winsync / kavsvc

Discussion in 'Malware Help (A Specialist Will Reply)' started by dr_chumpy, Jul 19, 2005.

  1. dr_chumpy

    dr_chumpy Private E-2

    I seem to have spyware entitled winsync or kavsvc. The files that it is generating are rblna.exe and jpjuak.exe. It is also creating several dll files. I cannot seem to find those files in system32. I deleted them once and have not seen them back. I also cannot delete datadx.dll even if I unregistered it and am in safemode.
    I have read the thread "read this before posting..." and have tried everything. I am stuck. Can you help?

    -Doctor Chumpy
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure you ran all steps in the READ ME FIRST including the BitDefender and RavAntivirus online scans in safe mode?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After running ALL steps in the READ ME FIRST, do the below.

    Download RKFiles Tool and extract the files from it into its own folder named - C:\Program Files\RKTOOL.

    Then, Please boot to SAFE MODE and navigate into the above folder and doubleClick rkfiles.bat to run the tool. Let it run and then, when it finishes, look for a log at C:\Log.txt .

    Now reboot in normal mode and post the C:\Log.txt file and then also do the below steps exactly.

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  4. dr_chumpy

    dr_chumpy Private E-2

    Yes, I have run everything on the list. However, I did have a problem getting into the internet from "safemode with networking" so I ran bitdefender and RAVAntiVirus from normal mode, bot produced no results.
    I have attached my two logs
    RK Files from Safemode
    and HJT running no unnecessary programs.

    I also like to run spybot tea timer, but I closed it for now, since I know you prefer we do not use it.

    I also hear it's best to leave you with information about my computer:

    Dell Dimension 8200
    Pentium 4 2.0 GHz
    512 MB RDRAM (PC800)
    80GB Hard Drive (about 50% free)
    I also have an HP Photosmart printer (I thought I'd mention since HP loads all kinds of junk when you install anything of thiers)

    If there is anything unnecessary from Dell or HP I won't mind stopping that as well, but that's not what I am asking for help on.

    Please let me know if you any more information would help at all.

    I also have seen a thread:
    http://forums.majorgeeks.com/showthread.php?t=67292
    Which seems to be a similar issue, but since the actual process names are different (and his thread is still open), I decided to wait to hear from you first. I hope that's ok.

    Thank you soo much!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your Windows OS and IE versions are way out of date and represent a major security risk. You must get updated after we fix your current problems.

    If you do not use Viewpoint Manager (unrequested stuff from AOL that most people do not use) uninstall it via Add/Remove programs.



    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).


    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\System32\rbrlna.exe


    After killing all the above processes, click "Back".

    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\rbrlna.exe reg_run
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)


    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\rbrlna.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.


    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  6. PhilliePhan

    PhilliePhan Guest

    Hey Chas,

    This looks like a new variant of the WebNexus/Qoologic nasty we used to ID from the (KavSys) entry. RKFiles detected the hidden baddies with the old variant, but this new one is (as yet) hard to pin down.

    Take a gander at my thread here: Web Nexus Popup Issues

    We got the baddie, but the users did most of the work!

    PP :)
     
  7. dr_chumpy

    dr_chumpy Private E-2

    I'm checking this from my work computer, and I will not be home for another hour or so, but I will do this as soon as I get home. Just a note, I have deleted this file from safemode previously, which it eventually came back. And the startup entry "rbrlna.exe" I have deleted several times with it always coming back (even in safe mode). (I will still do this again when I get home)

    I have also run Panda Active Scan previously, which is how I found several dll files which I was able to delete most of in safemode, except the file "datadx.dll" I also tried unregistering the file from command prompt (which gives me a sucessful notice) but the dll re-registers itself before I can delete it.

    I am also reviewing the thread on "I am not a geek" to at least get some background/prep information.

    One more thing, would you like me to run any of the other tools? Qoologic, pocket killbox, or Panda Active scan. I will do this if requested.

    Thanks!!!!!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks PP! Yes I know they are related and that RKFiles does not locate the problem files. I had a couple of these and just like KavSvc problems, some went away easily with no special steps and some did not.

    Still looks like finding the file in C:\Documents and Settings\All Users\Start Menu\Programs\Startup can be the key but they do not always show up at first.

    I have also been finding some baddies right in c:\Program Files and it looks like you did too.
     
    Last edited: Jul 20, 2005
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Post as an attachment the log from Panda. It can be useful for these problems. Also make sure you complete the steps in my previous post and attach the followup HJT log.

    If you are still having problems at this point, complete the below steps too.

    Download Autoruns and extract it to its own folder. Then locate the autoruns.exe file and double click on it. It will immediately do a scan which can take a minute or so. But I want to configure some options first to eliminate some know good items from Microsoft. Otherwise the log can be too long.

    So when it opens, first make sure the Everything tab is selected and then click on Options and make sure the below two items are checked:
    Verify Code Signatures
    Hide Signed Microsoft Entries

    Then hit your F5 key or click the Refresh button which is right under the Entry menu selection. Give it a minute or so (watch the bottom of the Window - it will tell when it is Ready which means done scanning). Then click File and Save As and save the autoruns.txt file. Then upload it here as an attachment.
     
  10. dr_chumpy

    dr_chumpy Private E-2

    ok,

    I have not updated windows yet.

    I have not uninstalled Viewpoint Manager yet, but I'm going to do that (I don't think this is related to the malware).

    system restore disabled

    Killed process: rbrlna.exe

    Then fixed:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\rbrlna.exe reg_run
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

    Went in safe mode and deleted:
    C:\WINDOWS\System32\rbrlna.exe
    (had to kill process again)

    Ran Ccleaner
    emptied: c:\windows\Prefetch

    I have also deleted registry entry a while ago (before requesting help) but I never found the actual exe file "Global startup: kikc.exe" I think this is related. I searched for the file, but never found it.

    Here's my HJT Log and my previous Log from Panda (I will re-run), I am working on the next step.

    thx
     

    Attached Files:

  11. dr_chumpy

    dr_chumpy Private E-2

    I did actually uninstall Viewpoint manager, I don't know why I wrote I didn't.

    Here's the log from Autoruns

    I am continuing to find pop-ups, but tea timer seems to have finished stopping winsync.

    Now my desktop just went gray. This window is ok, but that's really weird.

    I'll keep you posted.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Before running Panda again, please do the below.

    You must disable SpybotSD TeaTimer or it could cause us problems.
    To disable TeaTimer, run Spybot and click Mode and select Advanced Mode. Then click Tools and select Resident. Now in the right window pane, uncheck TeaTimer.
    Also while this is open, in the left column now select IE Tweaks and then in the right pane make sure all the Miscellaneous locks are unchecked.
    Now quit Spybot!

    Run Ccleaner again and make sure that under the System check box that Temporary Files is checked (in fact all boxes here should be checked). Then run the cleaner.

    Then try finding the below files and delete them (from safe mode if necessary):

    C:\WINDOWS\cfgmgr52.dll
    C:\WINDOWS\LastGood\ceres.dll
    C:\WINDOWS\SYSTEM32\akayu.dat
    C:\WINDOWS\SYSTEM32\datadx.dll
    C:\WINDOWS\SYSTEM32\ghgwsfd.dll.tmp
    C:\WINDOWS\SYSTEM32\InstallerV3.exe
    C:\WINDOWS\SYSTEM32\nsa183.dll
    C:\WINDOWS\SYSTEM32\supdate.dll

    Also look for an delete the file you mentioned previously. Look for it here:
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\kikc.exe

    Then run Panda and post the new log.
     
  13. dr_chumpy

    dr_chumpy Private E-2

    That was terrible grammar, I apologize, I think I was just dumbfounded by what happened. The gray went away.

    Let me try again. The pop-ups are still coming (and my PC, a bit slower then it should be), but tea timer is not blocking the winsync entry, and I just re-checked HJT and winsync is not back.

    It's very strange. I cannot see rbrlna.exe running from task manager, only from HJT. That is what I had to do in safemode to delete the file, but it is running, so I'm sure it has returned (unless it is supernatural :D ).

    btw, I can use this command (ntsd -p [pid] -c "q") to kill rbrlna.exe from normal mode. And then if I delete it right away it will go away for the time being.

    I did that (above) and I was able to delete all the files you mentioned except datadx.dll that I have tried to delete from safemode several times. I will try going into safemode again though. (I have not tried again from safemode yet)

    thx
     
  14. dr_chumpy

    dr_chumpy Private E-2

    whoops I did not catch that. Tea timer is disabled now.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We do not use Task Manager for things like this for a reason. Basically it is simple, not very useful.

    See my previous message and complete those steps which includes a new Panda scan.


    Did you find:

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\kikc.exe
     
  16. dr_chumpy

    dr_chumpy Private E-2

    I could not find kikc.exe

    I'm going to run Ccleaner again and the run panda over night.

    I'm tired, I will post the results of the scan in the morning.

    thx
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Post a new HJT log with it and do not fix anything or stop any of the processes.
     
  18. dr_chumpy

    dr_chumpy Private E-2

    All I have done is run Ccleaner and the scans.

    Here are my new panda and hjt logs.

    I also saw nanka.dll, datadx.dll, ghgwsfd.dll, returned in my system32 folder.

    I am also getting a new file (Which I think is suspicious) named nmnqacb.exe in my system folder.

    The only fixing or stopping was the rbrlna that I did just before deleting the dll files, I have not done anything since. I have not rebooted.

    Going to work now, I'll try to come back on my lunch break.

    thx
     

    Attached Files:

  19. dr_chumpy

    dr_chumpy Private E-2

    I went home on my lunch break only to find out that the power went out :eek: while I was at work. For that reason I did not do anything to my computer.

    Let me know if you want me to boot into safemode to delete any files. I will be working for a while, but if I do not hear anything I will have to boot into normal mode just to get into the internet (and see what you have to say).
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try doing the below:

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixreg.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixreg.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes

    Now find and delete the below files (from safe mode if necessary):
    C:\WINDOWS\System32\ghgwsfd.dll
    C:\WINDOWS\System32\nanka.dll
    C:\WINDOWS\System32\datadx.dll
    C:\WINDOWS\SYSTEM32\cache32dsrf4535dfs
    C:\WINDOWS\SYSTEM32\datadx.dll
    C:\WINDOWS\SYSTEM32\ghgwsfd.dll
    C:\WINDOWS\SYSTEM32\nanka.dll
    nmnqacb.exe <--- whereever you found it delete it.

    Let me know if you cannot find any of these files.

    Then get a new Panda Scan and a new HJT log and post them. Let me know how things are working.
     
  21. dr_chumpy

    dr_chumpy Private E-2

    I ran the fixreg.reg as you requested.

    I also was able to delete all the dll files this time. (I had to delete nanka.dll and datadx.dll from safemode with command prompt (del c:\...)

    Panda found a few registry entries, they may have just been re-names from when my computer went down (as mentioned earlier), but I'll wait before I do anything.

    Here are my new HJT and Panda scan logs.

    So far only one pop-up since reboot, which could have been a legit pop-up (who knows?)

    thank you soo much
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You seem to be getting this IEBAR back again even though we fix it. You may have something else hidden on your PC.

    Find and delete: C:\WINDOWS\abiuninst.htm
    Also look for c:\windows\system32\IEBAR.DLL or c:\windows\IEBAR.DLL and delete if found.

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixreg2.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixreg2.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes

    At this point, your log is clean and we need to get you updated and better protected. You need to run ALL the steps in the below but let's start by first running step 1 to get your Windows OS updated and then run step 3 to get a firewall installed. These are critical steps to keeping your system safe.

    How to Protect yourself from malware!
     
  23. dr_chumpy

    dr_chumpy Private E-2

    I deleted IEBAR manually (after fixreg2.reg) and it seems to be staying away this time.

    I'm working on updating windows, and running the steps from "How to pretect yourself from malware"

    I also was wondering if you think it's worth buying panda titanium antivirus? This is not the first time, I've seen panda scan able to track malware before any other program. I don't think it's that expensive if it works. Let me know!

    Thanks again Chas, you rock!

    :) :cool: :D
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Panda is a good program. Personally I would use it over Norton.

    However just a word of caution, every program can find things others may miss. Some of the items being detected can often be trivial non-issues (just left overs that really have no impact). In fact if you now ran Ewido or MicroWorld scans and maybe a SpySweeper scan, chances are you would find even more things.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds