Help!! Tried Everything

Discussion in 'Malware Help (A Specialist Will Reply)' started by ladyberdan, Feb 16, 2005.

  1. ladyberdan

    ladyberdan Private E-2

    Help!! I have the virus on my computer that infects the screen and makes it pixilated with residue from each page that comes up. After I tried all the below the virus got worse so the screen is even more densely filled with streaks and pixillation.

    Here’s what I’ve tried to get rid of it:

    1. Ran Norton Anti-Virus 2004 Professional with all updates downloaded automatically and redownloaded manually and performed numerous full system scans including in safe mode. No detections.
    2. Found 5 files in my Temp folder that won’t delete. One is Perfib_Perfdata. The others are numerical and change names each time I open Windows Explorer.
    3. Tried deleting all of them but get an error message saying the file is being used by another person or program.
    4. Tried deleting all of them using Move On Boot and tried in safe mode.
    5. Tried to right click on properties and advanced to take ownership of the file, but that option is not available. Simple file archiving and compression are my only options.
    6. Opened Task Manager, but cannot determine which of the processes running are tied to the virus, so don’t know which to shut down.

    See below for everything else I’ve tried. Any suggestions would be greatly appreciated!Getting Prepared; Steps to be sure your system is ready to be scanned:

    1: Disable System Restore temporarily
    DONE
    2: Network Security, Workstation Netlogon Services & Remote Procedure Call (RPC) Helper (Windows XP, 2K, NT);
    DONE—No listed services found3: Enable viewing of hidden files and folders and extensions;
    DONE
    4: Downloading Tools; Download the following tools
    Ad-Aware SE.......Install, click Check for Updates now and get any updates, then exit. DONEAd-Aware VX2 Cleaner Plug-In.....Install only DONE
    CCleaner.............Install only, then exit DONE
    Spybot................Install, do the search for updates now and get any updates, then exit. DONESpybot - Search and Destroy DSO Exploit Fix - Install this patch on top of Spybot to fix the DSO Exploit bug DONESpywareBlaster...Install, click Download Latest Protection Updates, Check for Updates, and then Enable All Protection, then exit. It does a great job of blocking known vulnerabilities as well as known malicious websites. DONE
    McAfee AVERT Stinger.....No installation required! Ready to run as is. DONE
    CWShredder......No installation required! Just unzip it to a folder. DONE
    Kill2me..............No installation required! Just unzip it to a folder. DONE
    about:Buster......No installation required! Just unzip it to a folder. Click Update & download any before scanning. DONE
    HSRemove........No installation required! Ready to run as is. DONE
    All of the above were run in safe mode—problem still not solved

    Scanning And Cleaning Steps: (note steps 1 thru 4 are NOT optional!)

    1: Virus And Trojan Scanning
    DONE—No viruses found with Symantec or with Avert Stinger. Trend Micro found the following viruses:
    TROJ_RVP.D (non-cleanable)
    C:\programfiles\commonfiles\jav
    C:\programfiles\commonfiles\xmc\xclean.exe
    C:\programfiles\commonfiles\xmc\xcpyl_inst.exe
    When the screen prompted, I clicked Delete.
    2: Clean Your Hard Drive; Remove temporary internet and other files not needed with CCleaner. Run CCleaner DONE in normal mode and in safe mode
    3: Main Spyware Scan And Removal; Scan your machine with Ad-Aware SE (remember to install the Ad-Aware VX2 Cleaner Plug-In for it) and Spybot. Look for the Immunize feature in Spybot and use it. Make sure you install the Spybot DSO Exploit patch before running a scan with Spybot. DONE—no threats found

    4: Secondary Spyware Scan And Removal: Other Removal Tools; Run the other programs you downloaded; CWShredder (make sure you select Fix), Kill2me, about:Buster and HSRemove. They are free, standalone and easy to use. DONE in normal and in safe mode
    These final 2 OPTIONAL steps require you reboot back to normal mode.

    5: OPTIONAL: If you can not remove the stubborn "Only the Best" aka "HSA" HIJACKER please view this thread by Chaslang, an expert in removing these things, can be found here: http://forums.majorgeeks.com/showthread.php?t=38772

    Did not do this. The tutorial was complicated, I wasn’t sure of what I was doing. I’m also not sure which viruses I have.

    6: OPTIONAL: Scan With Hijack This; If you have gotten this far without success, you may need to download Hijack This!.
    DONE see below for my log file.

    Make sure that you tell us in your post that you've already followed the instructions on this page so we don't waste your and our time by posting a link to it in your thread. Also, it would be helpful to indicate what kind of problems the above steps have found and fixed (or failed to fix).

    I’ve already followed the instructions on this page.

    Alternative Scans - If still having problems

    If you are still having problems after performing all the above, these alternative scans below may prove to be useful. As mentioned above, it would be good to perform these in safe mode since it may assist in the ability to remove an infection. However, there are cases where a problem does not show itself completely until you boot in normal mode. So first run these scans in normal boot mode, and if they have problems cleaning any particular items repeat the scan in safe mode to see if it helps. Always keep track of what these scans find (save logs or take notes), and report them back in your thread to anyone helping you.

    Bitdefender online scan DONERavAntivirus online scan <-- select Auto Clean then click Scan My PC
    TrojanScan online scan

    a-squared (a²) Free edition free but requires an email address to register
    avast! Virus Cleaner Tool
    ADS SPY - Alternate Data Streams Spy from Merijn

    Recent browser hijackers started using ADS to hide their files, and very few anti-malware scanners detect this. Use ADS Spy to find and remove these streams. Note: this app also displays legitimate ADS streams. Don't delete streams if you are not completely sure they are malicious! You should consult with an expert before deleting any files with this tool.

    I have not done this. I’m not an expert.


    Edit by chaslang: Inline log changed to an attachment.
     

    Attached Files:

    Last edited by a moderator: Feb 16, 2005
  2. seaside

    seaside Corporal

    hi i cannot help with the virus solution.but it might be worth trying to reinstall your graphics card drivers
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to follow the guidelines in the HijackThis tutorial. You are not running HJT from the proper folder and you must only post logs when they are requested, and they must be posted as an attachment to your message.

    You have HJT running directly from the ZIP file which is exactly what we request that you not do. You have it here: C:\Documents and Settings\Kris\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe


    Microsoft Word should not be running when you are using HJT. It is a totally unnecessary application for normal PC operation:
    C:\Program Files\Microsoft Office\Office\WINWORD.EXE

    Follow the steps below and also make sure you get the new version of HijackThis and use it:

    Make sure you have HijackThis 1.99.1 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
    Last edited: Feb 16, 2005
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are the below entries for Proxy Servers required by your ISP:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=192.168.0.1:87
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://www.direcwaysupport.com;192....waysupport.com: 192.168.0.1;<local>

    Please make sure you have correct the issue with running HJT out of the ZIP file and have installed as requested before continuing.

    Verify you have system restore disabled and viewing of hidden files enabled.

    First download and run this: Adware T.V. Media Removal Tool
    Let me know if it finds anything.

    Run HijackThis VERSION 1.99.1 and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - C:\Program Files\TV Media\TvmBho.dll
    O2 - BHO: (no name) - {7CD20E91-1F31-41da-8379-479EA31DF969} - (no file)
    O3 - Toolbar: (no name) - {BDF6CE3D-F5C5-4462-9814-3C8EAC330CA8} - (no file)
    O4 - HKLM\..\Run: [Spyware remover] C:\WINDOWS\Remove_spyware.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete (if still there):
    C:\Program Files\TV Media <--- the whole folder
    C:\WINDOWS\Remove_spyware.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Let me know if you have any problems finding or deleting any of these files.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. ladyberdan

    ladyberdan Private E-2

    Dr C.

    Thanks a lot for your help and for your patience. I really appreciate it! Still I haven’t had any success. See below>>
    Are the below entries for Proxy Servers required by your ISP:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=192.168.0.1:87
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://www.direcwaysupport.com;192....waysupport.com: 192.168.0.1;<local>

    Yes, the two entries listed are required by my ISP.
    Please make sure you have correct the issue with running HJT out of the ZIP file and have installed as requested before continuing. DONE
    Verify you have system restore disabled and viewing of hidden files enabled. DONE

    First download and run this: Adware T.V. Media Removal Tool
    Let me know if it finds anything.

    It gave me an error message saying my system was missing 1 or more critical updates. However, I had installed all updates when I first started working on this virus problem. Now when I got to get the updates, Internet Explorer becomes non-responsive and won’t load the page. I tried this several times though IE is working for accessing other sites.
    Run HijackThis VERSION 1.99.1 and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - C:\Program Files\TV Media\TvmBho.dll
    O2 - BHO: (no name) - {7CD20E91-1F31-41da-8379-479EA31DF969} - (no file)
    O3 - Toolbar: (no name) - {BDF6CE3D-F5C5-4462-9814-3C8EAC330CA8} - (no file)
    O4 - HKLM\..\Run: [Spyware remover] C:\WINDOWS\Remove_spyware.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete (if still there):
    C:\Program Files\TV Media <--- the whole folder
    C:\WINDOWS\Remove_spyware.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Let me know if you have any problems finding or deleting any of these files.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Did all of the above. Put HJT 1.99.1 in its own folder on the D drive, fixed the items listed above, deleted the files listed above without a problem. I’m attaching the new HJT log. Still No improvements found.

    Two questions:

    Do you have any suggestions or insights about the temp files that won’t delete including the perfib-perfdata?

    Also, is my last resort uninstalling and reinstalling Windows? If I had to do this, how would I assure the virus wasn’t transferred back in when I reconstruct everything and load my programs and data?

    Thanks again for your help!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re installing is the last resort. Let's worry about that when necessary. Nothing is guaranteed if you reinstall from backups that have infections within them.

    Did you try to delete those files after booting in safe mode? If that does not work, provide me full path information to the files.

    You forgot to post your log!
     
    Last edited: Feb 18, 2005
  7. ladyberdan

    ladyberdan Private E-2

    Thanks. Here's my log.

    Yes, I tried deleting those temp files in safe mode.

    There are 10 of them now. C:/WINDOWS/Temp/perfib_perfdata_2d0.dat

    This one says it has 16 kb in the file. Also the numerical extension changes each time I try to delete the file.

    The other 9 are
    C:/WINDOWS/Temp/JETC8E8.tmp

    and other similar names starting with JET that each show 0 kb in the file but that change the file name every time I try to delete them.

    Thanks!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What I want you to try is to boot into safe mode and kill all unnecessary processes and exit browser sessions and any other applications except for one Windows Explorer window to be used to delete the file.

    Here is what to do:

    Print these instructions or save locally because you should be physically disconnected (unplug cable) and exit all browsers before continuing.

    Boot into safe mode.

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side.
    Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
    C:\Program Files\Apoint\Apoint.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Sony\HotKey Utility\HKserv.exe
    C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
    C:\Program Files\Apoint\Apntex.exe
    C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
    C:\Program Files\QuickTime\qttask.exe
    C:\WINDOWS\System32\ezSP_Px.exe
    C:\program files\support.com\client\bin\tgcmd.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Sony\HotKey Utility\HKWnd.exe
    C:\Program Files\Norton AntiVirus\SAVScan.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    D:\bin\iPodManager.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    C:\Program Files\Sony\VAIO Media Integrated Server\Music\SSSvr.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    C:\Program Files\Exif Launcher\QuickDCF.exe
    C:\Program Files\PowerPanel\Program\PcfMgr.exe
    C:\Program Files\Venturi2\Configurator\ventcfg.exe
    C:\Program Files\Sony\VAIO Media Integrated Server\Photo\appsrv\PhotoAppSrv.exe
    C:\Program Files\Venturi2\Client\ventc.exe
    C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
    C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
    C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
    C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
    D:\bin\iPodService.exe
    C:\Program Files\AIM95\aim.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\WINDOWS\System32\wuauclt.exe


    Don't worry if some of them are not found or cannot be killed just continue thru the list.

    The exit HijackThis.

    Now open one Windows Explorer session and navigate to c:\windows\temp

    Try to delete the problem files.

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Let me know if you have any problems finding or deleting any of these files.

    Reboot in normal mode and tell me what he result was.
     
  9. ladyberdan

    ladyberdan Private E-2

    Hi Dr. C,

    Thanks for your suggestions. I followed your instructions exactly and ran Hjack This in safe mode. I didn't kill any processes because the processes that came up were not on the list you posted. Here are the 8 processes that came up when I ran HijackThis

    C:\WINDOWS\System32\winlongon.exe
    C:\WINDOWS\System32\services.exe
    C:\WINDOWS\System32\lsass.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\explorer.exe
    D:\9programdownloads\virusremoval\hijackthis.exe

    Let me know if you want me to kill any of the above processes and then try to delete the files. Thanks again for your help!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you cannot kill any of those other processes!

    When you boot into safe mode just try to delete those files.
    Do you have other user accounts?
    Also try deleting them after logging in as Administrator.
     
  11. ladyberdan

    ladyberdan Private E-2

    Dr. C,

    I've tried all of that. The files do not delete in safe mode even when I run Move on Boot, Ccleaner, and all the other removal programs. There's only 1 account on the computer. When I run Norton Anti-Virus in safe mode it doesn't detect anything.

    Any other suggestions??

    Thanks!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You know I'm finally starting to realize what files you are talking about. I don't know why I did not realize this sooner. The files you are talking about are Windows files created by System Monitor. The default directory is normally c:\documents and settings\username\Local Settings\Temp
    where username would be your actual user account name.

    You just happen to have them in a different folder.

    These files do not need to be deleted. They do not cause any problems and are typically pretty small (like around 16kb). I would not worry about them.

    As far as the JETC8E8.tmp type files, I'm not exactly sure which aspect of Windows is using them but they are normal too. Right now on my WinXP PC I have 4 JET named temp file and 6 perflib_perfdata_ named files. The only ones not deletable are ones with todays date.
     
  13. ladyberdan

    ladyberdan Private E-2

    Ok, the temp files are not a problem. Any more suggestions then for getting rid of the virus that pixillates and puts streaks across my screen?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure you don't have a graphics card or a monitor issue?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds