win32:ups

Discussion in 'Malware Help (A Specialist Will Reply)' started by Kileybrokeit, Apr 13, 2009.

  1. Kileybrokeit

    Kileybrokeit Private E-2

    Avast found
     
  2. Kileybrokeit

    Kileybrokeit Private E-2

    avast detected Win32:Vupa and Win32:Ups also idarocoh.dll and uditoganide.dll errors

    Avast found win32:vupa and win32:ups.
    Startup error message from windows uditoganide.dll error.

    Please help.
    Thanks
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to tell me exactly what Avast is reporting.

    In the meantime, lets do this:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now let's use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\idarocoh.dll
    C:\WINDOWS\eduwakev.dll
    C:\WINDOWS\ofuvacas.dll
    
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "Uditoganide"=-
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run CCleaner.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combo.
     
  4. Kileybrokeit

    Kileybrokeit Private E-2

    Avast found
    4/14/2009 10:15:27 PM Cathlin 2108 Sign of "Win32:WinSpy-CK [Trj]" has been found in "F:\pagefile.sys" file.

    also please see attached
    Avast Warning list
    and Avast Infected file list.

    I will work on the rest of what you wrote and report back to you.

    Thanks very much for the help.
    Kileybrokeit
     

    Attached Files:

  5. Kileybrokeit

    Kileybrokeit Private E-2

    I'm attaching the 2 files you asked for.

    There was a problem with Zone Alarm Security Suite not being completely closed but I don't think it was a problem.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What is your F:\ drive?

    Other than this:
    C:\WINDOWS\idarocoh.dll (--> just use windows explorer to see if it still exists and delete it if it does).
    the rest of what AVG is reporting is either in quarantine files or system restore files.
     
  7. Kileybrokeit

    Kileybrokeit Private E-2

    My F:\ drive is the original 74gb drive that came with my computer also used for backup.

    When I checked C:\WINDOWS\idarocoh.dll
    I didn't find the file.


    I do have this startup error
    RUNDLL Error loading C:\WINDOWS\idarocoh.dll
    The specified module could not be found.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your pagefile sys should clear itself on shut down. The startup notice can be fixed by doing this:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  9. Kileybrokeit

    Kileybrokeit Private E-2

    Thanks
    I went thru the startup steps
    and the message is still there
    when I start windows.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you get a success message when you ran the reg fix?

    Run the C:\MGtools\GetLogs.bat file again by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  11. Kileybrokeit

    Kileybrokeit Private E-2

    Hi Tim,
    I'm getting confused now but I hope I did this right.

    You want me to attach the MGlogs.zip file I don't see a date on it when
    I look MGlogs.zip so I hope this is right.

    You are going to shoot me now
    I can't remember anymore if I had a success message on the reg fix.
    Is there any way too tell now?

    Thanks,
    Kileybrokeit
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please Disable Spybot's TeaTimer

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Now let's use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\idarocoh.dll
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "Uditoganide"=-
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combo.
     
  13. Kileybrokeit

    Kileybrokeit Private E-2

    Boy do you have a lot of patience.

    I've attached the 2 files.

    I did still notice that ComboFix detected Zonealarm Security Suite Antivirus.
    I did disable where it says Shutdown Zonealarm before the tests though.



    Sorry I have 3 teens and a 12 year old
    off from vacation this week
    and well a a a 47 year old too.
    smirk
     

    Attached Files:

  14. Kileybrokeit

    Kileybrokeit Private E-2

    Hi Tim,
    The startup message is gone!

    Does this mean my computer is all clean now?

    Thank you so much for the help.

    How do you think I got this virus to begin with?
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are running two AV programs. I suggest if you want to keep ZoneAlarm, you uninstall Avast.

    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds