Author Topic: Recurring worm?  (Read 18535 times)

0 Members and 1 Guest are viewing this topic.

BigTree

  • Guest
Re: Recurring worm?
« Reply #15 on: December 16, 2009, 01:35:45 AM »
Here is the log of the scan done in the quarrantine: folder......

Scanning of selected files
------------------------------------------------------------------------------------------
Program will try to scan 1 selected file(s) in the Chest

Move files to temporary folder: C:\Users\Earl\AppData\Local\Temp\_avast4_\unp13986436.tmp
FileID: 0000000006  Original file name: C:\Users\Earl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\23P2M67H\newer[1].htm  New folder: C:\Users\Earl\AppData\Local\Temp\_avast4_\unp13986436.tmp\6.htm

Scan files in the temporary folder: C:\Users\Earl\AppData\Local\Temp\_avast4_\unp13986436.tmp
C:\Users\Earl\AppData\Local\Temp\_avast4_\unp13986436.tmp\6.htm  HTML:IFrame-KT [Trj]
------------------------------------------------------------------------------------------
Action was completed successfully!

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: Recurring worm?
« Reply #16 on: December 16, 2009, 08:58:04 AM »
You could try this - you will need to download defraggler, so may have to do so on different clean computer and transfer to your system with a flash drive. So take adequate precautions to prevent virus spread through flash drive having been connected to yr computer.

http://www.filehippo.com/download_defraggler/

Anyways, once defraggler set up and is running, click Analyze for a reading of your system drive (Drive C: - for most people)

This should bring the difficult file to surface - click View Files  and look under Filename column for the file.
(screenshot shows files in Content.IE5 on this computer highlighted by red arrows - I will choose file 'prototype [1].js' as my example)

If the file is located, rightclick the file and choose Open Containing Folder.
This will give you a tree hierarchy of your computer in a left hand pane and the files contained in the Folder in a right hand pane. (next screenshot shows file and containing folder in red circles with a red line connected the two. You will now be able to take action)

I have found this method to be one of the best ways to search for files that are contained in Content.IE5 location.

I'm sending this through from a clients computer, so now I continue to clean up his system. This folder 7AI3X128 can be deleted as it it superfluous to the smooth running of the system.


Edited post -
« Last Edit: December 16, 2009, 09:17:07 PM by mkis »
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

BigTree

  • Guest
Re: Recurring worm?
« Reply #17 on: December 16, 2009, 11:48:55 PM »
Response to the above post....more stuff learned.
Using the above method I was able to locate the Content.IE5 folder and delete all the folders under it except one....33G7C990. I was not able to delete that folder because the system said that a file in that folder was in use by another program. I entered that folder and was able to delete all files but one.....IPADDRESSD[1].HTM.
Again the system says the file is in use by another program. There were no user programs running but the file browser. This is the same file that shows up in the Avast logs. The mystery continues.....

BigTree

  • Guest
Re: Recurring worm?
« Reply #18 on: December 17, 2009, 12:10:42 AM »
Further to above.....
If I use the cmd prompt and navigate to Content.IE5, a DIR command finds nothing.

YoKenny

  • Guest
Re: Recurring worm?
« Reply #19 on: December 17, 2009, 12:16:47 AM »
Just run CCleaner and it will clean out IE's Temp files:
CCleaner v2.26.1050 - Slim
- No Toolbar
http://www.ccleaner.com/download/builds

BigTree

  • Guest
Re: Recurring worm?
« Reply #20 on: December 17, 2009, 12:40:52 AM »
I have tried CC Cleaner and it will not remove \Content.IE5\33G7C990\IPADDRESSD[1].HTM
I can find no way to remove that folder/file.

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: Recurring worm?
« Reply #21 on: December 17, 2009, 12:46:14 AM »
hmm. I thought you might target the difficult file and post back before deleting files. But should be okay. I don't delete all files under Content.IE5 but anything that is express needed can be returned by Restart and reconnect. Are you still getting alerts or warnings from avast? If everything otherwise normal, I wouldn't bother trying to improve anything just run the system for a while and see how go.

PS - Make sure empty Recycle bin
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

BigTree

  • Guest
Re: Recurring worm?
« Reply #22 on: December 17, 2009, 01:28:02 AM »
I have been empying the recycle bin every time I delete something just in case. The problem is stlii there.
I have tried to post a screen capture of the Avast warning as an attachment.

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: Recurring worm?
« Reply #23 on: December 17, 2009, 02:04:16 AM »
See if you can locate difficult file again and this time upload to virustotal

http://forum.avast.com/index.php?topic=52222.msg442296#msg442296

This tool may help

http://forum.avast.com/index.php?topic=19387.msg442474#msg442474

Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

BigTree

  • Guest
Re: Recurring worm?
« Reply #24 on: December 17, 2009, 04:49:37 AM »
File uploaded to VirusTotal and it found nothing. It is happening more often now, maybe once an hour. If I restart my computer with wifi turned off it is fine. Within 5 minutes of turning wifi on I get the first attack, even if I have run no web browser or email.

jeffj4873

  • Guest
Re: Recurring worm?
« Reply #25 on: December 17, 2009, 05:07:51 AM »
Trouble with worms is Avast needs to run the hard drive scan before windows comes up. You almost can kill a worm in windows

jeffj4873

  • Guest
Re: Recurring worm?
« Reply #26 on: December 17, 2009, 05:21:58 AM »
one thing that helped me deal with malware and a worm together was to go to system in control panel and under advanced, and then performance is data execution prevention. Turn on DEP for ALL programs. Best way to contain a replicating virus or malware. Like I said above, you need Avast to do that Boot scan to kill a worm, But I am not sure How to do that.

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: Recurring worm?
« Reply #27 on: December 17, 2009, 05:33:23 AM »
You have tried a bootscan haven't you Big Tree? If not, here is guide.
I think always best with System Restore turned off. So check status of you're System Restore and reply post here first.

Perhaps, if first time through, run boot scan with System Restore on and we see what comes up.

  
Here is guide --

right click icon in system tray lower right hand corner of screen--choose to Start avast!
--scanner comes on screen – right-click body of scanner - choose Schedule boot time scan

To run boot scan ---set thorough---check archive---select move to chest ---check allow move
Restart

Reply post outcome to forum
« Last Edit: December 17, 2009, 05:35:01 AM by mkis »
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

jeffj4873

  • Guest
Re: Recurring worm?
« Reply #28 on: December 17, 2009, 05:39:57 AM »
Thanks Mkis, I wasn't sure how to force a boot scan. That is what he has to do to kill a Worm or Trojan. :)

micky77

  • Guest
Re: Recurring worm?
« Reply #29 on: December 17, 2009, 06:24:30 PM »
Further to above.....
If I use the cmd prompt and navigate to Content.IE5, a DIR command finds nothing.

Try showing ' hidden files' and unchecking ' hide protected system files '
Vista
    * Right Click Start
    * Select Explore
    * Select Organize
    * Select Folder and Search Options
    * Select the View tab
    * Under the Hidden files and folders heading select Show hidden files and folders.
    * Uncheck the Hide extensions for known file types option.
    * Uncheck the Hide protected operating system files (recommended) option.
    * Click yes to confirm that you really want to do this.
    * Click Apply
    * Click OK
Then reboot in safe mode by tapping f8 key, then go to Content.IE5 folder and delete contents
« Last Edit: December 17, 2009, 07:03:12 PM by micky77 »