Cleaning Avt.exe

Discussion in 'Malware Help (A Specialist Will Reply)' started by Alaina, Aug 17, 2010.

  1. Alaina

    Alaina Private E-2

    I’m trying to clean my daughter’s computer of antivirus pop-ups (avt.exe). She tried using mbam and restore a couple of times until we figured out Windows Restore must be infected.

    This virus gets worse every time you reboot and puts everything back in that’s been taken out. It redirects the internet to their site. It took down her antivirus program and then deleted it. It stopped all executable and command files from installing, opening or running. It started giving black screens and we had to keep shutting it off to get it back up.

    I did the Run & Read Me First through Step 6 by using safemode and downloaded all tools from my computer and put them on her flash drive. I couldn’t update the Java but everything else was okay. I did run Defogger but it looks like I didn’t need to.

    I got stuck on Windows XP cleaning. The instructions said SAS would not install or run in safemode. I didn’t know where to go from there or what else I could run (except mbam) so I posted for help but it got lost somewhere.

    Bleeping Computer had a page on getting rid of avt.exe, so I tried that but it didn’t work. They had a list of files for this virus so I manually deleted them all plus a batch file I found that wasn’t listed (I didn’t touch the registry—I don’t go there). That worked great. Then I realized I had forgotten to unregister the dll’s before I deleted them.

    I was able to go back and do all the R&RMF in normal mode (no pop-ups!). Everything installed and ran and the reports are attached.

    I had a little trouble with Combofix. It went to the internet for the Recovery Console and I got a Windows Security and balloon pop-up. I couldn’t tell if it was the real thing or not. At Stage 48 I got an error message “Pev.exe has encountered a problem and must close. All data will be lost”. I did eventually click “Don’t send report” but the program didn’t close. It finished and I hope it’s okay.
     

    Attached Files:

  2. Alaina

    Alaina Private E-2

    Remaining log
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What anti virus were you using before it destroyed it? AVG or Norton?

    What is this?

    C:\dr.com <--- If you do not know then just delete it.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\system32\drivers\tnzgef.sys
    c:\documents and settings\NetworkService\Application Data\ranmiq.dat
    
    Folder::
    c:\documents and settings\Sara Milam\Local Settings\Application Data\mpoleiowb
    c:\program files\Ask.com
    c:\documents and settings\All Users\Application Data\Viewpoint
    
    Registry::
    [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\tnzgef]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know how things are running?
     
  5. Alaina

    Alaina Private E-2

    Thanks for your quick reply, that was really wonderful.

    The antivirus program my daughter was using was Live OneCare. After that was removed, she tried AVG but her system can't handle it. I think she wants to try Avast. I'll install that and see how it works.

    Norton has never been installed on her machine. That came bundled with the malware. They used Norton pop-ups and Windows Security Center pop-ups along with their own. I'll have to clean those out, it's just leftover log files now.

    C:\dr.com is just a small ms-dos program I use. It's okay.

    I'm attaching the two reports you wanted. Everything looks okay so far. Once I have an antivirus program installed and working, the pop-up I'm getting now will go away if it's legit. If the reports look clean I can start finishing up and do something with Windows Restore. So please let me know how the reports look.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Don't install any anti virus yet. Reviewing your logs now.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What is this, seen on your desktop?

    • fhjksd.com <--- If you do not know then just delete it.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    c:\documents and settings\LocalService\Application Data\ranmiq.dat
    
    Folder::
    c:\documents and settings\Sara Milam\Local Settings\Application Data\Symantec
    c:\documents and settings\All Users\Application Data\Norton
    c:\documents and settings\All Users\Application Data\NortonInstaller
    c:\documents and settings\All Users\Application Data\avg9
    c:\program files\AVG
    c:\program files\Microsoft Windows OneCare Live
    C:\Documents and Settings\Sara Milam\My Documents\Symantec
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Install some anti virus at this point.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this. Don't forget to address my question regarding the file on the desktop.
     
  8. Alaina

    Alaina Private E-2

    Kestrel, I really thank you for helping me so much.

    The file on the desktop “fhjksd.com” is tdsskiller.exe. The instructions were to rename it to make the malware not recognize it. But then no one recognizes it so my daughter did the same thing. Hence the same file under Administrator desktop named 321.com. I deleted both of them since it’s included in MGTools.

    Thank you for noticing Symantec. That one passed right by me even though I can remember seeing it earlier. There’s another Symantec file I can delete unless you prefer I use Combofix again:

    C:\Documents and Settings\Sara Milam\Application Data\Tific\tificocs.symantec.com.tfc

    Two other things I noticed I’d like to ask about.

    Windows Sidebar and Gadgets came out with Vista (I’m running Windows XP). The folders for it are now in Program Files but are empty. I don’t know anything about this Windows tool so don’t know if I should be looking for something else that may have been put in with it or if it’s okay to just delete the folders and not worry about it.

    The other thing is Windows Update. On the Start Menu the link name was changed to 77. It still points to c:\system32\wupdmgr.exe. Is it possible they could have changed the .exe file? I really don’t want to click it to find out.

    Reports are attached. Avast Antivirus is installed. The pop-up I kept getting when running Combofix went away after Avast updated the database.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Maybe you were once using XP compatible sidebars/widgets? Although the folder date is from only a few days ago. You can further discuss this in software forum because considering they are empty, and therefore contain no malware files, I would rather you did ask in software.

    Yes you can just delete that using windows explorer.
    Let's have jotti scan it and I'll have you see if you can zip it up.

    Please go to Jotti's malware scan

    (If more than one file needs scanned they must be done separately and logs posted for each one)
    • Copy the file path in the below Code box:
      Code:
      c:\system32\wupdmgr.exe
    • At the upload site, click the browse button.
    • Use Windows Explorer to navigate to the file(s) we need scanned and click "submit file"
    • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    • This will perform a scan across multiple different virus scanning engines.
    • Important: Wait for all of the scanning engines to complete.
    • Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.

    Could you please get this: wupdmgr.exe into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:
    log retrievable @ C:\collect.zip

    Now also (I am using a windows 7 computer at present) I believe you can rename a shortcut to a program on your start menu, so you could just rename it back to what it should be. Try that if Jotti reports nothing, which I suspect it will.
     
  10. Alaina

    Alaina Private E-2

    Hi Kestrel

    Just as you suspected, everything looks good, nothing was found. Yes, I can easily change the link name back, it just really hit me as strange that it did that.

    Here's the link to jotti's scan results (I hope I did this right):

    http://virusscan.jotti.org/en/scanresult/3a8b51e4f2f2292a531a58ab323957dc4b920a3c/9a182604a8ec325cfd1f4394822d1e95fef8f7b8

    The zip file for wupdmgr.exe is attached.

    Everything looks great on this side. Doing the jotti scan is the first time I've been on the internet since this happened. I'm amazed at the results. If everything on your side looks good, I'd say we're clean and good to go, and thank you so much for all your help. You've been absolutely wonderful!
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's good to hear! :) And you are more than welcome for the assistance.

    Safe surfing!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds