I completed the "Read & Run Me First malware removal guide," still problems

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by tonymiggs, Dec 16, 2008.

  1. tonymiggs

    tonymiggs Private E-2

    I have been having problems with my computer for two weeks now..when none of the other software removed the infection I knew I had a big problem...I found your site and I've gone through the "Read & Run Me First malware removal guide," but still have problems. (troj/virtum-gen)
     
  2. tonymiggs

    tonymiggs Private E-2

    I have submitted to you my logs...I thank you in advance
     

    Attached Files:

  3. tonymiggs

    tonymiggs Private E-2

    I have been having problems with my computer for two weeks now...everytime I click on to IE an additional site would pop up...my external hard drive letter has been changed from (k:) to (L:)...when none of the other virus software removed the infection I knew I had a big problem...I found your site and I've gone through the "Read & Run Me First malware removal guide," but still have problems. (troj/virtum-gen)
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to attach the last required log from MGtools (the c:\MGlogs.zip file).

    Run this procedure: Resetting Registry and File Permissions Make sure you reboot as instructed.

    Afer reboot, run SUPERAntiSpyware and first check for updates. Then run a new scan and attach the new log. Do the exact same with Malwarebytes.

    Then reboot and run another scan with SUPERAniSpyware and Malwarebytes to see if they come back clean or still has detections. Let me know.
     
  5. tonymiggs

    tonymiggs Private E-2

    Thanx for the welcome...sorry here it is
     
  6. tonymiggs

    tonymiggs Private E-2

    thanx for the quick response
     

    Attached Files:

  7. tonymiggs

    tonymiggs Private E-2

    here is part of it
     
  8. tonymiggs

    tonymiggs Private E-2

    The scan was very slow, but didn't pick up any infection.
     

    Attached Files:

  9. tonymiggs

    tonymiggs Private E-2

    here is the other log.
     

    Attached Files:

  10. tonymiggs

    tonymiggs Private E-2

    malware bytes still shows the infection
     
  11. tonymiggs

    tonymiggs Private E-2

    here are the logs
     

    Attached Files:

  12. tonymiggs

    tonymiggs Private E-2

    malwarebytes and sophos antivirus...still detects the infection
     
  13. tonymiggs

    tonymiggs Private E-2

    Hello Chaslang...I completed the procedure that you suggested...however the malware bytes and sophos antivirus still detects the troj/virtum-gen.The logs you requested are on my thread...thanx again in advance.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


    Important Notice: A new version of SUPERAntiSpyware is out that should help with this problem from Vundo.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this first log later.
    • Since this infection has been reappearing after a reboot, you will have to reboot again and then run an additional scan to make sure it comes back clean. Attach this second log too.
     
  15. tonymiggs

    tonymiggs Private E-2

    Here are the logs you requested
     

    Attached Files:

  16. tonymiggs

    tonymiggs Private E-2

    I ran sophos anti-virus and no virus was detected...Wow...you are the man! lol thank you...I hope that's end of it...Do you recommend that I keep the programs that I downloaded? This site Rocks!!!
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Execellent news. Now let's address some other issues.





    First two important notes:
    1. You really should cleanup the clutter on your Desktop.
    2. You need to remove all the files in the C:\Documents and Settings folder that you have been saving there. I don't know why you are doing this but this folder should mainly contain only user account names. You should not be installing programs here or saving files here. You need to fix this. All you should be seeing in this folder are the below folders
    Code:
    "C:\Documents and Settings\"
    ADMINI~1      Nov 14 2005              "Administrator"
    ALLUSE~1      Nov 14 2005              "All Users"
    APPLIC~1      Jan 16 2007              "Application Data"
    DEFAUL~1      Nov 14 2005              "Default User"
    HP_ADM~1      Mar 12 2008              "HP_Administrator"
    NETWOR~1      Feb 22 2006              "NetworkService" 

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: AT&&T Toolbar - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - (no file)
    O3 - Toolbar: AT&&T Toolbar - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (file missing)
    O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (file missing)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).





    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  18. tonymiggs

    tonymiggs Private E-2

    here are the logs...
     

    Attached Files:

    Last edited by a moderator: Jan 1, 2009
  19. tonymiggs

    tonymiggs Private E-2

    My computer is running great....Thank you so much...if there are any issues pls don't hesitate to tell me...Should I keep the software that I downloaded from this site? This site is awesome!
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean. But we have one final fix to do and then final steps.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.




    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds