Page 1 of 2 12 LastLast
Results 1 to 10 of 13

Thread: Please HELP - Think I Deleted Files Incorrectly

  1. #1
    Junior Member
    Join Date
    Jan 2009
    Posts
    10

    Unhappy Please HELP - Think I Deleted Files Incorrectly

    I was browsing the internet in Firefox (windows XP) and clicked on a link to another site but all of a sudden 10-12 new windows came up. I found through the cookies that I had adtrgt or something like that...

    I called the help desk at my work (since its my work laptop) but only the "extended" help is on during the weekends. They recommended AdAware and a co-worker recommended SpyBot. I downloaded SpyBot and ran it on the computer after a restart. It found a lot more stuff than I thought... and it also found two Virtumonde trojans.

    This is strange because I have had a virtumonde trojan on my home computer in the past and it was very noticeable. On my work computer I have noticed nothing. Also on my home computer I ran an .exe file which triggered the virus. I have no recollection of doing this on my work computer from any unreliable source.

    Anyway, I followed the cleanup suggested... I looked through the items they found and nothing (other than the Virtumonde) looked strange or unexpected.

    After the fix completed, SpyBot was asking me to "Allow Changes" or "Deny Changes" when deleting or adding some files from/to the system. I do not know what the files were for, but for deleting (first pop-up) I clicked allow, and for the next couple that were adding files, I clicked deny. I had no idea what these meant and they kept popping up so I just shut down the computer with an End Program to SpyBot.

    I restarted the computer and immediately when it got to the desktop I got a couple errors saying the dll was missing from a few of the folders where I deleted stuff. Then some black C prompt windows popped up. I just closed them but the Allow/Deny box came up again and I couldn't get rid of it. I tried to use IE6 and it worked fine (I uninstalled Firefox for the time being - plan to reinstall after this is all over).

    I am just wondering... should I do a system restore to whatever time is available before 4am this morning when I saw the pop-ups? I did do the back-up that SpyBot asked me to do before running the scan. I am just afraid to touch it at this point. I plan to ask my DLS service for help on Tuesday when I return to work but wondering if I completely damaged my system and they need to reinstall the operating system or if this can be fixed without any of that? Is there anything I can do in the meantime?

    Also, if there are any ideas on that weird Virtumonde appearing in the scan but no symptoms of the virus that would be helpful too..

    thanks!

  2. #2
    Senior Member drragostea's Avatar
    Join Date
    Jan 2008
    Location
    @Home
    Posts
    3,674

    Default

    Here's the problem, a domino effect.
    Let me explain. Virtumonde is a trojan not a virus. And your infection does not need to be an execution of a malicious .exe. It could be merely a drive-by-download. But your description about a "new 10-12 new windows" coming up, sounds very suspicious. I'm suspecting that they were ads or malicious banners.

    And I would suggest you disable TeaTimer (the prompts;Allow or Deny) if you are not familiar with it, because you were probably denying Spybot's attempts to remove the trojan. Usually the symptoms of a successful Virtumonde removal, would be a few prompts about startup items and a bad image of some .dll file missing. Then, I would suggest you allow all the changes, because Spybot successfully removed it.

    How is your work machine doing at the moment? And I would not suggest a system restore, because that might mean bringing back the trojan.

  3. #3
    Junior Member
    Join Date
    Jan 2009
    Posts
    10

    Default

    Hello,

    Thanks for the reply! I have not turned my machine back on since I posted here yesterday.

    The 10-12 new windows immediately popped up when I clicked on a link from one site to go to what I thought was another page in the same site, but obviously was not. The site did not appear shady at the time, but I guess I should have assumed it was... I was researching Chinese Astrology. I was also on a site that was #2 or3 from a google search.

    Anyhow, I just want to make sure I understand - it is the TeaTimer that is creating those pop-ups asking me to accept/deny? I am not familiar at all with TeaTimer but during the install I included it in the options to allow.

    Does this mean the Trojan is not completely gone? Its so strange because I had no other indicators... maybe the ads were part of the Trojan or something.

    I did DENY some of the attempts for SpyBot to "Add" files to the computer... I had no idea what was going on and why SpyBot wanted to add files. Should I just disable the TeaTimer, allow all the changes SpyBot wants to make, and try to run the SpyBot again to make sure there is nothing I missed in allowing/denying?

    What about those pop-ups I get that the dll is unavailable? They seem like system messages...

    I am really afraid to ruin my work's laptop... and remove things from the registry, etc. that I should not. There were definitely registry keys affected by the Trojan...

    Just as curiosity, with a system restore - I know deleted files (such as .doc, etc.) can't be retrieved but what about removed applications or registry keys that were removed... what is the point of system restore anyway?

    Thanks again!

  4. #4
    Junior Member
    Join Date
    Jan 2009
    Posts
    10

    Default

    Another thing - I wrote down the first request SpyBot or TeaTimer, which ever it was, made to me:

    Change: Value Deleted (the others said Value Added)
    Entry: CPM83b0daff
    Old Data: Rundll32.exe "c:\windows\system32\nuyajuk..

    And the small window wouldn't let me see the rest of the name, but when I rebooted the windows popping up as system messages told me it could not find the dll file in nuyajuk... whatever the rest of the name was...

  5. #5
    Senior Member drragostea's Avatar
    Join Date
    Jan 2008
    Location
    @Home
    Posts
    3,674

    Default

    Another problem here is that Spybot itself is not "adding" files but rather the Virtumonde trojan is. Spybot merely prompts you about what something is doing and what is happening.

    Like I said before, I would recommend that you disable TeaTimer, but you could possibly deny something good (like Spybot's attempt to remove the Trojan).

    What Virtumonde attempts to do on the infection machine is to download more garbage (malware components) and create random generated files and startup entries to ensure that it'll run everytime you boot up the machine.
    What Spybot is detecting is Virtumonde itself, not a false positive.

    And I wouldn't trust "Sponsored Ads" from Google, because a majority of the time it's not what they really say.
    Anyhow, I just want to make sure I understand - it is the TeaTimer that is creating those pop-ups asking me to accept/deny?
    Yes, that is Spybot-SD's Resident Shield.
    Does this mean the Trojan is not completely gone? Its so strange because I had no other indicators... maybe the ads were part of the Trojan or something.
    It is possible that it is removed by Spybot. Does Spybot still detect it?

    And to your second post, I would suggest you Allow that. This tells us that Spybot was able to remove Virtumonde and it's startup files (the trojan tends to startup when your machine boots).

    The prompts about a bad image or a unavailable .dll file (usually randomly named) is normal about a reboot. It should not reappear on the next reboot.
    Just as curiosity, with a system restore - I know deleted files (such as .doc, etc.) can't be retrieved but what about removed applications or registry keys that were removed... what is the point of system restore anyway?
    Not really... your documents remain unchanged. No documents are deleted. And they remain in the same place as they were last time.
    And for the removed applications, it could be possible that a uninstalled application would be brought back.

    The whole point of the System Restore is to bring your machine to an earlier state. So like if you're infected at one point, you can always take advantage of this feature. So it'll be like in a way you were never infected.

  6. #6
    Junior Member
    Join Date
    Jan 2009
    Posts
    10

    Default

    Ok I am starting my computer now...

    How do I disable the TeaTimer? I am not sure if SpyBot deleted all the Trojan since I have not run it again...

  7. #7
    Junior Member
    Join Date
    Jan 2009
    Posts
    10

    Default

    Ok I got two RUNDLL errors with a red circle and X inside...

    I just clicked OK...

    I went through the other questions and clicked Allow Changes on the Deletion of the files from the registry... the names were pretty weird so I think they must have been Trojan...

    It just finished and I am going to try to run SpyBot again... I also keep getting an error when I start SpyBot - it says:

    Spybot SD.exe - Unable to Locate Component
    Theis application has failed to start because framedyn.dll was not found. Re-installing the application may fix this problem.

    I click OK and then Spybot opens fine. I am going to try to uninstall and reinstall Spybot and see what happens...

  8. #8
    Junior Member
    Join Date
    Jan 2009
    Posts
    10

    Default

    On second thought... when I just tried to remove Spybot it reminded me that I had backed-up the PC... if I ever want to undo changes I will lose those... If you think that dll is not useful for the program to run accurately and successfully, I will keep using this version and install another one after I know this is working properly....

  9. #9
    Junior Member
    Join Date
    Jan 2009
    Posts
    10

    Default

    I have no disabled TeaTimer because I do not know how to or where it is.

    My scan is about 50% complete and the Spybot found 2 Virtumonde files.

    Here are the details:

    Virtumonde.prx (4 entries) - Last time there were 8 I think...
    all locations are Registry Values
    The CPM83b0daff is there again but I thought I allowed the delete.

    Virtumonde (1 entry) - Last time there were 2 or 4 I think...

    Do you recommend I just allow all the changes when the scan is finished?

    Thanks again!

  10. #10
    Junior Member
    Join Date
    Jan 2009
    Posts
    10

    Default

    So those two issues were the only ones found. I ran the fix and allowed the changes to delete. I am running a 2nd scan before reboot to make sure they were really gone. I will reboot and then run the scan again to make sure there isn't a start-up option somewhere that Spybot is not finding.

    Thanks!

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •