Malware and Virus RemovalProblems removing malware/viruses? Get help from our Malware removal experts.
Mission Statement
WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.
Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.
I have a problem at the moment in which the computer i have inherited has a virus. I have a virus alert permantly planted to the clock on the RHS and i cannot view my hard drives. i have lost all programs from the start menu.
please help,
here is my log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:54: VIRUS ALERT!, on 07/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
Please then reboot your computer in Safe Mode by doing the following :
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, the Advanced Options Menu should appear;
Select the first option, to run Windows in Safe Mode, then press Enter.
Choose your usual account.
Open the extracted SDFix folder and double click RunThis.bat to start the script.
Type Y to begin the cleanup process.
It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
Press any Key and it will restart the PC.
When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum).
Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
Now this.
Download Malwarebytes' Anti-Malware (MBAM) from here or here and save the file to your desktop.
Double click mbam-setup.exe to install the application.
Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select 'Perform Quick Scan', then click Scan.
The scan may take some time to finish,so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and click Remove Selected.
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note below)
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Post the entire report in your next reply along with a fresh HijackThis log.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
virus alert next to clock now gone and i can access my hard drives. all seems ok now. thanks
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:55:01 AM, on 07/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Now close all windows other than HiJackThis, then click Fix Checked.
Close HJT.
Now lets get a on-line scan.
Download ATF Cleaner by Atribune and save it to your Desktop.
This is a good tool to get rid of the temporary garbage you pick up while surfing the net.
Double click ATF-Cleaner.exe to run the program.
Check the boxes to the left of:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache
Recycle bin
The rest are optional - if you want it to remove everything check "Select All".
Finally, click Empty Selected. When you get the "Done Cleaning" message, click OK.
Once you are on the Panda site click the Scan your PC button
A new window will open...click the Check Now button
Enter your Country
Enter your State/Province
Enter your e-mail address and click send
Select either Home User or Company
Click the big Scan Now button
If it wants to install an ActiveX component allow it
It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
When download is complete, click on My Computer to start the scan
When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report
;************************************************************************** *************************************************************************** ******************************
ANALYSIS: 2008-07-08 17:54:46
PROTECTIONS: 1
MALWARE: 5
SUSPECTS: 1
;************************************************************************** *************************************************************************** ******************************
PROTECTIONS
Description Version Active Updated
;========================================================================== =========================================================================== ==============================
Norton Antivirus 2007 14.2.0.29 No Yes
;========================================================================== =========================================================================== ==============================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;========================================================================== =========================================================================== ==============================
00035753 adware/sidestep Adware No 0 Yes No c:\windows\downloaded program files\sbcie028.inf
00035753 adware/sidestep Adware No 0 Yes No hkey_current_user\software\sidestep
00035753 adware/sidestep Adware No 0 Yes No hkey_local_machine\software\microsoft\code store database\distribution units\{640b39c1-d713-464f-92c3-75bd972b95ee}
00035753 adware/sidestep Adware No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D714 A94F-123A-45CC-8F03-040BCAF82AD6}
00139535 Application/Processor HackTools No 0 No No C:\System Volume Information\_restore{125CBB4E-60A8-4E31-84D6-47AB90B3C817}\RP1\A0000049.exe[C:\System Volume Information\_restore{125CBB4E-60A8-4E31-84D6-47AB90B3C817}\RP1\A0000049.exe][SDFix\apps\Process.exe]
00139535 Application/Processor HackTools No 0 Yes No C:\System Volume Information\_restore{125CBB4E-60A8-4E31-84D6-47AB90B3C817}\RP4\A0002296.exe
00139535 Application/Processor HackTools No 0 No No C:\Documents and Settings\Owner\My Documents\SDFix.exe[C:\Documents and Settings\Owner\My Documents\SDFix.exe][SDFix\apps\Process.exe]
00520936 Application/ViewPoint HackTools Yes 0 Yes No C:\Program Files\Viewpoint\Viewpoint Toolbar\3.8.0\ViewBarBHO.dll
00520936 Application/ViewPoint HackTools No 0 Yes No C:\WINDOWS\Temp\0\Private\Vendor\ProgFiles\ViewBarBHO.dll
00549173 Application/SpywareStormer HackTools No 0 Yes No D:\System Volume Information\_restore{125CBB4E-60A8-4E31-84D6-47AB90B3C817}\RP4\A0002481.exe
00958927 Generic Malware Virus/Trojan No 0 Yes No C:\Program Files\Netscape\Netscape\Plugins\npwthost.dll
00958927 Generic Malware Virus/Trojan No 0 Yes No C:\WINDOWS\wt\wtupdates\wtwebdriver\files\3.3.1.001\npwthost.dll
;========================================================================== =========================================================================== ==============================
SUSPECTS
Sent Location
;========================================================================== =========================================================================== ==============================
No C:\Documents and Settings\Owner\Application Data\dvdfindload\eumqslug.exe
;========================================================================== =========================================================================== ==============================
VULNERABILITIES
Id Severity Description
;========================================================================== =========================================================================== ==============================
120815 HIGH MS06-022
;========================================================================== =========================================================================== ==============================
I do not use any of the items mentioned as I have been given this laptop and trying to clean it up.
I have now removed WildTangent from control panel. Please tell me how to remove sidestep. Also can you please tell me how to remove moodlogic as i cant remove with control panel or with safemode. i get an error saying program is running.
I thougt i had removed SDfix as i deleted it from my C: directory. Cant find any evidence of this program.
Please go to Start > Control Panel > Add/Remove Programs (Windows Vista it’s Programs and Features) and remove the following (if present):
sidestep
Using Windows Explorer (to get there right-click your Start button and go to "Explore"), please delete these folders (if present):
C:\WINDOWS\wt
Using Windows Explorer (to get there right-click your Start button and go to "Explore"), please delete these files (if present):
c:\windows\downloaded program files\sbcie028.inf
C:\Documents and Settings\Owner\My Documents\SDFix.exe
C:\Program Files\Netscape\Netscape\Plugins\npwthost.dll
Open “Notepad” Copy the contents of the code box below to the blank Notepad.
Click "File" > "Save as"
In the "Save In" box at the top click the down arrow and select DeskTop
In the “File name” type in: fix.reg
In the “Save As Type” select: All Files
Once saved, Go to your desktop double click “fix.reg file” and let it merge with the registry.
Code:
REGEDIT4
[-hkey_current_user\software\sidestep]
[-hkey_local_machine\software\microsoft\code store database\distribution units\{640b39c1-d713-464f-92c3-75bd972b95ee}]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D714 A94F-123A-45CC-8F03-040BCAF82AD6}]
We need to turn off and on system restore. There are infections in it and by using system restore you would reinfect yourself.
You must be logged in as an Administrator to do this. If you are not logged in as an Administrator, the System Restore tab will not be displayed.
Turning off System Restore will clear out all previous restore points.
To turn off Windows XP System Restore:
NOTE: These instructions assume that you are using the default Windows XP Start Menu and have not changed to the Classic Start menu. To re-enable the default menu, right-click Start, click Properties, click Start menu (not Classic) and then click OK.
1. Click Start.
2. Right-click the My Computer icon, and then click Properties.
3. Click the System Restore tab.
4. Check "Turn off System Restore" or "Turn off System Restore on all drives"
5. Click Apply.
6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
7. Click OK.
8. Restart the computer and follow the instructions in the next section to turn on System Restore.
To turn on Windows XP System Restore:
1. Click Start.
2. Right-click My Computer, and then click Properties.
3. Click the System Restore tab.
4. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives."
5. Click Apply, and then click OK
6. Make a new restore point.
7. Click Start, All Programs, Accessories, System Tools, System Restore.
Choose Create a restore point and clicked Next, Under “Type a description for your restore point…”put a name in the box,. Click Create. In the next window click Close.
After that, Reboot.
Now do this please.
Open HijackThis, click Config, click Misc Tools
Click "Open Uninstall Manager"
Click "Save List" (generates uninstall_list.txt)
Click Save, copy and paste the results in your next post.
Please post another Panda scan and the uninstall list from HJT.
Did all that you said, couldnt find sidestep in add/remove programs or in C:Windows/wt.
Panda scan
;************************************************************************** *************************************************************************** ******************************
ANALYSIS: 2008-07-11 19:55:34
PROTECTIONS: 1
MALWARE: 5
SUSPECTS: 2
;************************************************************************** *************************************************************************** ******************************
PROTECTIONS
Description Version Active Updated
;========================================================================== =========================================================================== ==============================
Norton Antivirus 2007 14.2.0.29 No Yes
;========================================================================== =========================================================================== ==============================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;========================================================================== =========================================================================== ==============================
00035753 adware/sidestep Adware No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D714 A94F-123A-45CC-8F03-040BCAF82AD6}
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\Owner\Cookies\owner@doubleclick[1].txt
00139535 Application/Processor HackTools No 0 No No C:\RECYCLER\S-1-5-21-3275979046-3272418547-2337929287-1003\Dc2.exe[C:\RECYCLER\S-1-5-21-3275979046-3272418547-2337929287-1003\Dc2.exe][SDFix\apps\Process.exe]
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[2].txt
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\Owner\Cookies\owner@questionmarket[2].txt
;========================================================================== =========================================================================== ==============================
SUSPECTS
Sent Location 3
;========================================================================== =========================================================================== ==============================
No C:\Documents and Settings\Owner\Application Data\dvdfindload\eumqslug.exe 3
No C:\Documents and Settings\Owner\Desktop\ComboFix.exe 3
;========================================================================== =========================================================================== ==============================
VULNERABILITIES
Id Severity Description 3
;========================================================================== =========================================================================== ==============================
120815 HIGH MS06-022 3
;========================================================================== =========================================================================== ==============================
Hijackthis scan
Active Desktop Calendar 7.27
Adobe Reader 6.0
AppCore
Apple Software Update
ATI - Software Uninstall Utility
ATI Control Panel
ATI Display Driver
AV
ccCommon
HijackThis 2.0.2
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB952287)
HotKey Utility
Internet Worm Protection
InterVideo WinDVD 5 for VAIO
Java 2 Runtime Environment, SE v1.4.2_01
LAN-Express AS IEEE 802.11 Wireless LAN
LiveUpdate 3.2 (Symantec Corporation)
LiveUpdate Notice (Symantec Corporation)
Malwarebytes' Anti-Malware
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft Office Standard Edition 2003
Microsoft Works 7.0
MoodLogic
Norton AntiVirus
Norton AntiVirus (Symantec Corporation)
Norton AntiVirus Help
Norton AntiVirus Parent MSI
Norton AntiVirus SYMLT MSI
Norton Protection Center
OpenMG Limited Patch 4.1-05-14-24-01
OpenMG Secure Module 4.1.00
Panda ActiveScan 2.0
PC Connectivity Solution
PowerISO
QuickTime
RealOne Player
Realtek AC'97 Audio
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB953839)
SoftV92 Data Fax Modem with SmartCP
Sony Certificate PCH
Sony Notebook Setup
Sony USB Mouse
Sony Utilities DLL
Sony Video Shared Library
SPBBC 32bit
Symantec
SymNet
Synaptics Pointing Device Driver
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
VAIO Help and Support
VAIO Media 2.6
VAIO Media Integrated Server 2.6
VAIO Media Redistribution 2.6
VAIO Power Management
VAIO Registration
VAIO Survey Standalone
VAIO Update 2
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live Messenger
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Service Pack 2
WinRAR archiver
WinZip 11.2
ZoneAlarm Pro
Please delete the fix.reg you have on your desktop.
Open “Notepad” Copy the contents of the code box below to the blank Notepad.
Click "File" > "Save as"
In the "Save In" box at the top click the down arrow and select DeskTop
In the “File name” type in: fix.reg
In the “Save As Type” select: All Files
Once saved, Go to your desktop double click “fix.reg file” and let it merge with the registry.
;************************************************************************** *************************************************************************** ******************************
ANALYSIS: 2008-07-12 16:51:07
PROTECTIONS: 1
MALWARE: 4
SUSPECTS: 2
;************************************************************************** *************************************************************************** ******************************
PROTECTIONS
Description Version Active Updated
;========================================================================== =========================================================================== ==============================
Norton Antivirus 2007 14.2.0.29 No Yes
;========================================================================== =========================================================================== ==============================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;========================================================================== =========================================================================== ==============================
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\Owner\Cookies\owner@doubleclick[1].txt
00139535 Application/Processor HackTools No 0 No No C:\System Volume Information\_restore{125CBB4E-60A8-4E31-84D6-47AB90B3C817}\RP3\A0000071.exe[C:\System Volume Information\_restore{125CBB4E-60A8-4E31-84D6-47AB90B3C817}\RP3\A0000071.exe][SDFix\apps\Process.exe]
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[2].txt
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\Owner\Cookies\owner@questionmarket[2].txt
;========================================================================== =========================================================================== ==============================
SUSPECTS
Sent Location K
;========================================================================== =========================================================================== ==============================
No C:\Documents and Settings\Owner\Application Data\dvdfindload\eumqslug.exe K
No C:\Documents and Settings\Owner\Desktop\ComboFix.exe K
;========================================================================== =========================================================================== ==============================
VULNERABILITIES
Id Severity Description K
;========================================================================== =========================================================================== ==============================
120815 HIGH MS06-022 K
;========================================================================== =========================================================================== ==============================
Did you turn off and on system restore? If so please do so again, if not please do so.
The rest are cookies and running ATF Cleaner should clear them out.