Please help identifying an removing found malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by ronfranks, May 13, 2007.

  1. ronfranks

    ronfranks Private E-2

    I have followed and ran 7 steps in your Read me first Tutorial and although the Counterspy program found nothing, the Panda found and removed the Trojan virus, Lineage.CWB, plus 10 malware programs it did not remove. I have enclosed 3 of the pertinent logs (will submit rest in follow-up post) and would appreciate your advices as to further actions I need to take to assure my computer (a compaq pressario running on Windows Home XP) is clean so that I can do Step 8.
    Thanks for your posting that allowed me to find the probable cause of my computer's recent erratic behavior and in advising me on how to resolve this problem.

    :eek: Ron

    P.S I will submit remaining logs in my next follow-up post
     

    Attached Files:

  2. ronfranks

    ronfranks Private E-2

    Follow-up Re: Please help identifying an removing found malware

    Here are the additional logs you require before helping me further with this problem ( please note that Counterspy program did find adware in the form of "Weatherbug" which it deleted(37 objects) so my first post is now corrected to address my erroneous advices that the program detected no problems..

    Again I want to thank you for your help in advising me of any further steps I need to take to assure my computer is now clean and I can proceed with your final step 8.

    ;)

    Ron
     

    Attached Files:

  3. ronfranks

    ronfranks Private E-2

    Oooopps- follow-up Re: Please help identifying an removing found malware

    Yipes, somehow I overlooked attaching the enclosed log with my first follow-up so please excuse and forgive me for that omission and hope I have not confused the issue by any erroneous remarks I may have made in these posts as I feel now that it perhaps might have been best if I had just let the logs point out my findings ( I ran so many programs I'm not sure I correctly attributed the findings of each to the right program - I sure hope so). I sure can get lost in all of this technical process.

    Appreciatively,

    Ron confused
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You logs do not really show any malware issues (other than WeatherBug minor adware that CounterSpy removed). What malware problems are you having?

    Is the below something you installed and recognize?
    O4 - HKLM\..\Run: [TradingRooms] C:\Program Files\Trading Rooms Technologies, Inc\TradingRooms\Avx\TradingRooms.exe


    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    If you don't use People PC anymore ( I see Optonline so I would expect they are your ISP now) then delete the below folder:
    C:\Program Files\Online Services\PeoplePC
     
  5. ronfranks

    ronfranks Private E-2

    Wow and thanks so much for your rapid reply and suggestions.
    As to the "O4 - HKLM\..\Run: [TradingRooms] C:\Program Files\Trading Rooms Technologies, Inc\TradingRooms\Avx\TradingRooms.exe", I recognize Trading Rooms as a chat service I visit and others in the room complain they are also experiencing issues being in the room (systems slowing, erratic,etc. since coming to the room. The room is important to me so is there a way I can find out if it was the cause of my computer's eratic behavior. The room has just issued an update which may address some of these issues but last update prevented me from using the room so I'm hesitant to do the update till others assure me it's ok on monday. Any thoughts you might have re: this will be appreciated.

    Strange but People PC was never my ISP and I never heard of them till now.

    Appreciatively,

    Ron
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's fine if you trust the site, but why does it need to run at startup and always run. Things like this should only be run when you need them.

    If you uninstalled CounterSpy, that will help speed things up a little since installing it would impact PC performance just like all active protection tools do. You can use HijackThis to fix the below few lines too if desired. They are not malware but you really don't need them to load. It is a minor tweak for performance.

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"

    Other than that, the only thing that may be contributing to a slow PC is the security suite you have running from Trend Micro. Internet Security Suites are notorious resource hogs and using separate tools (we have very good free tools) for an antivirus, antispyware, and firewall are often much better and less resource intensive on your PC.

    Was your first HJT log from safe boot mode? It looks like it since none of your Trend Micro processes seemed to be running in the process list but all the services showed. Or are you filtering items from your HJT log. Attach a new HJT log and make sure it is from Normal Boot mode and than you are not filtering items and also make sure you are not using MSconfig to control any startups (see step 0 of the READ ME).
     
  7. ronfranks

    ronfranks Private E-2

    Thanks very much for all this guidance and I have, of coarse, followed all of it and am attaching a new hijack log from a normal boot mode. (I do not recall what mode I was in for the original but I was following your Tutorial to the best of my ability and hope that it was in accordance with those instructions and am sorry if that was not the case).

    I sure would appreciate it if you wouldn't mind telling me what antivirus, antispyware and firewall you personally use as I believe I could not go wrong modeling your prefences since they are undoubtedly based on a much more informed decision than I am able to make.

    I don't like running any more background programs than I have to and I'm wondering if you could point me to info or a tool I might use to safely remove any of the many, many background processes on my machine (it's hard for me to believe all those are necessary and I would deeply appreciate removing any that I safely can).

    Thank you again and I look forward to your kind and generous advices in this matter.

    :eek: ,

    Ron
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay this log shows that your first log was from safe boot mode as I suspected.

    All the tools we recommend, will be listed in a link given in my final steps given below. There are a load of free tools and a few pay tools are mentioned if you decide to go that way. What I would say is that if you are basically happy with TrendMicro, keep it at least until your subscription period expires. Then if you don't want to renew, you could then switch to the free tools in the link I give.

    In reality there are no programs that do such a thing. No one can really know for certain what programs and features of programs each person really uses and needs. What you need and I need and what someone else need will be different. However that being said, you don't have a lot running. Besides TrendMicro, you only have the below which I assume you use:

    O4 - HKLM\..\Run: [TradingRooms] C:\Program Files\Trading Rooms Technologies, Inc\TradingRooms\Avx\TradingRooms.exe
    O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
    O4 - Startup: Check for TWS Updates.lnk = C:\Jts\WiseUpdt.exe


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. ronfranks

    ronfranks Private E-2

    Many thanks for these latest guidelines. My mouse sometimes fails to respond and so I did the "alternative scan"and here is the log. My mouse failing to respond on an intermittent basis is my remaining concern - is this issue related to the malware issues or is it now appropriate for me to toggle the system restore and seek help for my mouse problem through some other means?

    Ron
     
    Last edited by a moderator: May 16, 2007
  10. ronfranks

    ronfranks Private E-2

    Oooopppps, I forgot to enclose the logs with my last post - here they are for the Trojan scan as well as for hijack this to show current situation.
    This mouse problem is getting increasingly worse and sometimes it takes so long for the mouse to respond and move.


    Ron
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I stated in message # 8, you are clean and you need to complete all the steps I gave you in message # 8. That includes toggle system restore.

    Your mouse problem is more than likely not related to malware. You should try another mouse as a quick test (power down before changing the mouse). Also see if the problem occurs in safe mode.
     
  12. ronfranks

    ronfranks Private E-2

    Ok, again and finally I thank you for all your help and advices. Enjoy your day.

    Ron
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds