Malware/Virus/Worm removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by thedon01, Dec 10, 2010.

  1. thedon01

    thedon01 Corporal

    i seem to have a serious problem with my computer when it comes to viruses/worms/and all types of junk.

    Here's my issue. I opened a file after downloading and my computer was affected with a multitude of crap. My norton Antivures was able to delete, get this, 532 threats of trojan viruses I'm farely new to getting rid of this stuff hence why it's my first time posting, but here are my problems that i've found.

    I have used a handful of software to fix the problems but they continue to reappear after restart. I've tried everything from scanning in safe mode to scanning in regular windows. nothing has worked and i'm getting a tad frustrated, not knowing if i'm doing something incorrectly.

    Here are my programs:
    Spybot Search & Destroy
    Spydoctor
    Ad-Aware
    Malwarebytes
    No Adaware
    RegUtility
    Klwk registry scanner
    Avast Antivirus
    Norton Antivirus
    CWShredder

    I used Spybot Search & Destroy and have found
    Adbrite (cookie)
    Double Click (cookie)
    Microsoft.Windows Security Center.Antivirusoverride (registry change)
    Right Media (cookie)
    Stat Counter (cookie)
    Win32.Autorun.tmp (registry change, Trojan)
    Win32pornpopup (cookie)
    Zedo (cookie)

    I've also found with No adaware
    Coolwebsearch.xpsystem
    located at HKEY_CURRENT_USER\SOFTWARE\Microsoft\WindowsNT\Current Version\Windows\Run

    Lastly i've found
    Rootkit.TDSS
    Rogue.Agent located at:
    C:\system volume information\_restore {f0c009da-8f3c-4de9-bc61-e7905cb30227}\A0030150.dll

    i'm willing to do whatever someone is willing to teach me. Thank you for helping me out.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.

    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.


    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this aother user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:

    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. thedon01

    thedon01 Corporal

    i am reading the "Read and Run me first", which program's should i remain to use? I'm not sure which one is the best.

    Antivirus:
    Avast
    Symantec

    Malware
    Malwarebytes
    Spy doctor
    spybot S&D
    Adaware
    no-adaware

    misc
    Regutility
    CWShredder
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I want the logs from doing the following scans:
    SAS ( SuperAntispyware )
    MBAM ( MalwareBytes Antimalware )
    ComboFix
    RootRepeal
    C:\MGLogs.zip ---> from doing the C:\MGTools.exe

    You should have only 1 AV software installed.
     
  5. thedon01

    thedon01 Corporal

    that is fine, which AV program and which spyware program should i keep installed?

    I have all the programs i listed currently installed.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Antivirus:
    Avast
    Symantec ---> uninstall this!

    Malware:
    Malwarebytes
    Spy doctor ---> uninstall this!!
    spybot S&D
    Adaware ---> uninstall this!!
    no-adaware ---> uninstall this!!

    misc
    Regutility ---> uninstall this!!
    CWShredder ---> uninstall this!!
     
  7. thedon01

    thedon01 Corporal

    thank you, i'm going to go through all the steps right now
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I will be around when you have attached your logs. :)
     
  9. thedon01

    thedon01 Corporal

    i have read and completed steps 1-6 of the "read & run me first" link.

    i currently have avast/malwarebytes/spybot S&D installed.

    using a 32bit system

    now working on window's XP cleaning procedure
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok, just save your replies until you have the logs to attach. ;)
     
  11. thedon01

    thedon01 Corporal

    I'm working on the scans right now however i'm concerned about losing my internet connection with the combo fix scan. is it a must that i run this scan? either way i will do as you direct.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes. Run Combofix.
     
  13. thedon01

    thedon01 Corporal

    root repeal freezes everything i try to start the program. i have tried downloading it twice and continue to have the same problem.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If something does not run, skip that step and continue.
     
  15. thedon01

    thedon01 Corporal

    i could only get 4/5 scans to work and they were

    Superantispyware
    malwarebytes
    combofix
    Mgtools

    Rootrepeal would freeze everytime i doubleclicked the rootrepeal.exe icon.

    After we fix this computer i would like to hear recommendations on which software to purchase, both antivirus and spyware protection.

    thank you again, you guys are amazing.

    attachments below
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing much in the way of actual malware, but we do have some things to clean up.

    First, please take ComboFix out of the folder it is in and put it directly on your desktop, not here:
    Running from: c:\documents and settings\Owner\Desktop\majorgeeks\ComboFix.exe

    Please Disable Spybot's TeaTimer --> Should have been done as per the R&R instructions!

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 3
    J2SE Runtime Environment 5.0 Update 4
    Java 2 Runtime Environment, SE v1.4.2_06
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7
    LiveUpdate 3.1 (Symantec Corporation)

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Driver::
    pvkoddu
    vaxscsi
    
    File::
    c:\winnt\system32\sjhex\pvkoddu
    c:\winnt\system32\Drivers\vaxscsi.sys
    C:\2F9E.tmp
    C:\2F9F.tmp
    C:\2FA0.tmp
    C:\2FA1.tmp
    C:\2FA2.tmp
    C:\2FA3.tmp
    C:\2FA4.tmp
    C:\2FA5.tmp
    C:\2FA6.tmp
    C:\WINNT\Wsituteroyowuya.bin
    C:\Documents and Settings\Owner\Desktop\majorgeeks\MGtools.exe
    
    Folder::
    c:\winnt\system32\sjhex
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\NoExplorer]
    
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}]
    
    [HKEY_LOCAL_MACHINE\System\ControlSet002\Services\pvkoddu]
    "ImagePath"=-
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  17. thedon01

    thedon01 Corporal

    i will follow your instructions and post the results. Thank you again. I do have a question though.

    Before i followed your directions I had did some scans myself and found the items listed in my original post (#1). With your instructions does this mean my computer is clear of those items?
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would like to see the results of doing the fix before I comment on that question. After doing my fix, re-run both SAS and MBAM and attach the logs if they find anything.

    What scans did you run?
     
  19. thedon01

    thedon01 Corporal

    sounds good, i will work on it now.

    before i came onto this site:

    I used Spybot Search & Destroy and have found
    Adbrite (cookie)
    Double Click (cookie)
    Microsoft.Windows Security Center.Antivirusoverride (registry change)
    Right Media (cookie)
    Stat Counter (cookie)
    Win32.Autorun.tmp (registry change, Trojan)
    Win32pornpopup (cookie)
    Zedo (cookie)

    I've also found with No adaware
    Coolwebsearch.xpsystem
    located at HKEY_CURRENT_USER\SOFTWARE\Microsoft\WindowsNT\Current Version\Windows\Run

    Lastly i've used malwarbytes & spydoctor and found
    Rootkit.TDSS
    Rogue.Agent located at:
    C:\system volume information\_restore {f0c009da-8f3c-4de9-bc61-e7905cb30227}\A0030150.dll
     
  20. thedon01

    thedon01 Corporal

    before i use, is C:\MGtools\analyse.exe the same as C:\MGtools.exe?
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    NO!! You have a seperate C:\MGTools folder that contains a number of files, one of which is analyse.exe.
     
  22. thedon01

    thedon01 Corporal

    found it
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Attach the new logs once you are finished with the fix. ;)
     
  24. thedon01

    thedon01 Corporal

    i thought i had disabled the scanners for avast but combofix told me they were still active. i wasnt sure how to disable them so i uninstalled avast. if there is a better program to install please give me your suggestion or tell if i should re-install avast.

    logs are attached below
     

    Attached Files:

  25. thedon01

    thedon01 Corporal

    should i re-install avast or another program?
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. You can re-install Avast if you wish. Or you can switch and install Microsoft Security Essentials. It just depends on which one you prefer and which one works best on your system.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  27. thedon01

    thedon01 Corporal

    ok i'm going to walk through that last post, but how do i know if the below list of problems are deleted?

    Rootkit.TDSS
    Coolwebsearch.xpsystem
    Win32.Autorun.tmp
    win32.Pornpopup
    adbrite/double click/right media/stat counter/zedo (cookies)
    microsoft.windows security center.antivirus override

    i found that my computer had these items by doing spydoctor/no-aware/& spybot S&D scans
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Unless Spyware Doctor is a paid for version, I wouldn't trust it. And there are no traces of any of that in your logs. If you want to hold off for a day or so before you do the final cleanup, just to be sure all is well, than that would be fine. Let me know how things are running.
     
  29. thedon01

    thedon01 Corporal

    if i wait a day should i do any scans outside of your last instruction?
     
  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can always do an online scan:

    eSet Online Scan.

    See what that finds, if anything.
     
  31. thedon01

    thedon01 Corporal

    using the ESET online scanner and it's already found 5 threats and only 9% done. I'll upload the log when it's finished
     
  32. thedon01

    thedon01 Corporal

    the Esetscan found 10 threats.
     

    Attached Files:

  33. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    None of those items are any major threat. Cleaning up your java software, finding some issue with No Adaware and three items in your system restore folders. You can only remove the system restore items by toggling system restore, which you will do when you run the final instructions.
     
  34. thedon01

    thedon01 Corporal

    didn't we already clean up the java software?
     
  35. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, so I suspect they were false positives. ;)
     
  36. thedon01

    thedon01 Corporal

    haha i can't thank you enough, you are a blessing and extremely intelligent when it comes to these problems. so i thank you very much, i'll finish your final step and let you know how things are.
     
  37. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     
  38. thedon01

    thedon01 Corporal

    working through the "how to protect yourself from malware". do i need to have all three of the following?

    Superantispyware
    Spybot
    spywareblaster
     
  39. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I would keep SpywareBlaster and SAS, just wouldn't bother with SpyBot.
     
  40. thedon01

    thedon01 Corporal

    i've done a little homework on the best anti virus software but im at a crossroads.

    i've used Avast and Norton before, both are good, but i've read good things about
    VIPRE
    Kaspersky
    Bitdefender
    Shiled deluxe
    Panda
    Webroot anti virus.

    can anyone give me some expert advice on which to use?

    thank you
     
  41. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    All of those are "paid for" AV programs. Did you read the How to Protect Yourself link?

    We recommend Avira, Avast or Microsoft Security Essentials.

    If you are adamant about purchasing protection, I personally would go with either Kaspersky or Panda Cloud AV.
     
  42. thedon01

    thedon01 Corporal

    yes i read the "how to protect yourself" link.

    is there a major difference between a purchased version and a free version? i always thought a purchased version was the better option and i was willing to buy a one but wanted to get the best one i could.
     
  43. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't think you will find that a purchased version is that much better than the free versions. Any version is going to be dependant on how quickly they update their virus definitions to met new threats. Look over some of the malware threads and you will see that we deal with systems that have paid for AV programs as well as free versions. So all I can say is that "paid for" does not necessarily mean better. A lot depends on you and your surfing habits.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds