Bad Virus/Worm

Discussion in 'Malware Help (A Specialist Will Reply)' started by Chala, Feb 25, 2008.

  1. Chala

    Chala Corporal

    I am fairly knowledgeable about computers (i thought) but I am just stunned on this one. I downloaded and ran an application that had a bad virus/worm. I cannot connect to the Internet through dial-up or high speed cable or anything. I want to try to do everything to avoid reinstalling windows. I do not have the original XP disk that came with the machine, i do have a XP Professional though.. Its an old machine running windows XP Home, 533 MHz, with only 256 MB of ram, but I like this machine and want to save it. I mostly use it as an alternate connection to the Internet (using dial-up) but I can route high speed to it when necessary. I use AOL to get to the Internet this worm won't let AOL load, won't let Internet explorer load, and has shut off all services and connection to the Internet. I deleted the files but rebooted before i could toggle system restore so i know it spread to all kind of files. I don't know where to start. I do have the Windows XP disk if all fails.
     
    Last edited: Feb 25, 2008
  2. Chala

    Chala Corporal

    This is my log
     

    Attached Files:

  3. Chala

    Chala Corporal

    I can see why the experts have not even answered my post i did not follow the "READ & RUN ME FIRST" i am in the process of doing that now, but the worm i have disabled my installer and i cant update (anything no connection to internet) i hope after i follow instructions that i get help.
     
  4. Chala

    Chala Corporal

    Wow, trying to do "READ & RUN ME FIRST" i uninstalled Java when i tried to install the new one the virus won't let me, tell me java "is not a valid Win32 application" i am so screwed.
     
  5. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Because on average there are 200 people in this forum and maybe 2-3 volunteers helping you for FREE. Im sure if you take it to a shop, they will be glad to help you for a large fee. Otherwise, you could have simply read the sticky threads here, rather then repeatedly bumping your own thread and private messaging people, for example:

    http://forums.majorgeeks.com/showthread.php?t=104916

    Please be patient, they will get to you in order :)

     
  6. Chala

    Chala Corporal

    I will think twice before i private messge that "person" again. Did not mean to offend that person.I am fairly new to posting on here and will be more prone to follow protocal in the future. I apologize, i will be patient and see what happens.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Unless you can get us the logs requested in the READ & RUN ME, we cannot help you. There is nothing in HJT log that you posted but that does not mean very much since HijackThis is not that useful by itself especially when not properly installed.
     
    Last edited: Feb 28, 2008
  8. Chala

    Chala Corporal

    Thank you very, very, much Chaslang, for posting in my thread and offering your expertise, i really appreciate it.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Are you attempting to run as much of the READ & RUN ME as possible? You can also attempt to run things in safe boot mode as an alternative if you have issues in normal boot mode.
     
  10. Chala

    Chala Corporal

    I did run many of the scans, and amazingly after running combofix I was able to get a connection. Then I just ran numerous scans i.e. spysweeper...adaware...SUPERAntiSpyware...Kaspersky... CWShredder etc I pretty much have my machine up and running 100% again. Did not want to bother you guys with logs there are many others who need help, I am fine and satisfied. Thanks for your time and help!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  12. Chala

    Chala Corporal

    Opps Chaslang i misspoke, i do need something removed. I have ISTsvc\istsvc.exe in my Program files, i don't think it's good can't find it can't remove it. Combofix brought it to my attention, log attached. Please tell me what you think if you need other logs posted i will not have a problem doing so.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes please attach the other requested logs from SUPERAntispyware and from MGtools.exe Make sure that you are not using MSconfig to control startups. See step 1 of the READ ME. Based on your ComboFIx log you ignored this step. You need to attach new logs after you are in Normal Startup mode.
     
  14. Chala

    Chala Corporal

    Gotcha this will take quite a few hours so i will hear from you tomorrow thanks.
     
  15. Chala

    Chala Corporal

    Chaslang I am trying to run scans as per READ & RUN ME in Normal Startup mode but Spysweeper is giving me major problems as it is part of my Normal Startup mode. Can i just disable Spysweeper to run some of these scans?
     
  16. Chala

    Chala Corporal

  17. Chala

    Chala Corporal

    Ok Chaslang, I am posted the logs requested. I had to disable spysweeper by going to msconfig and unchecking. I did not change startup selection, if unchecking spysweeper the startup selection changed to selective, well this is the best I can do. I cannot possible run those scans with spysweeper in the background. So if you and the other experts won't read my logs I understand, I did my best. Thanks for your help just the same.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see AOL Spyware Protection, Spy Sweeper and Windows Defender installed. Is AOL's Spyware Protection actually Spy Sweeper? You may be running three antispyware protection programs which is not recommended. They will conflict and make each less effective. If you are going to keey Spy Sweeper, uninstall Windows Defender now and uninstall AOL Spyware Protection too if it is not actually Spy Sweeper.

    Did you setup the below yourself?
    O24 - Desktop Component 0: (no name) - http://www.defjam.com/llcoolj/assets/images/home-photo2.jpg

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    Java(TM) 6 Update 3
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    You have a load of malware trapped in MSconfig. I'm going to give you a fix below to remove this but it will also remove the Spy Sweeper startup unless you put your system into Normal Startup mode first. So put it in normal startup mode now. Later when you go to run ComboFix, just shutdown Spy Sweeper.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
     
    Driver::
    iMSPQMn
     
    File::
    C:\DOCUME~1\Owner\LOCALS~1\Temp\iMSPQMn.sys
    C:\WINDOWS\qyhsotqe.exe
     
    Folder::
    C:\Program Files\ISTsvc
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds