Malware/WinAntiVirus Pro Problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by gfedor, Aug 25, 2006.

  1. gfedor

    gfedor Private E-2

    Great forum! I hope you can help me.

    Laptop was running slow - infected by malware. Followed all your steps to cleanup malware. System running much better, but HJT log still shows remnants of WinAntiVirus Pro (and potentially other issues that I don't have the knowledge to detect)

    All required logs will be attached in the next couple posts.

    Important Note: I was unable to run cleansing programs in safe mode. Laptop would shutdown about 5 minutes into a scan.
     

    Attached Files:

  2. gfedor

    gfedor Private E-2

    more logs
     

    Attached Files:

  3. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download
    - Pocket Killbox
    - ExplorerXP

    You are running an anti-spyware program which is not trusted or recognised to be safe, this link provides some details: http://www.spywarewarrior.com/rogue_anti-spyware.htm

    Therefore it is recommended that you remove it using the Add/Remove option on your computer:

    Start-Control Panel-Add/Remove

    Look for the following program and remove it: Spyware Cleaner

    Using Add or Remove Programs in the Control Panel; uninstall the following:
    << The installed version of Java on this compter is out-dated. Install Java Runtime Environment (JRE) 5.0 Update 8 available from http://java.sun.com/javase/downloads/index.jsp. Uninstall all older versions of Java on your computer, before installing the latest version of Java. >>

    Copy the contents of the below quote box to Notepad; Save As FixReg.reg to your Desktop. DO NOT run it as this time we will do that later in Safe Mode.
    Close Notepad.

    Run HijackThis, choose "Open the Misc Tools Section", choose "Process Manager", Highlight:
    Choose Kill Process. Click on the "Back" Button

    Click the 'Scan' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click Delete Selected Temp Files

    Then after it deletes the files click the Exit (Save Settings) button.

    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue..

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open ExplorerXP navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Follow the directions for Virtumonde aka Trojan Vundo Removal.

    Post the log from VundoFix and a fresh HijackThis log.
     
  4. gfedor

    gfedor Private E-2

    Shadow

    Thanks a bunch for your analysis and instructions....

    I checked "Add/Remove Programs" high and low and could not find a reference to SpywareCleaner.

    Any ideas on that?

    Thanks
    G
     
  5. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    If it's not there, it's not there. Continue with the instructions and if it still shows in HijackThis, which it shouldn't, we'll deal with it.
     
  6. gfedor

    gfedor Private E-2

    Instructions have been executed.

    Java 5.0 U8 installed

    FYI, your instructions never told me what to do with FixReg.reg

    C:\WINDOWS\System32\4nm2qeao.exe was not there when I ran HJT


    Never got the PendingFileRenameOperations message when running Killbox

    Killbos seemed to do alot as I could not find any of the files you requested for delete with ExplorerXP

    Vundo ran and no infected files found, log attached

    Attached is the new HJT log

    Thanks again for your help!!!!

    G
     

    Attached Files:

  7. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Locate FixReg.reg on your Desktop. Double-click on it and answer 'Yes' when asked if you want to merge with the registry.

    Reboot post a fresh HijackThis log.
     
  8. gfedor

    gfedor Private E-2

    HJT log posted.

    I place the check and ran the fix in HJT, but the 023 entries viewmgr.exe and ethernet.exe appear to have hung on.

    G
     

    Attached Files:

  9. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.

    On the page that opens, scroll down to Ethernet Service or EthernetService (Whichever is present) ... right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the 'None of the above, just start the program' button at the bottom of the choices. At the lower right, click on the 'Config' button, and then the 'Misc tools' button ... select 'Delete an NT Service' ... copy/paste the following into the box that opens, and press 'OK':

    Ethernet Service or EthernetService (Whichever you found above)

    Repeat the process for the following Services:
    Close Hijackhis

    Reboot

    Post a fresh HijackThis log.
     
  10. gfedor

    gfedor Private E-2

    'Ethernet Service' and 'Plug And Pray' (note that the display names DID have spaces) found when services.msc executed. When checked properties for each, neither service was running, so did not have to stop them. Both were Automatic though, so changed to disabled.

    Ran HJT. Tried to delete NBT services:

    'Ethernet Service'
    'Plug And Pray'

    Popup stated that neither 'Ethernet Service' nor 'Plug And Pray' existed. Decided to try deleting the following:

    'EthernetService'
    'PlugAndPray'

    Service found and removed.

    The display names in services.msc showed spaces, but the real NT name was without. You probably have seen that before, just thought I would relay my experience.

    Attached is new HJT log

    Thanks

    G
     

    Attached Files:

  11. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Your HijackTHis log is clean.

    You need to install SP2, without it your system remains vulnerable to attack. SP2 closes many vulnerabilites in Windows XP.

    This is the complete SP2.

    http://www.microsoft.com/downloads/ details.aspx?FamilyId=049C9DBE-3B8E- 4F30-8245-9E368D3CDB5A&displaylang=en

    Ignore that it says for IT Professionals and Developers, it's the full offline Service Pack.

    This is best installed disconnected from the Intermet, and with your AVntiVIrus and Firewall disabled during the Install. Once SP2 is installed you will have to reboot. Immediately run Windows Update and bring your system Up2Date.

    Flush all your restore points and create a new clean one for your system.

    Disable And Enable System Restore
    How to Protect yourself from malware!

    Safe surfing
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds