Need help, Panda says there is more to remove

Discussion in 'Malware Help (A Specialist Will Reply)' started by Don-B, Dec 19, 2006.

  1. Don-B

    Don-B Private E-2

    I've gone through the entire 'read this first..' instructions and things are much better, but the Panda scan says there is more to remove. I also got some popups that looked a lot like a hyjacking, but it only happened twice. Can you help, I would really appriciate it. Thanks, here's the files from the list (remainder to follow in next post). Thanks for the help,

    Don
     

    Attached Files:

  2. Don-B

    Don-B Private E-2

    Here are the next set of files, the HJT log will be next.
     

    Attached Files:

  3. Don-B

    Don-B Private E-2

    And now the HJT log. Thanks again for the help,

    Don
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You are the owner of a few problems. One of them that seems to be appearing a lot lately is a Rustock.b RootKit. Let's see if we can fix it first.


    Another tool that could be useful is ADSspy.
    • Please download ADS Spy, save to your desktop.
    • Once you have downloaded this utility, extract the contents and double click "ADSSpy.exe" to run the utility.
    • Once the utility has loaded, make sure the first 2 boxes are checked.
    • Now click Scan the system for alternate data streams
    • After the scan has finish look for any lines that have the below on them
      • C:\WINDOWS\system32:lzx32.sys
    • Select ONLY THOSE LINES and nothing else! And then have ADSspy remove them (there may only be one instance).
    Then reboot your PC into safe mode. Make sure you have enabled viewing of hidden & system files per step 2 of the READ ME. Look for C:\WINDOWS\system32\lzx32.sys and if found, delete it.

    I'm looking thru the rest of your logs now and will give you other steps too. Please complete the above ASAP.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After complete my instructions in message number 4, continue on with the below.


    You did not follow the directions for installing and renaming HijackThis. You have it here:
    C:\Upgrades\SpyWareRemover\HijackThis\Temp\HijackThis.exe

    That is not where we requested it to be installed and you did not rename it. SpyWareRemover is the name of a rogue antispyware tool, so that is a bad idea for a folder name. Also you put program in a Temp folder which is also a bad idea since temp and folders are prone to be deleted during cleanups. You should have the below:

    C:\Program Files\HJT\analyse.exe

    Please correct this now!

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 9
    Java 2 Runtime Environment Standard Edition v1.3.1_04

    Make sure you reboot after uninstalling the above!

    If you need the Sun Java Development kit you can get it here: http://java.sun.com/javase/downloads/index.jsp

    Do you know what the below 2 files (all created on Nov 10 th) are for? Are they all part of this "VisCalc" program you have installed? What is this for?
    C:\WINDOWS\system32\ViscalcUninstaller.exe
    C:\WINDOWS\system32\vismuwgh.exe


    What is the below file on your Desktop? Is it something from your ISP? Is it this Safe & Secure program (that includes Authentium Antivirus) that you installed on Nov 28th?
    C:\Documents and Settings\Diane Hlavac\Desktop\syusrelease.exe



    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: SelasI Class - {59F4F380-01A0-4083-9FA4-E3B827319F7E} - C:\WINDOWS\System32\vcbhylch.dll
    O4 - HKLM\..\Run: [system spool] C:\WINDOWS\System32\syspools.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [system spool] C:\WINDOWS\System32\syspools.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O21 - SSODL: XofDVHMtMNu - {0412E42D-AEB8-4E87-04A5-86EA4B9F74E8} - (no file)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\justin2a.exe
    C:\WINDOWS\thiselt.exe
    C:\WINDOWS\system32\dlh9jkd1q8.exe
    C:\WINDOWS\system32\druid_cchoice.exe
    C:\WINDOWS\system32\druid_redux.exe
    C:\WINDOWS\system32\durvilx.exe
    C:\WINDOWS\system32\google.png.exe
    C:\WINDOWS\system32\oeALFr7.exe
    C:\WINDOWS\system32\se.exe
    C:\WINDOWS\system32\slimiwwt.exe
    C:\WINDOWS\System32\syspools.exe
    C:\WINDOWS\system32\nsl5.dll
    C:\WINDOWS\System32\vcbhylch.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Documents and Settings\Diane Hlavac\Local Settings\Temp\

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. Don-B

    Don-B Private E-2

    Hi, I'm working on it (could take a few minutes). The HJT thing is really interesting. I did put the program under c:\prog.... and renamed it. But I have an old copy (from 2005) in the c:\upgrades..... directory you pointed to. How the heck did you see that one?

    Anyhow, I'll be back in a few minutes.

    Don
     
  7. Don-B

    Don-B Private E-2

    There were no instances of:

    C:\WINDOWS\system32:lzx32.sys or C:\WINDOWS\system32\lzx32.sys

    Should there have been at least one?

    Do you know what the below 2 files (all created on Nov 10 th) are for? Are they all part of this "VisCalc" program you have installed? What is this for?
    C:\WINDOWS\system32\ViscalcUninstaller.exe
    C:\WINDOWS\system32\vismuwgh.exe

    --I assumed those were from MS Visio, but this box doesn't have that program. I believe we can get rid of them if we need to.

    I went to add/remove program and saw visca... in the list. I highlighted it and clicked the change/remove button. It disappeared from the list.



    What is the below file on your Desktop? Is it something from your ISP? Is it this Safe & Secure program (that includes Authentium Antivirus) that you installed on Nov 28th?
    C:\Documents and Settings\Diane Hlavac\Desktop\syusrelease.exe

    -- I think it was supplied by the ISP. By the way, this is not my computer, so I'm doing some guesses. The date is about the time the problems started. It was the first thing I tried to get rid of, so let's dump it if we need to. Let's dump it even if we don't need to, it seems kind-of evil.

    I'm about to run HJT again, so I need to close the browser. See you again in a little bit.

    Don
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I expected one. Panda ActiveScan showed it and Panda was the last scanning tool you ran before attaching all the logs. Have you run any other tools since posting your logs? Run the below and attach a log from it:

    AVG Anti-Rootkit




    That file is probably the installation file. Deleting it will not uninstall all the applications which are already installed. I'm not sure you want to uninstall these anyway because you do need to have an antivirus, antispyware, and firewall program installed.
     
  9. Don-B

    Don-B Private E-2

    Everything went pretty well, here's the results: (in blue)

    Now click Scan the system for alternate data streams
    After the scan has finish look for any lines that have the below on them
    C:\WINDOWS\system32:lzx32.sys
    Select ONLY THOSE LINES and nothing else! And then have ADSspy remove them (there may only be one instance).
    Then reboot your PC into safe mode. Make sure you have enabled viewing of hidden & system files per step 2 of the READ ME. Look for C:\WINDOWS\system32\lzx32.sys and if found, delete it.


    -- No instances of lzx32.sys found


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 9
    Java 2 Runtime Environment Standard Edition v1.3.1_04

    Make sure you reboot after uninstalling the above!

    -- Done, all went fine

    If you need the Sun Java Development kit you can get it here: http://java.sun.com/javase/downloads/index.jsp

    -- Not needed, but thanks

    Do you know what the below 2 files (all created on Nov 10 th) are for? Are they all part of this "VisCalc" program you have installed? What is this for?
    C:\WINDOWS\system32\ViscalcUninstaller.exe
    C:\WINDOWS\system32\vismuwgh.exe

    --No action taken other than looking at it in add/remove. It disappeared, so is it gone?

    What is the below file on your Desktop? Is it something from your ISP? Is it this Safe & Secure program (that includes Authentium Antivirus) that you installed on Nov 28th?
    C:\Documents and Settings\Diane Hlavac\Desktop\syusrelease.exe

    -- No action taken

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: SelasI Class - {59F4F380-01A0-4083-9FA4-E3B827319F7E} - C:\WINDOWS\System32\vcbhylch.dll
    O4 - HKLM\..\Run: [system spool] C:\WINDOWS\System32\syspools.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [system spool] C:\WINDOWS\System32\syspools.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O21 - SSODL: XofDVHMtMNu - {0412E42D-AEB8-4E87-04A5-86EA4B9F74E8} - (no file)

    After clicking Fix, exit HJT.

    -- Done, all went fine

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    -- Done, all went fine

    Now run Pocket Killbox by doubleclicking on killbox.exe .......

    -- Done, all went fine. No problem deleting, no message about Pending...., reboot took a while, but it worked.

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Documents and Settings\Diane Hlavac\Local Settings\Temp\

    -- Nothing to delete, everything was dated from today

    Let me know how it looks. Should I try any other stuff to exercise it, or just wait for your reply? Thanks,

    Don
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you see message number 8?
     
  11. Don-B

    Don-B Private E-2

    Yes, working on it, be right back.
    Don
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay. I also just notice that Authentium and Safe & Secure are really no longer installed. Thus, you should delete the below folders from them:

    C:\Program Files\SafeandSecure
    C:\Program Files\Common Files\Authentium Shared


    Also delete the below link that references a malware program!!!!!
    C:\BraveSentry.lnk


    The below file is still there so it probably was not part of that VisCalc program. Delete the below file.
    C:\WINDOWS\system32\vismuwgh.exe

     
  13. Don-B

    Don-B Private E-2

    Good call! I did run the AVG spyware/virus scanner in between. OK, the AVG tool found the file you were looking for (log attached). What's next?

    Don
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now did you see message #12?

    Also tell AVG Anti-Rootkit to fix that file. Then reboot and run another scan to make sure it is gone. Then also check to make sure the file does not exist. Tell me the results.
     
  15. Don-B

    Don-B Private E-2

    Okay. I also just notice that Authentium and Safe & Secure are really no longer installed. Thus, you should delete the below folders from them:

    C:\Program Files\SafeandSecure
    C:\Program Files\Common Files\Authentium Shared

    -- Done

    Also delete the below link that references a malware program!!!!!
    C:\BraveSentry.lnk

    -- Done

    The below file is still there so it probably was not part of that VisCalc program. Delete the below file.
    C:\WINDOWS\system32\vismuwgh.exe

    -- Done

    Next? This is going really well, isn't it?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We'll see! ;) Let's find out if AVG AntiRootkit removes the rootkit.
     
  17. Don-B

    Don-B Private E-2

    Also tell AVG Anti-Rootkit to fix that file. Then reboot and run another scan to make sure it is gone. Then also check to make sure the file does not exist. Tell me the results.

    -- Yes, I did that. Scan (found it), delete, reboot, re-scan, nothing found. Must have worked.

    Don
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Great! If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  19. Don-B

    Don-B Private E-2

    If we used Pocket Killbox during your cleanup, do the below
    Run Pocket Killbox and select File, Cleanup, Delete All Backups

    -- Done

    If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.

    -- Not used

    If we user SDFix you can delete all the SDFix related files and folders from
    your Desktop or whereever you installed it.

    -- Not used

    If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.

    -- Not used

    If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.

    -- Not used

    If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.

    -- Deleted fixme.reg

    You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created

    -- Done

    If you are running Windows XP or Windows ME, do the below:
    go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    Then reboot and Enable System Restore to create a new clean Restore Point.

    -- Doing it now, be back in a couple of minutes
     
  20. Don-B

    Don-B Private E-2

    OK, that's done. Is there anything else to do, other than putting the protections in place? By the way, thanks a lot for the help! I'll let the owners of this box know they owe you a donation.

    Don
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's it! And also have he owners read the info in the How to protect link. They need to know all of the tips in there.

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds