Infected with 2 viruses/trojans. Please help!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Amaranth, Jul 11, 2008.

  1. Amaranth

    Amaranth Private E-2

    Hello-

    My system is currently infected with 2 trojans:

    Troj/Virtum-Gen and Troj/Dialer-FI

    I don't know why I pay for Spysweeper with Antivirus, because this is the third time it has let Virtum-Gen onto my system. Most programs I have already run in safe mode, and they can detect the trojans, but always fail to quarantine or clean. I have already tried removal via Spysweeper, Super Anti-Spyware, Malaware Bytes' Anti-Malaware, VundoFix, and VirtumundoBeGone. I have even reinstalled and repaired Windows. This sucker is staying put! Please help! I have been trying to get this thing off for days!

    I use Windows XP.

    Thank you in advance!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. Amaranth

    Amaranth Private E-2

    Hello- thank you for getting back to me.

    After failure with Webroot Spysweeper, when I first ran Malaware Bytes, the program detected it and claimed to disinfect it. However, when I ran Webroot again, it was still showing the two trojans a being on my machine.

    I ran the Malaware Bytes and Super Anti-Spysweeper a second time each to get the logs as suggested. This time neither of them detected it, although one of them detected a Troj/BHO of some kind. However, I ran Webroot again and both the dialer and the virtum-gen are still showing on the computer.

    I am attaching the log files for super-anti-spyware and malaware bytes. I tried running combofix. The first time I tried to run it, it said it gave me an error. So I went back, redid the rename part of the instructions and tried again. This time, when I ran it, a little box that said "ComboFix" and a green-lighted progress bar showed up. Then, my desktop screen blinked once, and then nothing. I tried a second time and it did the same thing.

    I tried running MGTools and it firstly told me I was missing an installation file. I hit ignore and it ran a little before it gave me the error about "16 bit ms-dos". I read the page on how to go into the registry and delete the value and then create a new multi-string one. I did that and tried running MGTools again, but still kept getting the errors. So I'm afraid that at this point, I don't have any logs for those two programs.

    Hopefully this still can be resolved!!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You came here for our help! You need to do only what we ask you to do and absolutely nothing else. You should not be playing with Spy Sweeper and you should only be running what we ask you to run in the READ & RUN ME and in the order written from beginning to end and then attach the logs we request. We need to see the first logs!! Secondary logs are really not that helpful to us since we don't see the original problems. You can skip ComboFix for now until we see the rest of your logs.

    Please read the instructions for Using MGtools. This is all documented on how to fix. Fix the problems and run MGtools and attach the requested MGlogs.zip file.

    I also recommend that you attach a log from Spy Sweeper (even though their logs are typical very poor) so we can see what it thinks it is finding.
     
    Last edited: Jul 13, 2008
  5. Amaranth

    Amaranth Private E-2

    Sorry. I ran the first original scans BEFORE I came looking for help because after trying to remove them with my own programs, my system's performance seemed still inhibited and because Spy Sweeper was telling me it was still on my system.

    I did. This is one of the errors I'm still getting:

    "C:\WINNT\System32\cmd.exe
    An installation file required by NTVDM is missing, execution must terminate.
    C:\WINNT\System32\ntio.sys Choose 'Close' to terminate the application."

    I didn't see any of those particular errors on that page. I just did it again and this time I just hit "ignore" the million of times it showed up, so it eventually produced a log. I am attaching it now. I am also attaching one of the last Spysweeper logs.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just hitting return will not allow the programs to run properly. The do eventually terminate but the logs are not complete. I suggest you run the fix for error message type 1. And then I suggest that you run sfc /scannow from the Start, Run box. Have you Windows CD ready because it may ask for it.

    You are just detecting files in Eset's NOD32 Quarantine. Step 1 of the READ & RUN ME asked you to empty quarantines.

    The very first instruction in the READ & RUN ME also stated that you must not have more than 1 antivirus installed. Your logs both Avast and NOD32. You must uninstall one of these immediately and then do the below.



    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button.
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
    Uninstall the below as requested in step 1 of the READ & RUN ME:
    Java 2 Runtime Environment, SE v1.4.2
    Java 2 Runtime Environment, SE v1.4.2_04
    Java 2 Runtime Environment, SE v1.4.2_05
    Java(TM) 6 Update 2
    Viewpoint Media Player


    Now please put your PC into Normal Startup mode with MSconfig as also requested in step 1 of the READ & RUN ME.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O23 - Service: Network DDE (NetDDE) - Unknown owner - C:\WINNT\system32\netdde.exe (file missing)
    O23 - Service: Network DDE DSDM (NetDDEdsdm) - Unknown owner - C:\WINNT\system32\netdde.exe (file missing)

    After clicking Fix, exit HJT.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). Hopefully it runs now after doing all of the above.


    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jul 13, 2008
  7. Amaranth

    Amaranth Private E-2

    I empty all my quarantines everytime I finish a scan, so I obviously missed that NOD32 was even still installed on my machine. I read that part about having only one antivirus installed, and I didn't even realize that NOD32 was still on my system. I "uninstalled" it quite some time ago, but obviously, I didn't do it thoroughly/and or/correctly. I don't even see it in my programs directory. But I'll go through the control panel and see if I can get it from there. Then I'll do everything your last post instructed me to and then get back to you. Thanks.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you do not find NOD32 in Add/Remove programs, we will have to remove remnants manually because it is still in your registry and the folder does exist.

    Also you should try deleting the c:\program files\eset folder yourself.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds