vtstt removed - Thanks MajorGeeks!

Discussion in 'Malware Help (A Specialist Will Reply)' started by tinutuva, Jan 12, 2008.

  1. tinutuva

    tinutuva Private E-2

    First I want to say that this forum is great. I've been coming here for updates for about 2 years and I've sent my friends here.

    I was having a real problem trying to get rid of this nasty trojan :( . It was showing up when I checked my system with System Mechanic, BHO Demon, XP Repair, & Spybot and none of them were able to remove it. So I came here and searched the forum. As I read through the posts I saw the link for the sticky READ & RUN ME FIRST.Malware Removal Guide here http://forums.majorgeeks.com/showthread.php?t=35407

    I followed ALL the steps. When I had errors the solutions were already there so I followed them too.

    And now... No More problem :D . I rechecked my system with all those programs and it finally didn't come back.

    Thanks guys, You're the Best
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi and Welcome tinutuva


    Glad the guide helped you remove the nasty pests of malware, but if you want a full ok, then do attach the logs to your next post as malware is sneeky and while you may have removed the main malware components, their maybe the odd one lurking still and our malware experts will give you their expert opinion.

    But of you feel your OK then please do read this How to Protect yourself from malware! and happy safe surfing.
     
  3. tinutuva

    tinutuva Private E-2

    Log Files

    Hi Halo,

    I'm taking your advice and attaching the ComboFix.txt and MGlogs.zip logs. When I ran AVG I had everything checked properly but after I selected "Apply all actions" the Reports icon was grayed out and couldn't be selected to run the report. Let me know if you think I should run it again to try and get a report.

    tinutuva
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • Download and save to RenV.exe from following link to Desktop ( it must be on the Desktop)
    • Open Notepad and copy/paste the text in the below quote box into it. Save it as Log.txt to your desktop
    • Now using your mouse, drag Log.txt onto RenV.exe
    • When finished, RenV.exe will produce a log names Log.txt on your Desktop which will overwrite the one you just made. Attach the new Log.txt to your next reply.
    It's a good thing you did post the follow up logs. You are still pretty badly infected.
    You also have a load of left overs from having Symantec software not uninstall itself properly. We will attempt to fix these too.

    Uninstall the below old versions of software:
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll (file missing)
    O20 - Winlogon Notify: nnnmkhf - nnnmkhf.dll (file missing)
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (file missing)
    O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (file missing)
    O23 - Service: GhostStartService - Unknown owner - C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartService.exe (file missing)
    O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe (file missing)
    O23 - Service: Norton Unerase Protection (NProtectService) - Unknown owner - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE (file missing)
    O23 - Service: ScriptBlocking Service (SBService) - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe (file missing)
    O23 - Service: Speed Disk service - Unknown owner - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe (file missing)
    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    • Now run Ccleaner!
    • Now run the C:\MGtools\GetLogs.bat file by double clicking on it.
    • Then attach the below logs:
      • Log.txt (on your Desktop from RenV.exe)
      • C:\avenger.txt
      • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. tinutuva

    tinutuva Private E-2

    Hi chaslang,

    Thanks for your help. I put additional info in the Log.txt file, mostly problems I had trying to uninstall Java(TM) 6 Update 2.

    When I tried to upload all 3 logs I got this error:

    Upload Errors
    MGlogs.zip:
    You have already attached this file in thread : vtstt removed - Thanks MajorGeeks!

    I tried changing the name of the MGLogs.zip file but it gave me the same message. How do I upload it?

    tinutuva
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That means you did not do one of the steps I gave you.
    This would have produced a NEW log.

    NOTE: You must not edit the log files to attach your own comments. Comments belong in the thread. Now the log file cannot be used for its intended purpose because you modified it.
     
  7. tinutuva

    tinutuva Private E-2

    Sorry about editing the log file and you're right I missed that step. I'm attaching the new MGlogs.zip file.

    I tried running AVG again. It found 4 malicious entries but then froze up halfway through the scan.

    I also looked at Spybot S&D > Tools> System Startup and there's a Key HK_CU:Run that it lists as having no filename and it flags it as a "virus, spyware, malware", etc. I exported the System Startup report and I can attach that if you want.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't need it. We already list all of your startups in MGlogs.zip and there is nothing at all in your HKCU run section and that is not a problem.


    Okay now we need to use a new tool.
    • Download and save to RenV.exe from following link to Desktop (must be on the Desktop)
    • Now Copy the bold text in the below code box to notepad. Save it as Log.txt to your desktop. (It must be on your Desktop).
    Code:
    C:\Program Files\iolo\System Mechanic 5 Professional\StartupGuard    .exe
    C:\Program Files\iolo\System Mechanic 5 Professional\StartupGuard  .exe
    
    
    • Now using your mouse, drag Log.txt onto RenV.exe
    • When finished, RenV.exe will produce a new log names Log.txt on your Desktop I will ask for this log later.
    Now try again to uninstall Java(TM) 6 Update 2

    Now delete the below file:
    C:\WINDOWS\system32\aswBoot.exe

    Now reboot!

    Now run Ccleaner!
    • Now run the C:\MGtools\GetLogs.bat file by double clicking on it.
    • Then attach the below logs:
      • Log.txt (on your Desktop from RenV.exe)
      • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jan 15, 2008
  9. tinutuva

    tinutuva Private E-2

    I did what you said, here are the log files.

    Java(TM) 6 Update 2 still didn't uninstall, it says "Internal Error 2753. RegUtils".

    I saw in the Add/Remove programs 2 entries that don't have a Remove button, Safari browser that I uninstalled a while ago, and DJS Shared Licensing that caused a problem with uninstalling Symantec products and I ran the Symantec fix that it said to use in the forum. Do you know how I can get rid of any pieces that might still be in my computer and delete them from the list of programs?
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I inadvertantly used a Quote box in my previous fix instead of a Code box. Because of this, spacing within the fix was corrupted. Please go back to message # 8 and run the fix with RenV again. Start over again by recreating the Log.txt file from what is posted there now. The correct spacing is in the fix now.

    Then attach a new Log.txt file.

    Your logs are otherwise clean.


    Perhaps that program messed up more than Symantec since you have issues uninstalling even Sun Java. These are really issues for the Software Forum but you can try using the below program:

    Your Uninstaller! 2008

    Or you can simply try using the Tools feature of Ccleaner where you can Delete items from the installed program list.
     
  11. tinutuva

    tinutuva Private E-2

    Thanks for all your help chaslang, I really appreciate it. Here's the new Log.txt file.

    I did a reg scan with CCleaner and it found a lot of issues with symantec and safari entries so just deleting the entries won't remove all the garbage. I'll post the uninstall issues in the Software Forum like you suggested.

    tinutuva
     

    Attached Files:

    • Log.txt
      File size:
      189 bytes
      Views:
      1
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes we know that. That is true for ALL applications. Even when uninstalled via add/remove programs they leave many things behind. My statements was only in regards to getting it removed from the Add/Remove programs list.

    You log is now clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     
  13. tinutuva

    tinutuva Private E-2

    Thanks chaslang, my system is so much better. Startup and shutdown are faster and everything is running smoothly. I really appreciate all your help.

    tinutuva
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds