1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Many problems with net-worm.win32.mytob.t

Discussion in 'Malware and Virus Removal Archive' started by soxfan93, 2009/12/29.

  1. 2009/12/30
    soxfan93

    soxfan93 Inactive Thread Starter

    Joined:
    2009/12/29
    Messages:
    26
    Likes Received:
    0
    MBAM Log:

    I'm a little confused as to why those files were detected as viruses... they aren't.
     
  2. 2009/12/30
    soxfan93

    soxfan93 Inactive Thread Starter

    Joined:
    2009/12/29
    Messages:
    26
    Likes Received:
    0
    Okay, problem. Windows crashes after about 3 minutes worth of a GMER scan. Should I try Safe Mode?
     

  3. to hide this advert.

  4. 2009/12/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    My bad. You can skip GMER. It was run, when you ran Combofix.
     
  5. 2009/12/30
    soxfan93

    soxfan93 Inactive Thread Starter

    Joined:
    2009/12/29
    Messages:
    26
    Likes Received:
    0
    Oh, okay. So go to HijackThis?
     
  6. 2009/12/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Yes, please.
     
  7. 2009/12/30
    soxfan93

    soxfan93 Inactive Thread Starter

    Joined:
    2009/12/29
    Messages:
    26
    Likes Received:
    0
    I know you said to uninstall Avira, but it's not letting me... I can't find a way to uninstall it: there's no uninstaller file, it's not in the uninstall program list in the control panel, etc.

     
    Last edited: 2009/12/30
  8. 2009/12/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    It looks like files are gone and we're dealing with some leftovers.
    We'll remove them manually. Hold on there.
     
  9. 2009/12/30
    soxfan93

    soxfan93 Inactive Thread Starter

    Joined:
    2009/12/29
    Messages:
    26
    Likes Received:
    0
    Okay. I want to thank you so much for helping me out. I couldn't do it alone. :)
     
  10. 2009/12/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please download JavaRa to your desktop and unzip it to its own folder
    • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
    • Accept any prompts.
    • Open JavaRa.exe again and select Search For Updates.
    • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.

    Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

    ================================================================

    Unless you installed Viewpoint Manager knowledgeably...
    Go Start>Control Panel>Add\Remove (Programs and Features in Vista), and...
    Uninstall any of the following programs associated with Viewpoint:
    * Viewpoint Manager
    * Viewpoint Media Player
    * Viewpoint Toolbar
    This program does not do anything bad such as deliver ads or spy on you, but it is considered foistware ( "drive-by-install ") as it is installed without your consent through programs like AOl, AIM, Compuserve, etc.

    ===============================================================

    Uninstall Ask.com through Programs & Features (if present).

    ================================================================

    Print this post out, since you won't have an access to it, at some point.

    1. Open HijackThis.

    2. Close all windows, except for HijackThis.

    3. Put checkmarks next to the following HijackThis entries:

    - O2 - BHO: (no name) - {465E08E7-F005-4389-980F-1D8764B3486C} - (no file)
    - O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    - O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    - O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min



    4. You should also checkmark following entries (these are unnecessary startups; no actual programs will be removed):

    - O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
    - O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
    - O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
    - O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll



    5. Click on Fix checked button.

    6. Go Start>Run (Vista users - "Start search "), type in:
    cmd
    Click OK (Vista users - hold CTRL, and SHIFT keys, press Enter).

    Command Prompt window will open.
    Type in:
    sc stop AntiVirSchedulerService
    Press Enter.
    Wait for the service to be stopped.

    Type in:
    sc delete AntiVirSchedulerService
    Press Enter.
    Wait for confirmation.

    Repeat same set of two commands (sc stop, and sc delete), replacing AntiVirSchedulerService with AntiVirService.

    7. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to Show hidden files, and folders.

    8. Delete following files/folders (if present):
    - Ask.com and Avira folders from C:\Program Files
    Note. If deletion doesn't work, attempt it in Safe Mode - restart computer, and keep tapping F8 key, until menu appears.

    9. Restart computer.

    10. Post new HijackThis log.
     
  11. 2009/12/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You're very welcome :)
     
  12. 2009/12/30
    soxfan93

    soxfan93 Inactive Thread Starter

    Joined:
    2009/12/29
    Messages:
    26
    Likes Received:
    0
    Here's the newest HijackThis log.

    Also, is there a reason why I now have a C:\ProgramData folder? I don't think that folder was ever there before.

     
  13. 2009/12/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    It's a hidden folder and you see it now because of:
    You can re-hide it, if you wish.

    Other than that....


    Your computer is clean :)

    1. Download Temp File Cleaner (TFC)
    Double click on TFC.exe to run the program.
    Click on Start button to begin cleaning process.
    TFC will close all running programs, and it may ask you to restart computer.

    2. Turn off System Restore:

    - Windows XP:
    1. Click Start.
    2. Right-click the My Computer icon, and then click Properties.
    3. Click the System Restore tab.
    4. Check "Turn off System Restore ".
    5. Click Apply.
    6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
    7. Click OK.
    - Windows Vista:
    1. Click Start.
    2. Right-click the Computer icon, and then click Properties.
    3. Click on System Protection under the Tasks column on the left side
    4. Click on Continue on the "User Account Control" window that pops up
    5. Under the System Protection tab, find Available Disks
    6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C: ")
    7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
    8. Click OK

    3. Restart computer.

    4. Turn System Restore on.

    5. Make sure, Windows Updates are current.

    [SIZE= "4"]6. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately![/SIZE]

    7. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    8. Run defrag at your convenience.

    9. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

    10. Please, let me know, how is your computer doing.
     
  14. 2009/12/31
    soxfan93

    soxfan93 Inactive Thread Starter

    Joined:
    2009/12/29
    Messages:
    26
    Likes Received:
    0
    It still won't let me into the Security Center in my Control Panel. Is there something else that I need to do?
     
  15. 2009/12/31
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    What happens when you try?
     
  16. 2009/12/31
    soxfan93

    soxfan93 Inactive Thread Starter

    Joined:
    2009/12/29
    Messages:
    26
    Likes Received:
    0
    Nothing, it just doesn't open.
     
  17. 2009/12/31
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Go Start> "Start search ", type in:
    WSCUI.CPL
    Hold SHIFT and CTRL, press Enter.
    Will it open?
     
  18. 2009/12/31
    soxfan93

    soxfan93 Inactive Thread Starter

    Joined:
    2009/12/29
    Messages:
    26
    Likes Received:
    0
    No. And there's still an Avira AntiVir Personal selection under the Security tab in the CP.
     
  19. 2009/12/31
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Go Start> "Start search ", type in:
    services.msc
    Press Enter.

    In services list, find Security Center service.
    See, if it's running and if it's set to automatic start.
     
  20. 2009/12/31
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
  21. 2009/12/31
    soxfan93

    soxfan93 Inactive Thread Starter

    Joined:
    2009/12/29
    Messages:
    26
    Likes Received:
    0
    I don't even see Security Center. Closest I see is Security Accounts Manager.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.