various infections?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by armstrong, Mar 29, 2006.

  1. armstrong

    armstrong Private E-2

    Ewido reported that rock.exe was found in my computer. I’ve got rid of most of it, but have got the following report from Ewido: C:\system volume restore.\RP317\A0023607.exe/keyms.exe Not-a-virus.PSW Tool.Win32.RAS.a The file c:\System Volume information\_restore{B37680B2-BAOA-4E5D-BF30-83E44C588624}RP317\A0023607.exe/xpkey.exe cannot be removed because it is embedded in the archive c:\System Volume Information….etc.etc Do you want to remove the whole archive? I can’t find this archive in the computer, so I don’t know what else it contains. Is it safe to tell Ewido to remove the whole archive? Scans by Spyware Doctor produced a staggering total of 3259 infections – which turned out to be all the files in Vcom Fixit. For some reason the Doctor seems suddenly to think that Fixit is an infection and, altho’ it [Fixit] was running ok earlier today, part of it its AV [Trend-Micro] has been uninstalled and PC Dr is now refusing even to let it open. And now PC Dr won’t run either. Earlier today MS AntiSpyware removed Rivarts.A - twice, even tho' I hadn't been online between the 2 scans. PC Doctor removed Fast Video Player Dialer. This is the first time I have found any malware in either of my computers. The only unusual thing that has happened in the last couple of days is that Dell fitted a replacement video card and updated the drivers online. I hadn't been able to use the computer during the 3 wks it took Dell to get the replacement to me, so he went online before I could update all my protection. Help will be much appreciated. Dell Dimension 8300, 2.92GHz, 1024 MB RAM. XP Home SP1 Ms Antispyware, Ad-Aware, Spybot, PC Tools Spyware Dr, Spyware Blaster, ewido (trial), Trend-Micro AV, ZA
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    To remove files in System Restore, you must disable System Restore and run your cleaning programs. The enable System Restore again after you are all clean. This is covered in are standard cleaning procedures which you may want to consider running since it sounds like you have been having problems. I have included these procedures below.


    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  3. armstrong

    armstrong Private E-2

    Thanks, chaslang. Have been thro’ the cleaning procedure. Scan reports attached, + HJT log (looks nasty).

    MS Antispy found and removed Rivarts.A
    Ewido still can’t remove the 3 infections without deleting the entire archive in which they are embedded (see my original query)
    SpyBot found nothing
    Ad-Aware found and deleted Alexa
    (PC Doctor found FastVideo dialer but can’t remove it. No other app. found this. I have now uninstalled the Dr as it was behaving erratically)

    I have replaced ZA and Trend-Micro AV with BitDefender 8 Pro Plus, which I was already using on my other computer and is clearly better than what I had on this one. BitD’s online scan wasn’t able to remove all the infections, and ‘delete’ wasn’t an option, but I deleted them using the program I have installed. BitDef confirmed deletion. This morning I ran another scan and they are still there.

    NB My ISP runs a virus check on all mail and notifies me when it has deleted messages that were infected. My internal AV also checks mail. Up till now I have had no infections, apart from the occasional Alexa reported by Ad-Aware, which it removes. I check every day for AV updates and once or twice a week for the other progs, and run daily or weekly scans. All clean until now.

    For info’: I couldn’t use this computer since 1 March, when the video card stopped working and it took until 28 March for Dell to supply a new one. The Dell technician went online to download new drivers before I could update all the protection. I updated everything and, having earlier downloaded mail on my other computer went online once that day to check my inbox, which had only 3 or 4 messages.

    After completing the cleaning procedure I booted into normal mode, and, still offline, modem disconnected, I opened Thunderbird. Instead of the few messages left in my inbox, 34 unread messages had appeared, the oldest dated 9 Feb 2004, the newest 27 Feb 06. Most of these were spam, others from regular senders. I have deleted them all – but where did they come from? And they seem to be the source of the infections listed by BitDef.

    Today another irritation. When I was trying to convince Dell that my problem was a video card and not the monitor I ran the Dell diagnostic from their disk. This morning I keep getting interrupted by a box telling me the computer can’t find the Dell disk.

    Sorry for long post, but hope details may be helpful.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! You need to disable Spybot's Teatimer as requested in the READ ME. To disable TeaTimer, run Spybot and click Mode and select Advanced Mode. Then click Tools and select Resident. Now in the right window pane, uncheck TeaTimer.
    Also while this is open, in the left column now select IE Tweaks and then in the right pane make sure all the Miscellaneous locks are unchecked. Now quit Spybot!

    Also you have not installed HijackThis properly as instructed in step 7. You are running it exactly how we ask that it not be run....directly from the ZIP file and from a Temp folder, and from Documents and Settings.

    Please install it properly before continuing or you will not get backups for anything fixed using HijackThis.

    You need to manually delete all the below infected file from your email folders:
    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKCU\..\Run: [Windows Compliant] gehmkl.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\windows\system32\gehmkl.exe

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  5. armstrong

    armstrong Private E-2

    Sorry this is taking ages because I’ve been trying to do it in between trying to meet 2 work deadlines (which is probably why I didn’t notice that I hadn’t already unpacked the HJT zip when I clicked on it).

    I have followed instructions, but C:\windows\system32\gehmkl.exe is not there. Instead there is a text file named C:\windows\system32\gehmkl.exe-up
    which reads:
    windows error Access is denied.000
    at z:\projects\Molestudio\Molebox\molebox\bootup\mbx_DLL.cpp(540)0

    Shall I delete this in safe mode?

    New HJT log attached.

    Still 3 infections in System Volume...... Will they go when Sys. Restore is disabled?
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Delete this.


    Yes!

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  7. armstrong

    armstrong Private E-2

    A v. big thank you for sorting this out for me.

    All seems ok now apart from the vanished Word icons in My Docs, but that's a minor inconvenience, so I have disabled/re-enabled System Restore.

    I read through the How to Protect doc and I already do all of this, except that I had to uninstal SP2, which almost killed this computer.

    Thanks again.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds