TechSpot

Please help me remove viruses/spyware!

By sublime487
May 24, 2007
Topic Status:
Not open for further replies.
  1. I recently reformatted my computer, like I have many times in the past, but this time was different. It didn't entirely wipe the harddrive and I had to insert a windows xp cd to get it to boot up.

    Since then my computer kept instantly restarting as my desktop loaded. It woudl do this repetedly... For hours on end. So I started in safe mode and redownloaded my anti-spyware program and was able to start it up in non-safe mode finally. I've ran hijackthis and avg so far, but I can't find where to DL a legit version of combofix.

    -My computer is riddled with viruses/spyware. So much that my isp has contacted me saying that I'm spamming people and sending viruses out.
    -My computer is incredibly laggy, which it shouldn't be.
    -Whenever I pull up the task manager it says my cpu usage is at 100% at all times... it never used to be like that! Help me!
  2. momok

    momok TS Rookie Posts: 2,272

    Hi sublime487 and welcome to techspot. =)

    I noticed that your AVG log displays 'Ignored' for all the files detected.

    I suggest you run AVG again and quarantine the files. Pictorial instructions HERE. Do that after the following instructions.

    You may wish to copy and paste these instructions on notepad for easier reference later.

    Download Vundofix from HERE.

    Double click the Vundofix.exe to run it.
    Right click in the vundofix window and click add files.

    Enter the following file path/s to the files you want Vundofix to delete and click the add files button, followed by the close window button:
    C:\WINDOWS\System32\awtsr.dll
    C:\WINDOWS\SYSTEM32\igfcpl.dll


    Click the remove vundo button and let Vundofix do its stuff.

    Once you click yes, your desktop will go blank as it starts removing Vundo.
    When completed, it will prompt that it will shutdown your computer, click OK.
    Turn your computer back on.

    Boot into safe mode under your normal user name. See how HERE

    Next turn on "Show all files and folders, including hidden and system". See how HERE

    After that, run HijackThis and fix the following entries, if found (do this by placing a tick in the check boxes beside these entries and clicking "Fix checked"):

    O2 - BHO: Shell Event Object Class - {00534B55-3155-CA4F-B41D-0E922121D03C} - C:\WINDOWS\System32\cscentfy.dll
    O2 - BHO: (no name) - {0A632402-D155-45BC-B034-25A9477E58B6} - C:\WINDOWS\System32\awtsr.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {A24B57F8-505D-4fc5-9960-740E304D1ABA} - C:\WINDOWS\System32\tmp33.tmp.dll
    O2 - BHO: (no name) - {ad96f148-7931-473f-ba36-a369862fca45} - C:\WINDOWS\system32\igfcpl.dll
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O20 - AppInit_DLLs: c:\windows\system32\jkklijg.dll
    O20 - Winlogon Notify: awtsr - C:\WINDOWS\System32\awtsr.dll
    O20 - Winlogon Notify: igfcpl - C:\WINDOWS\SYSTEM32\igfcpl.dll

    Close HJT.


    Navigate in Windows Explorer and delete the following files and folders in bold.

    C:\WINDOWS\System32\awtsr.dll
    C:\WINDOWS\System32\cscentfy.dll
    C:\WINDOWS\System32\tmp33.tmp.dll
    C:\WINDOWS\system32\igfcpl.dll
    c:\windows\system32\jkklijg.dll

    Run your AVG Antispyware now and quarantine all items.

    Reboot into normal mode and rehide your protected OS files.

    Thereafter, please post fresh HJT, ComboFix and AVG Antispyware logs from normal mode as well as C:\vundofix.txt as attachments into this thread. The utilities can be downloaded from the links in my signature.


    Regards,
    Your friendly Momok =)

    This thread is for the use of sublime487 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  3. sublime487

    sublime487 TS Rookie Topic Starter Posts: 33

    Wow, I am about to do all of that. However I feel that I should tell you taht I have taken action on the current viruses/spyware. I have quarantined them like 3 times with AVG and with Spyware Sweep...
  4. momok

    momok TS Rookie Posts: 2,272

    I see. Go ahead with the recommended instructions first, and then try running your AVG scan and performing the quarantine action again.
    If it prompts you for permission to quarantine the archive in which the infected file is embedded in, click ok/yes.


    Regards,
    Your friendly Momok =)

    This thread is for the use of sublime487 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  5. sublime487

    sublime487 TS Rookie Topic Starter Posts: 33

    A Quick Update:


    I have completed the VundoFix step. Unfortunately, it can't remove either of the files that you listed. I will continue with the rest of the steps now...
  6. sublime487

    sublime487 TS Rookie Topic Starter Posts: 33

    K, here are the new logs.
  7. sublime487

    sublime487 TS Rookie Topic Starter Posts: 33

    Momok, where are you!?
  8. momok

    momok TS Rookie Posts: 2,272

    Hi,

    Sorry, I had to go to sleep. (I belong in a different timezone hehe)

    Your ComboFix shows your system is so horribly infected(easily 30 over different .exes) I've decided to use avenger to facilitate things.

    Please follow these instructions carefully.

    1. Download The Avenger by Swandog46 from HERE. Save it to your Desktop and extract it.

    2. Download the attached avengerscript.txt (from my attachment) and save it to your desktop

    Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

    3. Now, start The Avenger program by double clicking on its icon on your desktop.

    Under "Script file to execute" choose "Load script from file".
    Now click on the folder icon which will open a new window titled "open Script File"
    navigate to the file you have just downloaded, click on it and press open
    Now click on the Green Light to begin execution of the script
    Answer "Yes" twice when prompted.

    4. The Avenger will automatically do the following:

    It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
    On reboot, it will briefly open a black command window on your desktop, this is normal.
    After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
    The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.

    5. Please visit the thread in my signature and run the AVG Antirootkit tool and fix anything related to xpdt. Let me know the results (if anything else turns up in the scan, don't fix it yet)

    6. Please attach the content of c:\avenger.txt into your reply, as well as a fresh HJT log and ComboFix log.


    Regards,
    Your friendly Momok =)

    This thread is for the use of sublime487 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  9. sublime487

    sublime487 TS Rookie Topic Starter Posts: 33

    Here you are, sir.
  10. momok

    momok TS Rookie Posts: 2,272

    Hi,

    I noticed that avenger did not work correctly. Did you experience any problems whilst using it? I need you to run avenger in the exact same way as per my previous instructions.

    After performing the avenger cleaning, do the following.

    You may wish to copy and paste these instructions on notepad for easier reference later.

    Boot into safe mode under your normal user name. See how HERE

    Next turn on "Show all files and folders, including hidden and system". See how HERE

    Go to start > run and type services.msc. Press the enter key.
    Search for the following services. Double click to select stop if they are running. Set the startup type to disabled. Click apply/ok for each service you disable.

    Windows Auto Update Tool
    Windows Tune service


    After that, run HijackThis and fix the following entries, if found (do this by placing a tick in the check boxes beside these entries and clicking "Fix checked"):

    O23 - Service: Windows Auto Update Tool - Unknown owner - C:\WINDOWS\wault.exe (file missing)
    O23 - Service: Windows Tune service - Unknown owner - C:\WINDOWS\tune.exe (file missing)

    Close HJT.


    Navigate in Windows Explorer and delete the following files and folders in bold.
    C:\WINDOWS\wault.exe
    C:\WINDOWS\tune.exe

    Reboot into normal mode and rehide your protected OS files.

    Thereafter, please post fresh HJT, ComboFix and AVG Antispyware logs as well as c:\avenger.txt from normal mode as attachments into this thread.


    Regards,
    Your friendly Momok =)

    This thread is for the use of sublime487 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  11. sublime487

    sublime487 TS Rookie Topic Starter Posts: 33

    I cannot obtain a log from AVG AntiSpyware because my computer prompts me that it is shutting down in 60 seconds and I can never finish the scan. I will include the logs of each program that I do have a log for though.

    I ran AVG antiroot and it came up with nothing.

    *Edit: The notification that prompts me about a system restart in 60 seconds says that my remote procedure protocal (or something along those lines) was unexpectedly terminated. It just popped up again -- "This shutdown was initiated by NT AUTHORITY\SYSTEM.
     
  12. momok

    momok TS Rookie Posts: 2,272

    Hi,

    Your Combofix log shows tonnes of new random-filename-nasties everytime I check it. You have not posted the results of the AVG antirootkit scan.
    I suspect something is throwing out these files and the cleaning process can take forever if we don't get to the source of this. Also, the randome forced shutdown is very likely to be part of the malware infection.

    Please run AVG Antirootkit scan and let me know the results. Do a deep scan via the instructions HERE.

    Also, do not use the internet for any other usage other than the forums here until your system is fully clean.


    Regards,
    Your friendly Momok =)

    This thread is for the use of sublime487 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  13. sublime487

    sublime487 TS Rookie Topic Starter Posts: 33

    I just ran AVG Antiroot again and nothing was found. It didn't even give me an option to save the log. It came up with absolutely nothing.
  14. momok

    momok TS Rookie Posts: 2,272

    Hi,

    I'll have to run you by these instructions again, and we'll see what happens.

    (Please back up your registry before you do the next step.)
    Go to Start > Run and type regedit. Press Enter.
    Press ctrl + F and search for all instances of the following and delete them.
    csrs.exe
    ALCXMNTR.EXE
    myqughq.exe
    rabblinn.dll
    ipmon.exe
    spoolsvc.exe
    spoolvq4.exe
    winIogon.exe
    < note its and 'i' not 'L'. winiogon.exe.

    Close the program.

    Please follow these instructions carefully.

    1. Download The Avenger by Swandog46 from HERE. Save it to your Desktop and extract it.

    2. Download the attached avengerscript.txt (from my attachment) and save it to your desktop

    Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

    3. Now, start The Avenger program by double clicking on its icon on your desktop.

    Under "Script file to execute" choose "Load script from file".
    Now click on the folder icon which will open a new window titled "open Script File"
    navigate to the file you have just downloaded, click on it and press open
    Now click on the Green Light to begin execution of the script
    Answer "Yes" twice when prompted.

    4. The Avenger will automatically do the following:

    It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
    On reboot, it will briefly open a black command window on your desktop, this is normal.
    After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
    The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.

    5. Please attach the content of c:\avenger.txt into your reply, as well as a fresh ComboFix and HJT log.


    Regards,
    Your friendly Momok =)

    This thread is for the use of sublime487 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  15. sublime487

    sublime487 TS Rookie Topic Starter Posts: 33

    Meh, what exactly is the registry? C drive? D drive? I have no idea.
  16. momok

    momok TS Rookie Posts: 2,272

    Hi,

    Click the link 'backup your registry' in my previous post. ;)


    Regards,
    Your friendly Momok =)

    This thread is for the use of sublime487 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  17. sublime487

    sublime487 TS Rookie Topic Starter Posts: 33

    I went there, I just don't know which boxes to check... I'm a compnoob.

    I read further on, and I also don't know what destination I should save the backup files to. Does it matter?
  18. momok

    momok TS Rookie Posts: 2,272

    Hi,

    No worries man.

    Go to Start > Run. Type regedit and press enter.
    Click file > export and save anywhere you want that would not be touched in the near future at least.

    Continue with the rest of the instructions as given previously.


    Regards,
    Your friendly Momok =)

    This thread is for the use of sublime487 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  19. sublime487

    sublime487 TS Rookie Topic Starter Posts: 33

    One more quick question about the registry process. When I search a file, say "ipmon.exe" and I get a list of like 5 items do I delete them all? Or only the file that says "ipmon.exe" verbatim?

    Also, what happens if I try to delete a file and it denies me? Just move on to the next step? Sorry for asking so many questions... I really appreciate all of this immensely.
  20. momok

    momok TS Rookie Posts: 2,272

    Hi,

    I last checked your ComboFix log and the only entry that ipmon should appear under is in
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ipmon

    Delete only ipmon.exe and nothing else. Same for the other entries I asked you to delete. Just let me know in your next post if you are unable to delete any registry keys and which of those you can't.


    Regards,
    Your friendly Momok =)

    This thread is for the use of sublime487 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  21. sublime487

    sublime487 TS Rookie Topic Starter Posts: 33

    Here are the updated logs. xD
  22. momok

    momok TS Rookie Posts: 2,272

    Hi,

    Please run the AVG Antirootkit scan. The rootkit has finally appeared in your ComboFix log. Fix anything related to xpdt Please let me know if anything else also shows up.

    Also, please repeat the registry deletion step previously for this entry:
    spoolvq4.exe

    Post fresh ComboFix and HijackThis logs after you've done the above.


    Regards,
    Your friendly Momok =)

    This thread is for the use of sublime487 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  23. sublime487

    sublime487 TS Rookie Topic Starter Posts: 33

    Nothing showed up in the AVG rootkit scan... Nothing has ever showed up there though! Take a look at my new logs though.
  24. momok

    momok TS Rookie Posts: 2,272

    Hi,

    Hm. That doesn't quite make sense. xpdt is an entry commonly detected by AVG antirootkit. Could you visit the preliminary removal thread link in my signature and run the antirootkit according to the instructions there once more?


    Regards,
    Your friendly Momok =)

    This thread is for the use of sublime487 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  25. sublime487

    sublime487 TS Rookie Topic Starter Posts: 33

    It didn't find anything.
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.