This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojans, Malware, and who knows what else.

45 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Satchfan, I'm again very sorry for the delay. We woke up the day before yesterday with no hot water, and had to wait until yesterday to finally get it fixed. This morning we woke up with no heat, and we get to wait until at least tomorrow to hopefully have that taken care of; living in a 48 degree house is not fun… Once things manage to HOPEFULLY calm down here in a day or two, I will jump right back on the horse with running the McAfee removal tool, MBAM, and Kaspersky. Thanks for your continued assistance, once more.
OK, Satchfan, let's continue…

The McAfee Removal Tool was successful this time in removing the remnants of the programs, so that has been completed and the computer restarted. Upon the restart however, Windows installed an update which thankfully to the best of my knowledge was an ACTUAL update, as the other netbook has already installed it.

The MBAM scan turned up absolutely nothing, but I will paste the log into the end of this post just the same for your convenience and review.

Kaspersky, however, ran into some trouble with updating. It ran for at least an hour and a half to download the updates, and then turned back the following error window:

"The page at http://www.kaspersky.com says:

Update has failed The program could not be started. Please close the window of Kaspersky Online Scanner 7.0 and start the program again from the web site of Kaspersky Lab.

Successful updating of Kaspersky Online Scanner 7.0 and scanning of your computer requires uninterrupted Internet connection. Pleaase make sure that the Internet connection is established.
[ERROR: Anti-virus database was updated after license expiry]"

As I am certain our internet was not at all interrupted whilst the updates were downloading, I don't know what you would like me to do in terms of re-running the scan. I'm more than happy to do so at your instruction, but will leave it be until I'm certain what you would like me to do.

Thanks again for all your help, and here is the MBAM log:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 5134

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

11/17/2010 9:35:28 AM
mbam-log-2010-11-17 (09-35-28).txt

Scan type: Quick scan
Objects scanned: 138125
Time elapsed: 13 minute(s), 0 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Glad things seem to be running better mediaklepto.

It won’t let you run another Kaspersky scan until you have deleted the old ActiveX download component. The easiest way to solve this is to close your browser and uninstall the program via Start, Control Panel, Add/Remove programs.When you have removed/uninstalled it, download and try running it again.

If it still doesn’t work, try the scan below instead.

Run ESET Online Scan

Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan 1. Click the Eset online Scanner button.
2. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

• Click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
• Double click on the Eset installer icon on your desktop.

3. Check Yes, I accept the Terms of Use
4. Click the Start button.
5. Accept any security warnings from your browser.
6. Check Scan archives
7. Push the Start button.
8. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
9. When the scan completes, push List of found threats
10. Push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
Note - when ESET doesn't find any threats, no report will be created.
11. Push the back button.
12. Push Finish
If a log has been produced post it in your next reply.

Please also let me know if there are any outstanding issues with your computer

Satchfan
Sorry for the late reply again, Satchfan. I realize how annoying the lack of response/action must be. With the upcoming holiday, we have been extremely busy shopping and preparing, and I have not yet had time to spend with the computer. I will make an effort to do so over the weekend. Thanks again, for the umpteenth time.
OK, Satchfan, it looks like I'll be able to get things rolling again tomorrow. We will be working around the house, and thusly the computer can have a length of time to scan uninterrupted.

I would like to note, however, that we have no been using that computer at all except to run your requested scans. I'm incredibly worried about having it on at all, for fear of anything else making its way onto it, or even just making itself known. Do you have any suggestions on what I could be using it for? I could play The Sims, but it's a fullscreen game, and if anything was happening in the background, I'm afraid I'd be unaware.

Thanks for any input you can offer.
All right Satchfan, here we go. We attempted, as you suggested, to remove the Kaspersky component from the Add/Remove Programs menu, but came to a dead end. We were unable to locate anything named Kaspersky, and were unsure what other programs we may need to look for. We decided to attempt to run it once again, just to see if it would accomplish anything, but were greated with the same error message as before. If you can tell us what else we can do to remove and retry, or what to look for under Add/Remove Programs, we'll be more than happy to try Kaspersky once again. We moved on to ESET after failing with Kaspersky, again as you requested. My husband tried first using Internet Explorer, but was caught in a loop of attempting to allow the DirectX component and reloading the page over and over again. Is there an issue there we must address? We moved on from there to download ESET through Firefox and were successful in downloading, installing, and running the scan. It found a single threat, which it quarantined. At the end of the scan, it offered a check box to delete all quarantined files, but as you did not tell me to do so, I left the box unchecked, exported the log, and clicked finish. The single line from the log will be at the end of this post. I do however have a couple quick questions, if I may: First, I mentioned at the start of the thread that SUPERAntiSpyware found and quarantined some files, but I did not delete them. Should I do so now? Second, I also mentioned that after the incident with attempting the first time to run the McAfee removal tool, I was greeted with duplicate warnings from Avast! about "dwm.exe" trying to run and install a trojan from my temp files. As I said, on the first warning, I told it to quarantine. On the second warning, I told it to delete the file, and was told repeatedly that it could not find it to delete it (presumably because it was quarantined), and it would attempt to do so on restart. After that, the first three or so times the computer was restarted, it would give me a couple of notices saying that it couldn't find it to delete it. Now, it is no longer giving me these warnings at startup. Should I be worried about "dwm.exe" somehow finding its way back and downloading more such threats? And lastly, as the infection found by ESET is listed as a worm, is there any threat of it infecting the other two computers on the network? Filesharing is turned off on them all, if that means anything, and since the first appearance of the infection (when Spybot alerted me to "virtumonde"), the other two computers are not even turned on at the same time as this one, and not until this one has been off for some time. I apologize for my many questions, and for my paranoia. Thanks again, and here is the one line from ESET: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchOleHelp1.zip Win32/Bagle.gen.zip worm cleaned by deleting - quarantined
Hi mediaklepto

SUPERAntiSpyware found and quarantined some files, but I did not delete them. Should I do so now?

As long as your computer is running OK you can delete them

Should I be worried about "dwm.exe"

No, dwm.exe was removed with one of the directions I gave you previously.

as the infection found by ESET is listed as a worm, is there any threat of it infecting the other two computers on the network?

Most worms need a user to to allow it access to the machine (eg, click on an infected e-mail attachment or accept a bluetooth transmission) before it can start replicating. As the computers have been switched off it’s unlikely that they are infected. Also, the infection found was a zip file which had not been extracted yet.


Your computer appears to be clean.

Now that you’re free from malware, as long as your computer seems to be running well, please follow these simple steps to tidy up you computer and decrease the likelihood of getting infected again:

Uninstall OTL
• Double-click OTL.exe
• Click the CleanUp! button.
• Select Yes when the Begin cleanup Process? prompt appears.
• If you are prompted to reboot during the cleanup, select Yes.
• The tool will delete itself once it finishes, if not delete it by yourself.
NOTE: If you receive a warning from your firewall or other security programs regarding OTL attempting to contact the internet, please allow it to do so.

===================================================

Create a Restore Point
• Click Start Menu, Run
• Copy and paste the following:

%SystemRoot%\System32\restore\rstrui.exe

• Press OK
• Choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create
• When the confirmation screen shows that the restore point has been created, click Close.
Remove old restore points• Go to Start, Programs, Accessories, System tools, Disk Cleanup
• When the Disc Cleanup dialog box appears, click OK
• When it finishes running, a box with tabs will appear, select the ”More options” tab
• On this tab you will find a section for System Restore
• If you press the Clean Up button for that section, Windows will delete all restore points except for the most recent one.
===================================================

Re-enablr you CD emulation software

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.

Your Emulation drivers are now re-enabled.

===================================================

Update Java

You have multiple versions of Java that are out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version

Please go here to download JavaRa to your desktop and unzip it to its own folder
  • Double-click on JavaRa.exe to start the program
  • From the drop-down menu, choose English or the appropriate language…and click on Select.
  • Click Remove Older Versions to remove the older versions of Java installed on your computer
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.
===================================================

Firewall

You're using the Windows Firewall which is not adequate protection. The main reason you should use a third-party firewall over the Windows XP Firewall is because Windows Firewall only stops incoming signals from accessing your computer. However, it will not stop Outgoing signals (possibly ones that could intrude your privacy) from sending information to the Internet or to other networks. That means if malware happens to compromise your PC again, it will be able to SEND OUT out your credit card data and any other personal information.

I suggest you install a more robust third party firewall that filters both incoming and outgoing traffic.

Download\install one of the following freeware firewalls from below:

Sygate Personal Firewall Free Edition:
Zone Alarm Free:
Comodo Personal Firewall:

NOTE only install one firewall. Having more than one could cause many programs to stop working altogether. Also, the firewalls may get in each others' way and cause some security holes that would not be there with just one firewall.

You should take the time to read Understanding and Using Firewalls


Disable Windows firewall:• Click on Start, Settings and then Control Panel
• Click on the Security Center icon.
• Click on the Windows Firewall icon
• Click Off (not recommended) and then click OK.
When you have done that:

===================================================

Set your computer to automatically check for Windows updates.

To turn on Automatic Updates:
• Click Start, Settings and then click Control Panel.
• Double-click Automatic Updates.
• Choose Automatic (recommended).
===================================================

I suggest that you run SUPERAntiSpyware and Malwarebytes’ AntiMalware on a regular basis, probably weekly.

===================================================

I also recommend that you read the following:

“So how did I get infected in the first place”? by Tony Klein
"How to prevent malware" by miekiemoes

Remember to keep updating all of the above programs to help your computer remains clean. You can never update too often and your computer will not be protected from new malware if your programs are not up-to-date.

Safe computing

Satchfan
Thank you very much, Satchfan, for all of your much assistance. I'm in the process of downloading the ZoneAlarm firewall for this (uninfected) computer right now, and will download it to the other two systems a little later, after more of the Thanksgiving chaos has subsided. Just a couple other quick notes, if you don't mind my asking… When we ran the OTL cleanup, it finished and asked to restart. Upon the computer rebooting, OTL, GMER, and DeFogger, had ALL been removed from the desktop. There may have been another, but I'm not entirely sure all how many tools we had downloaded. Is this normal? We downloaded DeFogger again to re-enable the CD emulators. Also, the ESET scan only seemed to quarantine the infection it found. Should I, and how should I, go about removing it? Thank you so very much again for your persistence in helping with this whole thing. It's very much appreciated.

Thank you very much, Satchfan, for all of your much assistance

You are welcome.

OTL, GMER, and DeFogger, had ALL been removed from the desktop. We downloaded DeFogger again to re-enable the CD emulators.

My apologies mediaklepto. I should have asked you to re-enable your CD emulators before uninstalling OTL. It is perfectly normal for OTL to “clean up”, (remove), the programs that we used.

the ESET scan only seemed to quarantine the infection it found. Should I, and how should I, go about removing it?

Yes, you can remove Eset.

Regards

Satchfan
Satchfan, I'm incredibly sorry about being a nag, but I have one (HOPEFULLY) final question. I assume by "remove ESET" you mean to go ahead and run the uninstaller that came with the installation. How about that quarantined worm though? Will running the uninstaller delete the quarantine, or is there some other way I can make sure it's gone before running the uninstaller? Thank you, yet again, for your abundant assistance.
Hi mediaklepto

Sorry for the delay but your post somehow slipped by me unnoticed until now.

Uninstalling the online scanner will remove the items in quarantine.

See here if you have problems

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI