need help removing malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by kona, Mar 15, 2006.

  1. kona

    kona Private E-2

    I have followed Read and Run Me First.

    Under Add/Remove: removed Viewpoint, Weatherbug (free edition), GAIN, AlphaCleaner(?)

    I've also used Virtumonde

    I ran these under safe mode in administrative and another account:
    CCleaner
    Windows Malicious Software Removal Tool
    Ad-Aware SE ( one MRU site deleted)
    Spybot S&D ( showed Windows.ActiveDesktop removed)
    Microsoft Defender
    CWShredder
    Kill2me
    Avast virus cleaner
    McAfee
    Ewido
    Trojan Scan
    A-squared ( malicious object found: C:Documents and Settings\Administratior\cookies\administrator@tribalfusion[2].txt ...removed)

    Bitdefender (found virus: wheaterbug.A - update failed. See attatched log)

    The panda scan was unable to run in safe mode- it was run in normal boot mode with network connection.
    Panda scan (it keeps finding tribalfusion, alfacleaner even after all the scans. Also unable to delete virus:Bck/Ced.A(?)

    My computer uses Authentium for firewall,spyware and antivirus. It states that I have Tribalfusion and AlfaCleaner. It is only able to delete Tribalfusion. In regard to AlfaCleaner it states: error deleting registry key hkey_local_machine\system\currentcontrolset\enum\root\legacy_alfacleaner

    I used to have SpySweeper (trial version which has expired. I deleted it), also I had Norton/Symantec trial version which came with the computer bundle -it expired so I deleted it)

    Please take a look at the Hijackthis log.

    What do I need to do next?

    Thank you for your help!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    When you say you deleted SpySweeper and Norton AV, do you mean uninstalled. SpySweeper does not look like it was uninstall correctly.

    Empty your Authentium and MS Antispyware Quarantine folders.

    You should not install applications like this:
    C:\spyware\MSASCui.exe

    This is MS Windows Defender. You should make a point of installing software to their default folders. That way they don't get confused to be malware posing as valid software file names.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to add into the registry.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll (file missing)
    O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll (file missing)
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
    O16 - DPF: {46A33317-EEA7-7FCB-A279-0AAA7B1246CB} - http://85.255.115.226/1/gdnUS1402.exe
    O16 - DPF: {60BD3A24-CFAB-3D67-C51D-753178AE0BA8} - http://85.255.115.226/1/gdnUS1402.exe
    O16 - DPF: {63D599AD-DC10-1557-0154-214738DC93D0} - http://85.255.115.226/1/gdnUS1402.exe
    O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\Viewpoint <-- the whole folder
    C:\Program Files\AWS <-- the whole folder
    C:\keys.ini
    C:\WINDOWS\SYSTEM32\MYDLL.dll
    C:\Documents and Settings\hom\Application Data\tvmdmns.dll
    C:\WINDOWS\system32\svphostu.exe
    C:\WINDOWS\kwv2.dat


    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  3. kona

    kona Private E-2

    follow up report

    I went back to windows explorer and searched for Webroot (SpySweeper). I found two files and selected all files and deleted it. I couldn't find it in the Add/Remove section under the control panel. Would that clear the partial uninstall that was done?

    Under Windows Explorer, I searched and emptied quarantine folders for Authentium and MS Antispyware.

    I also uninstalled MS Windows Defender under spyware and reinstalled it in the default folder.

    After all that, I followed the instructions that was given and posted a new HJT log.

    After I followed the instructions and rebooted, my computer started quickly. It used to go blank for a few seconds right after the initial windows screen came on and restart again.

    Also, in the thread- Understanding, Cleaning and Preventing Spyware , one of the suggestions were to install Spyware Blaster. Would that be something that I should install?

    Thank you for your help.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: follow up report

    My previous message gave you steps to remove the left overs I was referring to. What I wanted was an answer to my question when you said "deleted" did you mean "uninstall" . There is a big difference. Programs should be uninstalled and then anything they leave hanging around should be deleted. If you delete first the uninstall routines will not work and you are left with tons a remaining items in the registry.

    The correct way to do this is from within the programs themselves. They typically give you a procedure or button in the program to empty quarantines.

    Good! But is your copy of Ewido the free version or paid version. You should not have both Ewido and MS Windows Defender installed as a long term solution.

    Yes Spyware Blaster is worth using. The steps you need to take are all covered in the below link.

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  5. kona

    kona Private E-2

    follow up report

    Thanks for the reply to the previous memo.

    I wanted to make sure that I had done all the steps correctly, so I did another full Read and Run Me First scans again.

    CCleaner
    Microsoft Windows Malicious Software Removal Tool
    Spybot Search & Destroy
    Microsoft Defender
    CWShredder
    Kill2Me
    Avast Virus cleaner
    Ewido ( free version)
    McAfee Avert Stinger
    Bitdefender ( virus detected- C:\Program Files\Sysfiles\WxBug.exe update failed) see attached log

    Panda( spyware detected- see attatched log)

    In regard to the Ewido, it is the free version. Should I still uninstall one of the programs ( Ewido or MS Defender)?

    SpySweeper (trial version) was uninstalled using the Add/Remove tab.

    Also, I did use the quarantine view tab under Authentium to delete its file and in addition to double checking it under Windows Explorer search. I wasn't sure which one I needed to do, so I emptied the folder items in both programs.

    The bitdefender and panda scans both report that I still have malware on the computer.

    What do I do now?

    Thanks for all your help!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: follow up report

    You have not attached any logs.

    NOTE: C:\Program Files\Sysfiles\WxBug.exe is an incorrectly install AIM application. If you do not use AIM, uninstall it and delete this folder. Otherwise as I already said, ignore BitDefender since it will always detect this junk from AOL.

    Uninstall Ewido unless you are going to buy it.
     
  7. kona

    kona Private E-2

    Sorry! in the previous note, I somehow couldn't get the attachments loaded.

    I uninstalled the free version of Ewido and uninstalled the AIM as well.

    I repeated all the previous instruction that were provided.
    Empty Authentium and MS Antispyware Quarantine folders.
    Did the notepad, ran HijackThis -clicking fix only on

    06-HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    06-HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    Booted in safe mode and used Windows Explorer to try to delet the listed files. But none were found in administrative and another user account.

    Then went to Prefetch and deleted all files that were present.

    Ran ccleaner and checked on reset web settings instructions.
    I ran a Panda scan and a HJT scan as well.

    Why does Panda still list alfacleaner? Is it something to be concerned about?

    When should I do disable System Restore, reboot and re-enable system restore?

    Thank you for your continued help.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Because you need to delete the C:\WINDOWS\uninstDsk.exe file yourself! Yes it is adware!

    Not until I tell you to do so. Once we have decided that you are clean I will tell you.

    So delete the above file and let me know if you succeed.

    Also tell me if you are having any actual malware problems.
     
  9. kona

    kona Private E-2

    computer is running slow again

    I noticed that the computer was running slow again. After the Windows XP screen comes on, the monitor flickers and turns off for a few seconds before restarting with the startup. Trying to go online seems to be taking a long time as well.

    The kids had installed AOL-AIM Triton. The previous older AIM version was uninstalled. The current problem seems to have started immediately after that.

    I also installed Spyware Blaster. Enabled all the features. I noticed that on the IE browser page it listed 12 items.

    1) "my home web page"
    2) http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    3) http://search.msn.com/spbasic.htm
    4) c:\WINDOWS\system32\blank.htm
    5) http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
    6) http://www.msn.com
    7) http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    8) http://home.microsoft.com/search/lobby/search.asp
    9) http://microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    10) http://microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    11) c:\WINDOWS\system32\blank.htm
    12) http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

    I noticed the " c:\WINDOWS\system32\blank.htm". I thought it might be the "about:blank" and looked up the "About:Blank and HSA Hijackers-generic Solutions" site. I am completely confused and could not identify anything from my Hijack this log. I don't know if the Spyware Blaster IE browser list is important. Please advise.

    Viewpoint Media Player was uninstalled using Add/Remove
    I re-scanned my computer using the read me instructions
    Asquared found and removed the following: trace.Registry.DLSearchBar
    HKEY_CLASSES_ROOT\catalyst.httpclientctrl.1
    HKEY_CLASSES_ROOT\clsid\{edd6ba26-9ebb-11d2-b89c-00104b30757b}
    HKEY_CLASSES_ROOT\clsid\{edd6ba27-9ebb-11d2-b89c-00104b30757b}
    HKEY_CLASSES_ROOT\interface\{edd6ba24-9ebb-11d2-b89c-00104b307...
    HKEY_CLASSES_ROOT\interface\{edd6ba25-9ebb-11d2-b89c-00104b307...
    HKEY_CLASSES_ROOT\typelib\{eddba23-9ebb-11d2-b89c-00104b30757...
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\sh

    I've attatched the bitdefender, panda and Hijackthis files.
    After the original cleaning of malware, the flickering and restarting of the computer had gone away! Now it's back and logging online is slow as well.
    I need some help!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: computer is running slow again

    You should not be doing anything on your own. That setting is a default setting and as absolutely nothing to do with an about:blank hijacker.

    You did not attach any new log files and I did not ask for any. Are you saying you ran them all again?

    A momentary flashing of your Desktop is normal. It happens as antivirus, antispyware, and firewalls hook themselves into windows to protect you.

    Did you delete the file I said to delete: C:\WINDOWS\uninstDsk.exe
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds