Problems with VX2 cleaner.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Antimon, Aug 11, 2004.

  1. Antimon

    Antimon Private E-2

    Ok so I run "ad-aware se" in safe mode, without network support, system restoring disabled and all the other steps in your guide followed. Ad-aware comes up with 2 hits, StopPop 1 object and VX2 malware 10 objects. So i tried deleting them and they just reappers. But then I noticed i got sloppy and missed the Add-on Vx2 cleaner and thought it would solve the problem. But when I execute it, it only says that the system is clean. So problem is not solved.
    So could this be another spyware disguising as VX2 or is the cleaner not always fully functional?
    Appreciate any help guys
    //

    WinXp,
    P 2,6@3,12 : asus P4P800-deluxe : 512 ram
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the VX2 finder, run it and select "click to find abetterinternet". Then select "make log" and copy/paste the log back here as an attachment.
     
  3. Antimon

    Antimon Private E-2

    Ok, i have no idea what that did but here is the log..
     

    Attached Files:

    • vx2.txt
      File size:
      278 bytes
      Views:
      4
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It was a double check for VX2 problems. You are clean.

    For the 10 VX2 malware objects Ad-aware found, can you give more info (like the filenames and full path information).

    Try the below with Ad-aware:

    General Button
    Safety:
    Check (Green) all three.

    Advanced Button
    Logfile Detail Level:
    All options under this should be checked (Green).

    Tweak Button
    Check (Green) the following:
    Log Files
    Include basic Ad-Aware settings in logfile:
    Include additional Ad-Aware settings in logfile:
    Please do not check (Green): Include Module list in logfile:

    Click on "Proceed"

    3) Click on "Scan Now"

    4) Please deselect "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat.

    5) Run the scanner using the Full Scan (Perform full system scan) mode.
    A full scan is the in-depth scan mode that scans your whole computer for Spyware infections. When performing a full scan the following scan settings are used:

    - Full Memory Scan is performed
    - Registry Scan is performed
    - Deep Registry scan is performed
    - Cookie-Scan is performed
    - Favorites are scanned
    - Hosts file is scanned
    - Conditional scans are performed
    - Archive files are scaned
    - All fixed drives are scanned
     
  5. Antimon

    Antimon Private E-2

    Those options were already checked. I did a new scan, and it found some more objects under Vx2. I attach a log from the scan and a picture from ad-aware if it could be of any help.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well first of all, you are already out of date with your Ad-aware version. Please get the current version here: http://www.majorgeeks.com/download506.html and check for any reference file updates.

    I need to see a HijackThis log. I see some items in you Ad-aware scan that indicate some manual cleanup may be needed. So get the current HijackThis here: http://majorgeeks.com/download3155.html
    and post its log as an attachment (shut down all unnecessary applications especially Internet Explorer before running HijackThis).
     
  7. Antimon

    Antimon Private E-2

    Heh, I downloaded it yesterday morning and it's already out of date..

    Here comes the log:
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's why we constantly tell users "check for updates first". Too many people ignore this and wind up running with older versions. Updates can be hours apart sometimes. It never hurts to check first.

    I'm looking at you HJT log now.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Any idea who this file belongs too:
    C:\WINDOWS\System32\bgbwlckd.exe

    It is a running process. Can you right click on it and get Properties and Version/Company info?
     
  10. Antimon

    Antimon Private E-2

    Hmm, when I right click properties I dont get the usual "exe properties". So I cant get any version information..
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you do not know what the C:\WINDOWS\System32\bgbwlckd.exe process is, bring up Task Manager (click CTRL-ALT-DEL) and select processes. Locate the bgbwlckd.exe process and End it.

    Run HijackThis and put checks on the following items (but DO NOT click fix yet):
    O2 - BHO: TwaintecObj Class - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINDOWS\twaintec.dll
    O4 - HKLM\..\Run: [tdwscdd] C:\WINDOWS\System32\bgbwlckd.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O16 - DPF: {68BCE50A-DC9B-4519-A118-6FDA19DB450D} (Info Class) - http://www.wow-europe.com/signup/en/wowbeta/Si.cab

    Also if you did not know what C:\WINDOWS\System32\bgbwlckd.exe was for,
    check the following line for HJT to fix too:
    O4 - HKLM\..\Run: [tdwscdd] C:\WINDOWS\System32\bgbwlckd.exe


    After putting checks on each of the above, shut down all applications
    especially browsers (like Internet Explorer) then click FIX on HJT.

    Reboot in safe mode:
    http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406

    Enable viewing of hidden files and folders and system files:
    http://forums.majorgeeks.com/showthread.php?t=37650


    Now use Windows Explorer to locate and delete:

    C:\Documents and Settings\Administratör\Lokala inställningar\Temp\THI6C4.tmp\preInsTT.exe
    C:\Documents and Settings\Administratör\Lokala inställningar\Temp\THI6C4.tmp\twaintec.cab
    C:\Documents and Settings\Administratör\Lokala inställningar\Temp\twaintec.ini
    C:\Documents and Settings\Administratör\Lokala inställningar\Temp\twtini.cab
    C:\WINDOWS\preInsTT.exe
    C:\WINDOWS\twaintec.dll
    C:\WINDOWS\twaintec.ini

    Also find this file
    C:\WINDOWS\System32\bgbwlckd.exe
    and rename it to:
    C:\WINDOWS\System32\bgbwlckd.bad

    (Since we do not know what it is yet, let's not delete it yet. Renaming it just makes it impossible to run it.)

    Now reboot in normal mode and run your scans.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I forgot something. Before running HijackThis we should have done this:

    Type, or copy and paste, the following text:
    regsvr32 /u C:\WINDOWS\twaintec.dll
    then click OK. If a dialog box confirming this action appears, click OK
     
  13. Antimon

    Antimon Private E-2

    Hmm i did marked the things and clicked fix. Then I did a new scan and I noticed another item showing up
    O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe
    Isn't that odd? Never seen it before.. Should i ignore it and reboot, go to safe mode and delete the items?
     
  14. Antimon

    Antimon Private E-2

    Oh, I didn't see the last one. Where should I type that text?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry! I left out a line. Here is the all the info:

    Click Start, Run, and in the Open dialog box,
    type, or copy and paste, the following text:
    regsvr32 /u C:\WINDOWS\twaintec.dll
    then click OK. If a dialog box confirming this action appears, click OK


    Where did you go since the last log to get alchem.exe?
    Yes, have HijackThis fix that line too and then boot to safe mode and delete the file.
    O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe

    Are you sure there were no new O2 BHO lines that came with alchem.exe?

    When finished, post a new HJT attachment.
     
  16. Antimon

    Antimon Private E-2

    I didn't go anywhere. I ran the scan, fixed them, and then right after I did a new scan and alchem.exe was there. Here is the new log. Edit// I fixed alchem before this log..
     

    Attached Files:

  17. Antimon

    Antimon Private E-2

    OK, I've deleted it then scanned in normal and found nothing. I have rebooted a couple of times and ad-aware scanned both in normal and safe mode and it looks clean. I post the last log here, but it looks good from my newbie point of view. Maybe an expert opinion before I overwhelm you with thanks?
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks good now and your welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds