Help PC still infected

Discussion in 'Malware Help (A Specialist Will Reply)' started by jbutler01, May 14, 2009.

  1. jbutler01

    jbutler01 Private E-2

    I have run the Read me First procedure followed by the Windows Xp Cleaning Procedure.

    I am still having very slow Internet reponse, and today a new tool bar called LiveInfoPro appeared. I ran mulitple scans yesterday of Symantic anitvirus and Spy bot search and destroy. The anti virus found nothing. Spybot found Virtumonde.sdn, Win32.tdss.rtk, WIn32.Agent.pz, and Win32.zbot.

    I ran your procedures today and I am attaching the logs per your suggestion. I believe I ran the MGTools scan twice since I followed the instructions for Windows 7 instead of Windows XP. The first time I ran it, it told me that it found the following:

    c:/Windows/Sys32/driver/ovfsthxrqjwsoui.sys
    c:/Windows/Sys32/driver/ovfsthxuowqgkut.dll
    c:/Windows/Sys32/driver/ovfsthxrgmupaot.dat
    c:/Windows/Sys32/driver/ovfsthxgvxobgli.dll
    c:/Windows/Sys32/driver/ovfsthxphxexylh.dat

    Any help you can provide would be greatly appreciated.

    Thank you
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    MGTools doesnt pop anything up as to finding malware. Do you mean one of the other scans? Combo found what you are referring to and removed it so we only have a few items to deal with.

    First!! You should not allow all users to have admin. privileges!! Very bad idea!!
    Second you should run both SAS and MBAM on each user account. Attach any log that shows malware and label it for the user account.

    Please use add/remove programs to uninstall:
    URL Assistant

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now use windows explorer to find and delete:
    c:\program files\wt3d.ini
    C:\WINDOWS\Tasks\At1.job

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. jbutler01

    jbutler01 Private E-2

    Thank you for the guidance. I have completed all of the steps as requested, except removing the admin capabilities from the other users. I will do that today, but no one has used this laptop except me since the last post.

    Both SAS and Malware found some issues within the other user accounts. I have attached all the logs here. I will also attach the MGlogs to a follow up posting.

    Thanks again.
     

    Attached Files:

  4. jbutler01

    jbutler01 Private E-2

    The MGlogs are attached.
     

    Attached Files:

  5. jbutler01

    jbutler01 Private E-2

    I decided to run Spybot Search and Destroy as well as Symantic Antivirus to see if it detected anything.

    Each did. Spybot found Virtumonde, and Symantic found a few trojans. I am attaching those files as well. The Spybot log is broken into two sections since the log was too big and this PC does not have zipping software.

    Thanks again.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean......you can use windows explorer to see if this still exists and delete it if it does:
    C:\WINDOWS\system32\zipfldr.dll

    but it is not showing in your logs.

    You still have all users with admin. privileges!! I again suggest that you set all of them save one to power user status. ( Or with children..limited status).

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds