Help removing virus and malware.

Discussion in 'Malware Help (A Specialist Will Reply)' started by whatever55, Oct 8, 2006.

  1. whatever55

    whatever55 Private E-2

    I keep getting these pop ups everytime my Internet explorer is open, sometimes it pops on my screen and sometimes it just runs in the background eating up my resources. I ran an antivirus scan with avg but nothing showed up, and then I did ad-aware scan, removed some cookies and tracker cookies. Later on ran house micro trend online virus scanner cos the problem persisted and it detected these uncleanable files :

    - yazzle1281oinadmin.exe Troj PuritySC.AC
    - ssqnmkh.dll Troj ADCLICK.CD
    - eim03.exe TSPY DYFUCA.BB

    After all that, one of my friends suggested this website so I registered and ran all the scans and programs you mention in the thread dealing with removal of malware. The problem still persists, I am not even sure what exactly it is trojan or some adware or what. I was hoping you could help me fix this problem. I am attaching all the said logs along with this post and I would be really greatful if you could help me fix this problem.
     

    Attached Files:

  2. whatever55

    whatever55 Private E-2

    Also, here is the "hijackthis", runkey, newfiles log.
     

    Attached Files:

  3. whatever55

    whatever55 Private E-2

    Err, are these forums active? If I missed something any log let me know, I ll post it, but pls help !
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Your Windows OS version is way out of date and represents a major security risk. After we correct your malware problems you must get your updates.

    Please run this procedure Virtumonde aka Trojan Vundo Removal and then attach the requested log.

    Then attach new logs from HijackThis and ShowNew.
     
  5. whatever55

    whatever55 Private E-2

    Thank you so much for helping and god bless. I ran the vundofix.exe and attached with this post are the new logs.
     

    Attached Files:

  6. whatever55

    whatever55 Private E-2

    so, umm whats next step?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach the requested log from VundoFix!


    Start by downloading a tools we will need- Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later.

    Now Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 2
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 8
    Java 2 Runtime Environment, SE v1.4.1_011)

    Now Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)
    O2 - BHO: (no name) - {3C6B0D3C-43B0-482A-8DCF-1E27008D57A9} - C:\WINDOWS\System32\vtutt.dll (file missing)
    O2 - BHO: (no name) - {849B9523-785F-4014-9CAF-079FB4A74C61} - C:\WINDOWS\System32\mtqpelbi.dll (file missing)
    O4 - HKLM\..\Run: [septpop06apsept] C:\program files\popupwithcast\septpop06apsept.exe
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/17df3da9f321f9bcfd05/netzip/RdxIE601.cab

    After clicking Fix, exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\apvsitoq.dll
    C:\WINDOWS\system32\nsa11D.dll
    C:\WINDOWS\system32\nsl24.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    After reboot, also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\User\Local Settings\Temp

    Now attach a the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Oct 12, 2006
  8. whatever55

    whatever55 Private E-2

    I am so sorry, I probably missed that. I am attaching the vundo log here.

    Will complete the steps you listed in your post above and post all the logs asked for.

    Once again sorry about that, I somehow missed the vundo log.
     

    Attached Files:

  9. whatever55

    whatever55 Private E-2

    I ran all the steps posted above in your post. Attached with the post are the logs from HJT, shownew,getrunkey.

    I think the virus has been removed for the most part. Avg found no viruses today in its scan, and I dont see any more of those annoying pop ups. My computer seems to be running smomother as well.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We have a little more to do!

    Run Windows Explorer and locate the below and delete them:

    C:\Documents and Settings\User\Application Data\Dxcknwrd.dll
    C:\Documents and Settings\User\Application Data\SearchToolbarCorp <--- the whole folder

    Then run CCleaner!


    Then attach a new log from ShowNew.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    3. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and enable System Restore to create a new clean Restore Point.
    4. After doing the above, you should work thru the below link:
     
  11. whatever55

    whatever55 Private E-2

    Done with all the steps you listed, and here is the shownew log.

    Once again, thank you so much for helping out. God bless.

    EDIT : TYPO
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. You're log is clean now. Surf Safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds