also @ TechSpot: Tech Tip: Unlock Hidden Region-Specific Themes in Windows 7
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > Operating Systems & Software > Virus & Malware removal

Vundo; Infostealer; W32 Spybot

Closed Thread
Page 2 of 2 1 2
Bookmark Thread Tools
  #21  
Old 01-05-2009
Newcomer, in training
 
Member since: Dec 2008, 16 posts
Killbox is a cool little tool! Zapped that partition file right outta there (for good, I hope).

Here is the Combofix log.

Thanks for your help
Attached Files
File Type: txt combofixlog.txt (22.9 KB, 1 views)
  #22  
Old 01-05-2009
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,368 posts
Ok, so now how is it running?

Actually before answering that, do this:
Un-install SuperAntiSpyware (if still installed)

Clear & Reset System Restore's Cache

Go to Start >> Run - type or copy/paste control sysdm.cpl,,4 and then press Enter
* Tick on the checkbox - Turn off System Restore on all drives
* Click Apply
Turn it back 'On' by unticking the same checkbox & click Apply, and then OK

Run CCleaner

Restart
Then tell me
To remove this ad, sign in. To register for a new account, click here.
  
  #23  
Old 01-06-2009
Newcomer, in training
 
Member since: Dec 2008, 16 posts
Uninstalled Super Anti Spyware

Cleared and reset system restore cache

Ran CC Cleaner

Restarted computer, ran Norton scan and it found two infected files: Help.exe and stm.exe.

Help.exe no longer loads as a process with restart, which is progress.

I've attached the scan log.

Thanks
Attached Files
File Type: txt symantec log.txt (129 Bytes, 1 views)
  #24  
Old 01-06-2009
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,368 posts
That's strange, didn't we already remove that
Please supply a new HJT log (after restart, just in case)
  #25  
Old 01-07-2009
Newcomer, in training
 
Member since: Dec 2008, 16 posts
Yes, we removed both those files (the stm.exe file was removed multiple times). Here is the latest Hijack file after a fresh restart.
Attached Files
File Type: txt hijackthislog.txt (7.3 KB, 1 views)
  #26  
Old 01-07-2009
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,368 posts
OOOhh ! I haven't actually checked your HJT log (that's why all seems strange)

Here's what you need to do (but I might not continue - info later on, why)

Un-install Trend
Uninstall Norton
Uninstall Bittorent
Run the Norton Removal tool

Re-open HJT and fix all the following (tick then fix all)

Quote:
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/tech...bs/tgctlsr.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1182124299375
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor...fo/webscan.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD5/JSCDL/j...ws-i586-jc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2D8FC4FE-7B21-4A21-860E-1D9D6448155E}: NameServer = 207.69.188.185,207.69.188.186
O17 - HKLM\System\CCS\Services\Tcpip\..\{964ED87D-3637-4023-B922-D2DF7B426B2B}: NameServer = 207.69.188.185,207.69.188.186
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
Finally restart

Then

Install Avira free AntiVirus
Run a full scan
Actually if you just install and update Malwarebytes and run that (with Avira installed) that'll be fine

Attach the logs.

Note: I usually never support users with FileSharing programs installed, basically there's no use (in my mind) These programs are the most likely cause of Malware infection, and here's the punch line - re-infection ie I don't help users with this installed.
Your choice to uninstall Bittorent
  #27  
Old 01-07-2009
Newcomer, in training
 
Member since: Dec 2008, 16 posts
Yes, this was self-inflicted and I learned my lesson - bittorrent goes. Do I have to uninstall Trend to get this cleared up? Digging up my disc to reinstall it and then finding the email where I got a free upgrade to their 2009 security suite will be problematic.
  #28  
Old 01-07-2009
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,368 posts
Well no.

But I find Trend to be overly slow (back in 2005 and 2006 it was ok - but not now)
So I tried Trend (actually I tried them all )
And found Avira (free) Antivirus to be the best
It's user preference

Therefore some of the above will not be correct !!
  #29  
Old 01-07-2009
Newcomer, in training
 
Member since: Dec 2008, 16 posts
I'll probably wind up deferring to your expertise, but Trend was awesome in blocking the infection from sending my browser off to the dark nasty corners of the world wide web. As far as preventing the infection in the first place, I clicked on an .exe file and I knew better. No program protects against that kind of stupidity. In any event, I will follow the latest instructions (mostly) and repost. - Thanks
To remove this ad, sign in. To register for a new account, click here.
  
  #30  
Old 01-07-2009
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,368 posts
Quote:
Originally Posted by kimsland View Post
Therefore some of the above will not be correct !!
If you keep Trend installed, some of the above (HJT entries asked to be removed) will be incorrect
  #31  
Old 01-07-2009
Newcomer, in training
 
Member since: Dec 2008, 16 posts
I don't have Norton installed so I skipped that step (I've been using the online scanner), but I downloaded and ran the remove Norton tool.

I left Trend installed.

I uninstalled Bittorrent

I fixed everything listed in Hijack except anything notated as Trend.

I downloaded Avira, installed, closed Trend, and ran Malwarebytes. I did the quick scan because previously when I ran it both ways, it picked up the same infections. I am doing a full scan with Avira as I write this.

Malwarebytes found those same two pesky files it keeps finding. I've attached the log.

Norton is the only scanner that's been picking up the Help.exe file - I suspect it's still there too.

What's the next step?

Thanks again for your help on this.
Attached Files
File Type: txt mbam-log-2009-01-07 (09-49-09).txt (961 Bytes, 1 views)
  #32  
Old 01-07-2009
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,368 posts
Well it would have been ideal if you had updated Malwarebytes first
The entire program is now at a new revision (just using the update button in Malwarebytes will automatically download the new version, and then update the defs)

By the way, once Avira finishes scanning, please remove it
There's no telling what corruption you may get with having more than 1 antivirus installed at the same time (ie what happens when Avira scans Trends quarantine folder who knows!)
So once Avira is done, please un-install it fully
  #33  
Old 01-07-2009
Newcomer, in training
 
Member since: Dec 2008, 16 posts
oops. Okay, after the Avira scan (it found two new infections) I uninstalled, restarted, then updated Malwarebytes and rescanned. Both logs are attached. Malwarebytes finally says everything is o-tay.
Attached Files
File Type: log AVSCAN-20090107-082955-D58A9F28.LOG (15.6 KB, 1 views)
File Type: txt mbam-log-2009-01-07 (11-18-18).txt (832 Bytes, 1 views)
  #34  
Old 01-07-2009
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,368 posts
Well done

Clear & Reset System Restore's Cache

Go to Start >> Run - type or copy/paste control sysdm.cpl,,4 and then press Enter

* Tick on the checkbox - Turn off System Restore on all drives
* Click Apply

Turn it back 'On' by unticking the same checkbox & click Apply, and then OK

Re-run CCleaner
Restart
Then let me know how it's presently running (Couldn't be worse! ; ok ; Fantastic )
  #35  
Old 01-07-2009
Newcomer, in training
 
Member since: Dec 2008, 16 posts
Fantastic
Closed Thread
Page 2 of 2 1 2

Tip: Download Advanced SystemCare 3 Freeware - 1 Click A Day to Clean, Repair, Protect & Optimize your PC.

Thread Tools


Similar Topics
Topic Category Replies Last Post
Do we need Spybot? Software & Utilities in General 15 10-05-2008 06:46 PM
SpyBot Software & Utilities in General 4 07-29-2008 02:20 PM
Spybot S&D 1.5.2 is now available News and Links from Around the Web 5 03-28-2008 06:20 AM
Experience of Infostealer.Gampass and Infostealer.Perfwo Virus & Malware removal 0 05-06-2007 04:35 PM
New Spybot Old Frontpage News & Comments 0 02-24-2004 08:37 AM


All times are GMT -4. The time now is 11:37 PM.