Malware removal help

Discussion in 'Malware Help (A Specialist Will Reply)' started by lilgj925, Mar 13, 2007.

  1. lilgj925

    lilgj925 Private E-2

    hi I did all the steps as stated in the read & run me first sticky and still have malware on my computer. I know for sure that virtumonde and smitfraud are still on my computer as they still keep coming up, and now i get a message at startup saying that my explorer.exe doesn't work. Attached are all the logs that I got from running the read and run me first antispyware programs. Thanks for any help.
     

    Attached Files:

  2. lilgj925

    lilgj925 Private E-2

    here are more of the logs..
     

    Attached Files:

  3. lilgj925

    lilgj925 Private E-2

    and..
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please always attach current logs! You logs are all out of date and do not reflect the current status of your system. And they were obtained in the wrong order too. HJT should be the very last log obtained and yours was obtained before BitDefender, Panda, GetRunKey, ShowNew, and VundoFix. Also you need to use the current version of ShowNew. Yours is out of date.

    Also only attach the logs we requested. mp4debug.log, debug.log, and SBCSTray.log have nothing to do with anything from the READ ME.

    You also need to uninstall the below 6 old versions of Sun Java as requested in step 6 of the READ ME. Do this now!
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 3
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 8
    J2SE Runtime Environment 5.0 Update 9


    So here is what I want you to do. Get new logs from the below and attach them (run them in the given order):
    • CounterSpy (you never attach this the first time as requested)
    • GetRunKey
    • ShowNew - download the current version first!!
    • HijackThis
    Why are you running without an antivirus program and without a true firewall?
     
  5. lilgj925

    lilgj925 Private E-2

    These should be the newest logs. I repeated the read and run first steps and dled the version of shownew that was posted there. I also deleted all the old java versions.
     

    Attached Files:

  6. lilgj925

    lilgj925 Private E-2

    And this is the latest HJT log. I wasnt sure how to get a log from counterspy so i just copy pasted what you said into a txt file. Thanks.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)
    Also make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of awtsq.dll once and then click the kill button. After you have killed all of the awtsq.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    rqronkh.dll
    sstqp.dll

    Next double click on explorer.exe and again click once on each instance of awtsq.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    rqronkh.dll
    sstqp.dll

    Next double click on iexplore.exe and again click once on each instance of awtsq.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    rqronkh.dll
    sstqp.dll

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {0AC86528-D8A3-4F10-9627-73F7FF2C291F} - C:\WINDOWS\system32\ssttq.dll (file missing)
    O2 - BHO: (no name) - {5D6C8168-AA6D-4CCB-B23F-646CB5F366CD} - C:\WINDOWS\system32\ddayw.dll (file missing)
    O2 - BHO: (no name) - {6B3E9D13-B300-426D-89F5-AC5DC578F172} - C:\WINDOWS\system32\awtsq.dll
    O2 - BHO: (no name) - {7F43CCEB-2B4D-44DD-B184-87FBD55D1920} - C:\WINDOWS\system32\awvts.dll (file missing)
    O2 - BHO: (no name) - {93F8AD63-8177-45A9-8E89-FEA279BCC6A8} - C:\WINDOWS\system32\sstqp.dll (file missing)
    O2 - BHO: (no name) - {9FEB8477-CA3A-4FC1-B9F0-1BF6BE1A8457} - C:\WINDOWS\system32\jtpibbeb.dll
    O2 - BHO: (no name) - {D38439EC-4A7F-42b4-90C2-D810D7778FDD} - C:\WINDOWS\system32\aukbnlwa.dll
    O2 - BHO: (no name) - {E51B9A9B-65D3-4ADD-86BF-FF5520F6D563} - C:\WINDOWS\system32\jtpibbeb.dll
    O2 - BHO: (no name) - {FEFC208F-4C1F-464C-A989-36F1C0D9FD20} - C:\WINDOWS\system32\rqronkh.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Winsystem] C:\WINDOWS\system32\winsystem16.exe
    O4 - HKLM\..\Run: [2chkdsk] rundll32.exe "C:\WINDOWS\system32\dgqllsnk.dll",setvm
    O4 - HKLM\..\RunServices: [Winsystem] C:\WINDOWS\system32\winsystem16.exe
    O20 - Winlogon Notify: awtsq - C:\WINDOWS\system32\awtsq.dll
    O20 - Winlogon Notify: rqronkh - C:\WINDOWS\SYSTEM32\rqronkh.dll
    O20 - Winlogon Notify: sstqp - C:\WINDOWS\system32\sstqp.dll (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\awtsq.dll
    C:\WINDOWS\system32\jtpibbeb.dll
    C:\WINDOWS\system32\aukbnlwa.dll
    C:\WINDOWS\system32\jtpibbeb.dll
    C:\WINDOWS\system32\rqronkh.dll
    C:\WINDOWS\system32\winsystem16.exe
    C:\WINDOWS\system32\dgqllsnk.dll
    C:\WINDOWS\system32\sstqp.dll
    C:\WINDOWS\system32\exec1.exe
    C:\WINDOWS\system32\khxjojeo.exe
    C:\WINDOWS\system32\uuqabusl.exe
    C:\WINDOWS\system32\ddcyaxv.dll
    C:\WINDOWS\system32\ralbyaer.dll
    C:\WINDOWS\system32\tuvvuts.dll
    C:\WINDOWS\system32\votasnjr.dll
    C:\WINDOWS\system32\pqtss.bak1
    C:\WINDOWS\system32\qstwa.bak1
    C:\WINDOWS\system32\pqtss.tmp
    C:\WINDOWS\system32\knsllqgd.ini
    C:\WINDOWS\system32\pqtss.ini
    C:\WINDOWS\system32\qstwa.ini
    C:\WINDOWS\system32\uwthxbpl.ini
    C:\WINDOWS\system32\vrsydmct.ini
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete if found:
    C:\Program Files\VSAdd-in

    Now please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  8. lilgj925

    lilgj925 Private E-2

    Here are the new logs I deleted the vsadd-in folder in the program files and have not yet rebooted my computer. I will wait fo your response to reboot so that i can fix the system restore stuff in the read & run first sticky. Let me know if there is anything else I should do.

    arghh.. i had a helluva time trying to attach the files to this post for some reason the manage my attachments option wasn't there, so i just kept restoring my firefox session until it did. I also got an error closing my session and prompting me to install some kind of firefox support software or something. Might be nothing but I thought Id let you know.

    Thanks so much for the help and quick response time!
     

    Attached Files:

  9. lilgj925

    lilgj925 Private E-2

    as an update I still havent rebooted yet, so that I can find out whether or not I am malware free and if i need to disable system restore or not. But while i was waiting i ran spybot and ad-aware. ad-aware detected 2 critical problems that i deleted and spybot detected 3 things, one was smitfraud toolbar, one was win.. something and i think the other was ust a cookie. hope this helps.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\CounterSpy

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {9FEB8477-CA3A-4FC1-B9F0-1BF6BE1A8457} - C:\WINDOWS\system32\jtpibbeb.dll (file missing)
    O2 - BHO: (no name) - {D38439EC-4A7F-42b4-90C2-D810D7778FDD} - C:\WINDOWS\system32\aukbnlwa.dll (file missing)

    Now quickly look at a new HJT scan and make sure the above lines were fixed. Let me know the results.

    After clicking Fix, exit HJT.


    You need to get an antivirus and firewall install ASAP. This is covered in the link give below.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  11. lilgj925

    lilgj925 Private E-2

    I did everything you said in the last post as well to fix my system restore. But, I am worried about one thing; I rebooted into safemode after I did all your steps and decided to run ad-aware, ccleaner, and spybot one last time just to be safe. nothing came up in ad-aware, but in spybot it showed that I still had smitfraud toolbar on my computer. I clicked to fix the problem and am now running in normal mode. My computer appears okay, but I am just worried because I heard that smitfraud is hard to get rid of.

    For right now my computer appears to be running smoothly and I havent had any pop-ups or anything, so unless what I stated above is a problem I think you may have fixed the problem. Either way thanks soo much for getting my machine to run properly and for all the help!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Run Spybot again and attach a log if it shows this tool bar again.
     
  13. lilgj925

    lilgj925 Private E-2

    Okay, hopefully this will be the last update :). I installed avast and zonealarm ala your instructions. They don't seem to be hogging resources so I dont mind them running in the background :) Anyway I think I am clean and zonealarm has already blocked 3 intrusions to my computer. The reason i wanted to update though is because my internet explorer and windows service pack 2 cannot be updated, so I'm not sure if that is the reason why my computer may be compromised. I tried to update my explorer but my software doesnt pass the windows genuine validation to let me upgrade. Also, it says that I have service pack 2, but my computer doesnt recognize all 250gb of my hd, only 127, and my friend said that is because i'm not upgraded to service pack 2 and I have to partition my hd. Any input on this would be greatly appreciated. sorry if this isnt malware related, but I read the post on not being fully upgraded with the Microsoft updates and I was wondering if that is how I got infected. Again thanks for any help, and thanks again to Chaslang for all the help.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You already have SP2. Whether you have all of the updates from Microsoft or not, I don't know. If your copy of Windows XP is not valid (i.e, valid licensed to you copy of Windows XP) then you cannot get updates from Microsoft. If it is a valid copy, you will have to speak to Microsoft about why you cannot be validated. There have been many many problems over the last few years with Windows Update not working. A few were due to malware but most were not.

    All of the remaining items you mentioned are not topics for this forum. You should discuss your Windows Update issue with Microsoft and your issue with your harddisk in the hardware or software forum. Problems recognizing full harddisk size can also be related to your system BIOS.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds