Evil Torpig!!!!! :(

Discussion in 'Malware Help (A Specialist Will Reply)' started by visageeza, Jun 1, 2007.

  1. visageeza

    visageeza Private E-2

    Hello all!
    Ive followed the steps 1 - 6 and Spybot is showing i have Torpig
    which it cant delete, in any mode, at any point. I also have Smitfraud on there, but ill deal with that later. If anyone could have a look at my txt files i would be most pleased.
     

    Attached Files:

  2. visageeza

    visageeza Private E-2

    Oh and if ive got any of it wrong or made any school boy errors, my apologies in advance...

    Cheers
    VG
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Why are you running without an antivirus program???

    Your logs do not show signs of Torpig (which is a serious infection since it is a keylogging password stealer). You do show a bunch of other problems including SmitFraud as you mentioned.

    Please attach a Spybot log!

    Also you need to disable Spybot's Teatimer as was requested in the READ ME. It will get in the way of clean.

    Then you need to uninstall the below as requested in step 0 of the READ ME:
    Internet Explorer Security Plugin 2006
    Internet Security Add-On
    Viewpoint Media Player

    After doing the above continue on with the below.



    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    Now attach new logs from:
    • GetRunKey
    • ShowNew
    • HJT
    How are things working now?
     
  4. visageeza

    visageeza Private E-2

    Hi
    Ive turned Spybots Tea Timer of and have removed IE Security Plug 2006, Internet Security Add On and the Viewpoint Media Player.

    This is my first Smitfraud rapport.txt
     

    Attached Files:

  5. visageeza

    visageeza Private E-2

    My second rapport.txt
     

    Attached Files:

  6. visageeza

    visageeza Private E-2

    My GetrunKey, Show New and Hijack logs...
     

    Attached Files:

  7. visageeza

    visageeza Private E-2

    Heres my Spybot report, which now tells me i have no problems! No more Torpig! If anyone could just have a quick butchers for me and make sure im not missing anything, that would be great :)
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your Windows OS is way out of date with updates and represents a major security risk. When you add this to the fact that you are running without an antivirus, it is just downright dangerous to your security. You must get updated and you must install an antivirus application. However do not attempt to update Windows yet! Wait until we finish removing your malware.

    In addition to the above, you did not follow the directions in the READ ME and install the current version of Spybot. You are using Spybot - Search & Destroy 1.3 which is about 3 years out of date. You must uninstall this now and then reboot. After reboot, install the current version from the link given in the READ ME.

    Also you did not uninstall Viewpoint Media Player as requested
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your Windows OS is way out of date with updates and represents a major security risk. When you add this to the fact that you are running without an antivirus, it is just downright dangerous to your security. You must get updated and you must install an antivirus application. However do not attempt to update Windows yet! Wait until we finish removing your malware.

    In addition to the above, you did not follow the directions in the READ ME and install the current version of Spybot. You are using Spybot - Search & Destroy 1.3 which is about 3 years out of date. You must uninstall this now and then reboot. After reboot, install the current version from the link given in the READ ME.

    Also you did not uninstall Viewpoint Media Player as requested in step 0 of the READ ME. Uninstall this now.

    Also uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software


    Now we need to remove a trojan service!

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to WindowInstallSystem
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pastef7c0ebf554fsvr into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O23 - Service: WindowInstallSystem (f7c0ebf554fsvr) - Unknown owner - C:\WINDOWS\f7c0ebf554f.exe (file missing)

    After clicking Fix, exit HJT.
    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.

    1. ShowNew
    2. HJT


    Make sure you tell me how things are working now!
     
  10. visageeza

    visageeza Private E-2

    Hi Chas
    I had uninstalled Viewpoint Media Player but it somehow appeared again??? not sure what i did wrong. I have have also now updated spybot and i will get one of the recomended anti virus programes from here once i have finished with the rest of my crap!

    I have gone through your last instructions, below are the attached files as requested. Everything appears to be running fine and spybot hasnt picked anything up.

    Anything else i need to do?

    Cheers
    V
     

    Attached Files:

  11. visageeza

    visageeza Private E-2

    And here is my latest and greatest Spybot log, incase its of any use?
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's back again!

    Run this ViewpointKiller to remove Viewpoint Media software.

    Save a log from ViewPointKiller and attach it.

    Also attach a new log from ShowNew. Then immediately get started on the below instructions. Make sure you do not skip step 1 of the How to protect yourself link.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  13. visageeza

    visageeza Private E-2

    ViewpointKiller tells me it was unable to find or delete Viewpoint etc. Below is the requested attachments. Ill crack on with the other steps now. Winner!:cool
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  15. visageeza

    visageeza Private E-2

    GetUnKeys as requested...
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Start, Run, and copy and paste the below into the run box and then click OK:

    C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u

    Do you get an error messages? If so tell me what they say.

    Does Viewpoint Media Player still appear in a new log from ShowNew? If so, do the below:

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Attach a new log from ShowNew.
     
  17. visageeza

    visageeza Private E-2

    Im no expert, but i think that might have done it!
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're clean now! Make sure you have followed all those instructions I gave in message # 12.
     
  19. visageeza

    visageeza Private E-2

    Chas
    Your a beautiful human being, may the gods smile upon you and bring you good karma! Thanks for the help, its very much appreciated, theres no way i could have gotten through that myself.

    Cheers
    V
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome and thanks! ;)

    Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds