also @ TechSpot: Blizzard talks Diablo 3 facts, nerfing and buffs for legendary items

TechSpot

JS Downloader.agent virus detected plus others

Discussion in 'Virus and Malware Removal' started by radski, Mar 11, 2008.

Thread Status:
Not open for further replies.
  1. radski Newcomer, in training

    Hi all, the other day my brother was using MSN and AVG popped up saying it has found viruses. He followed the AVG prompts to delete, some deleted others didn't
    I logged into my profile, and more problems became apparent. I wasn't able to open Adware, I wasn't able to right click, use CTRL ALT DELETE, or open an IE. I restarted and I was able to get IE open although search results through google kept redirecting to random sites. I stumbled across TechSpot after performing a virus scan in normal windows mode. It found JS Downloader. I followed the the 15 or so steps, although I wasn't able to down CCleaner first go. I restarted and I got a 'Activate this copy of Windows' pop up.
    I've followed the steps and here are the 2 attachments, for some reason I can't find the AVG Anti Spyware log.
    The Panda Anti Root kit found nothing

    Attached Files:

  2. kritius Newcomer, in training

    Download to your Desktop this self-extracting ZIP archive FixPolicies.exe

    • Double-click FixPolicies.exe
    • Click the Install button on the bottom toolbar of the box that will open.
    • The program will create a new Folder called FixPolicies
    • Double-click to Open the new Folder, and then double-click the file named Fix_Policies.cmd
    • A black box will briefly appear and then close. This will enable your Control Panel, Task Manager and stop any Administrative warnings.

    -------------------------------------------------------------------------------------------------------

    Update your Java Runtime Environment
    • First try going to Start -> Control Panel -> double click Java
    • Select the Update TAb at the top
    • Click the Check for Updates button at the bottom
    • If it finds the newer version (Java 6 Update 5) Follow the on screen instructions
    • After it installs the newest version Go back to Control Panel -> Add/remove programs
    • Uninstall any older versions of Java

    If for some reason you couldn't update through the above instructions.
    • Click the following link
      Java Runtime Environment 6 Update 5
    • The 4th option down is the one you want (click Download)
    • Check the box to agree to terms of service
    • Check the box for your operating system and click 'Download selected'at the bottom
    • After the install Go to Start-> Control Panel-> add/remove programs (Programs and features), and uninstall any old versions
    • Navigate to C:\programfiles\Java -> delete any subfolders except the jre1.6.0_05 folder

    --------------------------------------------------------------------------------------------------------

    See this pictorial guide on how to use AVG Antispyware.

    Boot into safe mode by tapping F8 as soon as windows starts,

    Show all hidden files and folders

    Run AVG Antispyware.

    VERY IMPORTANT

    Make sure AVG is set to quarantine it`s results.


    Make sure you read this step properly.

    Please note: If your AVG Antispyware log says all items have "No Action Taken" or "Ignored" That`s because you haven`t followed the instructions properly for using AVG Antispyware and will have to read them again and do a fresh AVG Antispyware scan.


    Once finished, click the save scan report button, followed by the Save report as button and save it to your desktop.

    Reboot into normal mode and rehide your protected OS files.

    Then post the log back.

    ------------------------------------------------------------------------------------------------------

    Go to the folder that HJT is located and rename the .exe file to something like crusty.exe and send the shortcut to the desktop.

    Run HJT and post back with a fresh log.
  3. radski Newcomer, in training

    AVG and HJT logs
  4. kritius Newcomer, in training

    Can you retry the AVG and try to get it to quarantine what it finds?

    [IMG]

    There is some stuff in there that should be dealt with.

    Go to add/remove programs and get rid of anything to do with this,
    iPIX ActiveX Control

    then boot into safe mode and show all hidden files and folders and do a search for it and delete whatever it finds.

    Run HJT and have it fix these entries,
    O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab

    Boot back into normal mode and rehide your protected files.

    Run Hijackthis again and post back with the 2 requested logs.
  5. radski Newcomer, in training

    hey kritius, what do you want me to do first? I've gone to Add/Remove and can't find anything to do with Ipix. With the AVG scan, do I do that in safe mode with all hidden files shown, as I've been doing before?
  6. kritius Newcomer, in training

    Sorry, yes, do the AVG scan in safe mode again with all the hidden folders visable and make sure that its set to quarantine the results like in the picture.

    Then do the HJT scan and delete the entry if its there from safe mode as well and delete the entry if its there.

    Then boot back into normal mode, rehide all the folders and do another scan with HJT.

    Thanks
  7. radski Newcomer, in training

    With the AVG scan I was only able to quarantine one of the files that had a risk of high, all the rest were medium.
    HJT, I was able to delete that entry.

    Rehiding and hiding files am I suppose to restart for the changes to take effect?
  8. kritius Newcomer, in training

    That got it. Can you delete the contents of the quarantine folder now please.

    Just need to check some more things.?

    O8 - Extra context menu item: Download all by Net Transport - C:\Program Files\Xi\NetTransport 2\NTAddList.htm
    O16 - DPF: {A8739816-022C-11D6-A85D-00C04F9AEAFB} (Web Camera Server Control) - http://66.91.151.66/wg_webeye.cab


    Do you recognise these?

    I take it you are using an Acer computer?

    Do a scan with the free Kaspersky on line scanner.

    Other than that, how is the computer running now? Any other occurences?
  9. radski Newcomer, in training

    Thanks kritius!
    I've deleted the file in quarantine.
    Net Transport is one of those programs that lets you download media streams etc.
    The Web Camera Server Control, I have no idea what it is, since I don't even have a web camera.
    Yes, I am on an Acer.

    Should I do the online scan now, or wait for further instructions regarding the top two things?
  10. kritius Newcomer, in training

    Run the scan for now, if it allows you to save a log file then post that log here for me, I just need to check a few things out.

    EDIT||||||||||||||||||||

    After you do the scan with Kaspersky, Close all browser windows, open HJT and do a system scan only,
    put a check next to this entry,

    O16 - DPF: {A8739816-022C-11D6-A85D-00C04F9AEAFB} (Web Camera Server Control) - http://66.91.151.66/wg_webeye.cab

    Select fix checked.

    Reboot and do another scan and post a log, I need to see if it comes back.
  11. radski Newcomer, in training

    Hi kritius.

    I've done the Kaspersky scan and I've followed the instructions regarding HJT, although none of the scans were carried out in safe mode.
    Here are the two logs.
  12. radski Newcomer, in training

    On my profile things seem to be working fine but on my brother's, IE doesn't have the top bar where it says File, Edit etc, and he's unable to do CRTL ALT DELETE, it says the administrator has disabled the task manager.
  13. kritius Newcomer, in training

    In regards to IE I have 2 recommendations:-
    • Right click on the top bar beside the tabs and make sure that Menu Bar is ticked.
    • Stop using IE and start using Firefox.
    For the taskbar, try running the fix ploicies download that I gave you earlier in his account.

    Let me know how it goes.
  14. radski Newcomer, in training

    The menu bar option isn't there, although the FixPolicy program did fix the task manager.
    Is my profile all clean?
    When I perform a virus or any other scan in my profile does it only look at my profile's files or everything on the computer i.e. do I have to log into my brother's account and do a scan?
  15. kritius Newcomer, in training

    Can you have another runthrough with Kaspersky? I want to check some stuff out. Do another HJT scan and a combofix one if you can.
  16. radski Newcomer, in training

    After restarting the computer yesterday the fix policies download seemed to do the trick and everything is ok now. Here are the logs in the order I did them.
    Kaspersky log
    combofix log
    HJT log
  17. radski Newcomer, in training

    kritius have you had a chance to look at the new logs?
  18. kritius Newcomer, in training

    Have you been experiencing any specific problems?

    Your HJT log looks clean.

    Go to start>run and type combofix /u (notice the space between the x and /)

    delete the three tools by putting them in the recycle bin.

    Also can you use the housecall online scanner from the 15 steps for me as well?
  19. radski Newcomer, in training

    During the uninstalling of Combofix, the Comodo firewall kept asking if I wanted to allow swreg.cfexe to do stuff. Is swreg.cfexe good or bad?

    What are the three tools you want me to delete, the ones from Step 10?
  20. kritius Newcomer, in training

    Yes those where the three tools.

    That file is BAD, deny it. Dont unistall combofix just yet, can you run another scan with it and post the log back here?
Thread Status:
Not open for further replies.