Annoying worm problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by Segan, Jul 1, 2006.

  1. Segan

    Segan Private E-2

    Well, it seems I have a worm on my computer. Unfortunately, it looks like a doozy, because only one program (that's not even on your list), was able to find it.

    The virus: W32/Rbot-EMH (info: http://www.sophos.com/security/analyses/w32rbotemh.html)
    located: C:\System Volume Information\_restore{727DD664-9803-4C41-A707-19E3640DBBB4}\RP564\A0632126.exe
    Found with: http://www.sophos.com/support/knowledgebase/article/3252.html

    What I did:
    -I first noticed the problem when my commercial virus scanner (http://www.bsafehome.com/moreinfo.asp?product=264) found some viruses on my computer. It managed to delete all but 1.
    -I was then directed to the program mentioned above to get rid of the final virus. It did, but managed to find another problem as well (the one mentioned above). While it was able to delete the infected files it found, the problem still persists, and my guess is that the virus respawned itself through the registry.
    -I came to these forums, and followed the list mentioned in the sticky. Not one of the programs found the virus mentioned above, but there were a few minor spyware problems detected. My guess is that virus is somehow tied to the spyware issues, because I didn't have any problems before it appeared.

    Symptoms:
    -The sound is distorted.
    -There are a few antivirus advertisements appearing.
    -The taskbar (I think that's what it's called), has disappeared on occasion in normal mode (minimising a program seems to fix this problem), and the whole desktop disappeared once in safe mode.

    I will attach the Panda activescan file below. I performed the bitdefender scan, but there was a mistake made and the log file was not saved (it found no problems). I am in the process of running it again, and will post the new log asap, but thought that there might be enough information here to start dealing with this problem.
     

    Attached Files:

  2. Segan

    Segan Private E-2

    And here is the bdscan file.
     

    Attached Files:

  3. Segan

    Segan Private E-2

    And here is the HijackThis log.
     

    Attached Files:

  4. Segan

    Segan Private E-2

    Update: I ran the sophos program again, and it found nothing this time (seems like it deleted the file successfully, but the symptoms still exist).

    The major problem is that sounds on my computer sounds are distorted to sound like they are echoing. Could it be that this problem is simply system settings that have not been corrected after the virus was deleted, or is there still something lurking on my hard drive?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Your sound problems are more than likely not related to malware but you do have malware. Also, you have no antivirus and no firewall on your PC. And you probably had no antispyware program unitl you installed Windows Defender while running the READ ME. This is very dangereous.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [Windows Recycler] gmecnl.exe
    O4 - HKLM\..\RunServices: [Windows Recycler] gmecnl.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    <--- the whole folder:
    C:\windows\system32\gmecnl.exe
    C:\WINDOWS\DWINSTALL329.bat
    C:\WINDOWS\system32\iifeedc.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file. Let me know if you cannot delete any of these files!

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.
     
  6. Segan

    Segan Private E-2

    Sorry about the long wait... Right after posting last, "life" happened to me, and I havn't been able to get enough time to fix the problems until now.

    Because it's been a month since my last post, and because the computer had to be used since then out of necessity (even though there was malaware still on it), I went through the entire list on your first page again, just to make sure there were no other problems. I have posted all three scan files again.

    Other news:
    -The sound problem is gone. You were right, it wasn't a malaware problem!
    -Because things have changed by themselves, I did not do the steps you outlined before. As you will see, the lines you told me to remove seem to have removed themselves!

    Finally, I find it odd that you didn't see a firewall or antivirus on my machine, because I do have a commercial one installed (albeit, one that is not commonly used).

    Thank you so much for helping me with this problem.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you have picked up a new problem.....Virtumonde.

    Run this Virtumonde aka Trojan Vundo Removal and attach the requested log.

    Also attach a new HJT log.

    Tell me how things are running now.
     
  8. Segan

    Segan Private E-2

    Thanks for your help!

    Here are the files.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {8F42B650-DB72-4F6B-AAD4-D0F36B4F53DA} - C:\WINDOWS\system32\ddabb.dll (file missing)

    After clicking Fix, exit HJT.:

    Make sure you tell me how things are working now. You did not answer the last time I asked.
     
  10. Segan

    Segan Private E-2

    Thanks again!


    My computer is running great now. I do not see any symptoms of viruses! (Note: This has not changed since I got rid of the sound problem as well as the popup problem, even though there were still viruses left on my system!)
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  12. Segan

    Segan Private E-2

    Thanks a bundle!

    I'll be sure to go through that list, and I'm also bookmarking this great site for future notice!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds