seems the virus is rightnow limited to cutting online functions
    Again, sorry about the whole not following protocol
    Its been a frustrating ordeal
    Thanks a bunch
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please install HijackThis into the proper location. You have it here:

    C:\Documents and Settings\cims\ƒfƒXƒNƒgƒbƒv\antivirus\analyse.exe

    This is one of the locations we specify not to put it. See the link in step 7 of the READ ME.

    First goto Add/Remove Programs and uninstall anything from Tencent_QQ instant messaging client. That includes the below two items:
    Tencent Media Player by Viewpoint
    Viewpoint Media Player (Remove Only)

    Also look for anything beginning with QQ and uninstall.

    I'm not sure whether the below are valid or not since I do not know what the real english translation would be. These came at the end of the newfiles.txt log and are installed programs of some type.
    "DisplayName"="‚¢‚«‚È‚è²ÝÀ°È¯Ä"
    "DisplayName"="µÝײÝÏÆ­±Ù"
    "DisplayName"="½ðɽ¶¾°Ôɱ¶¾Ì××°"
    "DisplayName"="‰w‚·‚Ï‚ ‚Æ"

    Make sure viewing of hidden files is enabled (per the tutorial).

    Some items mentioned below may no longer appear, if the above uninstalls worked properly. So just ignore anything that you don't see and continue.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Tencent SearchHook - {DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9} - C:\Program Files\TENCENT\Adplus\SSAddr.dll
    O2 - BHO: SOSO AddressBar Search - {0C7C23EF-A848-485B-873C-0ED954731014} - C:\Program Files\TENCENT\Adplus\SSAddr.dll
    O2 - BHO: QQBrowserHelperObject Class - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\QQ\QQIEHelper.dll (file missing)
    O4 - HKLM\..\Run: [stup.exe] C:\PROGRA~1\TENCENT\Adplus\stup.exe
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

    After clicking Fix, exit HJT.
    Now reboot in normal mode

    After reboot, delete all files in the below folder (Windows may not let you delete certain files from the current day).
    C:\WINDOWS\Temp

    Now attach the below new logs and tell me how the above steps went.
    1. ShowNew
    2. HJT


    Make sure you tell me how things are working now!
     
  5. Deechou

    Deechou Private E-2

    Progress!!

    Okay! well I got the hjt moved, got rid of some qq stuff(Im not sure if it is all of it), and cleared out the temp folder.
    now I found a folder named tencent I have a feeling it is ad stuff but I don't want to do anything without yalls greenlight right now, so should I eraticated it.
    (I have hated qq since the day I arrived in China and heard its wreched name spoken, so it was a bit fun killing that stuff)
    I need to also say that the problems started in the arrival of kav...
    also the soso thing came back...well you will see in the logs
    I also have an Idea on what the display names mean
    1.)something about suddenly internet "ikinariinternet"(beats me)
    2.)online manual
    3.)not a real language anymore(this came when the problems did...)(kav2007)(i dont know how to get rid of it, right after she got it, she tried to delete it but couldn't)
    4.)expert(some sort of japanese pun) came with the computer
    I still can't update the scanning programs though
    it seems to stop right when norton kicks in and asks something(japanese)
    Im told it says it says"blah blah blah is waiting to be scanned"
    then gives the option to ok or stop(norton 2004)
    well, after ok is clicked then the program stops and is unable to end and causes a bunch of trouble
    I have stopped nortons autoprotect and the updates are going through
    but i would like the autoprotect on oneday
    well Im going to continue in the steps now scanning now and I will give you updates soon
    Thanks again for helping me out
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Progress!!

    Yes delete any Tencent folder you found.


    I need to also say that the problems started in the arrival of kav...
    also the soso thing came back [/quote] Did you install the KAV software yourselves? It is this: http://www.kingsoft.com/en/ Does it have an antivirus as well as a firewall? If you did not install it or do not want it or if you believe it to be the cause of your problems, then goto Add/Remove programs and uninstall it.

    Let's continue with your cleanup!

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.1_02
    Java 2 Runtime Environment, SE v1.4.2
    Java 2 Runtime Environment, SE v1.4.2_04
    SOSO AddressBar Search

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: SOSO AddressBar Search - {0C7C23EF-A848-485B-873C-0ED954731014} - C:\Program Files\TENCENT\Adplus\SSAddr.dll (file missing)
    O4 - HKLM\..\Run: [stup.exe] C:\PROGRA~1\TENCENT\Adplus\stup.exe
    O11 - Options group: [TBH] SOSO AddressBar Search

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\TENCENT <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.

    1. ShowNew
    2. HJT


    Make sure you tell me how things are working now!
     
    Last edited: Dec 7, 2006
  7. Deechou

    Deechou Private E-2

    ok I ran the sbybot scan and found a few minor bad things but i think the main bastard is still running about
    I have gotten rid of tencent and now going to try the rest
    I will reply soon when I have completed
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Are you going to uninstall KAV2007?
     
  9. Deechou

    Deechou Private E-2

    the kav well, my girlfriend installed it not knowing what it was and Im not too clear about how, when, and why it was installed. But we have tried to delete it by file and by add/remove programs. any other way we can be rid of it?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The first step should have been Add/Remove programs! If you tried deleting any files from it first, that could make any uninstall non-functional.

    Try using the below to uninstall it. Let me know if it works:

    Your Uninstaller! 2006
     
  11. Deechou

    Deechou Private E-2

    Alright!

    thats what Im talking about. well after getting to be able to scan for viruses I was finally able to get the internet to work. I am getting that uninstaller right now. Im going to go ahead and just follow procedure now that I got some room to breathe so once I get the online scans done and the uninstaller installed I will report back to you with some logs and how its goin now.
    Oh yeah, thanks again
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Alright!

    You're welcome! Just attach the new logs and tell me if the uninstall worked. If not, we will use some manual steps.
     
  13. Deechou

    Deechou Private E-2

    sorry for the long wait

    Hey man Sorry about that I've been really caught up with work lately. well the computer seems to be fine it is going, and going well, but it does seem to be a bit slower and the temp folder keeps filling with kav things... If there is anything else that you might be able to see then I would appreciate it
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: sorry for the long wait

    There is more to do related to this KAV2007 stuff.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Kingsoft Personal Firewall Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below Service (if you do not find it or get any errors, just continue):
      • Kingsoft Antivirus KWatch Service
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste KPfwSvc into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below Service (if you do not find it or get any errors, just continue):
      • KWatchSvc
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Now run this Disable/Remove Windows Messenger to remove Windows Messenger!

    Now have HijackThis fix the below line:
    O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -

    Now reboot your PC and after reboot delete the below two folders (I'm assuming the KRECYCLE is also from KAV2007)
    C:\KAV2007
    C:\KRECYCLE


    Sun Java has updated again so you should get the new version.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10

    How are things working now?

    Now install the current version of Sun Java from: Sun Java Runtime Environment
     
  15. Deechou

    Deechou Private E-2

    hey, I tried, but it seems that I cant get rid of Kavext.dll in the kav2007... I have disabled it but it seems to be clinging to the comp some how
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:
    regsvr32 /u Kavext.dll
    then click OK. If a dialog box confirming this action appears, click OK.

    Now download Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\KAV2007\Kavext.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.
    After reboot locate the below folder and delete if found:
    C:\KAV2007

    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds