infected with several things...

Discussion in 'Malware Help (A Specialist Will Reply)' started by alysser, Oct 14, 2006.

  1. alysser

    alysser Private E-2

    Hi,

    Your site is really awesome. and has been very helpful so far. Thank you!!!

    I have followed all instructions in the Read & Run Me First and I am posting now to display my logs and to ask for your infinite wisdom in helping me rid myself of these malicious buggers. I suspected I had some problems on the machine here when Monday my Symantec Anti-Virus and my Zone Alarm stopped loading when I rebooted.

    Symantec found nothing.
    TrendMicro online found "Ardamax" but failed to clean it. That was 2 days ago.


    Msconfig is set to Normal Mode.
    Ran ccleaner in SafeMode.
    Ran SB S & D, found 4 benign things: "Microsoft.WindowsSecurityCenter.UpdateDisableNotify", "Microsoft.WindowsSecurityCenter.AntiVirusDisableNotify", "Microsoft.WindowsSecurityCenter.FirewallDisableNotify" , "Microsoft.WindowsSecurityCenter.AntiVirusOverride" that I have disabled in XP) Immunized, DID NOT use teatimer.
    Microsoft Malicious didn't find anything.
    Windows Defender would not run in SafeMode w/networking and found nothing in normal mode.

    BitDefender found Backdoor.Xbot.26 in system volume info. see attached bdscan.txt.

    Pandascan found many things. See attached ActiveScan.txt.

    Also attached is my HJT log.

    I hope I am doing this right, and that this can be cleaned out forever. I will also post a second time with my other logs. Thanks again!
     

    Attached Files:

  2. alysser

    alysser Private E-2

    Here are my logs from GetRunKey and ShowNew
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    What actual malware problems are you having? There aren't too many problems in showing in your logs.

    I do have some questions about some things I see related to a keylogger! Did you install Ardmax Keylogger and did you at one time have All In One Keylogger installed.

    Also did you knowingly install PalTalk? See this:
    http://research.sunbelt-software.com/threatdisplay.aspx?name=Paltalk&threatid=9494
     
  4. alysser

    alysser Private E-2

    Thank you for responding.

    The only problem I have noticed is that Zone Alarm and Symantec AV no longer load up when I start the computer. It will load my volume icon then seems to pause a bit before it will let me manually start Zone Alarm.

    I didn't install any keyloggers and it is freaking me out that they are there...can you help me get rid of them?

    Also, I did install Paltalk on purpose. Is it bad? Should I get rid of it?
     
  5. alysser

    alysser Private E-2

    Okay so I decided to just uninstall Symantec since it is not so great, and I got AVG instead. I scanned and it found "PSW.Generic2.HWX" Great I have not only keyloggers, but also a password stealer. I can't believe all those other scans I did never showed it. AVG was able to get rid of this PSW trojan for me. ::whew::

    I am upset about someone putting keyloggers on this computer. I Googled the names you mentioned and eventually figured out Ardamax was living in the directory "CKM" where an uninstaller was located (visible thanks to your instructions to unhide the hidden folders) and I uninstalled Ardamax, then deleted the directory. I have not been able to find anything on Google about getting rid of All in One Keylogger

    When I originally scanned with BitDefender, it found Backdoor.Xbot.26 in System Volume Info. Today's AVG scan has not found it and that may be because I disabled System Restore and rebooted before I scanned.

    Anyway, can you please help me get rid of the All in One Keylogger? I am going to follow your other threads about protecting myself and I am going to confront the people I share this computer with about the keyloggers.

    Thanks for your site, it has really helped me!!

    Alyssa
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As stated in the link I gave you to read, it is low risk adware. You need to decide for yourself whether you trust it and whether the benefits it provides to you outweigh whatever possible downsides there are (like advertisements....etc).


    Make sure viewing of hidden files is enabled (per the tutorial).
    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    After reboot locate the below file and delete it if found:
    C:\Program Files\Common Files\Microsoft Shared\Proof\flaupdate.exe

    Now attach a the below new logs and tell me how the above steps went.

    1. GetRunKey
    Make sure you tell me how things are working now!

    Are you still having problems with ZoneAlarm starting up? If so, try uninstalling it, reboot, and then reinstall.
     
  7. alysser

    alysser Private E-2

    What does this registry change do?

    I ran it even though I have no idea what it does, and attached is the new GetRunKey log.

    There is no flaupdate.exe anywhere on the machine.

    I fixed Zone Alarm by applying an update it had waiting and it loads just fine everytime now.

    The machine has been running fine since I ran all those scans and got AVG.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It removes registry keys related to malware!

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    3. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and enable System Restore to create a new clean Restore Point.
    4. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds