Trouble with VBS.Psyme

Discussion in 'Malware Help (A Specialist Will Reply)' started by lakeriedog, Oct 14, 2006.

  1. lakeriedog

    lakeriedog Private E-2

    Hello,
    Thank you in advance for any and all help. Last week McAfee started showing a message that it found and cleaned VBS.Psyme. It recommended that I scan afterwards which I did, but it kept coming back. I have worked through all of the steps mentioned in the Read and Run Me First post, and am now not sure if it is gone or merely waiting to pop back up.

    I have attached the BitDefender, Panda and GetRun Key, and will add another post for the ShowNew and Hijack this.

    The computer is an older model desk top that I bought used from the resale office where I work for a very cheap price. Here is Operating system information.

    Computer Model Dell Dimension XPST500
    BIOS Vendor Intel Corp.
    BIOS Version 4S4EB2X0.10A.0017.P05
    BIOS Date 04-22-99
    Windows Version Microsoft Windows 2000 Professional
    Manufacturer Intel Pentium III processor
    Clock Speed 500MHz
    L2 Cache Size 512
    Available Memory 33.22 %
    Page File Size 618.10Mb
    Available Page File 64.76 %
    Virtual Memory 873.64Mb
    Available Virtual Memory 55.53 %
    Memory Slot 1 [J6J1] 128Mb
    Memory Slot 2 [J6J2] 128Mb
    Adapters 3Com EtherLink PCI

    Drive Type Drive Size Total Available Space Used Space
    C: NTFS 12.72Gb 9.090Gb 3.633Gb

    Hardware
    Type Description
    DVD/CD-ROM Drives LG CD-ROM CRD-8400B
    Disk Drives IOMEGA ZIP 100
    WDC AC313600D 12.73Gb
    EPSON Stylus Storage USB Device
    Display Adapters NVidia Riva TNT2 32Mb
    Floppy Disk Drives (Standard floppy disk drives) Floppy disk drive
    IDE ATA/ATAPI Controllers Intel(r) 82371AB/EB PCI Bus Master IDE Controller
    Primary IDE Channel
    Secondary IDE Channel
    Keyboards Standard 101/102-Key or Microsoft Natural PS/2 Keyboard
    Mice and Other Pointing Devices PS/2 Compatible Mouse
    Monitors Plug and Play Monitor - (Standard monitor types)
    Sound Devices YAMAHA Native DS1 WDM Driver
    YAMAHA Legacy DS1 WDM Driver
    USB Controllers Intel 82371AB/EB PCI to USB Universal Host Controller

    Software
    Name Version
    J2SE Runtime Environment 5.0 Update 9 1.5.0.90
    Microsoft Office Standard Edition 2003 11.0.7969.0
    Windows Defender Signatures 1.20.0.0
    Windows Defender 1.1.1347.6
    Windows Genuine Advantage v1.3.0254.0 1.3.0254.0
    WebFldrs 9.00.3907
    Microsoft .NET Framework 2.0 2.0.50727
     

    Attached Files:

  2. lakeriedog

    lakeriedog Private E-2

    Not sure if this is too much information, but while running the Microsoft Malicious Software tool, there was nothing. The Spybot did not find anything, but I did find two things in the Recovery Section (Alexa Related) and purged them followed up with CCleaner. Windows Windows Defender wouldn't run in safe mode with networking so I did it in normal mode and it didn't find anything. Bitdefender also would not run in Safe with Networking, and didn't find anything. Panda Scan found and cleaned one virus, and found and did not clean 3 malawares.


    Here are the remaining two logs.
     

    Attached Files:

  3. lakeriedog

    lakeriedog Private E-2

    When I checked the site earlier, there was a post from Chaslang on what to do...and now I don't see it anymore.

    Chaslang, I did what you said and fixed the RO HKLM and 020 AppInit as soon as I got home from work. I have rebooted and done the new HJT, and am currently running McAfee just to be sure everything is gone. I am attaching my new HJT, and so far everything seems ok.

    I hope the fact that your response disappeared isn't a bad sign...and thank you for taking the time to help me out!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it was just due to the fact that we had to restore the forums to a point in time before the message was sent. So it (along with many other messages) was lost.

    I would also recommend that you now uninstall Windows Defender since you have Yahoo Antispyware installed.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and enable System Restore to create a new clean Restore Point.
    2. After doing the above, you should work thru the below link:
     
  5. lakeriedog

    lakeriedog Private E-2

    Thanks chaslang!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds