Bugged by ALQ.exe

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Oero, Aug 9, 2009.

  1. Oero

    Oero Private E-2

    Hello

    I downloaded a game today. Before I installed the game, I had it scanned by my AVG Free and my Zonealarm was also on. The scan results came up clean. I installed the game, shortly after my Zonealarm prompted me that a program called alq.exe was trying to access the internet. I blocked the access and I went to googled it to see what it was. This seems to be a rootkit?

    I ran my spybot, my AVG, and went to run Hosuecall at Trendmicro in that order. They all did not find the file alq.exe on my system. I went to the location of the file shown in Zonealarm c:/windows/common files/alq.exe

    The file was there but it had disappeared (it self deleted?) after some time. When I restart Windows XP, the process alq.exe is shown in my Windows Task Manager.

    I am attaching here a copy of my HiJackThis! log file. Please see if you can help. Thank you.

    p.s. After I made the HiJackThis! log file, I went to the Task Manager to end the alq.exe process, and I also cannot find the alq.exe file in my harddrive. But if I were to restart Windows XP, the Task Manager will again list it in the Processes.
     

    Attached Files:

  2. Oero

    Oero Private E-2

    I have finished running those scans specified in the Malware Removal guide.

    I was not able to run RootRepeal. When I went into the File tab and click Scan, the program would say 'it is initializing, please wait', but then my whole system will hang. Nothing happens that I can see for more than erm 2 mins? So I did not attach any RootRepeal log.

    I have disabled and re-enabled System Restore.

    I just checked from msconfig. There is no longer any listing to run alq.exe at Startup. I am hoping this means the infection is removed. If anyone still find traces of the infection from these log files, please post and I will check this thread as I monitor my situation.

    Thank you.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are basically clean, but we have some things you should do.

    First you really should not be using MSconfig as a startup manager. This was mentioned in the early steps of the READ & RUN ME.

    I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.


    Now run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - - (no file)
    R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

    After clicking Fix, exit HJT.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  4. Oero

    Oero Private E-2

    Thank you Chaslang

    Over the past week or so I am not seeing any visible abnormal pop-ups or programs asking to run.

    I will not be using MSconfig to manage my Startup. I just let it run everything. I only edited it to prevent alq.exe from running right away.MSconfig is now back to its default state.

    I am running SpyBot for protection. Is that program really good? MajorGeeks did not include that in their malware removal routine so I am checking. Also the teatimer. Since disabling it during malware removal, I have not yet re-enabled teatimer. Is there any good to using teatimer?

    I will work through your suggestions Chaslang. Thank you for your time :)
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you were not! At least not in your last logs. You were running AVG8, Windows Defender and ZoneAlarm for active protection. Thus you should not be using Teatimer anyway. That was even stated in the link given to you in my final instructions. AVG8 already has antispyware protection and so does Windows Defender (not too good but it does have protection).
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds