Need help with malware/virus removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by snickerdoodle, Jan 26, 2008.

  1. snickerdoodle

    snickerdoodle Private E-2

    Hi: First of all, total newbie here, so please be patient: My daughter is currently running an IBM pc with XP Pro service pack 2, broadband connection with router, and apparently ran into a virus problem that disabled the McAfee av program on 1/4; never able to recover or reinstall McAfee (now unistalled), so when I stumbled onto your forums I attempted to follow read and run me first, etc., to control or eradicate the virus.

    After downloading two different free (AVG and Avast) antivirus programs (one at a time) to scan for virus, only result was that I found a record of Trojan Horse Agent.MOP that had been archived, but something managed to get by McAfee and disable it. Spybot also found some adware and spyware that made it through McAfee (can supply the log, but it included virtumonde.generic and WinAntiVirusPro 2006), so ran the Virtumonde fix it, which found nothing). Scans since that time have indicated nothing but tracking cookies, but the system still is not operating correctly (VERY slow loading of programs, internet and e-mail, frequent hang ups, etc.), although the error messages to end programs at shut down is now looking better) so I'm not sure we controlled all of it. Re-ran the appropriate scans (first time with MGtools) and am attaching the records as requested (I also have the earlier scan from ComboFix if necessary).

    As a note, several days before this computer was infected, practically the same thing happened on My PC (XP Home with Norton Internet protection) which was also disabled. Contradicting info regarding what infected that one (windows quickly sent a msg saying it was a worm, a Symantec scan indicated W32.Hitapop, but the AVG scan showed several instances of PSW.OnlineGames.UYA.) Since I had most of my info backed up and found evidence that it was recording every keystroke, I decided to wipe the hard drive and start over. Really don't have that option on this PC, so I am desperate for help, as my daughter did NOT back up her system and has much to lose - not to mention I apparently don't have system recovery CDs for this PC as I did for mine. Thanks so much for any help you can provide - can't believe the education I've gotten from reading the forums since the beginning of January - you guys are great! :)
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!



    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Administrator\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  3. snickerdoodle

    snickerdoodle Private E-2

    Hi Chaslang:

    Completed all of the steps as requested with the exception of the following; I wasn't able to actually locate these two files when I searched for them (DID find C:\WINDOWS\TEMP - but it was dated today), so I just continued on with the CCleaner and MGTools... I hope that was okay.

    "Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Administrator\Local Settings\Temp"

    System is still much slower than it used to be - takes a long time to pull up IE (which will be changed after reading your forums) and/or any webpages or e-mail. I know I still have some tweaking to do with McAfee gone and following your recommendations (obviously now have AVG AV and anti-spy, still need a new firewall as I read Windows Defender wasn't great either), but was trying to get this thing cleaned up before I do too much more.

    Attached are the two reports you requested.

    Again, thanks so much for your help!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what you are referring to. I did not ask you to delete 2 files. I ask you to delete all files in your two temp folders and those two folders do exist. But you don't need to worry about them now as everything we needed to remove from them is gone anyway.

    What is your reference point in time?

    I'm not sure exactly what you are saying here. Are you saying IE runs slow until you open up Major Geeks in your browser.

    Windows Defender is not a firewall and you don't have it installed anymore and you don't want it.


    Your logs are clean at this time.
     
  5. snickerdoodle

    snickerdoodle Private E-2

    Hi Chaslang:

    Sorry, the newbie showing again: I meant I wasn't able to find the two files/subfolders you had listed (tried to quote you below my entry to help clarify).

    The computer is running slower when compared to before we first appeared to have been infected (on January 4 - when I noticed McAfee attempting to block a virus attack and then become "disabled"). Even after the fixes I ran between yesterday and today, the computer is VERY slow to boot, when opening any programs or the browser and when trying to open MS Outlook. Since we dumped McAfee I thought if anything it would get a little faster. Any suggestions?

    Out of curiousity, can I ask what you were able to find in the logs? Has been driving me crazy trying to figure out where we managed to pick up our malware issues - try to be careful with e-mail attachments, no myspace or music/game downloads, and thought we were pretty protected with McAfee on her system and Norton on mine (amazing that it got past BOTH of them). I'm also assuming it's time to add a more effective firewall to her computer from your recommended list. Please let me know my next steps - I've seen the list you usually provide at the end of a clean-up but am awaiting your advice on when to proceed with that and the system restore toggle - if that is what I should do.

    Thanks again - you guys are really amazing!
    Lin
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but you have a bunch of new software installed since January 4 th. All security software is going to impact start times on a PC. It is a necessary evil in order to provide you with protection. Some of you slowness could be an effect of the installing/uninstalling of too many antivirus programs which have a tendency to leave lots of junk lying around. You had multiple folders for Grisoft lying around and only one is current. That means you probably installed it more than once. Also there were still signs of Symantec and Avast. So this would mean you have had Symantec, McAfee, Avast, and AVG all installed at one time or another.

    We can try doing a couple more scans just to make sure nothing else is hiding. I will give you what to do further down.

    Virtumonde aka Vundo.


    Please run this Using ESET's Online Scanner and attach the requested log.

    Also run this Using Sophos Anti-Rootkit and attach the requested log.
     
  7. snickerdoodle

    snickerdoodle Private E-2

    Yeah, unfortunately, when McAfee was disabled I first scanned with the Symantec tool I found when trying to reinstall my Norton on my computer (the first system "down"), then found out about Avast and tried that when AVG failed to install. Around that point I found Majorgeeks and got an education and tried to follow the Read Me First, etc., etc., which eventually brought me to this point.

    Now the bad news (supplying the details in case they're significant): AFTER disabling my AVG, and when trying to "initialize and update" the ESET Online Scanner the computer was behaving fairly erratically (first "Virtual Memory Low" message popped up), and the process kept failing with the following message "Error: Update Failed (200)" after a fairly lengthy wait (being they said the process should take around a minute w/broadband and each time ir took 10-15 mins or so), but when I retried, I noticed it kept getting a bit further in the process each time, so I tried several times until the install was successful. However, during that time I noticed when I tried to get to the different pages in IE, there were sometimes two complete toolbars (Explorer/StatusBar, etc.) at the top of a single IE page, as if I had entered two searches at the same time, but there were NOT two tabs or two pages.

    As I was doing the scan, and until I rebooted, the dark blue "bar" at the top of any message or IE page was "invisible" and the minimize/maximize or close buttons were missing unless I hovered there. Also heard sounds at several points during the downloads indicating there were "pop-ups" but the number of pop-ups blocked hasn't changed all afternoon, and the Active X bar wasn't showing up, although I knew I needed to approve that install for the download to complete. Thankfully the scan completed and the report from the scan (6 threats found) is attached as you requested.

    After rebooting (which seemed to eliminate some of the craziness that had been occurring) I re-enabled the AVG (hope that was correct, double checked the thread and didn't see where I should have it disabled) and tried to do the Sophos Anti Rootkit download and install. First time, rec'd a message error from helper.exe "Not enough quota is available to process this command", and the location it was trying to install to was C:\Program Files\Sophost\Sophos Anti-Rootkit. Although I suspected it didn't matter as long as I could locate the file, you had said the default would be C:\SOPHTEMP, so I tried again and indicated that location, and then the helper.exe popped up with the message "Application failed to initialize properly (0xc 000012d) Click OK to terminate. Because I had such difficulty getting this to download to the desktop in the first place, I (with much regret) deleted that download and tried again. When I finally had "success" in downloading, running the scan, I got the message when it got to scanning local harddrives: "Error: Could not start the helper process- unable to complete scan. Please restart and try again. Incorrect function". Tried restarting the scan, and then restarting the computer and rescanning - to no avail. A fresh download and this time the download went smoothly, so I tried two more times to run the sargui.exe and got the same Error message at the same point in the scan. Saved the report to attach anyway, and when viewing the report, realized the same dumb thing was happening over and over, even the first time when the scan had appeared not to run. Pshew! I think that is all to report... I hope this helps, and am sorry for the lengthy post - just want to be sure I'm not leaving out anything important, and not sure I'd know what that is at this point!

    Thanks for your patience,
    Lin
     

    Attached Files:

    Last edited by a moderator: Jan 30, 2008
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The only items found by the ESET scan are in the quarantine from running ComboFix and in System Restore. Neither of these are issues. They will be removed during final steps which I'm going to give to you now anyway since whatever problems you are having with performance do not appear to be due to malware.

    You could uninstall AVG Antispyware and you can run analyse.exe (like you did in msg # 2) to fix the below unnecessary startups but obviously these are not malware issues:
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe



    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     
    Last edited: Jan 31, 2008
  9. snickerdoodle

    snickerdoodle Private E-2

    Hi chaslang:

    Thanks so much for all of your time and patience... don't know if it's a favor or not, but I have been telling all of my family/friends/students about your site - in hopes they'll visit BEFORE they ever need the malware assistance! Am still learning everyday, and can't tell you how much I appreciate finding MG's and feeling I can trust the information and help you provide.

    I followed the remaining steps you recommended, installed our new anti-spyware (Comodo) and while waiting to hear from you yesterday I went in and tried to find any and all remnants of files from the McAfee/symantec downloads, etc., to clean up the system as best I could. Removed all of the specified files/folders from our "clean-up" today, yet I'm still having problems with reeeallly slow bootup, and downloading of e-mail or internet.

    Yesterday I did a "print screen" of what is happening on the IE page so I can actually show you what I was referring to... if two search bars are trying to load on one page I'm sure it is slowing down the system, but cannot figure out why this started happening or how to fix it. If this is a question for another forum/thread, please refer me to the proper place and I will repost if necessary.

    Other than that (and the failure to successfully run the root-kit yesterday - took me several HOURS to get those two steps completed to that point!) things are working more smoothly - if alot more slowly. If ther are any other recommendations you (or another forum) can suggest for that (more memory??), please let me know.


    Attachment of IE "double bar" issue is below...

    Thanks so much!! Have a great day! :)
    Lin
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you deal with the items I mentioned in my last message? These items?

    You could also remove the below two items but again this is not malware:
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    Uninstall Google Toolbar for Internet Explorer and then reboot. Do you still have problems especially with the duplicate toolbars? This is really a topic for the Software Forum. This not malware.


    It is quite possible that your PC is just a slow PC. What are your PC spec? Like processor type and speed? Also how much RAM.? Or you could be having hardware problems.

    Does your PC boot up slow in safe mode?

    When you say it is slow, what are you comparing to? And how long does it take from the time you turn on the power until you see the Welcome Screen?

    For downloads being slow, you may need to check with your ISP. Are you on dialup, cable or DSL?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds