trj downloader.VFT & Win32.worm Kelvir found

Discussion in 'Malware Help (A Specialist Will Reply)' started by didean, Feb 1, 2009.

  1. didean

    didean Private E-2

    Hi there, I ve been having problems for months. I downloaded a free tool for Vista called Speeditup Free and since then - problems such as no Internet explorer, unable to update downloaded programs, moxilla constantly freezing.
    I ran Ad Aware today -it identified Win32 worm kelvir infection and disinfected.
    I then ran online panda scan which found a Trj/Downloader.VFT file and clearned that too. But I am unable to remove Speeditup Free from the installed programs and moxilla still constantly freezes.
    I have worked through you Malware section for Vista cleaning. I downloaded and ran all of your programs. Malware Bytes was not able to upgrade despite going to the updater site. Combofix generated an error " Prep.com" has stopped working and did not run at all.
    MGtools - I was unabe to access the download from your link, it referred me to a site that said I had no access.
    I have attached herewith scan files from SAS, Spy Bot S&D and from Malware Bytes.
    I do hope that you may be able to offer some advice

    with best wishes and many thanks for reading this post. :)
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    We need the requested log from MGtools which is c:\MGlogs.zip.

    Please also try running ComboFix in safe boot mode and attach the log if it runs.

    A word of warning. Never download any tools that say they will speed up your PC. They don't work and everything you need to do to keep your PC running properly can simply be done by you. Also DO NOT run any registry cleaners.
     
  3. didean

    didean Private E-2

    Hi, I've now downloaded MGtools, put it in the root C: drive, but when I try to run it I get the following error:

    C:\MGtools\Getlogs.bat
    "Windows cannot acces the specifid device path, or file. You maynot have persmisssions to access the item.

    Any ideas? thanks Deirdre
     
  4. didean

    didean Private E-2

    RE :
    Please also try running ComboFix in safe boot mode and attach the log if it runs.



    Here is the Combofix log from Safe mode.

    Thanks :)
     

    Attached Files:

  5. didean

    didean Private E-2

    I am really sorry. I just worked out how to run the MGtools properly.

    Here it is.C:\ MGlogs.zip attached.

    I really really appreciate your help, thank you so much.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You appear to have ignored the early important warnings in the READ & RUN ME. You have both AVG8 and Comodo Internet Security Suite installed and running. You need to decide which of these you want to use and immediately uninstall the other. You need to do this right now before doing anything else. If you decide to uninstall Comodo, make sure you also get Comodo Safe Surf uninstalled too.

    Then uninstall Ask Toolbar as requested in step 1 of the READ & RUN ME.



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now goto this link Using MGtools and download the new version of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. didean

    didean Private E-2

    Hello
    Thanks
    The reason I had both comodo and avg is that the computer failed to uninstall avg properly at last hurdle and I didn't think it was running too.
    so sorry for that.

    When I first tried to run Combofix I kept getting messages to say avg was running, -these processes were stopped. The the running program gave an error message and rebooted. I ran it again after stopping avg and it ran ok.

    The fixme.reg file failed to run first attempt. Then i went online to look at your post, it was different from post as copied to my email, so I copied text again and ran again, successfully this time.

    I got a message to say it was successfully added to the registry.

    In error I first double clicked MGtools.exe instead of
    going to Getlogs.bat file and running as administrator. (im running Vista)

    I now have a pagefile.sys size of 2.8 gb, can I safely delete this?

    I enclose the logs for Combofix and MGtools.

    Thank you so much for writing the registry edits, I really appreciate it

    The machine seems to running a lot better now, I havent yet experienced all the freezing that was going on before. However, I still am unable to run Internet explorer.

    Thank you for all your help, it really is appreciated very much. :zzz
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to go back and run GetLogs.bat properly by right clicking and selecting Run As Administrator. Your last log is incomplete.


    No! It is a required file by Windows and cannot be deleted. You can adjust the size a little but that is not a topic for this forum. Your C hard disk is just too full. It would have been better if you had not made two partitions. You only have 2.90 GB free on drive C and this is going to start having a noticeable effect of slowing you down as the free spaces gets smaller.
     
  9. didean

    didean Private E-2

    Here is the log for C:\MGlogs.zip

    thanks
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay your logs are clean but you have some left overs from Symantec to remove.

    Please run the below then reboot. After reboot run it one more time.

    Norton Removal Tool (SymNRT)


    Then if you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  11. didean

    didean Private E-2

    Dear Chaslang,

    My machine is a lot better now although I do still experience firefox freezing a lot and I am still unable to access the internet through internet explorer nor can I update certain programes (I think they require IE to update), for example, superspyware won't update. I suppose the malware corrupted some of the registry files. Should I swap over to one of the software forums to completely resolve these remaining issues?


    Thanks a lot for all your help.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the Software Forum.


    You need to make sure you have everything setup properly. Your logs showed you were using a proxy server to connect. You must configure everything to properly use the proxy server. If you do not need a proxy server then you need to remove the settings specifying a proxy server to be used in your Internet Explorer setup. Yes this is also more of an issue for the Software Forum.


    One last thing I recommend to remove some Symantec left overs. Please run the below then reboot. After reboot run it one more time.

    Norton Removal Tool (SymNRT)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds