# [Resolved] Darksma removal-need help

Discussion in 'Virus and Malware Removal' started by phoenix21, May 2, 2007.

Hello and welcome to Techspot.

Very Important: Before deciding whether you should clean or reformat your system, go and read this thread HERE and decide what it is you want to do.

If after reading the above, you wish to clean your system, do the following.

Go and read the Viruses/Spyware/Malware, preliminary removal instructions. Follow all the instructions exactly.

Post fresh HJT, AVG Antispyware and Combofix logs as attachments into this thread, only after doing the above.

Also, let me know the results of the AVG Antirootkit scan.

Regards Howard :wave: :wave:

This thread is for the use of phoenix21 only. Please dont post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
First off,thank you for taking the time to help me.Next AVG antirootkit found nothing.HJT is as follows-
Please repost the requested logfiles as attachments. See HERE.

Regards Howard

Ok I think I figured it out This is the HJT results
And here is the AVG antispyware results
You need to rename HijackThis_v2.exe as per the instructions. You also need to post the rest of the requested files.

You might want to copy and paste these instructions into a notepad file. Then you can have the file open in safe mode, so you can follow the instructions easier.

Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). See how HERE.

In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how HERE.

Open your task manager, by holding down the ctrl and alt keys and pressing the delete key.

Click on the processes tab and end process for(if there).

ALCMTR.EXE
IPClient.exe
kmufm.exe

Run HJT with no other programmes open(except notepad). Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

O2 - BHO: My Web Search Bar BHO - {8EAB99C1-F9EC-4b64-A4BA-D9BCAE8779C2} - C:\Program Files\MyWebSearchWB\bar\1.bin\W6BAR.DLL (file missing)

O3 - Toolbar: WeatherBug Browser Bar - powered by MyWebSearch - {8EAB99C9-F9EC-4b64-A4BA-D9BCAE8779C2} - C:\Program Files\MyWebSearchWB\bar\1.bin\W6BAR.DLL (file missing)

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

O4 - HKLM\..\Run: [IPInSightLAN 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l

O4 - HKCU\..\Run: [kmuf] C:\Program Files\Common Files\kmuf\kmufm.exe

O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/installdrivecleanerstart.cab

Click on the fix checked button.

Close HJT.

Locate and delete the following bold files and/or directories(if there).

C:\Program Files\Common Files\kmuf<Delete the entire folder.
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe
C:\windows\ALCMTR.EXE
C:\Program Files\MyWebSearchWB<Delete the entire folder.

Reboot into normal mode and rehide your protected OS files.

Post fresh HJT, AVG Antispyware and Combofix logs as attachments into this thread, only after doing the above.

Also, let me know the results of the AVG Antirootkit scan.

Regards Howard

OK I think this is it

Also the antirootkit found nothing again
You didnt attach a fresh Combofix log as requested.

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

Post the Avenger log as well as fresh AVGAntispyware, Combofix and HJT logs.

Regards Howard

heres the results of avenger

heres the HJT results

Finally heres the combofix results
It seems like the C:\Program Files\Common Files\kmuf\kmufm.exe doesnt want to go. Please do the following exactly.

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

* Click the Browse... button
* Navigate to the following file C:\Program Files\Common Files\kmuf\kmufm.exe
* Click Open
* Please let me know the results.

6. Please attach the content of c:\avenger.txt into your reply, as well as a fresh HJT log.

Regards Howard

here is the avenger results

and here is HJT
Also I could not find the kmufm.exe file.I even tried searching files and folders but nothing turned up
This is very stubborn. lets see if we can get rid of it this time, if not well have to try doing it manually.

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

5. Please attach the content of c:\avenger.txt into your reply, as well as a fresh HJT log.

Regards Howard

heres the avenger results

and heres the HJT results-am I doing something wrong
No, youre not doing anything wrong, its just proving difficult to get rid of the kmufm.exe file. Just a quick note: You can attach more than one logfile in the same post, so theres no need to make separate posts for each logfile.

Click start/run and type regedit into the run box and press the enter key. When the window appears maximise it. Click file/export and save a copy of your registry to wherever you want.

Click edit and choose find. Type kmufm into the dialogue box and click the find next button. Regedit will now search your registry for any entries that contain a reference to kmufm and display them in the righthand pane. Right click on any such kmufm.exe entries and choose delete.

Now click edit again and choose find next. Again, delete any entries that reference kmufm.

Repeat the above, until no more kmufm entries are found.

Post a fresh HJT log after doing the above.

Regards Howard

ok heres the HJT results-thanks for the tip also
Excellent, that got it. Your HJT log is now clean.

Turn off system restore.(XP/ME only) See how HERE.

Now, turn system restore back on. This will have deleted all your old restore points and any nasties that are in them. It will also have created a new, clean restore point.

If you have any further virus/spyware problems, please post in this thread.

Regards Howard