Malware removal problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by jjevans, Mar 23, 2007.

  1. jjevans

    jjevans Private E-2

    1st off, this is my 1st post and my skill level at dealing with cleaning a computer is limited as best. I tried to follow the directions in the closed post named Malware Removal Guide. It didn't go perfect, but I think I did it just about right. When I 1st found a problem (before I knew about your forum), I tried to fix it myself. Ran AdAwareSE: Found & removed18 trojans and 10 browser hijack attempts. Then ran Spybot. Found 2 problems but could fix only one. Prompted restart to fix 2nd problem. Upon restart the remaining malware got really aggressive and bogged the computer down. Every restart since gives message "WebProxy.exe has encountered a problem and needs to close.
    I read the guide on this site and found System Alert Popup right away. Tried to remove via add/remove programs and activated dialers to dial spydawn over and over. Spydawn later appeared on multiple scans.
    It looks like now that I'm done, there are a lot of items quarantined but not deleted. Should I wait before deleting? I still hear a lot of unprompted clicking sounds on the computer and the System Alert Popup program is still there. I will probably have to post 2 more times to get all the logfiles into this forum. Also, should I avoid using the computer until someone responds. I will disconnect the modem cable until I am ready to check this post again. Thanks.
     

    Attached Files:

  2. jjevans

    jjevans Private E-2

    This is 2nd posting to get more logfiles uploaded.
     

    Attached Files:

  3. jjevans

    jjevans Private E-2

    This is final posting of logs.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 8
    Java 2 Runtime Environment, SE v1.4.1_02

    System Alert Popup<-- This will not uninstall thru add/remove?
    Can you find and delete the folder and its contents?

    Is this an old program that you have deleted:
    C:\Program Files\Arovax AntiSpyware <-- if so go ahead and delete the folder.

    Use windows explorer to find and delete this:
    C:\Program Files\Video Access ActiveX Object

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
    O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab

    After clicking Fix, exit HJT.

    Now attach new logs for:

    * GetRunKey - please download the current version first!
    * ShowNew
    * HJT
     
  5. jjevans

    jjevans Private E-2

    Did everything except possibly getting newest version of GetRunKey. I just reloaded it from the link in the Malware Removal Guide. I assumed it would be current. I don't know where else to get it from and I didn't see any update options in the folder. Thanks for the fast response!
     

    Attached Files:

  6. jjevans

    jjevans Private E-2

    Forgot to mention I couldn't find "C:\Program Files\Arovax AntiSpyware" to delete it.
     
  7. jjevans

    jjevans Private E-2

    last post incorrect. I couldn't find "C:\Program Files\Video Access ActiveX Object"
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean. You may uninstall any programs we had you download.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  9. jjevans

    jjevans Private E-2

    Computer really seems clear of malware now. Thankyou very much! Only strange things still happening are upon reboot, I keep getting the message "WebProxy.exe has encountered a problem and needs to close" and System Restore doesn't respond at all even after toggling it back on. Neither problem affects performance, but I am curious about the WebProxy.exe and worried about a disabled system restore. Any advice is greatly appreciated. Thanks again for all your help
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    WebProxy is related to Panda software ....If it is not your AV ...and you downloaded it instead of the online scanning (I've slept) ....uninstall it and any traces of it (Files and foulders).

    Try to do this:
    Restore System restore
    You may be asked for the Windows XP CD. if you haven't got a retail copy of the XP CD, point your browser to the i386 folder, locate the INF folder and see if you can install System restore form there.

    1/ Open Windows Explorer

    2/ on the Main toolbar click Tools

    3/ From the drop down menu click Folder Options

    4/ The folder Options Properties window will now open

    5/ Click the View tab

    6/ In the advanced Settings list scroll down to the Hidden Files and Folders section

    7/ Click on the radio button next to the Show Hidden Files and Folders option

    8/ Click OK to close the Folder Options Properties window

    9/ In the left hand pane of windows explorer click the + sign next to My Computer

    10/ This now expands the drive list

    11/ Click the + sign next to the C: drive to expand the folder list

    12/ From the folder list navigate to the Windows folder and click the + sign next to this to expand the folder list

    13/ Scroll down and click on the INF folder

    14/ A list of INF files will appear in the right hand pane of Windows explorer

    15/ Look for a file called SR.INF

    16/ Once you have located SR.INF Right Click on the folder

    17/ From the drop down menu click on Install

    18/ System restore should now re-install

    19/ If you are asked at any time to insert your Windows XP CD (typically to copy files sr.sys and srframe.mmf) then do so. This enables fresh files to be copied over to your hard drive. Don't try browsing to the Windows directory on your hard drive for the relevant file as all you will be doing is replacing one corrupt file with another.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds