malware trojan pax.cax/virtumonde /downloader.swizzor

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by greek123, Apr 14, 2009.

  1. greek123

    greek123 Private E-2

    A couple of weeks ago my computer got infected and AVG found multiple(14) viruses trojan horse pax.cax,trojan horse AGENT.BCDN, downloader.swizzor.jvp It removed some and moved some to virus vault.After removal the computer has been slower. Have run through all the steps mention.Also Spybot keeps finding virtumonde evertime it runs. I have used virtumondebegone, fixvundo by symantec, attribunes vundofix and all three did not locate any infection.

    I ran superantispyware which did not find anything. I ran malware bytes both quick scan(which found and deleted one infection) and full scan. I ran combofix which deleted something and mg tools. I am attaching the log files

    i restored my spybot back to regular settings.it found a suspicious file and deleted.Now my firewall asks me that windows error reporting dump reporting tool may be preventing "kernelfaultcheck" from running each time your computer is started by modifying the registry key HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN......the application is dumprep.exe. Don't know whether to allow or not? and why this is happening?

    Need help.Attached is the Malwarebyte log(quick scan/detailed scan),combofix log/MG tools log/avg scan log

    Thanks in advance for the help
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Could you please attach the log from SUPERantispyware even though you say it found nothing.

    Where was AVG finding these threats?

    In the mean time I shall review your logs and get back to you with a set of instructions as soon as possible.

    Thanks for your patience during this time.

    Kestrel13!
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The main problem is that you are running two anti-virus at once.

    You must only have one installed as you are reducing the effectiveness of each of them by doing this. It also can cause malware to go by unnoticed and it slows a PC down tremendously.

    Decide whether you wish to keep hold of AVG Free 8.0 (which is out of date and needs upgrading to 8.5) or Symantec Anti-virus. If you decide to be rid of Symantec ensure that you use this special removal tool:

    Please give the Norton Removal Tool (SymNRT) a run > reboot your machine and then run it again for good measure.


    1. Please go to add/remove programs and uninstall the following out of date Java:

    • Java(TM) 6 Update 12

    2. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.


    3. Now we need to use ComboFix to remove a bunch of malware files.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    KILLALL::
    
    File::
    c:\windows\is-10E4R.exe
    c:\windows\is-10E4R.lst
    c:\windows\is-10E4R.msg
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    4. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6


    5. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    6. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  4. greek123

    greek123 Private E-2

    Firstly thanks for the help I really appreciate it.
    I am rewriting this message as I am not sure if I sent it out right.

    I uninstalled Norton ran the removal tool. Reinstlled the latest AVG.Then ran Hijack this as u instructed.Then ran Combofix. I then installed latest Java. I did not have my earlier Super antispware as i uninstalled.So i installed and ran it creating a log and lastly ran MG tools.

    Attached I have logs from Combo fix/Super antispyware/ Mgtools and i also created a notepad file of the infections found by AVG on multiple scans as dated.

    I did notice that it found trojan .pax in a file called RECYCLER.This file still exists on all my drives c-Internal H/G External although in G Drive it is called recycled

    When i try to remove it does not allow me to do so.If i rename it it deletes it but forms a new file.If you open the folder it has a recycle bin with the number as below

    :\RECYCLER\S-1-5-21-1645522239-492894223-839522115-500

    Need to get rid of the file please help. The computer is a Little better still slow
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Recycler is the Windows Recycle Bin however recycled is not valid

    I'm not seeing any more malware in your logs.

    Please explain what operations are slow! For example answer the below:

    • Is boot up slow?
    • Is shutdown slow?
    • Is browsing/surfing slow?
    • Is downloading slow?
    • Is running any application?
    • Is it also slow in safe boot mode?
    • Also are any process showing in Task Manager to be using a lot of CPU time?
    • Anything else slow?
     
  6. greek123

    greek123 Private E-2

    sorry for the delay in response.My computer is better it is a little slow on the restarting but it is a relatively old PC.

    Also my external H drive has a recycle bin hidden file called Recycled whereas the other drives have it recycler.Is this something to worry about.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    This I would like to kill, but let's first check the properties of the file and see if it has a signature. Let me know.

    The combo of AVG and ZoneAlarm is probably what is causing the slow start up.
    But to investigate further I would suggest that when this thread is finished you visit the software.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds