8 viruses found by BitDefender

Discussion in 'Malware Help (A Specialist Will Reply)' started by hagbag69, Nov 10, 2007.

  1. hagbag69

    hagbag69 Private E-2

    Hi all,

    Firstly, I've been through the READ & RUN ME FIRST instructions.

    I'm running a 3-year old and fully updated XP SP2 Home installation on a Shuttle AK35GT2/AMD Athlon 1500+/160GB Maxtor HD/GeForce4 440 MX and it's probably time to take it out into the yard and shoot it in the head. The humane thing to do perhaps, but as I only have an OEM recovery CD I would like to clean it up before I resort to recovery/reinstallation.

    Startup takes up to 10 minutes, all programs take twice as long to open as they do on a recent installation, and every time I right click on a file, or Ctrl+C or delete, the "Windows Installer/preparing to install" dialogue comes up. I can cancel that and the correct menu comes up, but it started happening a couple of months ago after I removed some spyware with Trend Micro House Call. At the same time, all my MS Office programs stopped opening, requesting the installation CD with the PRO11.MSI. As I inherited the PC, I haven't got the CD, so I found PRO11.MSI on the net and it required another .MSI file whose name I forget cos I gave up and installed Open Office and rescued my .pst file by various dark arts.

    I'll attach the various scan logs to this and the next post. Results of interest are:
    Spybot continually finds Zlob DNS Changer despite fixing it after every scan.
    CounterSpy found nothing
    BitDefender found 8 viruses as well as a few quarantined remains.
    Panda ActiveScan found nothing

    I can't find the Panda log, so I'll run it again. In the meantime, Counterspy and BitDefender logs are attached to this post. RunKey and Newfiles I'l attach to the next.

    Any help greatly appreciated,
    Stuart
     

    Attached Files:

  2. hagbag69

    hagbag69 Private E-2

    runkeys.txt and newfiles.txt attached to this post. I'll run Panda again and attach the log asap.
    Stuart
     

    Attached Files:

  3. hagbag69

    hagbag69 Private E-2

    The panda scan results are attached to this mail:
    1 virus found & disinfected
    1 spyware found & not disinfected
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Let's start by running ComboFix, also you did not attach a HJT log.

    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Once you complete the above, attach fresh logs from the below.

    • GetRunKey
    • ShowNew
    • HijackThis
    • ComboFix
     
  5. hagbag69

    hagbag69 Private E-2

    Hi BJ,
    While I was running the first Combofix scan, Counterspy popped up a "you've not activated Counterspy" dialogue and AVG detected a worm threat and automatically healed it. Not life-threatening, but I thought you should know what's happening (it's the first time in three months that AVG has found a virus).

    Before I got much further, Windows Firewall flashed up a warning that certain features of Messenger had been blocked and did I want to unblock/continue

    Combofix, GetRunKey and Shownew logs attached to this post. HJT and the newer Combofix logs to the next

    Thanks again for your help,
    Stuart
     

    Attached Files:

  6. hagbag69

    hagbag69 Private E-2

    HJT and second Combofix log attached
     

    Attached Files:

  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please rename HijackThis to "analyzethis.exe" and attach a fresh log once renamed.

     
  8. hagbag69

    hagbag69 Private E-2

    Renamed hijackthis.exe as requested, HijackThis log attached
     

    Attached Files:

  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Run GetRunKey once more and attach a fresh log, something didn't go right.
     
  10. hagbag69

    hagbag69 Private E-2

    Hi BJ,

    I'm running GetRunKey.bat from Windows explorer with all other programs closed. This is all the report in C:runkeys.txt gives:

    Binary file C:\rkeysxxx.txt matches

    I can't attach the report cos the "Manage Attachments" windows tells me I've already uploaded it in a previous post, despite me moving it and renaming it...

    Continuing thanks
    Stuart
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the attached GRK.zip file and extract the GRK.bat file from it into the C:\GetRunKey folder.

    Then run the GRK.bat file by double clicking on it. Does this give you a valid runkeys.txt log to upload? If yes, then attach it.
     

    Attached Files:

    • GRK.zip
      File size:
      10 KB
      Views:
      3
  12. hagbag69

    hagbag69 Private E-2

    Hi Chas,
    No valid runkeys.txt I'm afraid. The command line opens, write about 25 x*.txt file to C:\, asks me if I want to create runkeys.txt cos it doesn't exist, I say Yes, and notepad opens with a blank runkeys.txt.

    I had a look at runkeysxxx.txt cos it was referenced in my previous post, and it looks like a decent log file. I'll attach it - see what you think.

    Keep up the good work
    Stuart
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay this was sort of what I expected would happen. Your PC is having a problem with a certain command inside of the GetRunKey.bat file. I'm not sure why because I can take your rkeysxxx.txt file and process it just fine with the same command.

    Click Start, Run, and enter cmd and click OK. Then enter the below commands into the command prompt window.

    cd C:\GetRunKey
    grep

    What do you see after typing in grep

    Now type the below at the command prompt:
    cd c:\
    grep

    What do you see after typing in this second grep



    Note: The modified GRK,bat file left a whole bunch of temp files in your C:\ folder. They will get cleaned up by just running the original GetRunKey.bat file even though it does not create a full log.


    To get you started on a fix you need to empty the quarantine folders mentioned in your BitDefender log. We asked you to do this in step 1 of the READ ME. You need to delete the AVG and Housecall Quarantines which is all files in the below two folders:

    C:\$VAULT$.AVG
    C:\Documents and Settings\Stewart\.housecall6.6\Quarantine

    Then you need to also manually remove the email messages from Outlook Express that BitDefender mentioned.

    Now please uninstall the CounterSpy trial since we are finished with it.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 5
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java(TM) 6 Update 2
    Java(TM) SE Runtime Environment 6 Update 1

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Archivos de programa\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Archivos de programa\QuickTime\qttask.exe" -atboottime
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    After clicking Fix, exit HJT.

    Now attach the below new logs and tell me how the above steps went.

    1. ShowNew
    2. HJT


    Make sure you tell me how things are working now!

    You really don't have any malware in your logs. The above is just miscellaneous cleanup you need to do.
     
    Last edited: Nov 17, 2007
  14. hagbag69

    hagbag69 Private E-2

    Usage: grep [OPTION]... PATTERN [FILE]...
    Try 'grep --help' for more information.

    "grep" not recognised as an internal or external command, program or executable batch file

    Deleted C:\$VAULT$.AVG\*.*
    Deleted C:\Documents and Settings\Stewart\.housecall6.6\Quarantine\*.*

    Deleted C:\Documents and Settings\Stewart\Configuración local\Datos de programa\Identities\{41D8F490-C258-4DAF-B990-CF46DD0810D6}\Microsoft\Outlook Express\*.*
    I know, I've deleted the whole profile, but I don't use Outlook Express anymore and I've got all the mails elsewhere!

    Counterspy uninstalled
    None of these would uninstall in normal mode, booted into safe mode and uninstalled all except Java(TM) 6 Update 2 (doesn't disappear from the Add/Install Programs)
    Back in Normal Mode and all of them still appear in Add/Remove Programs...

    Done
    Attached

    Thanks again
    Stuart
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try using the Uninstall feature built into Ccleaner to remove them. You can find it under Tools. Let me know if that works. If not, I will give you another method.

    You should rerun the first version of GetRunKey.bat that you downloaded just to cleanup all of the temp files that were created.

    Is everything running OK otherwise?
     
  16. hagbag69

    hagbag69 Private E-2

    Hi Chas

    Cant' uninstall the Java updates with CCleaner, what other methods are there?

    All the xxx*.txt files have been deleted by GetRunKey.bat

    Still taking 10 minutes for XP to boot and the Windows Installer dialogue is still coming up every time I right click on a file, but that's damage to the installation, wouldn't you say?

    Once we're done here, I'm gonna try a repair install of XP - dunno if you have any experience of reinstalling XP, I'd like to wipe the HD and install afresh but I've only got a recovery CD. Any ideas where I could get help with that?

    Cheers,
    Stuart
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This could be cause by the same issues that are causing Windows Installer to popup. First try doing what I have given you below before we do manual removal.

    This is not due to malware. It is due to what you are loading/running or due to hardware issues with your PC.

    You also may have some broken or incomplete installs or uninstalls. Please run the below to see if it can fix any:

    Windows Installer CleanUp Utility


    This is a topic for the Software Forum. However, if you use a recovery CD, it will put your PC back into the same state as it was when you purchased it. Thus anything installed and all updates for software, hardware, etc will be gone. Also you could loose any personal data too. These are things you need to consider before using a recovery CD.
     
  18. hagbag69

    hagbag69 Private E-2

    The Windows Installer Cleanup Utility seems to have got rid of the Java updates, but that pesky dialogue window is still appearing when I right click on files.

    I've moved all my data to the external drive, so wiping the internal HD isn't a problem. I'd love to install Fedora and run this XP through VMware or VirtualBox, but the whole XP license thing is putting me off.

    If you've any more ideas about the Windows Installer, I'd love to hear them. Otherwise I guess we can close this thread.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You could try downloading and installing the latest version of Windows installed from the below link. I'm not sure if you will have any problems though due to the license issue.

    http://support.microsoft.com/kb/893803


    Other than that, all I can suggest are two things:
    1. try the Software Forum
    2. buy a valid copy of Win XP and reinstall ;)
     
  20. hagbag69

    hagbag69 Private E-2

    Reinstalling the installer didn't fix the problem. Bugger.

    FYI I found a forum which suggested deleting registry entries in
    HKEY_LOCALMACHINE > Software
    and
    HKEY_Current_User > Software
    for Norton/Symantec programs which may not have been uninstalled properly.

    Given that we've found a problem uninstalling those Java updates, I reckon that you were right about the Win Installer being screwed. If so, then all the software I've uninstalled which may appear on a properties menu, could be a candidate for causing the Installer to try and run whenever I right click on a file/icon/etc. Don't you just love finding Microsoft's holes?!

    Before we close the thread, I'm finding that I can't delete/rename/move some files as they are "being used by another process". An old chestnut, but symptomatic of malware, don't you think?

    And finally, thanks for all your help, I've learnt a lot but I can't say I'll be following your last piece of advice about buying another copy of XP! I'm only using it cos of the MP3 player, Nokia phone, and Canon camera, but now I've found Linux apps which will handle them all I think I can safely stick the XP recovery CD in and play about for a few more weeks!
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually these problems with incomplete uninstalls that leave things in the registry are quite common and they are not due to Microsoft. They are due to poor programming practices. Using a good registry cleaner you will find hundreds if not thousands of dead keys.

    What files? There are many files that are normally in use and cannot be removed. This does not mean they are malware.

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds