This is a read-only archive. No new posts or registrations. Privacy Page
Software

Got rid of the virus, but it left behind a mess

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

:pullhair:

Last week I did something I shouldn't have and ended up with a virus identified by PC Tools as win32.virtut.gen.4, as well as a whole whack of (in some cases hard to get rid of) malware I assume was downloaded via the backdoor the virus opens. Well, as far as I can tell I've gotten rid of all the carp** (it took two days and ended up involving ComboFix, which I wish I'd known about from the beginning!). But my computer hasn't been the same since.

First of all, I think my antivirus software deleted a crucial DLL or something for printing. (Mostly it claims to have simply disinfected the relevant files, but it outright removed a few as well.) My print spooler service refuses to start on the grounds that a file is missing; it doesn't say which one. How do I get that back, and more importantly, repair whatever else is broken or missing that I don't know about? I doubt that's the only thing affected, just the only one (barring the next paragraph) that I know about so far.

Second, since the virus first showed up my Web browsing and e-mail have been incredibly slow compared to before, and getting rid of the virus didn't return them to normal. Downloading large files is as fast as ever, but Web sites with a lot of little objects (e.g. forum topics, thumbnails) take several times longer to load than they used to. Rebooting without my antivirus software doesn't help with any of this (and isn't my first choice in light of recent events anyway), ruling out one possibility.

I wish I could be more specific. I do still have some of the logs from the incident. I just want my system back to the way it was!

(Also, I'm sure some here will question the wisdom of this, but I don't use system restore. I hate the constant, random slowdowns and the amount of disk space it chews up. Until now I've never had a problem I couldn't recover from some other way.)

Is it time to format and reinstall? That would be a pain with all the applications I'd have to reinstall and so on, so I'd prefer something less drastic if at all possible.
Hi Jeff

Well, that doesn't sounds to good at all.

Do you have an original windows CD? Not OEM or Recovery disc.
If you haven't got one, maybe you could borrow one from a friend or family member.

If yes, try run this command:

Goto start–>Run–>Type: SFC /Scannow (Notice the space between the C & / )

This scan will attempt to repair / replace lost or damaged files.
Keep your winCD in reach, if it ask for it, pop it in. The scan won't produce a log, but let me know if it asked for CD.

Also, regarding your printer problem, a re-install might be good here, or at least the printer drivers, if the above doesn't solve the problem.

You should check that all windows updates are installed correctly without any errors. To check this, goto Update.microsoft.com
To the left on the screen, theres a button that will let you see through all of your updates. The first option under settings.
Look all through, and look for any red points. Those are the ones not installed or failed to install. install or reinstall those.

If this doesn't solve the problem, i would consider a repair, a full install is alittle to drastic at this point.
Let me know how you fare with the above, and we will take it from there.

Kind regards Abydos :)
Formatting is always the last resort - too much is lost - besides all your personal data, installed programs, and personal settings, you lose any hardware driver updates too. But more importantly, your security is severely compromised as you end up months or even years behind in critical updates.

I am afraid you have a misconception about System Restore. If you disabled it because it impacted performance, something else is wrong. It only creates restore points in the background, or after the user initiates some action that triggers the creation of a point, such as installing new drivers/hardware, major program updates, system updates, or a manual creation.

Also, the user determines how much disk space is consumed. I have mine set to 3%, which is just 3Gb on my 100Gb drive - room for plenty of restore points. But more importantly, System Restore automatically shrinks when free disk space becomes limited, and disables itself completely, freeing up consumed space, if free space is drops to 50Mb. Running DiskCleanup will purge all but the most recent restore point - good for freeing up space, if sure the last point is of a properly working system. But the reality is, if that low on space, you need to delete some stuff, or get more disk space.

Did a trained analyst help you with your ComboFix? Was a HJT log analyzed? Since that was last week, I agree with Abydos and think that running a file check is a good idea, but I would suggest you make sure your system is clean of malware first. Here's a link to my canned text on Cleaning Out Malware. Use it if you don't already have a complete security suite and disk cleaning utilities to rid your system of malware and clutter. You can also use it as a guide to build your own security suite, and to help you develop a "Practicing Safe Computing" self-discipline.
Okay, I'm just about to do a thorough cleanup as the duck in the Indiana Jones hat told me to, and I can't help but notice that I'm uploading a suspiciously large number of packets. Not downloading any more than I would expect, though. I'm guessing from that that I still have malware and it's trying, quite aggressively, to call home, but my router is stopping it from downloading anything. I'll let you guys know how it goes. I did run SFC but I still get told a file is missing when I try to turn the spooler on. I'll try to reinstall the printer driver later on, but for now I'm going to follow the various other suggestions you guys gave first. I anticipate that, one way or another, I'll post back in a few hours in more detail. ADDED A COUPLE HOURS LATER ON EDITING: I've installed Comodo Firewall among other things. The preliminary virus check it does found five more infected files, and it says it's already blocked seven intrusion attempts. Also, I'm wondering if it's normal for svchost.exe to be opening connections by the half-dozen and be responsible for about half of my network activity even while I'm semi-actively web surfing? I'm thinking the answer is "no way, Jose". It also re-opens the connections as fast as I can close them in the firewall, which seems very malware-like to me. EDITED IN A FEW MINUTES LATER: I set the firewall to block svchost.exe (even though I realize there are legitimate reasons why it might want to access the Internet), just to see if doing so actually hurt anything I wanted to be doing, but the firewall isn't blocking it! How do I get it to respect my wishes?!?
Hi Jeff H

Well, with the info you posted above, regarding Comodo found some entries that shouldn't be, and your concern about the numerous outbound calls by SVC. I would recommend you posted a HJT-log in the HJT forum.

When its safe to say that your PC is clean, youre welcome to write back in this topic if you still are experiencing any problems.
Trying to fix something on an infected PC will not do any good, as the problem(s) may pop up as quick as we put them down, or faster :unsure:
Under any circumstances, we wouldn't accomplish anything if its infected.

Anyways, if you have any questions before posting the HJT-log, feel free to do so, but have the above written in mind.

Regards Abydos
Okay, I'll do HJT sometime this weekend. Just to give a more detailed idea of what I've done: * Attempted SFC. I did it with the disc already in the drive, so unfortunately I can't tell you whether it would have asked for it or not. But in any event, it didn't fix the printer problem. * Manually blown away multiple new .exe files that showed up in the root of my C drive. * Scanned with AVG Anti-Rootkit (found nothing), Ad-Aware (found nothing worse than tracking cookies), Comodo's built-in scanner (told you what happened with that). An AVG virus check is in progress right now. * Installed all of the above plus Comodo. * Gotten up to date on critical WinXP updates. I already had used PC Tools Antivirus (found and claimed to have fixed over 2500 problems, overwhelmingly Virtut-infected exe files for otherwise legitimate programs) and Spybot S&D (found 70 more, inlcuding some Vundo stuff it couldn't fix), VundoFix (found four instances, could only fix three of them) and finally ComboFix (zapped five more things including the file VundoFix couldn't). No trained analyst helped with ComboFix, I simply downloaded that day's update and ran it. What do you guys think of PC Tools, by the way? Which would you recommend that I set up for real-time scanning, that or AVG? (I tried Avast for a while, allegedly the most effective of the free ones, but found it to be a real resource hog, to the point where the cure seemed comparable to the disease.)
Actually, now that AVG has done its thing (and killed another seven infected files), I'm no longer getting all the svchost nonsense. All svchost is doing at the moment is listening to one port; I don't see anything unreasonable about that, any number of legitimate services could be responsible for that. Packets sent are no longer wildly out of line compared to what I've seen in the past. Surfing seems to be back to normal too, though it's hard to be 100% sure. Should I still post an HJT log just in case or can I go ahead and work on the printer problem? EDITED IN LATER: Actually, I can now print again too, having traced that problem to a missing spoolsv.exe and extracted said file from the XP CD. Firewall still isn't blocking svchost.exe, but at this point I'm cool with that. I am aware that it is a legitimate Windows system file and have a rough idea what it does and why it might occasionally need to access the 'net. svchost.exe is as much an innocent victim in this as I am (moreso considering I was the dayam fool who installed the original Trojan in the first place, and did it by doing something I knew dayam well was dodgy on my part). Thanks for all your help, both of you.
May have spoken too soon. I went in the firewall settings and noticed two momentarily surprising sorts of activity. One, svchost was sending a lot of packets. But on noticing they were all to the same IP, and all to port 53, a quick IPconfig cleared up that worry. These are legitimate DNS requests. services.exe, on the other hand, was sending packets, always the same size, to seemingly random IPs, always to port 25. I smell a rat. These are e-mails, or using the port normally reserved for such, coming from something other than my e-mail program. I barred services.exe from sending on port 25 in the firewall (and checked to see if this affected my own ability to send e-mail - it did not) but I want to cut this off at the source. See you in the HijackThis forum.
Hi Jeff H Always better to let a trained person look over your files, than try to fix them alone. Email sending is most often indication of various Trojan's and the Storm-worm. So getting it fixed is a really good and necessary thing to do. Best of lucks :thumbup: Regards Abydos

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI