Cleaning up AIM Virus, etc.

Discussion in 'Malware Help (A Specialist Will Reply)' started by tearsforsappho, Feb 11, 2006.

  1. tearsforsappho

    tearsforsappho Private E-2

    I apologize for having to seek help, but I am battling some malware here that is much more tech-savvy than I.

    Just for background, I contracted a strain of the AIM virus sometime over the last few weeks. My partner frequently forgets to sign off her aim, and the night before last, it randomly sent virus-infected links to everyone on her buddy list. I do not have the link, as everyone either contracted the virus or closed the window. However, it was something like "should I post this on Myspace?" with a link that appeared to be to a myspace image.

    That said, I am afraid there are many other things amiss. Before coming to this forum, I had run Ewido, Webroot Spysweeper, and per the advice of a freind, disabled system restore. I do have an expired version of Norton also, but it is of little use.

    I read and performed all steps in the "read me first before asking for support". Given that I already had system restore disabled, I re-enabled it.

    I am incredibly unsure that everything has been fixed. I still have strange exe files in my root directory, and a very suspicious "try aol free for 50 days" on both my desktop and start menu. I say it is suspicious, because the icon just doesnt look right. I know that sounds stupid, but if you saw it you would know what I meant.

    In any case, I am posting a HJT log, an activescan log, and adaware log.

    FYI:

    Microsoft Antispyware Detected:

    Yazzle Sudoku (deleted)

    EDonkey 2000 (deleted)

    Spybot S&D Detected:

    NewDotNet (not fixed)

    Windows Security Center.AntivirusDisableNotify (fixed)

    Windows Security Center.AntivirusOverride (fixed)

    Windows Security Center.FirewallDisableNotify (fixed)

    Windows Security Center.FirewallOverride (fixed)

    Windows Security Center.SP2Update (fixed)

    Windows Security Center.UpdateDisableNotify (fixed)

    Microsoft Windows Malicious Software Removal Tool detected nothing

    I hope someone can help me, as I am at my wits end. Thank you in advance.
     

    Attached Files:

  2. tearsforsappho

    tearsforsappho Private E-2

    Sorry, I forgot to attach the Bitdefender log, so here it is.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not a log! It is only a summary. A summary only indicates problems that were found by virus/trojan name but give no additional info on where the problems are. You should have followed the directions in step 6 and you would have a log.
     
  4. tearsforsappho

    tearsforsappho Private E-2

    I am so sorry. This is my first go at this sort of thing, I thought that was the log. Ill go ahead and do that now, and post the actual log.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I'm working on a fix for something I see in your log. But I have a question too.


    Is your Verizon Toolbar working OK! See if the below file is really missing.
    O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\PROGRA~1\COMMON~1\VERIZO~1\SFP\vzbb.dll (file missing)
    O3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\PROGRA~1\COMMON~1\VERIZO~1\SFP\vzbb.dll (file missing)
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Local Security Authority Subsystem Service (or if not found look for the short name: lsass) ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Local Security Authority Subsystem Service

    If that does not work try entering the short name: lsass

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
    O23 - Service: Local Security Authority Subsystem Service (lsass) - Unknown owner - C:\WINDOWS\scvhost.exe (file missing) <--- this entry may already be gone

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\PartyPoker <--- the whole folder
    C:\WINDOWS\scvhost.exe
    C:\WINDOWS\drsmartload.dat


    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.


    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  7. tearsforsappho

    tearsforsappho Private E-2

    Again, thank you so much for helping me out here. I did the bitdefender scan again in safe mode, and this was the only thing that came up when it said "click here to view report". I am afraid that it is the same thing as last time. If so, please tell me what I am doing wrong. I will complete the other steps and let you know what happens.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to follow ALL the steps in the READ & RUN ME in step 6. It says:

    You must follow it exactly as written. If you do, you will get an HTML file saved as a text file and that is what you will attach here.

    Did you do what I gave you in message # 6 yet? If not, do it immediately.
     
  9. tearsforsappho

    tearsforsappho Private E-2

    By the way, I looked for the files you asked about for the Verizon Toolbar, and they do appear to be missing. I wouldnt have noticed a phroblem though, since I dont use IE anymore. I switched to Firefox, and just log in from the webpage.

    Also, that is what came up, and it was an html page, that i saved as txt (per the instructions).

    Okay, on to steps in message 6.
     
  10. tearsforsappho

    tearsforsappho Private E-2

    Okay. I have finished the steps in message 6, and the new HJT log is attached.

    When I went into services.msc, I found lsass, but it was already stopped, however, I disabled it. Removing it with HJT appeared to work.

    When I ran HJT again (per instructions), the entry you said might be gone (O23 - Service: Local Security Authority Subsystem Service (lsass) - Unknown owner - C:\windows\scvhost.exe (file missing)) was indeed gone.

    Also, when booted into safe mode, i was able to delete the party poker folder and drsmartload.dat, however, scvhost.exe was missing. About scvhost.exe, this was something that was detected with the aforementioned ewido scan, and possibly that is why the entry was missing (it is also no longer in my processes).

    I was able to complete all steps without any issues, excepting those I just mentioned. Although the comp appears to be working better, I still have a couple exe files in C:\ that I am unsure of. they are:

    5050.exe
    ys5050.exe

    They both were created around the time I started having problems. Are they legit?
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if you can just delete those two files.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should also uninstall Verizon Broadband Toolbar since you do not use it anymore. Then if those two lines still show in HJT just fix them.

    Other than that, you are clean. I would not recommend using Ewido, SpySweeper and MS Antispyware as a permanent solution. This will slow your PC down and may cause conflicts.

    Did you purchase Ewido or SpySweeper?
    If not, do you plan to purchase them and keep buying yearly updates?
     
  13. tearsforsappho

    tearsforsappho Private E-2

    I was able to delete those two files. I was just unsure about whether or not it was alright to do so.

    I do have the paid version of SpySweeper (provided by my job), and it is good till October. Unfortunately, I am a very low budget student and have not been able to renew my Norton AV subscription.

    What should I keep? As of right now, i have:

    An expired (definitions have not been updated since i think april of last year) Norton AV. Should I just uninstall it? The definitions are so out of date that it is practically useless.

    In addition to that, I have the 15 day trial of Ewido, Spybot S&D, Microsoft AF, Windows MSRT, and Ad-Aware SE installed per the sticky thread. Should I delete some of these? If so, which ones? Should I get rid of HJT as well?

    Im sorry, I know I dont have the most up-to-date machine and with all these things running, it is slower than molasses on a cold winter day.

    Also, as soon as I am able to back-up my system, I am going to download the Windows XP SP2 (I am currently running SP1). Unfortunately, the recovery discs that were made on this computer were stolen, so I am not sure how to do that without losing everything.

    I am not sure how to uninstall the Verizon Toolbar, as the only entry for Verizon that appears in the "Add/Delete Programs" is the entire Verizon Online Program.

    Oh, and I discovered the culprit for the AOL icon actually was legitimately AOL. Those bastards will give you junk every chance they get. I am just going to delete the "AOD" folder from the Programs file (saw that on another thread).

    In any case, thank you so much. I am so glad you guys are around. I wish I had known about you last month when I nearly shot myself over a nasty SpySheriff infection on my work machine.

    Again, THANK YOU!
     
  14. tearsforsappho

    tearsforsappho Private E-2

    I am so sorry for being a bother, but I found this txt file in my C:\. What the hell is it?

    d.txt

    Im afraid to open it, but I know it wasnt there before all this crap started.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Keep Spy Sweeper for now since it is one of the best spyware removal programs.
    Uninstall MS Antispyware, Ewido, and since your Norton has expired you should completely uninstall it because it is not much good without the ability to update.

    You can install one of the free AV's recommended in the link I will give below with your next instructions.

    You do not need recovery discs to update to SP2. Just follow the step given further down.

    If you do not use any Versizon or AOL stuff, just uninstall all stuff related to them.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds