How do I know if I have successfully gotten rid of viruses/trojans ?

Discussion in 'Malware Help (A Specialist Will Reply)' started by angrybiscuit, Feb 18, 2008.

  1. angrybiscuit

    angrybiscuit Private E-2

    Hi,
    I think I might have a collection of nasty thing things on my computer. A list of bugs caught by Kaspersky 7 are:

    - Adware.Win32.Virtumonde.gen (which has come back numerous times !! :mad)
    -Trojan-Downloader.Win32.Small.hrg
    - virus Heur.Trojan.Generic (modification)

    and Trojan.Win32.Storageprotector.dt caught by Zone Alarm which was previously installed in my computer.

    Since then I've followed instructions from the read me thread but I'm not sure if it's all gone because I still have a large red 'X' where my hard disk icon should be.

    How do I tell if it's all gone, and if it isn't how should I proceed from here? :confused

    Your help is much appreciated. Thank you! :)
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just a few things to clean up:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    * On the page that opens, scroll down to Microsoft cache control
    * then right click the entry, select Properties and press Stop Service.
    * When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    * Click OK until you get back to Windows.

    * Next, run C:\MGtools\analyse.exe, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    * At the lower right, click on the Config button
    * Then click the Misc tools button
    * Select Delete an NT Service
    * Copy/paste MSControlService into the box that opens, and press OK
    * If you receive any error messages just ignore them and continue.
    * Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Run C:\MGtools\analyse.exe by double clicking on it. Select Do a system scan only and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and tell me how things are running.
     
  3. angrybiscuit

    angrybiscuit Private E-2

    Ok merging that last bit now...

    I managed to fix 3 out of the four thingamajigs but
    wasn't listed on HJT when I tried to fix it.

    Will be back soon-ish!
     
  4. angrybiscuit

    angrybiscuit Private E-2

    Hmm. I seemed to have killed something while following the instructions in the last post. I couldn't use my thumbdrive or connect to the internet after that sot I had to go back to a restoration point dated 2 days ago to get back online.

    Does that mean I have to re-run combofix and all the other programs?
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Unfortunately, yes.
     
  6. angrybiscuit

    angrybiscuit Private E-2

    Ok, I scanned everything again. New logs attached to this post. Hmmm ccleaner, spybot and SUPERanti-spyware didn't pick up anything but since reverting back to the restoration point the computer has been kind of buggy. It tends to stall, particularly when I'm using firefox or internet explorer and when I try to upload files. I'm also receiving the following error:

    http://img.photobucket.com/albums/v652/genoa16/rundllerror2.png

    And uhm, my word document icons have changed though I can still open the program itself after it prompts me to install Microsoft Word and fails.

    Eeps.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That error could be related to Office Pro ..or one of the tablet programs ...best to use your installation cd and go to start / run / and type
    sfc /scannow

    BUT FIRST:
    * Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    * On the page that opens, scroll down to Microsoft cache control
    * then right click the entry, select Properties and press Stop Service.
    * When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    * Click OK until you get back to Windows.

    * Next, run C:\MGtools\analyse.exe, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    * At the lower right, click on the Config button
    * Then click the Misc tools button
    * Select Delete an NT Service
    * Copy/paste MSControlService into the box that opens, and press OK
    * If you receive any error messages just ignore them and continue.
    * Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Now re-Run C:\MGtools\analyse.exe and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {3ED0480E-7160-4A53-A415-2CB4DF57E573} - (no file)
    O2 - BHO: {ddb6cf11-e45b-cc2a-7ec4-a5e9142f6e07} - {70e6f241-9e5a-4ce7-a2cc-b54e11fc6bdd} - (no file)
    O20 - Winlogon Notify: mljijkj - C:\WINDOWS\
    O23 - Service: Microsoft cache control (MSControlService) - Unknown owner - C:\WINDOWS\system32\windows (file missing)

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now use windows explorer to find and delete:
    c:\WINDOWS\system32\ZCfgSvc.exe

    You are aware that doing a system restore does not rid you of all malware as the restore files are often infected.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  8. angrybiscuit

    angrybiscuit Private E-2

    Ok I ran hjt and fixed the stuff but like the last time

    wasn't found on the list. I merged fixME.reg too but after that I couldn't delete ZCfgSvc.exe it said:

    Cannot delet ZCfgSvc: Access Denied

    Make sure the disk is not full or write-protected and that the file is not currently in use.


    Ehm but isn't that file my windows wireless configuration program?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry ...fighting the flu (ergo semi-brain dead) ..it is for your wireless ...but the rest was good .....how are things running?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds