also @ TechSpot: Tech Tip: Unlock Hidden Region-Specific Themes in Windows 7
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > Operating Systems & Software > Virus & Malware removal

Viruses/Spyware/Malware, preliminary removal instructions by howard_hopkinso

Closed Thread
Bookmark Thread Tools
  #1  
Old 12-01-2007
M0ntG0M3rY's Avatar
TechSpot Member
 
Location: New York, NY
Member since: Jul 2007, 50 posts
Viruses/Spyware/Malware, preliminary removal instructions by howard_hopkinso

The following two posts are exact citation of [COLOR="Blue"]Viruses/Spyware/Malware, preliminary removal instructions[/COLOR] by howard_hopkinso, which have been retrieved from Google cache and formatted to reproduce their original presentation.
  #2  
Old 12-01-2007
M0ntG0M3rY's Avatar
TechSpot Member
 
Location: New York, NY
Member since: Jul 2007, 50 posts
[color=Red]Very Important: [/color]Malware infections can possibly lead to [color=blue]identity theft[/color], [color=blue]stolen bank funds[/color], [color=blue]misuse of credit card information [/color]etc. Therefore I strongly encourage you to please read this thread HERE before deciding what course of action to take regarding your infection.

If after reading the above, you wish to clean your system, do the following.

-----------------------------------------------------------------------------------------------------------------------------------
[center][color=red]Please make sure you complete all steps in this thread,[/color] BEFORE [color=red]you post the requested log files.[/color]

[color=blue]Make sure you read and follow all the [color=red]STEPS[/color] below, otherwise it just makes it that much harder for us to help you effectively. [/color]
[color=blue][/color]
[color=blue]DO NOT SKIP ANY OF THE INSTRUCTIONS[/color]

If you have any problems following any of the instructions, please ask for assistance.
[/center]

-----------------------------------------------------------------------------------------------------------------------------------
[center]STEP1:


[color=red]Malware Removal: Temporarily Disable Real Time Monitoring Programs.[/color]
[/center]

This is because some real time protection programmes can interfere with any fixes we are trying to run.

Once your system is clean, you are advised to turn the protection back on.

See these instructions on how to disable some of the more common real time monitoring programmes. Thanks to CastleCops for the info.

------------------------------------------------------------------------------------------------------------------------------------
[center]STEP2:
[/center]

If you`re [color=blue]NOT running any antivirus or firewall software[/color], you should install some ASAP.


Download and install the free AVG or Avast antivirus programmes and either the free Zonealarm, Kerio or Comodo firewall programmes.

Install whichever firewall you chose, followed by whichever antivirus programme you chose. Reboot your system the required number of times. Run the antivirus updates.

[center][color=RED]ONLY INSTALL THE ABOVE ANTIVIRUS/FIREWALL SOFTWARE, IF YOU DON`T ALREADY HAVE ANY ANTIVIRUS OR FIREWALL SOFTWARE.[/color]
[/center]

-----------------------------------------------------------------------------------------------------------------------------------
[center]STEP3:
[/center]

Run this online virus scanner. You will need to use Internet Explorer for this scanner. It`s one of the very few online scanners that will actually disinfect viruses etc. NOTE: If you have any problems with the online scanner, skip it and continue with the rest of the instructions below.

-----------------------------------------------------------------------------------------------------------------------------------
[center]STEP4:

[color=Blue]Make sure you have the LATEST version of HJT [color=red](currently v2.0.2)[/color] from HERE.[/color]
[/center]

The above link will download the HijackThis installer. Run the HijackThis Installer and it will automatically place HJT in C:\Program Files\TrendMicro\HijackThis\HijackThis.exe. It will also automatically OPEN HJT, close it.

-----------------------------------------------------------------------------------------------------------------------------------
[center]STEP5:

[color=red]THIS IS VERY IMPORTANT.[/color]
[/center]

Open the C:\Program Files\TrendMicro\HijackThis folder in program files. Rename the Hijackthis.exe file to Crusty.exe. This is because some malware can hide from HijackThis.exe. Right click the HijackThis.exe file and choose rename. Click in the title box and press the delete key to clear what`s there, type Crusty.exe and press the enter key. [color=blue]Right click the Crusty.exe file and choose send to desktop(create shortcut).[/color]

[center][color=red]Under no circumstances should you add any items to the HJT ignore list.[/color]

Do not run a HJT scan, until step15 of this thread.
[/center]

------------------------------------------------------------------------------------------------------------------------------------
[center]STEP6:
[/center]

Download and install AVG Antispyware(formerly Ewido).
Double-click the icon on your desktop to run it.
On the top of the main screen click Shield. Click the word active to change it to inactive.
On the top of the main screen click 'Update'. Then click on 'Start
update'. The update will start and a progress bar will show the updates
being installed.
If you are having problems with the updater, you can get the manual update at http://downloads.ewido.net/avgas-sig...ll-current.exe
When you have finished updating, exit AVG Antispyware.

[color=blue]For a complete pictorial guide to the use of AVG Antispyware look HERE. Thanks to rik for the guide.[/color]

-----------------------------------------------------------------------------------------------------------------------------------
[center]STEP7:
[/center]

Download and install the latest version of SS&D from HERE. Make sure you have the latest definition files(updates). Click the immunize button in the lefthand pane, then click the green immunize cross in the righthand pane. Close SS&D. Make sure that during installation the Teatimer protection is disabled.

-----------------------------------------------------------------------------------------------------------------------------------
[center]STEP8:
[/center]

Download and install the latest version of Ad-Aware SE Personal from HERE. Make sure you have the latest definition files. Close Ad-aware se.

-----------------------------------------------------------------------------------------------------------------------------------
[center]STEP9:
[/center]

Download the Ccleaner programme from HERE.

Close all browsers. Run the programme and make sure all the boxes are ticked under the Windows(except for the Old prefetch Data option, this should be unticked) and Applications tabs and click the run cleaner button. Do this several times.


-----------------------------------------------------------------------------------------------------------------------------------
[center]STEP10:
[/center]

Download and run these three tools. [color=red]Follow the instructions for using each tool on the download site for each tool.[/color]

Tool1 Tool2 Tool3

-----------------------------------------------------------------------------------------------------------------------------------
[center]STEP11:
[/center]

Download the Panda Antirootkit programme.

Unzip it and run the PAVARK.exe file.

Tick the box that says In depth scan and follow the on screen instructions.

[color=red]DO NOT remove any UNKNOWN ROOTKITS at this stage. Instead, let me know the results.[/color]

[color=blue]Let me know the results in your reply.[/color]

PLease Note: Panda Antirootkit is not compatible with Windows Vista.

If you are running Vista, please download the AVG Antirootkit programme.

Disconnect from the net and install the programme.

Run the programme and tick Indepth scan. Do not have AVG Antirootkit fix anything, instead let me know the results.

Once the scan is finished, reconnect to the net.

-----------------------------------------------------------------------------------------------------------------------------------
[center]Please continue with instructions in the post below.[/center]
To remove this ad, sign in. To register for a new account, click here.
  
  #3  
Old 12-01-2007
M0ntG0M3rY's Avatar
TechSpot Member
 
Location: New York, NY
Member since: Jul 2007, 50 posts
[center]STEP12:

Delete all versions of Combofix you may already have.
[/center]

Download Combofix.exe.
Double click combofix.exe & follow the prompts. A window will open with a warning. Type "1" (and Enter) to start the fix. When the scan completes it will open a text window. Please attach that log back here together with a fresh HJT log. Caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop.

Combofix will automatically save the log file to C:\combofix.txt [color=red]Do not post the Combofix log, until you have completed the rest of the instructions below.[/color]


-----------------------------------------------------------------------------------------------------------------------------------

[center]STEP13:
[/center]

You might want to copy and paste these instructions into a notepad file. Then you can have the file open in safe mode, so you can follow the instructions easier.

Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). See how here.> http://www.bleepingcomputer.com/forums/tutorial61.html

In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how here.> http://www.bleepingcomputer.com/forums/tutorial62.html

Run a full system scan with your [color=red]antivirus programme[/color] and delete whatever it finds, including anything in the virus vault.

-----------------------------------------------------------------------------------------------------------------------------------

[center]STEP14:
[/center]

Run SS&D and fix whatever it finds.

Run Ad-Aware personal se. Click start, uncheck scan for negligible risk entries.
Select perform full system scan and click next, fix whatever it finds.

[center]See this pictorial guide on how to use AVG Antispyware.

Make sure all windows are closed.

Run AVG Antispyware.

[color=blue]VERY IMPORTANT[/color]

Make sure AVG is set to quarantine it`s results.

Make sure you read this step properly.

[/center]

[color=blue]That`s because too many members are posting an AVG log that says "No Action Taken" or "Ignored"[/color]

Please note:
[color=red]If your AVG Antispyware log says all items have[/color] "No Action Taken" or "Ignored" [color=red]That`s because you haven`t followed the instructions properly for using AVG Antispyware and will have to read them again and do a fresh AVG Antispyware scan.[/color]

There is absolutely no point in attaching an AVG Antispyware log that says items have "NO ACTION TAKEN" or "IGNORED"

Once finished, click the save scan report button, followed by the Save report as button and save it to your desktop.

Reboot into normal mode and rehide your protected OS files.

-----------------------------------------------------------------------------------------------------------------------------------

[center]STEP15:

Run HijackThis.
[/center]

Click on Scan. After the program is done with the scan, click on the "Save log". It should be the same button as the previous "Scan" button you clicked on. Save the log to wherever you want. You can now attach your HJT log without having to rename it as a .txt file.

Attach the HJT logfile as an attachment into a new thread in our security and the web forum(unless you`ve already got a thread here).

See this thread for instructions on how to post a HJT log and your other logs as ATTACHMENTS.

[center]Please note: HJT and any other logs must not be posted as .doc files. This is due to the risk of viruses etc.
[/center]


Once you`ve finished these instructions, you should have 3 log files. HJT, Combofix and AVG Antispyware logs. They are the only logs we need, unless otherwise requested.

I don`t want to see any other log files, unless I specifically request them.

That means no Smitfraud log, no Vundufix log, No VirtumundoBeGone log, or any other kind of damn logs.

[center]Don`t forget to: [color=blue]Let us know the results of the Panda Antirootkit scan[/color]


Let us know what symptoms you`re having if any.
[/center]

Regards Howard
  #4  
Old 01-26-2008
Newcomer, in training
 
Member since: Jan 2008, 2 posts
Here are the Logs after i finished with everything you directed ^^

Oh and the Antirootkit found nothing btw. What do i do next? I still get the "Can not find script file "C:\FS6519.dll.vbs". alert when i try to double click open my C: drive.
Attached Files
File Type: txt Report-Scan-20080126-145256.txt (1.3 KB, 2 views)
File Type: log hijackthis.log (5.9 KB, 2 views)
File Type: txt dss log.txt (18.7 KB, 0 views)
  #5  
Old 01-26-2008
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,368 posts
M0ntG0M3rY better to just provide a link, like this:

Viruses/Spyware/Malware, preliminary removal instructions

frogentott have you posted before about this ?
Quote:
Oh and the Antirootkit found nothing btw. What do i do next? I still get
Sounds as though you have some history to your issue.

You may want to check THIS link on startup issues.
Scroll down to STARTUP MANAGERS to download and hopefully remove your startup issue.
  #6  
Old 01-26-2008
Newcomer, in training
 
Member since: Jan 2008, 2 posts
Thank You!!!

Ooh after i ran Cracky.exe the problem was fixed!!! Thank You very much for the great help and tips!!! God Bless!!!
  #7  
Old 01-26-2008
M0ntG0M3rY's Avatar
TechSpot Member
 
Location: New York, NY
Member since: Jul 2007, 50 posts
Quote:
Originally Posted by kimsland
M0ntG0M3rY better to just provide a link
Check the time my message was posted... the link didn't exist at all, I just reconstructed the text, which have since been copied and put in its original place...


frogentott, I recommend you start a new thread instead.

Last edited by M0ntG0M3rY; 01-26-2008 at 09:57 AM..
  #8  
Old 01-26-2008
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,368 posts
I see by 2 Hrs yours is the original (format)

Apologies M0ntG0M3rY, when I saw the long post. I thought it was strange.
  #9  
Old 01-26-2008
M0ntG0M3rY's Avatar
TechSpot Member
 
Location: New York, NY
Member since: Jul 2007, 50 posts
no problem :-)
To remove this ad, sign in. To register for a new account, click here.
  
  #10  
Old 01-26-2008
tomrca's Avatar
TechSpot Addict
 
Location: sunderland, tyne and wear
Member since: Jun 2005, 1,050 posts
have you run NOOB KILLER yet AS this shows in your log R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = TAGA LIPA ARE!you can get it from HERE
in th meantime have hijackthis fix :
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)b

O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)

check to see if you know this: O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} (Imikimi_activex_plugin Control) - http://imikimi.com/download/imikimi_plugin.cab if not remove

Last edited by tomrca; 01-26-2008 at 10:27 AM..
Closed Thread

Tip: Download Advanced SystemCare 3 Freeware - 1 Click A Day to Clean, Repair, Protect & Optimize your PC.

Thread Tools


Similar Topics
Topic Category Replies Last Post
Requested logs from removal instructions of virus/spyware/malware Virus & Malware removal 12 12-04-2008 07:43 AM
I followed all Preliminary removal instructions, whats next? Virus & Malware removal 22 03-24-2008 08:52 AM
Viruses/spyware/malware preliminary removal; thread missing The Meeting Spot - Chat & Socialize 2 11-30-2007 11:18 AM
Viruses/Spyware/Malware preliminary removal log files Virus & Malware removal 9 11-27-2007 08:04 PM


All times are GMT -4. The time now is 08:57 PM.