I have 2 viruses found by Avast!

Discussion in 'Malware Help (A Specialist Will Reply)' started by ukchickk, Mar 26, 2006.

  1. ukchickk

    ukchickk Private E-2

    hi, i have 2 viruses found by avast.. the first is WMF Exploit. the second is win32:keylog-AL. i did the read this and run first.. but problem still apparent. i use a wireless broadband connection and since the keylog virus i have repeatedly had a <page cannot be found> problem when surfing the net.. it's really annoying... please could someone help i will attach hijackthis log and also activescan log.. bitdefender would not work, it scanned and finished but gave no report...
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Did you choose to keep MessengerPlus! 3 even though we warned you about it in the READ ME? Hopefully you refused to install the 3rd party malware that come with it!

    Did you purchase AdwareAlert that is running? It was on the rogue tool list for awhile and was recently de-listed but it still is not that useful. There are better pay choices and many free items that are also better. Consider uninstalling AdwareAlert.

    I also see you have the BullGuard Bundle installed! Did you read this info before you installed this:
    http://research.sunbelt-software.com/threat_display.cfm?name=Bullguard&threatid=26018

    Post a log from Avast showing exactly what and where it is finding problems?
    Have you tried running a fullscan with Avast while you are in safe boot mode? If not, please try that.
     
  3. ukchickk

    ukchickk Private E-2

    hi, I got rid of messenger plus when asked and no extras were installed at time of installation. Adawarealert was removed awhile ago and no longer in ad/remove programs so i don't know ow to get rid of it.
    Bullguard was pre installed on my laptop when i brought it so had no choice on that being there.
    Ran a full scan both in safe and normal mode but still same thing. i will post a log as soon as possible.
     
  4. ukchickk

    ukchickk Private E-2

    Avast logs are weird..i will enclose the error log and warning log.. all other logs came up empty..
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you referring to the below?
    Just use Windows Explorer to locate and delete the file.

    And these:
    .
    This may be a false positive or it could be that your Sims disks came with an infection. You should check with them. Other people have see the same thing. See the below.
    http://groups.google.co.il/group/alt.games.the-sims/browse_thread/thread/c3ed0b04af885c45/62797bde22ec2a41?q=TS2UPD.exe&rnum=1#62797bde22ec2a41
     
  6. ukchickk

    ukchickk Private E-2

    i scanned my disks and have used on other pc's without this fault so i think it may be a false positive.. it all seems clear which is why i was gonna sort my main pc out now.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay we have some things to fix up here though! And you should uninstall all the Bullguard stuff. You are conflicting it with ZoneAlarm and you must only use one firewall. Since Bullguard is considered adware/bundleware you should remove it.

    Make sure viewing of hidden files is enabled (per the tutorial).
    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\Program Files\MessengerPlus! 3\MsgPlus.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [AdwareAlert] C:\Program Files\AdwareAlert\AdwareAlert.Exe -boot
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to:
    C:\Program Files\AdwareAlert to <--- the whole folder delete
    C:\Program Files\MessengerPlus! 3 <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  8. ukchickk

    ukchickk Private E-2

    just about to do this now. how do i remove bullguard as it isn't present in add/remove programs at all. will do all other stuff and post hjt log for u
     
  9. ukchickk

    ukchickk Private E-2

    ok i've done that...how can i remove bullguard. i noticed the stuff in hijackthis when checking those files were gone..... bullguard doesn't show up on add/remove prgrams so unsure how to remove it
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to BullGuard LiveUpdate (if that is not found, look for the short name: BGLiveSvc)... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Now repeat the above stop and disable for the following services:
    BullGuard Main
    BullGuard File Monitoring
    BullGuard Firewall
    BullGuard Email Monitoring

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    BGLiveSvc

    Now repeat the Delete NT Service steps for:
    BGMainSvc
    BsFileSpy
    BsFirewall
    BsMailProxy
    If you receive any error messages just ignore them and continue.

    Now exit HJT and reboot when it tells you it needs to.
    After reboot, attach a new HJT log.
     
  11. ukchickk

    ukchickk Private E-2

    ok i had a message on all but the first saying system critical..but i carried on as u said and here's the new hjt file
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All cleaned up!

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  13. ukchickk

    ukchickk Private E-2

    ok kool. thnx. everything on this one is working as it should..
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds