Netsky.q and Advanced Virus Remover infections

Discussion in 'Malware Help (A Specialist Will Reply)' started by RicklessPI, Dec 2, 2009.

  1. RicklessPI

    RicklessPI Private E-2

    Hello all

    I followed the read and run forum post to the letter. I ran them in the order, and the only one I had trouble with was the Root Repealer. As soon as I launched it, it gobbled up all the memory and PC resources. I left it to run for 1.5 hours, but no scan menu came up, so I moved forward to the next step in your process. I have the logs you requested, except for the Root Repealer. I did run the Rootkit Revealer and generated that log, so I will include it as well. I do have control of my PC again after all of this and my wall paper is no longer the infected message. However, when I open a window and move it around, it leaves a ghost trail behind it for about .25 seconds. This is new and did not happen prior to the infection, which makes me think I may still have something lurking out there. I was able to do a screen capture of this even and will attach with the rest of the logs in post #2. Please let me know what you think and I'll be happy to try it.

    Thanks for everything so far!
    Rick
     

    Attached Files:

  2. RicklessPI

    RicklessPI Private E-2

    Here is part #2 with the rest of logs and the image.

    It looks like the image I captured is too large for the DL limits. Anyway, when I move a window around on the desktop, it leaves a trail behind it for .25 seconds or so. I think you get the idea.

    Thanks
    Rick
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    This really does not sound like it is due to malware and your logs are basically clean. I just have few more things you need to do. You may want to just quickly check that you mouse settings have not been changed.

    You really should stop using MSconfig as requested in step 4 of the READ & RUN ME.

    Uninstall the below software:
    Search Bar
    Spybot - Search & Destroy 1.5.2.20

    You have left overs from Symantec to remove. Please run the below then reboot. After reboot run it one more time.

    Norton Removal Tool (SymNRT)


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O15 - Trusted IP range: 206.161.125.149
    O16 - DPF: JT's Blocks -
    O16 - DPF: Toki Toki Boom -
    O16 - DPF: Yahoo! Blackjack -
    O16 - DPF: Yahoo! Pool 2 -
    O16 - DPF: Yahoo! Pyramids -
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) -
    O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} -
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
    O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} -
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) -
    O16 - DPF: {CE74A05D-ED12-473A-97F8-85FB0E2F479F} (dlControl.UserControl1) -
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
    O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) -

    After clicking Fix, exit HJT.

    Delete the below folder if it exists:
    C:\Program Files\SEARCH3 TOOLBAR

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. RicklessPI

    RicklessPI Private E-2

    Here we go...

    I noticed that my volume was bumped down during this infection and I had to turn it back up, so I thought maybe my video card or driver had suffered as well. I went in to display properties, went over each tab to make sure they were properly set, then clicked ok. Bingo, ghost image on the windows disappeared.

    I am no longer using MSCONFIG. Managing start up through Spybot S&D now.
    Software uninstalled.
    Removed Symantec leftovers.
    Fixed entries with HJT.
    Ran REGEDIT fix.
    Ran CCleaner.

    Here is the MGLogs.zip file. Trying to open and populate My Computer Window took 3 efforts (it reset Explorer along the way), but it is running fine now. It looks like everything else is working great! Thank you all so much for your help. Do you all take donations and such to share around anything like that? I'd send brownies, but those are tough on my email server.

    I have notebook I am trying to remove the same virus from. Will post on a new thread.

    Thanks again for all your help and let me know if there is anything else I should do on this PC.

    Rick
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds