troj/virtum-gen and Mal/Generic-A

Discussion in 'Malware Help (A Specialist Will Reply)' started by woofai, Jun 22, 2008.

  1. woofai

    woofai Private E-2

    Hello,

    I think my laptop still has these viruses and would need help for removal.

    Right now, these are the symptoms I see:
    - It takes VERY LONG to start or restart my laptop (about five minutes of a blank screen after the windows logo, and about another five minutes after I log onto windows.
    - It takes a VERY LONG time to start Spybot S&E, about five minutes or so after I click on the program.
    - In Sophos' Quarantine Manager, I still have Mal/VB-M (from trying vundofix.exe) and I have Mal/Generic-A (in a system restore location), neither of which I can Perform Action on.
    - In Sophos Quarantine Manager, I originally had the Troj/virtum-gen on the list too, but tried a clean up on it a few times before it seem to have worked, and now it's not on the list anymore

    I have followed the "Read & Run Me First" steps. Attached are the logs, (and the MGlog will be in the new post.)


    Thank you very much,

    Woo
     

    Attached Files:

  2. woofai

    woofai Private E-2

    And here is the MGlogs. Thank you.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean......the only things I see for you to do (which are not malware related) are:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    You might want to try a different anti-virus as Sophos may be part of the problem.

    You may wish to use a Startup Manager

    We will flush your restore points.

    1 If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)

    * Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    * "%userprofile%\Desktop\cf" /u
    o Notes: The space between the cf" and the /u, it must be there.
    o This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    * Delete the C:\cf folder from combofix.
    2 *If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3 *If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    6. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  4. abri

    abri MajorGeek

    Hi woofai,
    Welcome to Major Geeks!

    Your computer problems look more like they may be due to your programs exceeding your capacity than to malware problems.


    I would like to have you use ComboFix to remove some files. One of these files may or may not be malware, but the rest are just items which can be fixed.


    • Make sure that combofix.exe (cf.exe) that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):


    Code:
    KILLALL::
    
    FILE::
    C:\WINDOWS\Temp\inf1clrg.tmp
    C:\WINDOWS\Temp\JETCD2F.tmp
    C:\WINDOWS\Temp\JETCD3F.tmp
    C:\Documents and Settings\John Chan\Local Settings\temp\~DF2DAA.tmp
    
    FOLDER::
    C:\Documents and Settings\All Users\Application Data\Viewpoint
    C:\Documents and Settings\John Chan\Local Settings\temp\plugtmp
    
    REGISTRY::
    
    [-HKEY_CURRENT_USER\Software\Kazaa]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\knight]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "HideLegacyLogonScripts"=-
    "HideLogoffScripts"=-
    "RunLogonScriptSync"=-
    "RunStartupScriptSync"=-
    "HideStartupScripts"=-
    
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "HideLegacyLogonScripts"=-
    "HideLogoffScripts"=-
    "RunLogonScriptSync"=-
    "RunStartupScriptSync"=-
    "HideStartupScripts"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe (cf.exe)
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below


    Note: Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run CCleaner at the default setting with the Windows tab as the top one.

    Please attach the Combofix log.


    Let me know how things are running now?

    abri
     
  5. woofai

    woofai Private E-2

    Hi TimW and Abri,

    Thanks for verifying that the virus is gone. I have performed the tasks listed. (Attached is my combofix log.) However, my laptop still starts very slowly. What else could be the problem?

    The only thing I can think of is that I used to use msconfig to do selective startups, but during the READ AND RUN ME FIRST procedures, I switched back to normal startup. Would going through each startup item with another program help? I have not done that yet and will do it later tonight if that's the case.

    Thanks very much,

    Woofai
     

    Attached Files:

    • log.txt
      File size:
      18.2 KB
      Views:
      4
  6. abri

    abri MajorGeek

    Hi woofai,

    There is still a question about something in your Combofix log. One of us will get back to you about this. Thanks for being patient.

    abri
     
  7. woofai

    woofai Private E-2

    Hi abri,

    My laptop works better now. I just uninstalled Sophos Antivirus and installed Avast, and the startup time is okay without tweaking anything else. So I guess Sophos might have indeed caused the problem. Is there anything else I should do to make sure things are okay?

    Thanks for your help,

    John
     
  8. abri

    abri MajorGeek

    Hi woofai,

    Please do the following:




    I would like to have you use ComboFix to remove some files. One of these files may or may not be malware, but the rest are just items which can be fixed.


    • Make sure that combofix.exe (cf.exe) that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):

    Code:
    KILLALL::
    
    FILE::
    C:\WINDOWS\system32\Explorer.exe
    
    REGISTRY::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "Explorer"=-
    

    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe (cf.exe)
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below


    Note: Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run CCleaner at the default setting with the Windows tab as the top one.

    Please attach the Combofix log.

    Then, if you have not yet done the removal instructions posted to you by TimW, please go ahead with them now. If you have not cleared and reset your restore point, please wait with that.

    Thanks.
    abri
     
  9. woofai

    woofai Private E-2

    Hi abri.

    I have ran combofix and attached is my combofix log. (I have ran TimW's removal before and did not rerun it this time.) Will wait for your response on any next steps.

    Thanks,
    woofai
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you still having any issues?
     
  11. woofai

    woofai Private E-2

    I think I am okay, no issue after uninstalling Sophos. Thanks you abri and majorgeeks.com for the help.
     
  12. abri

    abri MajorGeek

    Hi woofai,

    I'm glad you found the solution in switching out Sophos. Unless you think you'll be needing Smitfraud Fix, you can remove the following files from your computer and then I'll give you the final cleanup instructions below.


    • Make sure that combofix.exe (cf.exe) that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    File::
    C:\WINDOWS\system32\VCCLSID.exe
    C:\WINDOWS\system32\SrchSTS.exe
    C:\WINDOWS\system32\VACFix.exe
    C:\WINDOWS\system32\IEDFix.exe
    C:\WINDOWS\system32\IEDFix.C.exe
    C:\WINDOWS\system32\404Fix.exe
    C:\WINDOWS\system32\Process.exe
    C:\WINDOWS\system32\dumphive.exe
    C:\WINDOWS\system32\WS2Fix.exe
    C:\WINDOWS\system32\tmp.reg
    
    Folder::
    C:\Documents and Settings\John Chan\SmitfraudFix
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe (cf.exe)
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below


    Note: Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run CCleaner at the default setting with the Windows tab as the top one.

    Now REBOOT your computer and see how everything is working. If you are satisfied, continue with the final cleanup instructions.

    Below are the final cleanup instructions which will have you remove all of the tools and logs we had you put on your computer:


    abri
     
  13. woofai

    woofai Private E-2

    Hi abri,

    I've ran through the cleanup steps. Attached is my log.

    Thanks,
    woofai
     

    Attached Files:

    • log.txt
      File size:
      20.8 KB
      Views:
      2
  14. abri

    abri MajorGeek

    Thanks woofai!
    Everything looks good!
    All the best of computer experiences to you.
    abri
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds