Problems solved?

Discussion in 'Malware Help (A Specialist Will Reply)' started by UVA, Jul 5, 2007.

  1. UVA

    UVA Private E-2

    Well, I recently came in contact with the awesome "Virtumonde" rolleyes and went through all the processes to remove. I believe I have defeated it.... it is not coming up in Spybot S&D, AVG Anti-Spyware, VundoFix, and BitDefender. However, PandaScan is detecting 28 spyware traces, 1 Hacking tool/rootkit, and 1 dialer program.

    Is PandaScan accurate? Am I in the clear?

    I have logs from runkey/shownew and can post if requested.

    Thanks.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes attach logs from GetRunKey and ShowNew. Make sure you have the current versions given in the READ ME.

    Note: If I still see infections in these logs, you will have to run the full READ ME and attach all 6 logs requested.
     
  3. UVA

    UVA Private E-2

    Thanks, chaslang.
    Here are the logs
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do still show some signs of infections which the below will remove. However will not mean you are totally clean. I can not say that based on only seeing these two logs.

    Delete the below folders:
    C:\Documents and Settings\Puntastik\Application Data\Sunbelt Software
    C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint
    C:\-736339097

    Also delete the below file:
    C:\WINDOWS\system32\xwvyb.tmp


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 7
    J2SE Runtime Environment 5.0 Update 9
    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
     
  5. UVA

    UVA Private E-2

    The BitDefender report is from yesterday, and the reason being is that BitDefender is automatically closing right before finishing the scan in both safe/normal mode. Could this be the nasties? or user error?
     

    Attached Files:

  6. UVA

    UVA Private E-2

    Rest of scans.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is not a complete HijackThis log. Please post a complete unfiltered log that shows everything including all running processes.

    Is your McAfee antivirus working OK?

    Does AOL work properly? Or did you uninstall AOL and install only AIM?

    Do the below files exist?
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\Program Files\Windows Defender\MsMpEng.exe


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Also delete the below files if found:
    C:\WINDOWS\system32\byvwx.dll
    c:\windows\switchagreement.txt

    Now run Ccleaner
     
  8. UVA

    UVA Private E-2

    Sorry, didn't realize it was filtered.
    New log attached.

    McAfee was thought to be removed. Not using at all.

    AIM is installed

    They do not exist. I'll go ahead and remove them

    C:\WINDOWS\System32\alg.exe
    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\Program Files\Windows Defender\MsMpEng.exe

    Was not found
    C:\WINDOWS\system32\byvwx.dll

    Removed
    c:\windows\switchagreement.txt
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If McAfee is uninstalled, then is AntiVir working properly? Do the below files exist:
    C:\Program Files\AntiVir PersonalEdition Classic\sched.exe (file missing)
    C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe (file missing)

    What antivirus program are you using?? Looks like none are installed!!

    But my question was do you use AOL. I guess not anymore.

    C:\WINDOWS\System32\alg.exe is a required Windows Service.
    Are you sure the file does not exist? DO NOT try to fix that line with HJT!!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How did you get this PC so messed up? Did you have things disabled with MSconfig when you did uninstalls?
     
  11. UVA

    UVA Private E-2

    AntiVir is not installed.

    Currently, there is not an antivirus program. This comp was a hand down, so Im not sure what all was done.

    AOL could have been installed at one time, but no, I do not use it. I only use AIM.

    I actually forgot to start removing programs before shut down, I did not remove any files including C:\WINDOWS\System32\alg.exe, however, I am not able to locate it.


    Thanks again for assisting me.
     
    Last edited by a moderator: Jul 6, 2007
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have your WinXP CD?

    Do you use/have the Lexmark 4200 Series printer for which you have processes running and a service trying to load for?

    Do you have the Ulead Burning Software also showing a service trying to load?

    Do you have the iPod?

    I'm asking all these question so I can determine what you need to fix/remove and what to keep.

    I will start you off with a fix below for removing Windows Defender, McAfee, AOL, and AntiVir which you do not have anymore.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to AntiVir PersonalEdition Classic Scheduler
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below two Services (if you do not find them or get any errors, just continue):
      • AntiVir PersonalEdition Classic Guard
      • AOL Connectivity Service
      • McAfee.com McShield
      • McAfee SecurityCenter Update Manager
      • McAfee.com VirusScan Online Realtime Engine
      • WAN Miniport (ATW) Service
      • Windows Defender Service
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste AntiVirScheduler into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below two Services (if you do not find them or get any errors, just continue):
      • AntiVirService
      • AOL ACS
      • McShield
      • mcupdmgr.exe
      • MCVSRte
      • WANMiniportService
      • WinDefend
    • Now exit HJT and reboot when it tells you it needs to.
    After reboot delete the below folders if they exist:
    C:\Program Files\AntiVir PersonalEdition Classic
    C:\Program Files\mcafee.com
    C:\Program Files\Windows Defender

    Now attach a new HJT log and be sure to have answered my other questions above.
     
  13. UVA

    UVA Private E-2

    I am not able to find my WinXP CD.


    I DO use the Lexmark 4200 Series printer.

    I DO NOT have the Ulead Burning Software.

    I DO use an iPod.



    These folders were not found
    C:\Program Files\AntiVir PersonalEdition Classic
    C:\Program Files\mcafee.com
    C:\Program Files\Windows Defender


    New log attached.
     

    Attached Files:

    Last edited by a moderator: Jul 6, 2007
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please don't quote my procedures! It is unnecessary and clutters up the thread. Quoting is only necessary to address certain line items like you see me doing below. But it is not needed when you are just posting to answer the whole procedure. In some forums, quoting is necessary because many people could be posting and it is the only way to know who is answering who. In this forum, only you (the original thread starter) and a helper can post.

    You need to find it or buy one. Otherwise you will not be able to replace this file and any others that could be missing or corrupted. In the long run, if you do not have your CD, you could run into problems that are not fixable.

    Then let's remove the service!
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Ulead Burning Helper
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteUleadBurningHelper into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot when it tells you it needs to.

    Now iIf you are not having any other malware problems, it is time to do our final steps which you need to complete ASAP. When you get to the How to protect thread make sure you do all steps to get your PC properly protected. You need an antivirus, a firewall, and a realtime antispyware blocking tool.
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  15. UVA

    UVA Private E-2

    Thanks Chaslang, everything seems to be clean now. Neither scans are picking up on anything.

    Ive installed ZoneAlarm and Avast!, which seem to work great.

    I have 2 last concerns:

    1) I am not able to disable System Restore. It is giving me a message stating that there was an error disabling/enabling a drive and to restart. I've restarted a few times, but to no avail.

    2)There is a pop-up notification from Windows Security Center stating that ZoneAlarm's firewall is currently turned off, but it is active. Should I just turn off Windows monitoring?

    Thanks again.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is something that you will need to discuss in the Software Forum if it continues to be a problem; however if you have multiple drives/partitions you have to choose to Turn off (or enable) System Restore on all drives.

    Yes disable Windows monitoring.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds