Various trojans and other malware; need help removing it all

Discussion in 'Malware Help (A Specialist Will Reply)' started by bjornhall, Dec 25, 2005.

  1. bjornhall

    bjornhall Private E-2

    Hi,

    I'm helping my folks get their computer back in order during Christmas; it seems to have been infected with all sorts of nasty stuff. I have cleaned out a lot, but I doubt I'll be able to get it all cleaned up by myself. I followed all the steps in the 'read this before posting' thread, then did an ewido scan in normal mode.

    I'm attaching logs of the Panda activescan, Bitdefender scan and ewido scan, along with my own log of what I did, what was found etc. (to be continued with HJT log in a second).
     

    Attached Files:

  2. bjornhall

    bjornhall Private E-2

    ... and here is a fresh Hijackthis log.

    I hope there will be someone else who also needs a break from all the X-mas eating and has the time to have a look at this stuff... Thanks a million for your help, and Merry Christmas to everyone! :)

    Best,
    - Björn
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to MG's!

    I still see Spyware Vanisher. And I also saw signs of an HSA hijacker. You should run

    about:Buster 6.0

    Get any updates and run the utility. Then save and post the log. Note it should be run in safe mode and run it twice.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After running about:Buster check to make sure the below files are gone. If not, delete them yourself.

    E:\WINDOWS\apihi32.exe
    E:\WINDOWS\appey32.exe
    E:\WINDOWS\appys32.exe
    E:\WINDOWS\atlav.exe
    E:\WINDOWS\crjg32.exe

    Did you try to delete the files Spybot could not delete? Delete them using Windows Explorer in safe mode.

    You can also use HJT to fix the below lines:

    O4 - HKCU\..\Run: [Spyware Vanisher] C:\spywarevanisher-full\SpywareVanisher.exe -FastScan
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)


    Then delete the C:\spywarevanisher-full folder.

    Are you having any malware issues at this time?
     
    Last edited: Dec 25, 2005
  5. bjornhall

    bjornhall Private E-2

    I got started on the steps in your first post before your second one...

    I ran about:Buster twice in safe mode; it found a bunch of stuff the first time, and nothing on the second. I also determined that Spyware Vanisher is not visible in add/remove programs, and its program folders were empty aside from a couple log files etc. Delete the C:\spywarevanisher-full folder, then manually removed the HKCU..\Run keys for Spyware Vanisher and SpeedItUpExtreme (using regedit).

    I then rebooted back to normal mode and saw your second post. Checked if the files you asked about were present; they weren't. I already deleted the files Spybot could not remove.

    Fixed the lines you told me to HJT, except the O4 line I already deleted in regedit above.

    I have no malware symptoms at this time; is my attached fresh HJT log clean?

    Thanks for your help!

    Best,
    - Björn
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Your log is clean.

    Yyou will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME.

    And then you should continue on to the below:

    How to Protect yourself from malware!
     
  7. bjornhall

    bjornhall Private E-2

    Excellent! Will accomplish those steps.

    Thank you so much for your help, it is very much appreciated!

    All the best,
    - Björn
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds