Desktop shortcuts won't go away

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by luciano991, May 22, 2007.

  1. luciano991

    luciano991 Private E-2

    Greetings,

    First I take the solemn oath that I have performed all required operations to the very best of my ability before submitting my problem. I had to substitute Counterspy for AVG because the AVG wouldn't update. I have attached the appropriate logs as I understand them to be. Please disregard any results for Drive J as that was my external drive that got scanned with C Drive.

    I have a Dell XPS running XP Professional with a Pentium D. When I boot I get an error message that says "error loading C:\Windows\awtstt.dll. Specified module could not be found. Three shortcuts appear on the desktop: Privacy Protector, Spyware and Malware Protector, Error Cleaner. All three are links to web addresses. A binking red triangle appears in the systray. After a time a message window appears saying that a trojan, adware.w32.expdwnldr has appeared on my system and urges me to click OK to download the software to fix it. Deleting the shortcuts removes them but the reappear on reboot as does the triangle and the trojan message.

    Again, I have attempted to follow all of your directions. I look forward to your reply.

    Luciano

    PS I have attached 3 logs. I will attach the others in a seperate post
     

    Attached Files:

  2. luciano991

    luciano991 Private E-2

    Re: Desktop shortcuts won't go away part 2

    Here are the other attachments you requested

    Luciano
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Desktop shortcuts won't go away part 2

    First please go back and complete step 2 of the READ ME properly. You did not follow the instructions for step 2 properly or completely.

    Also you can uninstall CounterSpy now!


    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    Now attach new logs from:
    • GetRunKey
    • ShowNew
    • HJT
    How are things working now?
     
  4. luciano991

    luciano991 Private E-2

    Thank you for your reply. I have now completed step 2 correctly and attached rapport.txt before proceeding to the next step.:eek::eek:

    I will send the second rapport.txt in a separate email along with the GetRunkey, ShowNew and HJT logs.

    Cheers,

    luciano
     

    Attached Files:

  5. luciano991

    luciano991 Private E-2

    Here is the rapport.txt, second edition, post cleaning in safe mode. Other three logs will be sent in 3d email.

    thanks

    luciano
     

    Attached Files:

  6. luciano991

    luciano991 Private E-2

    Here are the last three logs. The devil has apparently gone back in his hole. Everything looks great. Youse guys?gals are the very best. Thanks.

    Luciano
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    Not quite yet! ;)


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [WindowsService] rundll32.exe "C:\WINDOWS\awtstt.dll",realset
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O20 - AppInit_DLLs:

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\awtstt.dll

    Now run Ccleaner

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode

    Now attach a new HJT log.
    Make sure you tell me how things are working now!
     
  8. luciano991

    luciano991 Private E-2

    Hi,

    Better Late than never but here's the reply. Everything is working great now. You guys are the best.

    Luciano
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds