Viruses found over and over

Discussion in 'Malware Help (A Specialist Will Reply)' started by baloneybandit21, Sep 14, 2008.

  1. baloneybandit21

    baloneybandit21 Private E-2

    So a couple of months ago, I saw that my avg antivirus free 8.0 was telling me that there were no active components running. I was in a hurry, so I figured I would deal with it later. I forgot about this issue until about 4 days ago, which means I was running my computer without antivirus software for that time. I don't know if this problem was due to a virus or the avg software, but I uninstalled it and redownloaded/reinstalled it. When it finally came back, it found several things, including two trojan horse viruses and one other virus. Although I deleted them, I am continuing to get alerts from AVG that I have these same several viruses (SHeur.CAZB, win32/POLYCRYPT, Dropper.Delf.BLA, Delf.FLJ, Downloader.Small.DXN, BackDoor.Hupigon), with the first two being the most frequent. There was one (Dropper.Delf.BLA) that was found in "C:\WINDOWS\system32\splm\ncsjapi32.exe", and all of the rest were found in "C:\System Volume Information\_restore{4BIAEA69-B95E-4955-A6A6-502CD89CDA69}\RPI75\ some .dll file". I went through this sites extensive process to eliminate malware and most viruses and such. Unfortunately, while some of these scans found things, I still got a virus found alert from AVG. The only real visible effect from the virus is that I cannot see hidden folders or files, even when I attempt to go through the registry as was suggested on some sites. I have an above average knowledge of computers, I think, but can't seem to shake this one on my own.

    Here is my HijackThis log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:18:18 PM, on 9/14/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16705)
    Boot mode: Normal


    Edit by chaslang: Inline HJT log removed. READ & RUN ME sticky not followed.

    I also turned off system restore to delete all of the saved restore points. I will be grateful to anyone who can help, thanks for taking the time!
     
    Last edited by a moderator: Sep 15, 2008
  2. baloneybandit21

    baloneybandit21 Private E-2

    also, sorry to have posted the HJT log, I wrote this out for a different forum, but figured I would try this one too, which will hopefully be faster, and I just forgot to keep out the log. sorry again!
     
  3. baloneybandit21

    baloneybandit21 Private E-2

    my combofix log
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    QUESTION: Do you have a Intelli Mouse Pro installed? You may have an infection pretending to be this.
    These are in System Restore and can only be removed by disabling System Restore and then re-enabling.

    Unless you attach the logs that were clearly reuqested, we cannot help you. You need to attach the other 3 required logs from SUPERAntiSpyware, Malwarebytes, and MGtools.

    Also you have iolo System Mechanic Pro installed. Doesn't this include an antivirus program?

    I also see that you have Spy Sweeper install. Is it a paid version? Did you know that AVG8 already has antispyware protection builtin? Also you have Spybot's Teatimer running (which our instructions did say not to use). All of these items can be conflicting with each other.
     
    Last edited: Sep 15, 2008
  5. baloneybandit21

    baloneybandit21 Private E-2

    I don't have Intelli mouse Pro so that could be part of it.

    I've disabled system restore to delete all of these prior versions.

    I have attached the other three logs, sorry I forgot to put them on.

    I have system mechanic 8, i don't think it's the pro version, and it doesn't have an antivirus program on it, only for spyware.

    I have spy sweeper paid for, which i purchased prior to downloading avg as my antivirus program, so I just have both. Spy sweeper routinely picks up spyware and tells me about it. It's possible that I had spybot already on my computer and had installed teatimer, because I am sure I unchecked the box when I installed it this time, I was very careful in following the procedures.

    Thanks!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then you would have 3 antispyware protection programs running (AVG8, System Mechanic, and Spy Sweeper). This is not recommended.

    Based on the MGlogs.zip file just attached, Teatimer is actively running and being actively loaded in your start up list. You could be having difficulties changing settings due to all the protection software running and conflicting with each other. Please go check the Spybot Teatimer settings right now and see how they are set.

    What is Vidalia Bundle?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your logs you appear to be in pretty good shape now, but we have a couple of things to do. First you must make sure that Teatimer is not running and you also must make sure you shutdown Spy Sweeper to avoid having the block the changes. Also after rebooting your PC, if any protection program warns you about changes to your registry, you need to allow them or our fixes will not work.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now reboot your PC.
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. baloneybandit21

    baloneybandit21 Private E-2

    I got rid of the system guard that actively stays on my system from system mechanic, and only kept the application for its other uses.

    I think teatimer is gone, because there aren't any remnants of spybot that I can find.

    I uninstalled windows messenger.

    I attempted to merge the new registry file, but it only opens up the notepad with what i pasted in it. No success message.

    Vidalia bundle is a set of 3 programs designed to allow torrents through the university of connecticut network
     
  9. baloneybandit21

    baloneybandit21 Private E-2

    scratch that, I just figured out how to merge it, going with the rest of the processes now
     
  10. baloneybandit21

    baloneybandit21 Private E-2

    well, i ran the rest of the steps, and the first very good sign was that all of my hidden files were showing without any prompt. Everything seems good, and I haven't gotten any more virus alerts thus far, though I am still a little leary to dismiss it. attached is my log, hopefully you can give me more hope than I have.

    thanks for everything!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  12. baloneybandit21

    baloneybandit21 Private E-2

    did you forget to put the link in your post, or do you mean one from before in the thread?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  14. baloneybandit21

    baloneybandit21 Private E-2

    could there be a reason why all of a sudden my flash player doesn't work with firefox 3 now, when it did just yesterday?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on everything shown in your logs that was removed, nothing for Flashplayer was touched. Perhaps you need reinstall the plugin.
     
    Last edited: Sep 17, 2008
  16. baloneybandit21

    baloneybandit21 Private E-2

    alright, then everything's good. thanks for all your help!
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds