Need Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by GeauxSaints, Apr 22, 2006.

  1. GeauxSaints

    GeauxSaints Private E-2

    I have Trend Micro, and I have been getting "Real-time Scan" popups indicating that I have a virus called "SPYW PPNETWORK.B". The "Scan action result: Denied access". I have gone to the Trend Micro site, as well as Panda, Trojan Hunter, Trojan remover, and several others to no avail. I also rebooted in safe mode, and did a search for "P2P Networking", but the scan found nothing.


    Operating System: Microsoft Windows XP Professional
    CPU Type: AMD Athlon XP-A, 1833 MHz (5.5 x 333) 2500+
    Motherboard Name: Abit NF7(-S) v2.0 (5 PCl, 1 AGP, 3DIMM, Audio, LAN)
    Motherboard Chipset: nVIDIA nForce2 Ultra 400
    System Memory: 512 MB (PC3200 DDR SDRAM)

    Let me know if you need more info, and I will try to find it.

    Thanks
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    Make sure you follow the directions in step 7 to install HijackThis properly because you have not done so.

    Also disable Spybot's Teatimer as requested in the READ ME.

    Also you have two firewalls installed. You MUST NOT run multiple software firewalls. So you must uninstall ZoneAlarm since you already have your Antivirus and firewall from Trend Micro.

    I see the below in your log. Is drive D a hard disk or a CD ROM? Who is your ISP? Do they use BroadJump Client Foundation ?
    O4 - HKLM\..\Run: [WorkFlow] D:\Install\WorkFlow.exe
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  3. GeauxSaints

    GeauxSaints Private E-2

    Thank you so much for your help.

    The File name is: C:\System Volume Information\_restore{....etc.

    Ok, I went back and ran Ccleaner, Ad-aware, Spybot, and Counter Spy all in safe mode. Ccleaner found some trash, and I removed it. Ad-aware also found something which had "P2P Networking" in the file name. Spybot and counter spy both found nothing.

    I am not sure how to disable the "Teatimer" feature, so if I need to do that please tell me exactly how.

    I tried to run Bitdefender in the Safe/networking mode, but the scan refused to load. I downloaded "ActiveX" and "Java" and the scan still refused to load. I did manage to conduct a Panda Scan, and I have attached the saved report.

    I also tried to download HiJack this exactly as instructed. If it is still done incorretly please let me know exactly what I need to do differently. I did a HiJack scan, and that report is also attached.

    As of now, no more warnings have come up. If another one does, I will let you know in a post. Thanks again
     

    Attached Files:

  4. GeauxSaints

    GeauxSaints Private E-2

    It popped up again.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your forgot to answer my question. I repeat:
    To disable TeaTimer, run Spybot and click Mode and select Advanced Mode. Then click Tools and select Resident. Now in the right window pane, uncheck TeaTimer. Also while this is open, in the left column now select IE Tweaks and then in the right pane make sure all the Miscellaneous locks are unchecked. Now quit Spybot!


    Don't worry about files in C:\System Volume Information\_restore That is the System Restore folder. My final steps will take care of them later.

    You did not do what was requested in step 0 of the READ ME related to emptying your Norton Nprotect folder which is full of garbage. This made your scanning take longer and made your logs much larger than they should be. Empty it now!

    Copy the bold text below to notepad. Save it as fixMe.reg to your desktop (yes overwrite the previous one). Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    After clicking Fix, exit HJT.
    Now get a new HJT log and attach it here. If the above BHO lines came back, we will ha
     
    Last edited: Apr 23, 2006
  6. GeauxSaints

    GeauxSaints Private E-2

    Is drive D a hard disk or a CD ROM? It is a DVD Re-write drive.

    Who is your ISP? COX cable

    Do they use BroadJump Client Foundation? Not that I know of, but how would I check for it.

    I disabled TeaTimer, and I also made sure that the IE Tweaks were all unchecked (they were).

    I went to the “RECYCLER”  “Nprotect” and deleted all of the garbage, so let me know if there is something else I need to do.

    I created a fixMe.reg on the notebook and saved it on the desktop, and allowed it to merge with the registry.

    Finally, I went into HiJack this and deleted the three lines that you listed. The new HJT log is attached.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just have HijackThis fix the below line:

    O4 - HKLM\..\Run: [WorkFlow] D:\Install\WorkFlow.exe

    Are you still having any malware problems?
     
  8. GeauxSaints

    GeauxSaints Private E-2

    I had HiJack this fix the O4 – HKLM… etc. line, and the scan is still detecting problems.

    The virus is named “ADW AUREATE.B” and it is in the file: C:\System Volume Information\_restore{44B91D0B-D553-44C0-D65C-BDD5A73B2EC0}\RP199\A0015922.dll. Not sure if that helps. “The Scan action result: Denied Access” I have attached the new HiJack this log, after fixing the O4 – HKLM… etc line.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Remember what I said earlier????
    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
    Last edited: Apr 25, 2006
  10. GeauxSaints

    GeauxSaints Private E-2

    That fixed it. Your the man, thanks for your help.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds