Nutcracker virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by Dezoob, Aug 23, 2008.

  1. Dezoob

    Dezoob Private E-2

    Avast! AntiVirus tells me I have the Nutcracker family virus on my laptop. I have followed the READ AND RUN ME FIRST Malware Removal Guide. All went smoothly but I could not get ComboFix to work with the Microsoft file. I downloaded two Microsoft files but when I placed them over ComboFix file, Window Fix Console did not appear. I am using Windows XP Media Center Version 2002 Version Pack 3.

    I was not sure if it was a good idea to run ComboFix with out Window Fix Console. I did the rest of the instructions but when I went to run Avast! Antivirus, it alerted me again to the Nutcracker family virus!!! Help??
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can skip the combo if you are concerned about running it. But I need to see the other logs:
    SuperAntispyware
    MalwareBytes
    MGLogs.zip from running the MGTools.exe
     
  3. Dezoob

    Dezoob Private E-2

    Hi Tim

    I have attached two files as the AntiSpyWare did not find any viruses.

    When I run Avast! this morning, it did not find any viruses - nutcracker seems to have disappeared. Would it have been deleted when I ran all the virus checkers except ComboFix.

    My laptop seems to be running slower than normal yet I have used CCleaner and DeFrag to sort out the PC.

    THANKS for all the support and help on this website - it has been invaluable for a complete PC novice. The instructions are so easy to follow and I now understand how to look after my PC - brilliant advice.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Part of your problem is that you are running two anti-virus programs:
    avast! Antivirus
    Norton 360

    You need to uninstall one of them!

    If you haven't already, please disable the Guest account in User accounts.

    Also you have every user as an adminitrator --> do you really want it this way?
    (You will need to run MWB's on each user account).

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  5. Dezoob

    Dezoob Private E-2

    Hi Tim

    Thanks for this info...

    I am worried about uninstalling either Norton or Avast!. Norton, I have paid for but it does not seem to pick up any problems on my laptop so I don't know if it is protecting me!!! Avast! picked up Nutcracker. They both seems to pick up different viruses - do they not compliment one another?? Can I just disable one?

    We are all administrators because as soon as I make just myself an administrator, Norton stops protecting the other users. If I try and fix this in their accounts, Norton will tell me I am not an adminstrator so it cannot fix the problem and protect those accounts. I am not sure why or what I am doing wrong.

    I ran disable Windows Messager but as soon as I logged in as another user, it reinstalled itself!

    When I ran the C:\MGtools\analyse.exe, I could not find any of the the 09 lines to select. Does this matter?

    I have managed to do everything else mentioned in the email and please find attached the files from Avenger and MGtools.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to run the windows messenger removal on all user accounts ( as well as SAS and MWB's). Which is why it did not show in your HJT log as an 09 item because you had removed it on your account.

    If Norton is paid for, keep it and keep it updated. Remove Avast! We will give you guides on protecting yourself.

    Are you sure it is not running on their account or just that as a limited account they can't access it? If that isn't the case, you need to post in software to resolve that.

    I would like to know if either SAS or MWB's finds anything on the other user accounts before I give you the last instructions.
     
  7. Dezoob

    Dezoob Private E-2

    Tim

    I only managed to use this link to get rid of Windows Messenger on one account after that it would not let me access it again. I have tried to uninstalled Windows Messenger with CCleaner. Will this do the trick?

    I have nowu run SAS and MWB's on all accounts - there are no viruses found. I also ran SpyBot on all accounts which did find one Vundo virus.

    I will remove Avast! and keep Norton.

    When I make the other users, limited users, Norton does appear to be running but with a red cross instead of the green tick. I can open Norton in the other users accounts but when I click on Fix, it states that I must be an Administrator. When I log back into my account, Norton is running with the green tick! So Norton is running in all accounts but not protecting if limited user status is selected.

    I have run another MGTools\GetLogs.bat and have attached this if it will be helpful.

    All the instructions you have given me has related to my laptop but I also have issues with my PC. I have done the READ AND RUN ME FIRST instructions on my PC and would like to send you the GetLogs.bat from there as well but I will send it in another reply.

    Can you let me know if I should uninstall the programs that I installed during the READ AND RUN ME FIRST instructions such as SAS, MWB's, SpyBot, Combo etc? Do I also need to re-hide my system files and folders?
     

    Attached Files:

  8. Dezoob

    Dezoob Private E-2

    This is the second part to my email regarding my PC virus problems.

    I have attached the GetLogs.bat file.

    Do I need to do any more to my PC to ensure that I have removed all viruses from it? Do you need any more information from me?
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It should.

    You should start a new thread if you want help with a different computer....it can lead to confusion as I will now reply to two different issues.

    On the desktop:
    Same issue - two anti-virus programs. Uninstall Avast.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now use windows explorer to find and delete:
    C:\WINDOWS\system32\bbsywvwe.ini
    C:\WINDOWS\system32\jdiguebm.ini
    C:\WINDOWS\system32\ojpsnhei.ini
    C:\WINDOWS\system32\ponovyxx.ini
    C:\WINDOWS\system32\ponovy~1.ini
    C:\WINDOWS\system32\vssjbvon.ini

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.

    And for the laptop:

    If you are not having any other malware problems, it is time to do our final steps:


    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below

      * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combo-fix folder from combofix.

    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    9. Go to add/remove programs and uninstall HijackThis.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    12. After doing the above, you should work thru the below link:

     
  10. Dezoob

    Dezoob Private E-2

    Apologies for not starting a different thread - do you want me to do this when replying about the laptop?

    Unfortunately I unistalled MSN not Windows Messenger using CCleaner! How would I find out if Windows Messenger is still on my PC?

    PC Information.

    All instructions followed but I was unable to find the following file in Windows Explorer:
    C:\WINDOWS\system32\ponovy~1.ini

    Please find attached MGlogs.zip file.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Windows messenger is not running on this computer.

    Please use windows explorer to find and delete:
    C:\WINDOWS\system32\ponoVyxx.ini2

    Otherwise you look clean. :)
     
  12. Dezoob

    Dezoob Private E-2

    I have managed to find that file and deleted it.

    THANKS so much for your help with the virus problems on both my laptop and PC. It is amazing how fast the computer work now!!
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:


    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below

      * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combo-fix folder from combofix.

    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    9. Go to add/remove programs and uninstall HijackThis.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    12. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds