As many others I have got yesterday evening this virus which spreads infected file here and there, I have tried to follow some of the indications found on this matter but no help. I have disabled the restore configuration and reboot but again avast screens.
My system is Win XP Pro SP2 up to date, what I notice is IE7 poping up with some fishing site and then a pop-up inviting to install some sort of software to clean infections (I just close the pop-up), I notice also the volume slider to be not smooth anymore.
Tried also the Avast Cleaner tool, nothing detected.
I have installed only the “avast! v.4.7 Home Edition” for protection.
Attached are the warning log to see the infected files and the cleaner log.
It seems the virus regenerate after booting but avast can find only the files the virus creates.
Please any help will be appreciated.
Hi there first I will need to see the current state of play
Please download Deckard’s System Scanner (DSS) and save it to your Desktop.
[*]Close all other windows before proceeding.
[*]Double-click on dss.exe and follow the prompts.
[*]When it has finished, dss will open two Notepads main.txt and extra.txt – please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.
Download ComboFix from Here or Here to your Desktop.
[*]Double click combofix.exe and follow the prompts.
[*]When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix’s window while its running. That may cause it to stall
Attach the replies as it is easier for me to play with them
It was some problem with ComboFix, the first download was corrupted, the other one was ok but it showed some sort of error before starting, anyway it seems it quarantined few files (I had a suspicion already about the first two) but the problem is still there.
In the mean time I have done some investigation myself on the system, after ComboFix removed the BHO files it creates a new one after reboot in system32 with the name mllmk.dll (which I can’t remove manually). I have noticed that looking at the IE7 add-ons, if I try to disable it it will be enabled after booting.
OK there is one that does not want to play - Yet -
Download WinPFind35u.exe to your Desktop and double-click on it to extract the files. It will create a folder named WinPFind35u on your desktop.
[*]Close ALL OTHER PROGRAMS.
[*]Open the WinPFind35u folder and double-click on WinPFind35U.exe to start the program.
[*]Under Additional Scans click the checkboxes in front of the following items to select them:
Reg - BotCheck
[*]Now click the Run Scan button on the toolbar.
[*]Let it run unhindered until it finishes.
[*]When the scan is complete Notepad will open with the report file loaded in it.
[*]Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and attach the log. I will review it when it comes in.
The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. CLick the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here along with a new Hijackthis log.
I will review the information when it comes back in.
Also let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer.
Well at the moment everything looks quite and I see the volume slider working again smooth. Please tell me if the all malware was removed. I think you have done a great job.
It appear your ONLY security is Avast; not a wise decision . You complain
of trojan activity, yet you do NOT have any antiSPYWARE/antiTROJAN
programs . At a minimum, you should use the FREE version of
"SUPERAntiSpyware" from www.superantispyware.com .
And the "built-in" firewall that comes with the Win XP SP2 Operating
System is not that good. You should seriously consider installing a
firewall, and I recommend choosing between Zone Alarm, Sunbelt Kerio,
or Sygate, all FREE and available at www.filehippo.com/software/firewalls .
Looks good - now for a bit of house keeping - I would concur on SAS and a firewall
Now the best part of the day ----- Your log now appears clean
Double click Winpfind35 once again and you should see a CleanUp! button, press that button, you may get prompted by your firewall that OTMoveIt wants to contact the internet, allow this, a cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will delete all the tools you have downloaded plus itself
Now to get you off to a good start we will re-set your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your your restore point but this is my method:
Select Start > All Programs > Accessories > System tools > System Restore.
On the dialogue box that appears select Create a Restore Point
Click NEXT
Enter a name e.g. Clean
Click CREATE
You now have a clean restore point, to get rid of the bad ones:
Select Start > All Programs > Accessories > System tools > Disk Cleanup.
In the Drop down box that appears select your main drive e.g. C
Click OK
The System will do some calculation and the display a dialogue box with TABS
Select the More Options Tab.
At the bottom will be a system restore box with a CLEANUP button click this
Accept the Warning and select OK again, the program will close and you are done
Now that you are clean, to help protect your computer in the future I recommend that you get the following free program:
[*]SpywareBlaster to help prevent spyware from installing in the first place.
It is critical to have both a firewall and anti virus to protect your system and to keep them updated.
I have followed all your directives. Yes you are both right I don’t use too much protection, in 14 years is the first time I encountered a serious problem, this virus was smart, my good restore points were disappeared too. I have to say thanks to avast and I have to congratulate with you because you do a remarkable work, I cannot say the same about Microsoft, lately after few days I did a Win XP set up on this new machine I had a problem with their online updates which suddenely didn’t work, I got supported on the phone and we end up with a hanging machine and they told me “you have to do a full reinstall”, can you believe it?
I should at least offer you a drink, I’m sorry is not that easy to do. I think I will follow your suggestions for the protection software to install, with today’s stady internet connection is more easy to get such troubles.
I want to ask you if I can install the avast! on my notebook using the same key or I have to ask for another one. Also yesterday I noticed it has some problem with audio files reproduction, never before, but since a while the fun is working very intensively (perhaps needs a hardware clea up). On the notebook I had originally Trend-Micro but after updating to the latest I asked them to make a complete remove because it was too heavy and the system was slowing down too much. Now there is only a spyware protection downloaded from Google.
Well for now thanks a lot, let’s see in which condition is my notebook.