Solved Ukash, danish version

Discussion in 'Virus, Spyware and Malware Removal' started by TinaV, Jul 14, 2012.


Thread Status:
Not open for further replies.
  1. TinaV Bronze Member

    Bronze
    Message Count:
    33
    Likes Received:
    0
    My System
    Loading...
    My computer have been infected with the danish ukash :-(. I have tried all sorts of different things (malwarebytes, rkill and tdsskiller among others) and sometimes it seems as it has disappered, but only for a short time (5 minutes), then it returns.
    I can only work in safe mode else the Ukash blocks the computer.
    I really hope you can help.
    I have tried to follow the prework instructions and I hope it is correct.

    Attached Files:

  2. Ezsystemrepairs New Member

    Message Count:
    1
    Likes Received:
    0
    My System
    Loading...
    [Removed]

    Sorry but only Malware removal staff and authorized helpers may give support in this forum.

    - Mod Staff
  3. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,872
    Likes Received:
    3,650
    My System
    Loading...
    Hi,

    Can you attach the tdsskiller and MBAM log please?
  4. Google Advertisement

  5. TinaV Bronze Member

    Bronze
    Message Count:
    33
    Likes Received:
    0
    My System
    Loading...
    Hi
    I couldnt find the old tdsskiller so I have made a new and attched that.
    I have attached both an old and a new mbam log.

    Attached Files:

  6. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,872
    Likes Received:
    3,650
    My System
    Loading...
    Hi,

    Download Combofix from any of the links below, and save it to your desktop.

    Link 1
    Link 2
    Link 3

    When saving ComboFix rename it to PCHelpForum.exe to prevent it from being blocked by malware.


    Refer to this image:

    To prevent your anti-virus application interfering with ComboFix we need to disable it. See here for a tutorial regarding how to do so if you are unsure.
    • Close any open windows and double click PCHelpForum.exe to run it.

      You will see the following image:
    [IMG]

    Click I Agree to start the program.

    ComboFix will then extract the necessary files and you will see this:

    [IMG]

    As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. This will not occur in Windows Vista and 7

    It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

    If you did not have it installed, you will see the prompt below. Choose YES.

    [IMG]

    Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [IMG]

    Click on Yes, to continue scanning for malware.

    When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).

    Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so.

    Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.
  7. TinaV Bronze Member

    Bronze
    Message Count:
    33
    Likes Received:
    0
    My System
    Loading...
    Ok, now I have run it 2 times, both times it said that I hadnt disabled the McAfee anti virus and spy defender (even though I had) and the first time there also was an issue with the user/administrater witch I sorted out for the second run.
    I have attached both logs

    Attached Files:

  8. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,872
    Likes Received:
    3,650
    My System
    Loading...
    What sort of issues?
  9. TinaV Bronze Member

    Bronze
    Message Count:
    33
    Likes Received:
    0
    My System
    Loading...
    This computer was originally set up with more users, but I'm the only user now, and therefor is also administrater. But I really do not understand how Vista works, because I'm told that I do not have the administrater rights. Now I have disabled the control on the useraccounts. Then the problems disappered.
  10. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,872
    Likes Received:
    3,650
    My System
    Loading...
    Ok. How is the machine running?
  11. TinaV Bronze Member

    Bronze
    Message Count:
    33
    Likes Received:
    0
    My System
    Loading...
    So far fine :)
    When Combofix restarted the computer I didnt get it into safemode, so the last hour I didnt see any problems :)
  12. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,872
    Likes Received:
    3,650
    My System
    Loading...
    Ok. Give it a day or so and report back
  13. TinaV Bronze Member

    Bronze
    Message Count:
    33
    Likes Received:
    0
    My System
    Loading...
    Hi again, I'm still not having any problems with the computer. :)
    But I had a look at the logs from combifix. I noticed that this was the last file created before I had problems (about an hour later)
    2012-07-12 19:52 . 2012-07-12 19:52 -------- d-----w- c:\users\Tina\AppData\Roaming\hellomoto
    And now I can see a folder called hellomoto with 2 .DAT files in it.
    I'm wondering if I should delete the folder?
  14. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,872
    Likes Received:
    3,650
    My System
    Loading...
    What are the dat files named?
  15. TinaV Bronze Member

    Bronze
    Message Count:
    33
    Likes Received:
    0
    My System
    Loading...
    BukF.DAT
    TujP.DAT
  16. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,872
    Likes Received:
    3,650
    My System
    Loading...
    Yeah if you can, delete that folder

Ukash, danish version

Thread Status:
Not open for further replies.