win32/genetik variation won't go away!

Discussion in 'Malware Help (A Specialist Will Reply)' started by nonsenc, Mar 11, 2008.

  1. nonsenc

    nonsenc Private E-2

    NOD32 keeps saying I have this floating around my computer. I'm stuck and need your help. This computer is using a chinese operating system so some of the programs are not recognized by HiJackThis and come up in WingDings.
     

    Attached Files:

  2. Lev

    Lev MajorGeek

  3. nonsenc

    nonsenc Private E-2

    Did all the scans and saved the logs. After the scans I re-ran Nod32 and it came up with the following problems

    C:\WINDOWS\system32\xwqor8upyk.dll

    C:\System Volume Information\_restore{2BCEB3EB-106F-4CF6-89AA-8FFBAB3CBCED}\RP2\A0000233.exe

    Win32/Spy.Delf.NHF trojan

    C:\System Volume Information\_restore{2BCEB3EB-106F-4CF6-89AA-8FFBAB3CBCED}\RP2\A0000234.exe

    Win32/Spy.Delf.NHF trojan

    C:\WINDOWS\system32\xwqor8upyk.dll

    C:\WINDOWS\system32\drivers\ke0vx7wjum

    the scans are attached as requested. Thanks again for all your help.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please attach only the logs that are requested. The instructions did not request a HijackThis log as one from a properly installed program is already included as part of the MGtools program. You needed to only attach the C:\MGlogs.zip as requested. DO NOT try to create your own log from the files in C:\MGtools and do not add any logs to it on your own unless requested to do so. Did you have problems while running MGtools.exe? Did you get any error messages that were mentioned on the download page? Did you accept the license agreement for TrendMicro HijackThis as specified?

    Did you create the below policies yourself?
    I strongly advise that you uninstall QQ, QQ2007II Beta2, or Tencent (whatever it is called). This program has been the cause of many many people coming here with malware problems. It is also considered to be adware. See the below links:

    http://www.tenebril.com/src/info.php?id=441301950
    http://www.securemost.com/articles/rm_tencent_qq.htm


    Now we need to use ComboFix to remove some files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. nonsenc

    nonsenc Private E-2

    Here are the logs. NOD32 says the little fellow is still hanging around. Thanks again for your help and patience!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Delete the below two files:
    C:\WINDOWS\lov01.exe
    C:\WINDOWS\TEMP\os0yzk2f.TMP

    Now empty your Recylce Bin.

    Now use the instructions in the below link to toggle System Restore off and then back on (disable then enable).

    Afterwards, are you still having problems? If so, attach a log that displays the problems.
     
  7. nonsenc

    nonsenc Private E-2

    Sorry, there is no link for system restore.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  9. nonsenc

    nonsenc Private E-2

    Sorry about the long hiatus. I live in China and due to the Tibet thing most internet has been shutdown and blocked for the last a while. I ran all tests and everything is clean. Just wanted to thank you for your help and say that I really appreciate your time and effort!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    5. If we had you run Avenger, you can delete all files related to Avenger now.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds