ContextTool Removal Help Needed

Discussion in 'Malware Help (A Specialist Will Reply)' started by her00pala, Nov 21, 2007.

  1. her00pala

    her00pala Private E-2

    I had a security screen pop up yesterday that looked like it was a Norton screen which asked me to install a piece of software which is stupidly did. Now I get continuous (real) Norton Security warnings for a variety of malware, continuous popups in IE and a little box that pops up on the bottom right corner of my screen that says "Ad Served by ContextTool".

    Any ideas? I've run several scans with Norton, Adaware, Spybot with no positive results.

    I've attached my HijackThis txt file.

    Thanks in advance for your help.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. her00pala

    her00pala Private E-2

    My apologies for not following the instructions posted. I've now gone through all of the step and have my logs attached. Thanks in advance for your help.
     

    Attached Files:

  4. her00pala

    her00pala Private E-2

    The remainder of my log files.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still didn't. ;) You ran the older much longer procedure instead of click on the link I gave you in my first message. It would have save you a lot of time by just click on the link I gave to you. :) Don't worry about it now, we will just work from what you have already posted. I'll post a fix as soon as I finish going thru your logs.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you seem to have missed two important parts of the procedure. First in step 0 of the READ ME we specify not to use MSconfig to control startups. We stated that you must be in normal startup mode. You are in selective startup mode. Because of this, some of your problems may not be fixed in this first fix given below. Please get into normal startup mode now. Also you did not do all of what was requested in step 2. You are still hiding system files and also file extensions. Please complete this step now.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.
    Uninstall the CounterSpy trial program now since we are finished with it.

    Also uninstall the below software:
    J2SE Runtime Environment 5.0 Update 5
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_07
    SearchAssist <-- should have been uninstalled in step 0 of the READ ME

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/first_usage&s=sUE65T99vWPHteTEASdEGSvQxO8
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {200D0AAD-71B1-51C9-DDB0-092BA4662A54} - C:\Program Files\Boetzjad\wlluxjkv.dll (file missing)
    O2 - BHO: (no name) - {6AA3809C-6261-456F-8FCA-43FE39ADC5E9} - (no file)
    O2 - BHO: {d77b9cfa-9a9d-ed2a-c884-6816ffd0253c} - {c3520dff-6186-488c-a2de-d9a9afc9b77d} - C:\WINDOWS\system32\chgwvisk.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [2482596e] rundll32.exe "C:\WINDOWS\system32\tqqbreii.dll",b
    O16 - DPF: {00906302-0F14-442C-B39C-275F61BC25BC} (atSdaCfg Control) - file://D:\autorun\atSdaCfg.CAB
    O16 - DPF: {4E8AEBE0-31A6-43B0-A429-748DB14A70A0} (SysEngW2k Control) - file://D:\autorun\PC-CONFIG-CHECK.CAB
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://dealer.webex.com/client/T25L/webex/ieatgpc.cab
    O20 - Winlogon Notify: qommkih - qommkih.dll (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!
     
    Last edited: Nov 24, 2007
  7. her00pala

    her00pala Private E-2

    Got through everything and it seemed to go smoothly. My apologies again for taking the long route instead of the shortcut - I think I've hit panic mode (work computer). When I restarted after executing Avenger, I still got a security warning for Ezula. There haven't been any popups while in your site however. I've attached the first 3 files. Thanks - Lisa
     

    Attached Files:

  8. her00pala

    her00pala Private E-2

    Avenger file.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay some of your problems have mutated and spread. This could be due to reboots inbetween your posting logs and then getting my fixes. And it could also be doue to having been in selective startup mode like I had stated. This time after you complete my fix and you post the new follow up logs, DO NOT reboot or power down your PC. Keep it running until you here back from me.


    You still did not do step 2 of the READ ME!!! Please do it now.

    Did you run ATF-Cleaner properly last time? Did you select all check boxes? You Windows Temp folder did not get cleaned. Make sure you use the Select All option this time.


    There is also a chance that Windows Defender is getting in our way. So let's disable Windows Defender's realtime protection.

    To Disable Windows Defender:
    • Open Windows Defender
    • Click Tools
    • Click General Settings
    • Scroll down to Real Time Protection Options
    • Uncheck Turn on Real Time Protection (recommended)
    • Close Windows Defender
    Once your log is clean you can re-enable Windows Defender Real Time Protection.


    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {158A95B4-1F79-3B06-78BF-0424CDB17C2E} - C:\Program Files\Qduweegn\dvsqcyce.dll
    O4 - HKLM\..\Run: [vedmpwvu] rundll32.exe "C:\Program Files\qvqdupyb\gzwrqryx.dll",Init
    O4 - HKLM\..\Run: [hqpotcze] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\hqpotcze.dll"
    O4 - HKLM\..\Run: [olqnmtwr] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\olqnmtwr.dll"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKCU\..\Run: [Tair] "C:\DOCUME~1\LISA~1.VAN\MYDOCU~1\DOBE~1\ati2evxx.exe" -vt yazb

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt

    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!
     
  10. her00pala

    her00pala Private E-2

    OK, hopefully I have everything covered this time. I ran the ATF-Cleaner as instructed last time. So far no security warnings and no pop ups.
     

    Attached Files:

  11. her00pala

    her00pala Private E-2

    last log file
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You ran the wrong copy of HijackThis this time. Delete the below copy:

    C:\Documents and Settings\lisa.vance\Desktop\analyse.exe

    In the future, only run the one at C:\Program Files\HijackThis\analyse.exe

    What is in the below folder that does not want to delete?
    C:\WINDOWS\system32\tnrtmwuk


    Manually delete the below file:
    C:\Program Files\lflukjxo.txt

    Also delete the below files in your Windows Temp folder:
    Code:
    ":\WINDOWS\Temp\
    E-CENT~1      Oct 18 2007              "E-CENTER_PLUGIN_CDBURNER_U"
    hpzids.log    Oct 19 2007        2283  "HPZIDS.log"
    mpsigs~1.log  Nov 21 2007        6220  "MpSigStub.log"
    perfli~3.dat  Sep 28 2007       16384  "Perflib_Perfdata_2b8.dat"
    qtinst~1.log  Nov 20 2007         603  "QTInstallCode.log"
    remova~1.bat  Nov 19 2007          43  "removalfile.bat"
    SLU4230.TMP   Nov 23 2007              "slu4230.tmp"
    slu427b.tmp   Nov 23 2007     5291994  "slu427b.tmp"
    t30deb~1.txt  Nov 24 2007           0  "T30DebugLogFile.txt"
    v51nbn7i.tmp  Oct 31 2007      616448  "v51nbn7i.TMP"
    win134.tmp    Nov 20 2007         627  "win134.tmp"
    winad.tmp     Nov 19 2007         627  "winAD.tmp"
     
  13. her00pala

    her00pala Private E-2

    I've attached a directory listing for the folder it doesn't want to delete. I also ran hijackthis again and attached the log.
     

    Attached Files:

  14. her00pala

    her00pala Private E-2

    I also deleted the items from my Windows/Temp folder and the txt file from my Program Files folder.
     
  15. her00pala

    her00pala Private E-2

    Was looking at the items in the tnrtmwuk folder that won't delete: it looks like all of the graphics that were included in the original security screen (that looked like a Norton screen) that started this whole problem.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does any of this look familiar to you? If not, delete all the files in that folder. Then see if you can delete the folder. Let me know.
     
  17. her00pala

    her00pala Private E-2

    I deleted the folder, rebooted and it was there again after reboot.+
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run the below and attacht he requested log:

    Running GMER to detect rootkits


    Download this file - combofix.exe
    1. Double click combofix.exe & follow the prompts.
    2. When finished, it will produce a log ( C:\combofix.txt ) for you. Attach this log to your next reply See: HOW TO: Attach Items To Your Post
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    4. the ComboFix log
    5. and don't forget the GMER log
    Make sure you tell me how things are working now!
     
  19. her00pala

    her00pala Private E-2

    Ran GMER (log attached). Ran combofix and it looked like it ran through all of the stages then went to a screen that said "preparing log file". I left it overnight and a log file was never produced. I've also attached the other requested logs.

    I'm back at work this morning and haven't had any security screens or pop ups yet today. So far so good.
     

    Attached Files:

  20. her00pala

    her00pala Private E-2

    hijackthis.log
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Shut down Symantec and also disable Windows Defender (see below) and then try running ComboFix again.

    Disable Windows Defender:
    • Open Windows Defender
    • Click Tools
    • Click General Settings
    • Scroll down to Real Time Protection Options
    • Uncheck Turn on Real Time Protection (recommended)
    • Close Windows Defender
    Once your log is clean you can re-enable Windows Defender Real Time Protection.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also try the below but if ComboFix runs properly it may remove all of this. Run the below though, even if ComboFix runs and produces a log.
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. ShowNew
    3. HJT
     
  23. her00pala

    her00pala Private E-2

    I got a log for combofix this time. It is attached. The first time I ran it, my computer rebooted on its own. This time, it did not.
     

    Attached Files:

  24. her00pala

    her00pala Private E-2

    avenger, atf-cleaner & hijackthis files.
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are the below items from something you installed?

    O4 - HKLM\..\Run: [sda] "C:\Program Files\sda\bin\sprtcmd.exe" /P sda
    O23 - Service: SupportSoft Repair Service (sda) (tgsrvc_sda) - SupportSoft, Inc. - C:\Program Files\sda\bin\tgsrvc.exe

    Other than the above which I question, things look good now.
     
  26. her00pala

    her00pala Private E-2

    I don't recall installing anything similar.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then let's remove this.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to SupportSoft Repair Service (sda)
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pastetgsrvc_sda into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Now re-run HijackThis (select Do a system scan only) and select the following lines (the O23 line should be gone already) but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [sda] "C:\Program Files\sda\bin\sprtcmd.exe" /P sda
    O23 - Service: SupportSoft Repair Service (sda) (tgsrvc_sda) - SupportSoft, Inc. - C:\Program Files\sda\bin\tgsrvc.exe

    After clicking Fix, exit HJT.

    The reboot and after reboot, delete the below folder if it exists.
    C:\Program Files\sda

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. ShowNew
    2. HJT


    Make sure you tell me how things are working now!
     
  28. her00pala

    her00pala Private E-2

    disabled sda - ran hjt twice - 023 line was gone - deleted sda folder
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  30. her00pala

    her00pala Private E-2

    So far so good . . . seems to be gone. Whew! I don't know what I would have done without your help. I appreciate the amount of time and the value of your information and instructions so much. Now I can finally get back to work! Thanks again for all of your help.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds