Virus and Spyware trouble..

Discussion in 'Malware Help (A Specialist Will Reply)' started by brad3458, May 11, 2005.

  1. brad3458

    brad3458 Private E-2

    Hi there, would be much appreciated if I may have some advice in this matter. Yes, I am one of the unfortunate ones that got sucked in to executing a file which was sent to me through msn. As you know, my one is the version that said on one line "Rofl, is this you?", and the next line contained a link which which downloaded a file, which this silly man tapping these keys double clicked, the file then ate itself and disappeared and then of course started spamming all my contacts with the same thing.

    Things I have noticed since i 'obtained' this virus:

    1. Disabled NAV - a red cross appeared over icon in system tray therefore auto protect was not running and could no longer be enabled.
    2. I have a windows desktop password. On reboot, the section just before your windows user name comes up prompting for a password, where a box says (something like) 'Windows now loading', it used to blink past that and prompt me for my password, now it hangs there for around 30 seconds.
    3. When I right click on 'My Computer' it no longer shows my CPU and its mhz under where memory amount is shown.
    4. When I attempt to obtain "System Information" in accessories i get a message saying "Cannot access Windows Management Instrumentation software. Windows Management files may be moved or missing".
    5. system32 folder opens up on desktop on reboot [seem to have resolved this by unchecking two items in msconfig named simply with two quotation marks -> "" ]

    Have now reinstalled Norton but it was troublesome. Were errors and freezes during installation but on the 3rd attempt it is now reinstalled, updated and auto protecting.

    Measures I have taken since obtaining virus:

    1. Ran full updated: Spybot, Ad Aware SE, CWS Shredder, housecall at trendmicro, NoAdware.net, Spyware Doctor, ewido security, latest mcafee avert stinger, ran cleanup40 and the Panda online scan, SYSTEM RESTORE OFF ran NAV2005, SYSTEM RESTORE OFF, no detections, Xoftspy, 'Scan Spyware' this program detected numerous objects.

    What would u like me to do next (ps. i have HJT installed on my hard drive and not the temp folder, ready to go).

    Basically now a few days have passed am finding i cannot install alot of software. For eg, O&O Defrag when I opened it appeared totally disabled and an error along the lines the system has actively refused it. I uninstalled it and cannot reinstall it gets to the same point every time and just halts. I have tested the install file which i have used for a long time, on other comps and no probs with that. Attempted to install outpost firewall, the first blue install screen comes up and disappears and thats all that ever happens. The system is as stable as ever, and apart from the things 1-5 mentioned above, somethings definately still wrong, please help if you have the time..

    Thanks and a big HI! from New Zealand
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure if you have run all the steps in the below sticky thread, but it sounds like you may have. If so, just ignore that part and continue to the steps for posting a HijackThis log.


    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus RemovalMake sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. brad3458

    brad3458 Private E-2

    Hi there thanks for the reply. I have done the overkill with the scanners, and have performed the online virus scanners aswell. Ran them over a period of a couple of days and they all removed myriads of things. I will try to obtain the reports of what they contained but I think most of that information might not be available, I will do my best, in the meantime herewith my hjt scan log.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your Windows OS and IE versions are way out of date and represent a major security risk. After we fix any current problems, you must get updated.

    Also please remember to exit ALL browsers ( C:\Program Files\Mozilla Firefox\firefox.exe ) before using HijackThis.


    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O4 - HKLM\..\RunServices: [Microsoft Update Clinic] svsipconfig.exe

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    c:\windows\system32\svsipconfig.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.


    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. brad3458

    brad3458 Private E-2

    Hi there have done as requested, the problems I outlined in my original post still exist though, cant access advanced properties in local area network, cpu and its mhz not showing under memory amount in properties on my computer and cannot install other software, also it still hangs on 'Windows is loading..." when reboot.

    Thanks
     

    Attached Files:

  6. brad3458

    brad3458 Private E-2

    ...also I am now getting this error when I just went to run the Panda online scan..
     

    Attached Files:

  7. brad3458

    brad3458 Private E-2

    Did this, the file was not present...
    (sorry about all the posts, i cant edit my previous ones :p)
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  9. brad3458

    brad3458 Private E-2

    Hi there, thanks for all this, this has fixed most of the system information problems which is great, out of the three, 'event log' was somehow disabled. Just a couple more things though, when I now try to access system information it flicks me to the Help and Support Centre screen, also I am trying to install Panda Titanium AV 2005 and it is complaining that there is an incompatible program 'Kaspersky Anti-Virus (AVP) installed and that I should uninstall it first through the control panel. No such program exists on my computer and I am trying to figure out where the conflict is.

    Thanks
     
  10. brad3458

    brad3458 Private E-2


    I found a registry entry for kaspersky and deleted it, can now install Panda :)
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so please explain what problems still remain!
     
  12. brad3458

    brad3458 Private E-2

    Hi there, yes things are pretty much back to normal, actually the system seems to be running faster than ever ! I probably cleaned out some older rubbish that was in here before I got the msn virus! The only thing left that seems to be not right is what I mentioned above, when trying to access system information, it flicks me to the Help and Support Centre Screen. Thanks again.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is probably an issue for the Software Forum but how are you attempting to access system information (exactly).
     
  14. brad3458

    brad3458 Private E-2

    start, programs, accessories, system tools, system information...
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Use Windows Explorer to navigate your way to the below folder:

    C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools

    now locate the System Information file and right click on it and select Properties.

    Make sure the Target entry is (include the quotes): "C:\Program Files\Common Files\Microsoft Shared\MSInfo\msinfo32.exe"

    Make sure Start in entry is (include the quotes): "C:\Program Files\Common Files\Microsoft Shared\MSInfo"

    If not, change them to what I gave you.
     
  16. brad3458

    brad3458 Private E-2

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may want to ask about you problem with msinfo32.exe (System Info) in the Software Forum. If the properties were set as I stated I'm not sure why it does not come up.

    I see you were not using the proper version of Spybot. That problem is solved.
    I though you said you follow the steps in the READ ME FIRST??????
     
  18. brad3458

    brad3458 Private E-2

    Yup, just didnt realise there was another realease of SB, have had the same installation for so long... thanks for all your help..
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


    Yes but that is why the READ ME tells you to check our links and to make sure you have the same versions. Not checking means not following the steps and this quite often is the reason for some items not getting fixed since the software is not current.

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds