virus detected

Discussion in 'Malware Help (A Specialist Will Reply)' started by Wlfwo, Aug 21, 2006.

  1. Wlfwo

    Wlfwo Private E-2

    My son was complaining about his laptop being slow so I thought to run the sticky (read and run me first) and clean it up. Found all sorts of goodies it doesn't need, along with at least 3 viruses.

    So now I need help. I had to run bitdefender and panda under normal log on, seems I can't do safe mode with networking.

    I am pretty sure he has stuff he can get rid of if I just knew what to get rid of.

    So here are the logs, thanks in advance.

    Nancy
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the other two logs requested in the READ ME:

    - GetRunKey
    - ShowNew
     
  3. Wlfwo

    Wlfwo Private E-2

    I finally found them, so here they are. Sorry bout that. As far as I am concerned laptops are evil, lol

    Thanks much,
    Nancy
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's start with the below.

    Goto Add/Remove programs and uninstall these:
    Paltalk Messenger
    RelevantKnowledge
    Viewpoint Media Player

    Who installed the below? While they may not be malware, in many cases, screen saver stuff like these are spreaders of malware. Many come bundled with malware and that could be where you got the above Paltalk and RelevantKnowledge from.
    "DisplayName"="Active Dancer Strip Saver"
    "DisplayName"="All American Girls Screensaver"
    "DisplayName"="Girls of Bikinicom 4 Screen Saver"
    "DisplayName"="Screensavers Installer"
    "DisplayName"="Swimsuit Models Screensaver"

    After uninstalling the first 3, decide what you are doing with the others and tell me. Then attach a new log from HJT.
     
  5. Wlfwo

    Wlfwo Private E-2

    ok, I finally got them all. The paltalk was a pain since A&R wouldn't do it, it's uninstall wouldn't do it. I had to go after it everywhere it was hiding, but I think I got it all, search says I did anyway. So here is the new HJT log.

    As for HOW they got there? He's 14, little snot!

    Thanks ever so much.
    Nancy
     

    Attached Files:

  6. Wlfwo

    Wlfwo Private E-2

    Ooops, as for the others? I uninstalled them. <EG> Might be his laptop, but I am still Mom!

    Thanks again,
    Nancy
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I can understand that! And he will probably download and install them again or maybe other ones. It is hard to stop them from doing stuff like this especially on their own PCs. Even if you warn teenagers of the potential danger in this kind of software, they ignore the warnings (like everything else you warn them about ;) ). So let's just finish all the cleanup, and see how things are working afterwards.

    Now that you have uninstall all that stuff, there should already be an improvement.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.netzero.net/s/search?r=minisearch
    R3 - URLSearchHook: (no name) - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - (no file)
    R3 - URLSearchHook: (no name) - - (no file)
    O3 - Toolbar: (no name) - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZSYYYYYYDUUS
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    After clicking Fix, exit HJT.

    Now reboot into safe mode

    Now use Windows Explorer to locate the below files and delete them if found (let me know what you find. Some may be gone already.)
    C:\WINDOWS\ss3unstl.exe
    C:\WINDOWS\system32\rlvknlg.exe
    C:\WINDOWS\system32\cemetrix.dll
    C:\WINDOWS\system32\rlls.dll
    C:\WINDOWS\system32\silc_dll.dll
    C:\WINDOWS\system32\components\rlxf.dll

    Then goto the below folder and delete all files and subfolders in this Temp folder. Windows will not let you delete a couple from the current date because it will be using them.
    C:\Documents and Settings\HP USER\Local Settings\Temp\

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!


    Now reboot in normal mode and post a new HJT log.

    Also please attach new GetRunKey and ShowNew logs!

    Make sure you tell me how things are working now.
     
    Last edited: Aug 23, 2006
  8. Wlfwo

    Wlfwo Private E-2

    C:\WINDOWS\ss3unstl.exe
    C:\WINDOWS\system32\rlvknlg.exe
    C:\WINDOWS\system32\cemetrix.dll
    C:\WINDOWS\system32\rlls.dll
    C:\WINDOWS\system32\silc_dll.dll
    C:\WINDOWS\system32\components\rlxf.dll

    Ok, I didn't find any of these at all.
    Everything else is done.
    Laptop is running better so far.
    Here are the new logs.
    Thanks ever so much.
    Nancy
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not completely true! The first one ( C:\WINDOWS\ss3unstl.exe ) is still showing in your newfiles.txt log. Look for yourself at the log. Thus it is still on your PC and you need to delete it. Make sure you have follow the directions for viewing hidden and system files in the READ ME.


    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Then uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 2

    Your logs are clean (other than the one file mentioned above). If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  10. Wlfwo

    Wlfwo Private E-2

    <Not completely true! The first one ( C:\WINDOWS\ss3unstl.exe ) is still showing in your newfiles.txt log. Look for yourself at the log. Thus it is still on your PC and you need to delete it. Make sure you have follow the directions for viewing hidden and system files in the READ ME.>

    Darn! I maybe looked in the wrong place? I will hunt it up again. I will find it.
    Thanks ever so much!
    Nancy
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Let me know what you find and make sure to get started with the How to protect steps. Your son should read some of the information there. It may roll off his back like water on a duck, but maybe some of it will stick. ;)
     
  12. Wlfwo

    Wlfwo Private E-2

    :eek: OK, as I was getting ready to go get the Java, AVG popped up (it's doing it's scan) saying: A0099513.exe Trogan horse collected. 8.AP C:\ System Volu...

    Other than to do the malware stuff, we haven't used the laptop at all. So how did this one show up? And how do I fix it?

    Thanks,
    Nancy
     
  13. Wlfwo

    Wlfwo Private E-2

    OK, it says it deleted it. Then there is a back slash and it says restore? So I assume we can live with whatever AVG did?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then you did not do what I said previously in message # 9.
     
  15. Wlfwo

    Wlfwo Private E-2


    I was in the middle of doing message #9 when the trogan showed up. I had just deleted C:\WINDOWS\ss3unstl.exe (I don't know how I missed seeing it the first time) and was downloading the Java when AVG popped up.

    I let AVG do whatever it did (says it confined and then deleted it) finished with the Java update, went offline, uninstalled the old Java, installed the newer Java then disabled system restore and rebooted, then re-enabled system restore and re-hid my hidden folders.

    If the trogan was connected with C:\WINDOWS\ss3unstl.exe I should be ok now? Other than doing the "How to protect yourself from malware" thread, is there anything else I need to do?

    Thanks bunches,
    Nancy
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. No, that is all you need to do!
     
  17. Wlfwo

    Wlfwo Private E-2

    Thank you so very much! Hopefully I have impressed on him NOT to download such things on his laptop. I'd a thought that the lecture I gave him about doing it on the main computer would have "leaked" over. :rolleyes: Guess not.

    Thanks again,
    Nancy
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds