trouble removing agobot/gaobot worm

Discussion in 'Malware Help (A Specialist Will Reply)' started by elemenoh, Apr 29, 2005.

  1. elemenoh

    elemenoh Private E-2

    I can't seem to get rid of the agobot.gen (gaobot.gen, according to Norton) worm.

    I'm running XP, system pack 2, and I'm up to date on all patches and things. I've got Norton and AVG both running, and they've been trading off giving continual warnings about the virus. Norton detects and deletes the files (crss.exe and nvc32.exe, specifically), while AVG is unable to quarantine, fix or delete them.

    I ran the Symantec fix tool (here) multiple times, but it doesn't find an infection at all.

    So far, I've done everything recommended on your 'read first' thread, including all the optional stuff. (By the way, that thread's the best and most comprehensive virus removal how-to I've seen!) Here are the results of the virus scans:

    Trendmicro scan: found infection, but unable to clean or delete
    Symantec: page wouldn't load (possibly a problem with Firefox?)
    McAfee: no infection
    Bitdefender and TrojanScan: found popcap dialer, deleted
    RavAntiVirus, a2, avast: no infection

    I've also googled like crazy to find a manual fix, but the only available one seems to be the one recommended by Symantec (on the page linked to above). I can't find any of the registry values that correspond to the virus. (I ran RegScrubXP in case I was missing something, but to be honest, I couldn't make heads or tails of the results, so I didn't want to change anything.) Similarly, my hosts file is clean (only entry is the 127.0.0.1 localhost one).

    I'm at a bit of a loss now. So, hopefully you can give me some advice on how to get this thing gone. Sorry this post is so long!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you tried this: W32.Gaobot Removal Tool

    Please follow the steps below if you still have problems:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. elemenoh

    elemenoh Private E-2

    I did try the Gaobot fix tool, but it doesn't find an infection to fix.

    HijackThis log is attached. Thank you!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must only use one antivirus application. They can conflict with each other and cause problems on your PC (including making it difficult to fix problems). Pick which you prefer and uninstall the other.

    Please provide a list of which files you are having problems with. Give the full path to the file not just the file names.

    Which TrendMicro scan did you run (the Java version or the normal one)?

    Try the below:

    Download this virus checker and tool from eScan Mwav.exe (Use Download Link 3)

    1. Save it to a folder.
    2. Reboot into safe mode
    3. Double click the Mwav.exe file.(This is a stand alone tool and NOT just a virus checker......so it won't install anything)
    4.Select all local drives, scan all files, press SCAN and when it is completed, anything found will be displayed in the lower pane.
    5. In the Virus Log Information Pane......
    Left click and Highlight all the info in the Lower pane--- Use "CTRL C" on your Keyboard to copy all found in the lower pane and save it to a notepad file

    *Note* If prompted that a Virus was found and you need to purchase the product to remove the malware, just close out the prompt and let it continue scanning.

    We just want to use it to try to identify anything that is bad.

    Once you copy that to a notepad file, highlight the text and copy as an attachment.
     
  5. elemenoh

    elemenoh Private E-2

    The troublesome files are:

    C:\crss.exe
    C:\Documents and Settings\All Users\Documents\crss.exe
    C:\nvc32.exe
    C:\Documents and Settings\All Users\Documents\nvc32.exe
    C:\WINDOWS\System32\spool\PRINTERS\*.SPL (* is a 5 digit number, different each time it has come up.)

    I used the Java version of the TrendMicro scan.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should empty your virus vault and the Norton protect of your recycle bin too.

    Also boot into safe mode and delete:
    C:\crss.exe
    C:\nvc32.exe
    C:\Documents and Settings\All Users\Documents\crss.exe
    C:\Documents and Settings\All Users\Documents\nvc32.exe
    C:\WINDOWS\System32\spool\PRINTERS <--- all files in this folder should be removed
     
  7. elemenoh

    elemenoh Private E-2

    I removed the files, but as soon as I booted back in normal mode, c:\nvc32.exe came back. (The others haven't made an appearance yet.) The virus vault fills up as quickly as I can empty it...
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is system restore disabled and did you uninstall one of the AV applications as I previously mentioned?
     
  9. elemenoh

    elemenoh Private E-2

    System restore is off, and I uninstalled AVG.

    This morning I started getting this error when I start the computer:

     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run Ccleaner or manually delete those files:
    C:\DOCUME~1\sims\LOCALS~1\Temp\WER7b22.dir00\svchost.exe.mdmp
    C:\DOCUME~1\sims\LOCALS~1\Temp\WER7b22.dir00\appcompat.txt

    In fact you should be able to delete thw whole WER7b22.dir00 folder.

    Is that c:\nvc32.exe file still on your PC?

    Please download, install, and update: Spy Sweeper
    Then run a full scan with Spy Sweeper and fix what it finds. Post the log from Spy Sweeper as an attachment.

    Now post a new HJT log too. Tell me what problems you may still be having.
     
  11. elemenoh

    elemenoh Private E-2

    I wasn't able to find the WER7b22.dir00 folder at all manually, and when I ran CCleaner, those files were not on the list of deleted items. (Yesterday's error message didn't appear today.)

    C:\nvc32.exe is still there, and C:\Documents and Settings\All Users\Documents\nvc32.exe and all the entries in the C:\WINDOWS\system32\spool\PRINTERS folder have reappeared in the last few hours.

    I installed, updated and ran Spy Sweeper (in normal mode because it wasn't specified - is that alright?), log is attached.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Was that all that Spy Sweeper found and reported? Usually there is significantly more info than that.

    That nvc32.exe may be part of Norman Antivirus Control.

    Now download: Pocket KillBox

    And extract it to its own folder.
    Double-click killbox.exe on your desktop. Select the option "Delete on reboot".
    Now highlight and 'copy' the entire list of filepaths below:

    C:\nvc32.exe
    C:\Documents and Settings\All Users\Documents\nvc32.exe

    Open 'file' in the killbox menu at the top and choose 'Paste from clipboard'

    Now you will see, this is pasted in the "Full Path of File to Delete"-field.
    There's a little arrow (dropdown-arrow) next to that field.
    If you expand it, these lines should be there together!

    Then press the red button with a white X in it.
    Killbox will tell you that all listed files will be deleted on next reboot.
    Click YES

    When it asks if you would like to Reboot now, click YES
    If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just restart manually.

    Now after reboot check to see if those files are gone. How are things running.
     
  13. elemenoh

    elemenoh Private E-2

    That was all I got from Spy Sweeper, unless I took the info from the wrong place - I copied out what was in the window in the lower part of the screen.

    I had trouble with Pocket KillBox. It wouldn't paste the filenames correctly, so I tried to do them individually, but each time I got an error saying the files don't exist. Searching manually, I couldn't find them either. The Norton warnings are still coming, however, in fits and spurts - I'll get a couple hundred warnings over a few minutes, and then everything will be quiet for a few hours. Maybe what's happening is that Norton is actually doing a good job getting rid of the files when they show up, but somehow I'm periodically getting reinfected?

    The computer is running fine, other than the alerts - if it weren't for the Norton pop-ups, I wouldn't suspect anything was wrong.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Perhaps Norton is removing them and that is why PocketKillbox cannot find them. You need to get a real firewall installed and then disable the one in Win XP SP2 as it just is not good enough. Please see the link below (which includes a couple free ones). You should complete all those steps anyway. Make sure if it ever comes up on the firewall that you disable nvc32.exe from having any access in or out of your PC. There could be another file on your PC that is reloading this.

    If it does come back and you can actually see it, right click on it and select Properties and then the Version tab (if it has one) then scroll thru the Item name list so we can see who it belongs to.

    How to Protect yourself from malware!
     
  15. elemenoh

    elemenoh Private E-2

    I downloaded ZoneAlarm, and have had no more virus problems - thank you so much for all your help with that.

    I am still occasionally getting the error message I mentioned previously. The same files are reported, but with different paths each time. It's happened twice since I last posted, and the files were:

    C:\DOCUME~1\sims\LOCALS~1\Temp\WERc3ec.dir00\svchost.exe.mdmp
    C:\DOCUME~1\sims\LOCALS~1\Temp\WERc3ec.dir00\appcompat.txt

    and:

    C:\DOCUME~1\sims\LOCALS~1\Temp\WER8e81.dir00\svchost.exe.mdmp
    C:\DOCUME~1\sims\LOCALS~1\Temp\WER8e81.dir00\appcompat.txt

    Any idea what this is?
     
  16. chuddds

    chuddds Private E-2

    you are still are infected. at symantecs site do a search on: WERc3ec

    and any other file you have issues with.

    also, do a scan in DOS with F-Prot, google it.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please post as an attachment the appcompat.txt file. You may be having a software compatibility problem. The file may be too large to post and you may need to compress it with WinZip or similar before posting.

    If you run CCleaned, it should be delete all files in that Temp folder.
    Are you playing any games? If so, which ones? Do you play online?

    Are you using any P2P downloading software (like Kazaa, Morpheus, Limewire, Imesh, etc)?
     
  18. elemenoh

    elemenoh Private E-2

    I searched for appcompat.txt, and the only file that showed up was under a different user-name. (One that hasn't been used in quite some time, though the file was last modified May 4, 2005.)

    I don't usually play games, though I played Zuma (from this site) recently. I don't use any P2P software. I'm the only active user on the computer, as well.

    I've run CCleaner under my username - is there a way to get it to clean all usernames, or do I need to do it under each individually?
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It you are the only user, what are the other user accounts for? Are they all password protected?

    You need to run CCleaner (and all cleanup procedures for that matter) under all user accounts.

    Where was the file that you attached located? The full path. Still looks like software compatiblility issue.
     
  20. elemenoh

    elemenoh Private E-2

    The other user accounts are there because my family shares the computer when I'm home. I'm currently at school, though, so they've been unused for the last 4 months, approximately. They are password protected.

    The full pathname was:

    C:\Documents and Settings\Kathleen\WER2.temp.dir00\appcompat.txt

    I've gone through and run all the clean-up programs in each username. The only programs I've installed recently are the ones recommended here in the course of fixing the virus. Could one of these be causing trouble?
     
  21. elemenoh

    elemenoh Private E-2

    also: new strange thing. Something's gone screwy with the task manager. The tabs and menus have disappeared - even the top bar with the close/minimize/maximize buttons. All I've got is the lower part of the window - with the program list, status, and the three end task, switch to and new task buttons. There's no way to close it except right-clicking on the icon in the system tray. I'm not sure when this happened, as I don't open the task manager that often, but the computer was running slowly as I was trying to open a browser window, and I opened it to see if something was going on in the background. (Various Norton processes take over now and again, and I wanted to check what it was doing.)
     
  22. elemenoh

    elemenoh Private E-2

    Sorry, never mind that last post, fixed it. (Stupid me double-clicked somewhere I shouldn't have, apparently. Duh.)
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There should be no problems with any of the items you downloaded. These files are created by Windows. You do not need to worry about them. They are not malware related.
     
  24. elemenoh

    elemenoh Private E-2

    I figured as much...is there any indication in the file where the software conflict might be coming from?

    Should I move over to the software forum with this?
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Probably better to ask in the Software Forum. I have never really looked at these files that much. I'm also not sure they also indicate a true software compatibility issue. There are filenames on some of the lines. For example one of the filenames mentioned in the file you attached I'll highlite below in bold.

    <EXE NAME="Start.exe" FILTER="GRABMI_FILTER_THISFILEONLY">
    <MATCHING_FILE NAME="start.exe" SIZE="5877760" CHECKSUM="0x691E33FF" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0" LINKER_VERSION="0x0" LINK_DATE="08/01/2002 23:14:49" UPTO_LINK_DATE="08/01/2002 23:14:49" />
    </EXE>
     
  26. elemenoh

    elemenoh Private E-2

    Alright - thank you so, so much for all your help. This forum is really an awesome resource. Thank you for your (and everyone's) hard work in making this such a great place.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds