Problems with Trojan.dialer.pz and vtstt.dll, and just recovered from Trojan.nebuler.

Discussion in 'Malware Help (A Specialist Will Reply)' started by properbopeep, Jul 7, 2006.

  1. properbopeep

    properbopeep Private E-2

    Dear all

    Have been having some major problems with some viruses/malware. It all started when my NAV 2005 FW started to pop up with "Win##.temp.exe" is trying to access a DNS server". It creates a file in the \Windows\temp file each time it does this. This file soon fills up with 500 or so .tmp files.

    Since then, I get this message about every 5 mins. I have also noticed a vtstt.dll file as an IE7 addon, which keeps on crashing IE.

    Oddly, today the pop up Win.temp messages have stopped, although the \temp folder is still filling up with files (this makes me wonder has it found a way past NAV??). I also got a message saying NAV had picked up "Trojan.nebuler", which I think I have got rid off, (following directions of Symantecs site).

    In trying to get rid of these, I have run:

    Full NAV scan
    Ewido Spyware scan
    CCleaner
    ATF Cleaner
    AdAware SE Personal
    Spybot - search and destroy.

    Nothing seems to work. I have found an entry in the registry /Winlogon section that has vtstt in it - but am a bit concerned about just deleting this.

    I am tearing my hair out and thinking about a reformat !!! Would mean loosing a lot of important stuff and VERY time consuming.

    Any help would be greatly appreciated. I have HJT installed and have a log ready if someone needs it.

    Thanks

    BoPeep
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi and welcome


    Please scrap the HJT log you have already and follow the guide below as these steps will remove alot of the malware and issues you may have that HJT alone cannot do,

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis


    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
    • Bitdefender
    • Panda Scan
    • HijackThis
    .
     
  3. properbopeep

    properbopeep Private E-2

    Halo

    Many thanks for taking the time to reply. I will follow those instructions posted - and will get back to you. Unfortunately am away until Sunday night, so will be able to (hopefully) post back to you then.

    Appreciate your time.
    BoPeep
     
  4. properbopeep

    properbopeep Private E-2

    Halo

    ok - have run CCleaner, Ad-Aware, Spy-Bot S&D all in Safe Mode. No major problems detected here.

    Could get access to internet on safe mode (USB Modem didn't seem to be recognised - even when run with networking). So I ran Bitdefender, Panda scan and Defender in Normal mode.

    I am running IE7 Beta - and there is a problem with the vtstt.dll addon which keeps crashing IE as soon as I try to click on a link. This can be disabled through the "manage addon-options" but not permanently.

    So far - it would appear that the Trojan.dialer.pz has gone -as I am not getting warnings about this anymore and my Windows/temp file is not filling up with random files now.

    However - I still have this random vtstt.dll problem which I have also found in the Registry under the WinLogon part - is this something to be concerned about??

    Anyway- here are the logs in order you asked for:
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is a Virtumonde infections. Let's try the easy fix first. It may not work as there seems to be a load of new forms of this infection out there in the last week. If it does not work, we will use a manual approach.

    Virtumonde aka Trojan Vundo Removal

    Attach the log from VundoFix afterwards.

    Also please follow the directions in step 7 of the READ ME and install HijackThis properly. You have it installed exactly where we tell you not to install it.

    Also Run the below procedure and attach the newfiles.txt log.
     
    Last edited: Jul 9, 2006
  6. properbopeep

    properbopeep Private E-2

    Thanks for reply.

    Apologies for installing HJT in wrong file...

    ok - have run VundoFix and it said no files were picked up (attached log anyways).

    Also have placed HJT in C:/Program Files/HJT. Have closed down all active running programs, and have enclosed log (Question: do I need to close down all programs in the task bar too - Norton AV, Daemon, Java etc too before running this?)

    Thanks again.

    BoPeep
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of vtstt.dll once and then click the kill button. After you have killed all of the vtstt.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of vtstt.dll and kill it. (If you do not find the dll, just continue on.)

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O23 - Service: Asnartsf - Unknown owner - (no file)

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    Now back on Killbox's main window, Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.

    C:\WINDOWS\SYSTEM32\vtstt.dll
    C:\WINDOWS\SYSTEM32\ttstv.ini


    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now attach a new HJT log and a new log from ShowNew.

    Also tell me how the steps went.

    Make sure you tell me how things are working now!
     
  8. properbopeep

    properbopeep Private E-2

    Chaslang

    Thank you for your reply. Very concise instructions!

    I followed what you asked - all went smoothly. There were about 6 instances of vtstt.dll running in both the Winlogon and explorer.exe (from Process Explorer). All ended without problems.

    From Killbox, I think only the ttstv.ini file was found as when I prompted the reboot after having typed in both files, it said it was only deleting one file.

    On reboot (things seemed quicker to load - is this a good thing?) I ran HJT again (before plugging USB modem back in) and also ShowNew.

    So far - things look encouraging as there is no vtstt addon appearing in the IE7 addon-list!

    Fingers crossed.....
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We're almost there! Now that we removed the bad files, they showed up in your HJT log! So fix the below. The O23 item seems to be back.. Did you get an error message about fixing it?


    O2 - BHO: (no name) - {47AF0959-E8B5-4CBE-8ACB-3D0C1FA88E27} - C:\WINDOWS\system32\vtstt.dll (file missing)
    O20 - Winlogon Notify: vtstt - C:\WINDOWS\system32\vtstt.dll (file missing)
    O23 - Service: Asnartsf - Unknown owner - (no file)

    Let me know if the O23 line comes back.
     
    Last edited: Jul 11, 2006
  10. properbopeep

    properbopeep Private E-2

    I didn't get error message... I shall try fixing again...
     
  11. properbopeep

    properbopeep Private E-2

    Fixed those three entries on HJT.

    It appears that the 023 doesn't want to go away. Fixed 3 times, no error message but still appears on log?
     

    Attached Files:

    Last edited by a moderator: Jul 11, 2006
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Asnartsf ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Asnartsf

    If you receive any error messages just ignore them and continue.

    Now exit HJT and reboot if it tells you it needs to.
    After reboot check to see if the O23 line is gone.
     
  13. properbopeep

    properbopeep Private E-2

    Problem - when opened Service.msc - there is no Asnartsf running.

    Tried directly removing with the "Delete NT Service" part of HJT, but it says "Process running, please disable with HJT or services.msc".

    Is is masquerading as something else?? I could poss post you a screenshot of what services.msc pulls up??

    Thanks for your patience!!
     
  14. properbopeep

    properbopeep Private E-2

    attached is current list of running service...
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    My last instructions had the below line in it!
    Thus I expected error and just wanted you to continue thru each step and ignore errors.

    You don't really expect me to be able to read that file you posted do you! How did you format it like that?

    Download GetService.zip from here: Getservice.zip

    Extract the file to a folder where you can find it, then go to the folder and double-click on the getservices.bat file. A notepad will open up. Save it to a file named services.txt and upload it here as an attachment.


    Also download the Registry Search Tool

    Unzip to your Desktop and double click on regsrch.vbs
    (if you have script protection, please allow this to run)

    In the dialog that opens enter the following:

    Asnartsf

    Press 'OK'

    The search will run for a while then alert you when it is finished. Press 'OK' and copy the contents of the WordPad window and post in this thread as an attachment.
     
    Last edited: Jul 12, 2006
  16. properbopeep

    properbopeep Private E-2

    Did as you asked and the GetServices log is attached.

    I also ran the Registry Search Tool from the Desktop. It ran and said that 12 instances of Asnartsf had been found, but when I clicked OK to save a log to Word Pad, I got the following message:

    Script c:\Documents and Settings\Tom\Desktop\RegSch.vbs
    Line 76
    Char 1
    Error System couldn't find the file specified
    Code 80070002
    Source (null)

    hmm...

    (on previous thread - I didn't make it clear, that I did ignore the error messages and exited HJT then rebooted, and the 023 line was still there)

    Where next? Thank you!!
     

    Attached Files:

  17. properbopeep

    properbopeep Private E-2

    PS - Sorry abou that last attached file. I didn't realise quite how illegible it was! :(
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run Regsrch again and just copy and paste the info here if you cannot save the file. I need to see that before we continue.
     
  19. properbopeep

    properbopeep Private E-2

    I don't get to the see the log at all, let alone attempt to save it. I run Regsrch.vbs - there is a pause, then it says "There are # instances of Asnartsf (usually about 6 now) found. Click ok to save to WordPad"

    When I click ok - I just get the error message in previous post.

    I have tried running the vbs script from several locations and still get the same message. Anything I am doing wrong or is there a problem??

    Thanks again.
     
  20. properbopeep

    properbopeep Private E-2

    ... I have also tried downloading it again and reinstalling it again. Still no joy...:eek:
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Start, Run, and enter wordpad and click OK!

    Does a Wordpad windows open up?
     
  22. properbopeep

    properbopeep Private E-2

    ... it would appear the WordPad has disappeared!! I have tried reinstalling windows componants but still nothing. Don't seem to be getting much luck trying to download it either.... any ideas??
     
  23. properbopeep

    properbopeep Private E-2

    Ah Ha!! Success. Managed to copy Wordpad.exe from another PC and have got it working. Here is the log....
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now do the RegSrch procedure again and attach the new log. Also attach a new HJT log.
     
  25. properbopeep

    properbopeep Private E-2

    Ok - did as you asked. We are getting there.

    Did the regedit and repeated the RegSrch script - no instances of Asnartsf were found (so no log posted).

    Have also attached the new HJT log - and it appears the rogue 023 section has indeed gone!!

    Fingers crossed this all looks good...??
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  27. properbopeep

    properbopeep Private E-2

    Re: Problems with Trojan.dialer.pz and vtstt.dll, and just recovered from Trojan.nebu

    Brilliant - flushed the restore points and taken advise from the advice section. All appears to be running well and smoothly.

    I really can't thank you enough for your time and patience - you guys do amazing things here, highly commendable.

    Best wishes

    BoPeep
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Problems with Trojan.dialer.pz and vtstt.dll, and just recovered from Trojan.nebu

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds