Help needed please!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Funky Monkey, Jul 29, 2008.

  1. Funky Monkey

    Funky Monkey Private E-2

    Hi, I was wondering whether someone could help me. My parents’ PC has some kind of virus on it that I’m trying to remove. My parents say that they first noticed it on 22/7/08. My mum says she was visiting a website, accessed from ‘My history,’ when she thinks that the virus first struck (though she can’t be sure this is where the PC was infected). Her wallpaper had changed to one of a dark(ish) blue background, which displayed a “Warning! You’re pc is infected with spyware..” message (the message was much longer than this, and was displayed in red and white writing). Pop-ups and browser windows appeared also, directing her to some Canadian site advertising Viagra etc. Also, two Windows security shields appeared in the system tray in the bottom right. My mum says pop-ups kept appearing saying her computer was at risk, and a browser window opened advertising some kind of spyware removal site. Another pop-up appeared saying that she had a Trojan SPM/LX. My parents ran Norton (which didn’t pick up anything), and they ran scans using SmitFraudFix, AdAware and SpyBot S&D. After each scan, the virus seemed to disappear but would return after 5 or so minutes. Since running SpyBot, my mum says her browser has not been redirected and she hasn’t had any warning pop-ups (wallpaper had still been altered though).

    Since my mum did this, I have followed your malware removal guide to the best of my ability. The only problems I encountered were emptying all the quarantined items for Norton and also emptying the Norton nprotect folder (my parents’ copy of Norton runs through BT Yahoo! Online Protection and I couldn’t find how to do both of these things). Also I couldn’t check for updates when running Spybot S&D as it kept on displaying an error message. Since running ComboFix, I have noticed that the wallpaper (as described above) has not reappeared, and there is now only one Windows security shield appearing in the system tray. However, I’m not sure that the virus has entirely been removed. Also, either every time the PC loads or I attempt to connect to the internet, error messages appear (ones saying sysuxvmschra.exe, and syscdupretna.exe have encountered a problem and need to close, click here to send an error report etc). There was another error message but I can’t remember what it contained – this also disappeared after running ComboFix. Finally, whenever the PC loads, a message pops up asking whether I want to run the software Solita~1.exe. Even though I click cancel this message appears every time the PC is switched on. Basically, I’m wondering whether any of these issues are connected to the virus. I haven't run any of the scans in safe mode.

    Anyway, here are my logs, any help would be much appreciated. Thank you.
     

    Attached Files:

  2. Funky Monkey

    Funky Monkey Private E-2

    Here's the MGlog too.

    Thanks.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    This is a game that some one installed for playing Solitare. Do you really want to remove it? If so, add the below line to the fix further down with HijackThis:

    O4 - HKCU\..\Run: [SolitaireChampionshipSetup.exe] C:\DOWNLO~1\SOLITA~1.EXE /r

    Do you or your mom recognize what the below folder is?
    Code:
    2008-07-23 08:16 --------- d-----w C:\Program Files\WomensMurderClub_at


    Uninstall Viewpoint Media Player as requested in step 1 of the READ & RUN ME.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [{09E23F2C-ED1E-43FC-9AA1-1332162A35AE}] "C:\WINDOWS\sysuxvmschra.exe"
    O4 - HKLM\..\Run: [{0389E53C-62CF-4CD6-9F4E-955A740E4385}] "C:\WINDOWS\syscdupretna.exe"
    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game04.zylom.com/activex/zylomgamesplayer.cab

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
     
  4. Funky Monkey

    Funky Monkey Private E-2

    Thank you!!

    Hi,

    Thanks so much for all your help. I have followed your advice and I haven't noticed any more error messages popping up or the fake windows security icons reappearing either.


    This is a trial game that my Mum downloaded - don't worry she's not planning on killing anyone :-D


    Yeah - we got a success message.

    Here are the logs you requested. Thank you again!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the combo-fix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combo-fix folder from combofix.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds