Malware - Went Through Guide

Discussion in 'Malware Help (A Specialist Will Reply)' started by Kaneage, May 4, 2007.

  1. Kaneage

    Kaneage Private E-2

    Hi
    Here's what happened, my dad was using the computer and a popup came up saying a virus scanner had found some virus and to install some program to get rid of it. So he did and since then everything started screwing up, office files got deleted and the pop-ups started cranking.

    I d/l's some adware program, I can't remember which one, and ran it it. It picked up the virtumonde virus, I also fixed up tthe Office problem and thats all ok, but every now and then a virus was still popping up. So I then went through the malware guide and everything looks ok now, but i am not sure could someone have a look at the logs I attached and please tell me wether or not?
    Also should I go through the Special Removal Procedures?
    Thanks

    ps
    I didn't get the Panada Active log as for some reason my computer restarted while I was not looking.
     

    Attached Files:

  2. Kaneage

    Kaneage Private E-2

    Here are the other Logs
     

    Attached Files:

  3. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download
    - Pocket Killbox
    - ExplorerXP
    - ISeeYouXP by ShadowPuterDude

    Extract the contents of ISeeYouXP.zip to the root directory of drive C:\. This will create a folder named ISeeYouXP in the root directory of Drive C.

    Empty the Windows Defender Quarantine
    Empty the Norton AntiVirus Quarantine
    Empty the Recycle Bin

    Run CCleaner

    You have several infected Emails. See your BitDefender log to find out which ones.

    Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click Delete Selected Temp Files
    Then after it deletes the files click the Exit (Save Settings) button.

    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue..

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Using Windows Explorer (right click the Start button and select Explore to open Windows Explorer) navigate to C:\ISeeYouXP and locate the following scripts:
    ShowIT.bat
    FixExplorerPolicies.bat
    RegEditFix.bat
    TaskMgrFix.bat


    Double-click each file to run the batch.

    Open ExplorerXP navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:

    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Using Windows Explorer (right click the Start button and select Explore to open Windows Explorer) navigate to C:\ISeeYouXP and locate the following scripts:
    ISeeYouXP.bat

    Double-click to run the batch.

    Post the following logs:
    ISeeYouXP.txt (located at C:\)
    HijackThis
     
  4. Kaneage

    Kaneage Private E-2

    Hi
    Thanks for taking a look and sorry for taking so long to reply, but I couldn't get to the computer.

    I did all that you said with the following issues:

    - I couldn't find windows defender, so I don't know how to delete the Windows Defender Quarantine

    - I used to have Norton, but don't have it anymore (I now have NOD32), so I don't know how to delete the Norton Quarantine

    - I couldn't find O4 - HKLM\..\Run: [InfoData] rundll32.exe "C:\WINDOWS\vttrrr.dll",realset

    - There were NO pending operations type messages and I was prompted to reboot

    - I couldn't find
    C:\WINDOWS\Downloaded Program Files\UERT_0001_D19M2109NetInstaller.exe
    C:\WINDOWS\Downloaded Program Files\UPCTP_0001_91M1101NetInstaller.exe
    C:\WINDOWS\Downloaded Program Files\UWA7P_0001_N91M0809NetInstaller.exe
    C:\WINDOWS\Downloaded Program Files\UWAS7_0001_N91M1112NetInstaller.exe

    But as you said they may have been deleted by Pocket Killbox
     

    Attached Files:

  5. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    OK, GetRunKey should now run properly.

    Post logs for ShowNew and GetRunKey.
     
  6. Kaneage

    Kaneage Private E-2

    New Files and Run Keys Logs Attached
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds