IEDefender and Spyhunter malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by Phlegmbot, Jan 4, 2009.

  1. Phlegmbot

    Phlegmbot Private First Class

    Hi!

    Long-time listener, first-time caller...

    I've found the above-named viruses after several virus scans from different programs...FYI: spyhunter was something I downloaded based on approval from this site (it's in your Malware links page), but it was a trojan. Ah well...I think it's gone now.

    I HAVE read the rules for posting but...

    - I have NOT run ComboFix -- it makes me nervous. There are a bunch of warnings on the Web about not running it unless you're really sure you know what you're doing...and I'm not.

    - I'm also afraid to restart for fear of not being able to get back into Windows. I ran a program called 'Trojan Remover" and upon Uninstall, it asked me if some "unused," "shared" dll files should be removed. I stupidly said yes...and realize now that's caused problems in the past.

    Will combo fix give me a "Safety" to fall back on? Or is there ar DIAGNOSTICS TOOL I can run that can verify the stability of Windows before I restart?...Just to be certain I can get back in?

    Anyway, thank you for any help you can offer.

    Several Logs below as requested:
     

    Attached Files:

    Last edited by a moderator: Jan 4, 2009
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can hang off on COmbo for now, but we need both the:
    SAS Log
    C:\MGTools.exe ---> C:\MGLogs.zip
     
  3. Phlegmbot

    Phlegmbot Private First Class

    Hey, Tim!

    Sorry, Don't know how I forgot those 2...

    THANKS FOR THE HELP!

    This is the SAS log:
    SUPERAntiSpyware Scan Log

    Generated 01/05/2009 at 08:23 PM

    Application Version : 4.24.1004

    Core Rules Database Version : 3694
    Trace Rules Database Version: 1670

    Scan type : Quick Scan
    Total Scan Time : 01:31:28

    Memory items scanned : 527
    Memory threats detected : 0
    Registry items scanned : 470
    Registry threats detected : 0
    File items scanned : 6442
    File threats detected : 0
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only problem I see on your system is this:
    Symantec AntiVirus
    avast! Antivirus"
    AVG Free 8.0
    Viewpoint Media Player

    Did you not read this in the Read and Run First instructions:
    Or this:
    Uninstall Malware via Add/Remove Programs
    which tells you to uninstall Viewpoint?

    If you are not having any other malware issues, then:

     
  5. Phlegmbot

    Phlegmbot Private First Class

    Heya, Tim!

    I did INDEED read that stuff about the virus programs...

    Am uncertain if I actually RAN Combofix. That is, I DL'd it, placed "WindowsXP-KB310994-SP2-Home-BootDisk-ENU" file into the Combofix icon. Does that count as running it? Does it install with that?

    As for virus programs:
    Initially, I only had Symantec (which has never previously failed me), then several nights ago, I noticed a major slow-down suddenly (I'd not DL'd anything new. [Viewpoint's been on my computer for months w/out issue, but i HAVE removed it]). So I DL'd Avast and a bunch of other things in a panic (including the Spyhunter virus [as mentioned above] -- yay me!).

    I've since removed everything save for Avast, SAS, & Symantec. I turned off Avast's Real-time whatchamathingy (after I posted that log I guess).

    I've attached an updated HiJackThis Log. Please let me know next steps.

    THANKS!!
     

    Attached Files:

  6. Phlegmbot

    Phlegmbot Private First Class

    OK, I did a full scan with Avast! (I had done a Full Scan w/ONE virus programs I have/had, but no longer recall which...b/c I THOUGHT it was Avast I'd done it with but clearly not...), and in the System Information Folder, it found and quarantined the files:
    A0030549.dll
    A0030550.exe

    I deleted those 2 files. Also in the Avast! Chest (from past scans in the last week) are the following files:

    kernel32.dll
    winsock.dll
    wsock32.dll

    I should add that System Restore WAS set to OFF since discovering I had a virus last week, but, after this scan, I went and checked it and it was turned back on (by the virus I presume).

    Please let me know what to do next.
     
  7. Phlegmbot

    Phlegmbot Private First Class

    I realized Avast! changes the name of the files.

    It says the virus infection is Win32Agent-IPP

    Again, please let me know next steps!

    THX!!
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to tell me exactly what avast is reporting.....attach a log.
     
  9. Phlegmbot

    Phlegmbot Private First Class

    I see no way of copying and pasting the Avast! logs, so I've included two images.

    One of the Warning Log and one of the Error Log -- they were the only ones which had any info (save for the Updates log).

    Thx.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    They appear to be false positives......and the system restore infected files will only go away when you toggle system restore.
     
  11. Phlegmbot

    Phlegmbot Private First Class

    OK. Sigh. Thanks.

    So, a few questions:

    1. What a-v software would you recommend since Avast doesn't seem to be dependable (and Symentec Pro edition completely missed the IE Defender virus)?

    2. My computer slowed down tremendously and, later that day (one-and-a-half weeks ago), the IEDefender virus was found (as mentioned in my first post on this thread). The computer is still running slowly in spite of running CCleaner, removing unnecessary start-ups, and a number of other things I've done. I've 16.6 Gigs open, and I've not DL'd anything new. But I'm still running VERY slugglishly. Any thoughts on what I can do, aside from wipe the drive, to fix this? I can't even play audio in Windows Media player, it skips and echoes.

    3. The only other change is that the resolution of the screen as it's coming out of hibernation has changed (the type is small and in the center of the screen, rather than large and at the bottom). What the heck's with that?

    Any further tips would be greatly appreciated.

    Thank you, Tim!
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No AV program is 100% ...malware is written every day and those that try to stop it have to scramble to keep up.

    You may wish to look at the suggestions here:
    Computer maintenance

    These issues sound like software or hardware problems.I suggest you continue this in the software section.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  13. Phlegmbot

    Phlegmbot Private First Class

    Heya, Tim!

    I followed those steps and nothing changed. I have also done EVERYthing listed in the computer maintenance section -- defrag (not w/the Windows defrag program), Registry cleaning, removing extra programs, desktop icons, etc.

    A techie friend recommended I run sfc /scannow

    I've done that and it seems to have somehow RESET my computer back to the bad slow-down I had when this all first started 2 weeks ago. (And yet it's something I've never experienced before.)

    Any thoughts? And, yeah, after this, I'll post in the section you recommend from here on.

    Thanks for everything!!
     
    Last edited: Jan 16, 2009
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You could always try a repair install.

    However, to be double sure:

    This procedure explains how to get to the BitDefender Online Scan sites and how to setup and perform an online scan. It also explains how to obtain a log so you can attach it to a message. You must use Internet Explorer to run this scan and make sure your Sun Java version it current. Get Sun Java here: Sun Java Runtime EnvironmentBefore installing the current version, you should uninstall all previous versions first!!!!

    ****NOTE**** DO NOT INSTALL Bitdefender's Antivirus program. Make sure you follow the directions below and run the ONLINE SCANNER only.


    To start the online scan go here: Bitdefender
    • Agree to the license and then select Scan.
      • DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files.
    • Once Bitdefender completes the scan:
      • Click-on the Detected Problems tab. Then select Click here to export the scan report
      • When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt)
      • And then in the File name box enter bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html. If you do not follow these step, you will have an incorrect log or worse a log summary which is useless to us.
    • Post the bdscan.txt file as an ATTACHMENT. See: HOW TO: Attach Items To Your Post
    • If you run BitDefender Online scan and have previously run PandaActive scan, the below false detection may be seen in BitDefender:

      C:\WINDOWS\system32\ActiveScan\pskahk.dll
      Infected with: Generic.Malware.SIMDWYNVdprn.D9407F4E
     
  15. Phlegmbot

    Phlegmbot Private First Class

    Hey, Tim!

    BitDefender found a virus, but it found a virus in a file I've used before, several times, without issue (part of an illegal download, yes, but, again, one I've had on my computer for years [and even my previous computer] without issue).

    Let me know what that means, and if there's something else I should do from this point.

    The txt file is attached.
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What it means is the cracks and rar's are usually stuffed with malware.

    At this point, you need to post in the software section for any other issues. :)
     
  17. Phlegmbot

    Phlegmbot Private First Class

    Tim,

    What I'm asking is what are the next steps here? Should I do another full scan with something else?

    Also, as I explained to you in my preivous post, I'm fully aware that some of these DL'd programs are stuffed with Malware, hence my point that I've had this file on THIS computer AND my previous computer for several years now, with NO issues.

    I've done full scans before w/out finding anything, and I've run that software (the software deemed to be a virus) on several occasions. Why does BitDefender suddenly find it to be a virus?

    And, finally, Avast! again found the Win32:Agent-IPP and, strangely, it warned me about these files are are in Avast's VERY OWN "moved" folder. What is that about? (These are the files you said were false positives earlier in this thread.)
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you toggled system restore?

    You need to get me the avast log so I can see what it is reporting.

    Did you run SFC /scannow?
     
  19. Phlegmbot

    Phlegmbot Private First Class

    Yes, but I did it again just now...and will restart.

    Attached!

    Yes, I have done that.

    Any thoughts on the main question of my last post (why that file was never considered a threat before)?

    THX!!
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Updating your virus definitions could be the reason for this.

    As to what Avast finds....you can always uninstall Internet spyhunter and remove these:
    Code:
    1/4/2009 06:29:53    OKKeith    3696    Sign of "Win32:Agent-IPP [Trj]" has been found in "C:\Program Files\Internet Spy Hunter\SpyHunter.dll" file.  
    1/4/2009 09:08:36    OKKeith    3696    Sign of "Win32:Agent-IPP [Trj]" has been found in "C:\Program Files\Internet Spy Hunter\SpyHunter.exe" file.  
    1/4/2009 12:36:19    OKKeith    3696    Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\OKKeith\My Documents\ARCADE\Emulator.Pack\âGâ~âàâîü[â^ü[û{æ¦\Xbox\xbox_emulator.0.34.exe" file. 
    
    The other problems need to be addressed in software. :)
     
  21. Phlegmbot

    Phlegmbot Private First Class

    But the computer's not reacted in any negative way. And the friend who's also used it has not had any viruses or slow-down issues. Could it be a worm making it's way through my HDD?

    Tim, you're commenting on files in the log from 1/4. Spyhunter's been gone for about 2 weeks now. Please take a look at the log again and look at the files I referred to 2 posts back (where you then asked me to post this log). And look at the ones dated 1/18 -- that's what we're focusing on here.

    I don't want to post elsewhere until I know these issues are resolved. If you're stumped, that's totally cool, perhaps someone else on the site can take a look.

    Thanks for everything!!
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok....so you are referring to what Avast found on that date:
    Win32:Agent-IPP:
    Code:
    1/18/2009 18:09:22    OKKeith    1696    Sign of "Win32:Agent-IPP [Trj]" has been found in "C:\Program Files\Alwil Software\Avast4\DATA\[B]moved[/B]\A0030549.dll.vir" file.  
    1/18/2009 19:05:43    OKKeith    1696    Sign of "Win32:Agent-IPP [Trj]" has been found in "C:\Program Files\Alwil Software\Avast4\DATA\[B]moved[/B]\A0030550.exe.vir" file.  
    1/18/2009 19:05:53    OKKeith    1696    Sign of "Win32:Agent-IPP [Trj]" has been found in "C:\Program Files\Alwil Software\Avast4\DATA\[B]moved[/B]\A0030550.exe.vir" file.  
    
    There is the possiblility that it is still in a CLSID reg key, and so now I need you to run COmboFix. Just download it to your desktop and double click it.
     
  23. Phlegmbot

    Phlegmbot Private First Class

    OK-madokay, Tim!

    Attached is the Log file...

    I gotta say, that was the easiest scanning program EVER! Why are there warnings all over the Web about running it? It gives directions the whole way through and everything. Odd.

    Anyway, let me know next steps when you get a chance! THANK YOU!
     

    Attached Files:

    • log.txt
      File size:
      23.2 KB
      Views:
      3
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That log is clean. And your Avast results are just showing what was "moved" which you should delete. Again, not seeing any malware.

    Have you considered doing a repair install for any other issues?
     
  25. Phlegmbot

    Phlegmbot Private First Class

    Thx, Tim.

    RE: the Repair: Does sfc/ scannow repair problem files?

    Because I ran that.

    Also, the last time I did a repair install, I got locked out of Windows. Probably something to do w/Toshiba's settings.

    Is there any way to, I dunno, check what the problem is withOUT doing the repair until I've checked w/someone like yourself?

    Or is this a question for the software section?
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It looks for missing or corrupt system files and tries to fix them. But it is not always effective in fixing problems.

    Yes...they can better guide you on the rest of your issues.
     
  27. Phlegmbot

    Phlegmbot Private First Class

    Then I guess we're done here, sir...thank you for the help.

    PBot
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome...and good luck. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds