Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by cindydenney, Jun 23, 2008.

  1. cindydenney

    cindydenney Private E-2

    I had a virus alert so I used your Windows XP Cleaning Procedure,
    I didn't skip anything, I followed your instructions exactly.
    Everything seemed to be going great until I go to the Toggle System Restore. When I rebooted, all my icons are gone.
    I am running in safe mode. I don't know what to do now.
    Attached are 3 logs from the removal programs. It evidently is a root virus but the alert said it was win32.netbooster.
    I am a Realtor and I have most everything backed up but if I have to reinstall, how can I be sure, I'm not reinstalling a virus?
    What a vicious cycle!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You are not supposed to toggle system restore until your PC has been verified to be clean.

    You need to attach the requested MGlogs.zip file from running MGtools.
     
  3. cindydenney

    cindydenney Private E-2

    Sorry,
    Here is the log. I have a printed log from Spybot but it won't let me look for the log on the computer?
    I haven't been enjoying this for about the last 6 hours. It's rather like going to the dentist.
     

    Attached Files:

    Last edited: Jun 24, 2008
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We don't ask for a Spybot log! Also we do not ask for you to attach separate HijackThis logs. It is in MGlogs.zip already.

    What are the below?
    Code:
    2008-06-19 17:31 . 2008-06-21 17:13 51,477 --a------ C:\WINDOWS\Aware40.mch
    2008-06-19 16:48 . 2008-06-21 17:04 <DIR> d-------- C:\WINDOWS\A4W_DATA
    2008-06-19 16:48 . 2008-06-21 16:43 35 --a------ C:\WINDOWS\A4W.INI
    Looks like the scans took care of all of your malware. We just have a little to do.

    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 8
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) 6 Update 3
    Java(TM) SE Runtime Environment 6 Update 1
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    Is the below Password Door Loader something you installed? If not, fix it too otherwise skip it.
    O4 - HKLM\..\Run: [Password Door Loader] C:\DOCUME~1\SAWYER~1\Desktop\Computer\PASSWO~1\tlpd.exe

    O4 - HKLM\..\Run: [SpyHunter Security Suite] "C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe" -scan -minimized
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    After clicking Fix, exit HJT.

    Now reboot your PC into normal mode.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jun 24, 2008
  5. cindydenney

    cindydenney Private E-2

    I tried to uninstall those files from the control panel and it won't let me do it in safe mode. Is there another way to get to it?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can boot into normal mode and use CTRL-SHIFT-ESC to bring up Task Manager. Then click File, New Task (Run...) and enter appwiz.cpl and click OK. If this works, it will bring up Add/Remove programs. Did it work?
     
  7. cindydenney

    cindydenney Private E-2

    I can get to the add/remove programs from the control panel.
    When I click on remove for any of the Java files the computer tells me that it can't access Windows Installer in safe mode and it won't remove them.
    I was able to remove Viewpoint Media Player with no problem.

    I have no idea what those codes are that you asked about. I just play and work in this tech world that you live in. You'll have to assume that you are talking to an "outsider.":eek:
     
  8. cindydenney

    cindydenney Private E-2

    I'm sorry, it did work and I have uninstalled the java software.
    I ran the scan from MGtools.exe and I've found all the lines to delete except
    04 SunJava ........ I can't find it on the log.
    Should I fix and exit? (I closed the browser and I'm on another computer.)
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just fix and exit. I hope you did not uninstall the 6.0 update 5 version of Java which you had installed. I did not ask for that one to be uninstalled.
     
  10. cindydenney

    cindydenney Private E-2

    It seems to be working fine.
    What if I did delete that Java File?
    I'm punchy from fooling with this.
    I want to tell you that I called Dell before I talked to you and they suggested that I wipe out my computer and start over.
    I can't tell you how much I appreciate you for helping me and all your patience.:drool
    Also, I'm so proud of myself for finding you!!:-D
     

    Attached Files:

  11. cindydenney

    cindydenney Private E-2

    No Java file shows:cry
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I noticed, you uninstalled it. That's okay it was not the current version anyway but was recent enough. You can get the current version in the below link:

    Sun Java Runtime Environment

    I'm looking at your logs now.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your PC is not in normal startup mode. You are using MSconfig to disable something with boot.ini. Why?

    What did you do with Avenger and why? Are you also working on another forum? I see the below:
    Code:
    AVENGER       Jun 23 2008              "Avenger"
    avenger.txt   Jun 23 2008       11986  "avenger.txt"
    Is your copy of Spyware Doctor a paid version or free trial?
     
  14. cindydenney

    cindydenney Private E-2

    I didn't know it wasn't in normal startup mode. When I turned it back on after getting out of safe mode it worked and the screen looked like normal start up.
    I will reboot and see what happens.
    I'm not working on anything with Avenger?
    Spyware Dr. is a paid version.
    When I get this worked out, which one of the Java's should I install? There seems to be more than one choice.
     
  15. cindydenney

    cindydenney Private E-2

    Ok it started fine and I got a message saying that I had used the system configuration Utility to make changes to the way Windows starts.
    It says its currently in diagnostic or selective startup mode.
    It wants me to choose normal startup mode.
    At this point, I'm afraid to do anything without asking.
     
  16. cindydenney

    cindydenney Private E-2

    It also told me that no firewall was turned on.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then where did the files come from on 06-23-2008? Someone had to install it and run it. Attach the c:\avenger.txt log.

    The link I just gave you is to the current version which is Sun Java Runtime Environment 6 Update 10 Beta

    Does your paid version of Spyware Doctor also include their antivirus program?

    Download and install the below to address your firewall issue.

    PC Tools Firewall Plus <-- make sure you uncheck the options to install Google Toolbar and Threatfire free edition. There's is no sense in installing excess baggage.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is what step 1 of the READ & RUN ME stated that you must do. See step 1 of the READ & RUN ME.
     
  19. cindydenney

    cindydenney Private E-2

    After I ran all the instructions on Read Me and Run and my computer wouldn't boot up with icons, I thought it may have some other sort of problem so I called the Dell support line.
    The Representative asked if he could "look" at my computer and he nosed around from where he was - Manila I think - for awhile, checked some things and told me I still had a virus.
    He suggested that I "save what I wanted" and then wipe out the computer and reinstall windows and all the software.
    That's when I decided than he knew just enough more than me and we were both dangerous to this computer and I got on the forum.
    I never heard of Avenger and have no idea what it does. No one else except him has been on or in this computer. I'm attaching it with this post.
    I didn't change the start up on the computer to anything. That was the first rule! I made some errrors but I'm not taking the rap for this stuff:cry.
    I logged on in AOL because Explorer won't work. Did I disable it along the way?
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to answer my question about whether your Spyware Doctor includes their antivirus.

    I only wanted you to attach the C:\avenger.txt file not the avenger folder information in the ZIP you attached, but that's okay it gave me what I wanted to see. Some one ran it and tried to delete things that were not malware. They even deleted files for your DivX application, for Network Magic, and for games (some from AOL). Someone had no idea what they were doing.

    Is your PC in normal startup mode now (from MSconfig)?
    Did you install the new Sun Java?
    Did you install the PCtools firewall?

    If you answer yes to all three, get me a new MGlogs.zip file after running GetLogs.bat like you did in message # 4.
     
  21. cindydenney

    cindydenney Private E-2

    Well, I lied. I bought SpyHunter, from Enigma Software Group USA LLC.
    I haven't downloaded it. The Spyware Dr. is a starter edition but it does have protection. Which one of these should I use, and I know not both of them?

    What about all these other things that I have on here that I used to get rid of the virus? SuperAntiSpyware and the others. Should I get rid of them?

    The PC is in normal startup
    I installed the Java Software
    I installed the PCtools firewall

    How about Explorer?

    MGlogs zip file is attached.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure why but you are using MSconfig again to control startups. See step 1 of the READ & RUN ME for why you should not do this and how to deal with startups. The below shows that you are in Selective Startup mode because you disabled iTunesHelper and NapsterShell which you did not have disabled last time. I keep asking you not to use Msconfig but you keep using it.
    Sorry but a very bad choice.

    Spyware Dr, even just the starter edition is a much better choice.

    Final instructions below should answer this, but do not run these final instructions if still having problems.

    I assume you mean Internet Explorer (the browser). Explorer means Windows Explorer which is your Windows shell. If you are having a problem with your browser you need to tell me what the problem is. Make sure that you are not blocking iexplorer.exe, which is Internet Explorer, from having access thru the firewall.








    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    5. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    6. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    10. Go to add/remove programs and uninstall HijackThis.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     
    Last edited: Jun 25, 2008
  23. cindydenney

    cindydenney Private E-2

    What I was trying to do is to get Napster and iTunes not to load at startup. I unchecked them and I didn't notice until the last time I rebooted that it took it out of normal start up when I did it.

    When we switch to another user on this computer, we get a virus warning.
    It's not here on my user screen.

    I won't install the other spyware then.

    I'll check on my Explorer browser and see if it's blocked.

    Thanks.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But you need to stop using MSconfig to do this. See step 1 of the READ ME again.

    Then you need to run SUPERAntispyware, Malwarebytes and MGtools while logged into this account and attach new logs for this user account.

    Don't say Explorer. Say Internet Explorer or just say IE for short. But you still have not told me what your exact problem is.
     
  25. cindydenney

    cindydenney Private E-2

    Okay, I ran all 3 applications and the logs are attached.
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These logs are basically clean. You just need to uninstall Viewpoint Media Player again. If it keeps coming back then try running the below:

    ViewpointKiller
     
  27. cindydenney

    cindydenney Private E-2

    Okay, I'll do that.
    This computer just isn't acting right though. It takes a long time to search and it hangs up. I know you checked the logs and it looked clear on both user names and I'm convinced you know your stuff but I think it's still sick somehow.
    Also, when it's searching the hard drive makes a noise like a car excellerating.
    It wasn't doing that before. If I want to exit an application and I select the x in the corner, it won't close out until I click it a couple of times, It does this on just about any selection on any program and sometimes it hangs up.
    Is this a hardware problem or an infection of some kind? It wasn't doing this before it had a virus.
    I have an extended warranty on it it's a hardware issue but after my experience with the congenial but clueless tech. support guy, I have no faith in them.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We will dig a little deeper but you may have non-malware issues. Let's look for file system problems within Windows first.

    When you say search, do you mean on your PC or do you mean on the internet?

    Click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This is System File Checker. If it finds any problems it cannot repair from replacement files on your hard disk, it will ask for your Windows CD. Have it ready in case it asks for it.

    Now run this Running GMER to detect rootkits and attach the log.

    Also follow this procedure Using BitDefender Online Scan and attach the requested log which is an HTML file that has been renamed with a .txt extension so it can be attached. Follow the steps carefully to get the correct log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds