MajorGeeks Support Forums IOBit Software

Go Back   MajorGeeks Support Forums > Majorgeeks.Com - Support Forums > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.


Reply
 
Thread Tools Display Modes
  #1  
Old 07-20-09, 14:11
Master_Raul Master_Raul is offline
Private E-2
 
Join Date: Jul 2009
Posts: 2
Thanks: 0
Thanked 0 Times in 0 Posts
Question Need help with Win32/Virut please.

I will start out with this: That being said lets move on....

I have looked at the other threads pertaining to this infection and also gone through the read me first sticky and completed all of the required tasks including the Win XP Cleaning Procedure.

(I am trying to clean the system so that when I ghost the drive it does not come back. I ghosted once and it just came back.)

I was unable to run Combo Fix because it kept telling me that the package was corrupted by win 32/Virut. I then tried to run RootRepeal. It will get 3 min into the scan and pop up rr.exe has encountered a prob and needs to close. By running RR on the C: D: G: and I: drives individually I was able to get it to scan. Drive H: Crashed the program. Drive J: Came up with the error "Unrecognized partition type 6 (0x6)!" And would not scan the drive. Drive H: Contains copied Movies, TV Shows and other media. Drive J: is my backup Drive containing Ghost backup images and other backed up files. All of my drives are internal drives. Either IDE or Sata. I am attaching the RRlogs in a rar file with each drives report and the crash log from drive H:. Drive J: did not crash nor have a report to save.

I also went one step further and ran GMER.exe. I am attaching that as well.

I am still having issues with the computer. This Virut is proving difficult to remove. After reading the other threads on it I knew it would be. I still have hope to accomplish my goal of being able to restore my ghost image though.

I have also run the rmvirut.exe several times. I have no idea if it's working but I see little change. It's not getting everything. It did say in the threads I have read about it that it will "eventually" get it all. I'm just wondering when eventually is and how many times I have to run it. I've run it 17 times so far. Hope thats not bad.

I've run Windows Malicious Software Removal Tool as well. It seems to do a better job than rmvirut.exe but it still isnt getting all of it.

I have not run either of these since I started with your cleaning procedures.

If you need more info I will be happy to provide it. The Virus is still there because WMSRT still keeps popping up and so does WinDef. Bit Defender doesn't seem to function anymore.

I don't know how I got this in the first place. This all started on 7-18-09. It seems to have happened when I opened the ports in the router for a new game I installed through Steam. It was Americas Army 3. I have since disabled all port forwarding in the router and reset Zone Alarm Free Firewall so it would no longer allow traffic in or out through previously allowed channels. I will have to reconsider how to do this so i can play the game effectively and remain safe from intrusion. If you have tips it would be appreciated. If it helps I have a Linksys BEFW11S4 V2 Wireless Access Point Router w/ 4-port Switch.
Attached Files
File Type: log SUPERAntiSpyware Scan Log - 07-19-2009 - 23-20-48.log (4.6 KB, 4 views)
File Type: txt mbam-log-2009-07-20 (00-07-17).txt (5.6 KB, 2 views)
File Type: zip MGlogs.zip (117.2 KB, 4 views)
File Type: zip RRlogs.zip (13.6 KB, 3 views)
Reply With Quote
Sponsored links
  #2  
Old 07-20-09, 14:12
Master_Raul Master_Raul is offline
Private E-2
 
Join Date: Jul 2009
Posts: 2
Thanks: 0
Thanked 0 Times in 0 Posts
Red face Re: Need help with Win32/Virut please.

The remaining log.
Attached Files
File Type: txt gmerlog.txt (70.0 KB, 5 views)
Reply With Quote
  #3  
Old 07-22-09, 15:24
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 44,592
Thanks: 377
Thanked 4,192 Times in 3,983 Posts
Default Re: Need help with Win32/Virut please.

Let's see if we can get you cleaned up.

Please refrain from making any changes to your system (updating Windows, installing applications, removing files, etc.) from now on as it might prolong handling your log and make the job for both of us more difficult.

Please use add/remove programs to uninstall:
Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

Now download The Avenger by Swandog469, and save it to your Desktop.

* Extract+ avenger.exe from the Zip file and save it to your desktop

Please Disable Spybot's TeaTimer

* Run Spybot and click Mode
* Select Advanced Mode.
* Then click Tools and select Resident.
* Now in the right window pane, uncheck TeaTimer.
* Also while this is open, in the left column now select IE Tweaks
* and then in the right pane make sure all the Miscellaneous locks are unchecked.
* Now quit Spybot!

Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
Quote:
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {25b3bc47-445f-4793-8c4e-234a75639219} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {9514BE09-A05E-4078-906E-35350A6569A6} - (no file)
After clicking Fix, exit HJT.

Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
Quote:

REGEDIT4

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"pridl"=-

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25b3bc47-445f-4793-8c4e-234a75639219}]

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9514BE09-A05E-4078-906E-35350A6569A6}]

Make sure that you tell me if you receive a success message about adding the above
to the registry. If you do not get a success message, it definitely did not work.


* Run avenger.exe by double-clicking on it.
* -Do not change any check box options!!
* Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


Quote:
Files to delete:
C:\WINDOWS\system32\11c.tmp
C:\WINDOWS\system32\11d.tmp
C:\WINDOWS\system32\11e.tmp
C:\WINDOWS\system32\18.tmp
C:\WINDOWS\system32\1b.tmp
C:\WINDOWS\system32\2.tmp
C:\WINDOWS\system32\20.tmp
C:\WINDOWS\system32\23.tmp
C:\WINDOWS\system32\atl71.dll
C:\WINDOWS\system32\b3.tmp
C:\WINDOWS\system32\b4.tmp
C:\WINDOWS\system32\b5.tmp
C:\WINDOWS\Temp\tmp00003e07
C:\WINDOWS\Temp\tmp00002446
C:\WINDOWS\Temp\tmp000055f3
C:\WINDOWS\Temp\TMP00000028D0126CAFCE17949B
C:\WINDOWS\Temp\TMP000000E64EB6B5DF12405169
C:\WINDOWS\Temp\tmp00004d78
C:\WINDOWS\Temp\tmp00006256
C:\WINDOWS\Temp\uac3afb.tmp
C:\WINDOWS\Temp\uac3bb7.tmp
C:\WINDOWS\Temp\uac3c4a.tmp
C:\WINDOWS\Temp\uac3e1e.tmp
C:\WINDOWS\Temp\uac3f76.tmp
C:\WINDOWS\Temp\uac3f95.tmp
C:\WINDOWS\Temp\uac62e8.tmp
C:\WINDOWS\Temp\vrt119.tmp
C:\WINDOWS\Temp\vrt19.tmp
C:\WINDOWS\Temp\vrt1a.tmp
C:\WINDOWS\Temp\vrt4.tmp
C:\WINDOWS\Temp\vrtb.tmp

Folders to delete:
C:\WINDOWS\Temp\tmp00003e07
C:\WINDOWS\Temp\tmp00002446
C:\WINDOWS\Temp\tmp000055f3
C:\WINDOWS\Temp\TMP00000028D0126CAFCE17949B
C:\WINDOWS\Temp\TMP000000E64EB6B5DF12405169
C:\WINDOWS\Temp\tmp00004d78
C:\WINDOWS\Temp\tmp00006256
C:\Documents and Settings\Administrator\Application Data\pridl
* Now click the Execute button.
* Click Yes to the prompt to confirm you want to execute.
* Click Yes to the Reboot now? question that will appear when Avenger finishes running.
* Your PC should reboot, if not, reboot it yourself.
* A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
-
Now run Ccleaner to clean out only temp files and nothing else!

Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

Then attach the below logs:

* C:\Avenger.txt
* C:\MGlogs.zip

Make sure you tell me how things are working now!
__________________
Major cake licker.
YCLAHTW, BYCMHD!!

Major Geeks on Facebook

Major Geeks Newsletter
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
WIN32.Virut.56 Asinine08 Malware Removal 1 07-07-09 00:26
Win32/virut Young5 Malware Removal 1 06-23-09 02:49
Virus.Win32.Virut.ce/win32.vitro rulybatters Malware Removal 3 05-01-09 23:30
Win32/virut.a J B00gie Malware Removal 1 09-22-07 22:28
Win32/virut.o BILLMCC66 Malware Removal 8 09-20-07 15:48


All times are GMT -5. The time now is 16:43.


MajorGeeks.Com Home Page
| Admin Tools | All In One | Anti-Spyware | Anti-Virus | Appearance | Backup | Benchmarking | BIOS | Browsers | Covert Ops |
Data Recovery | Diagnostics | Drive Cleaners | Drive Utilities | Drivers | Driver Tools Ergonomics | Firewalls | Games | Game Tweaks | Graphics | Input Devices | Internet Tools | Macintosh | Mail Utilities | Memory | Messaging | Monitoring | Microsoft | Multimedia | Networking | Office Tools | Process Management | Processor | Registry | Security | System Info | Toys | Video | Miscellaneous
|

-->
Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger