Spyware, dialer problems

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by soler, Sep 13, 2006.

  1. soler

    soler Private E-2

    Thanks for triyng to help me!

    My computer works under W2000 and lately I'm having some problems with windows opening and asking me if I want to install certain anti-spyware tools and -more annoyingly- dialers that try to connect and say (in Italian) that one program had to close since the phone connection failed (thanks God I don't have phone connection).

    I've followed the procedure you reccomend here (http://forums.majorgeeks.com/showthread.php?t=35407) but I didn't get ride of the problems. And I couldn't do it in safe mode.

    I attach the files you ask for.
     

    Attached Files:

  2. soler

    soler Private E-2

    Three more attachments.
     

    Attached Files:

  3. soler

    soler Private E-2

    I don't know why GetRun file did't upload (anyway, it was empty). I'll try again. In the meantime, I'm uploading Vundo file.
     

    Attached Files:

  4. soler

    soler Private E-2

    Ok, the file is impossible to upload. But as I told, the original file is empty: nothing writen on it (and I followed the procedure: double clicking on GetRunKey.bat; the .txt file doesn't have anything).

    Thanik you very much in advance.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you are not following the directions for either GetRunKey or for ShowNew. You must extract all the files from the ZIP file. Then you need to double click on them from a Windows Explorer window. What you are doing is double clicking on them inside the ZIP file and this will not work. Try again and this time extract all the files into the suggested folder, then CLOSE Winzip (or whatever you used to extract the files) and then locate the files with Windows Explorer and double click on them. Attach new, complete logs from GetRunKey and ShowNew. You have a Virtumonde infection and we need these logs to find all associated files.

    Question: The below used to be on the rogue tool list and is not really that useful of an application. Did you purchase this or is it a free trial version?

    O4 - HKLM\..\Run: [SpywareTerminator] "C:\Archivos de programa\Spyware Terminator\SpywareTerminatorShield.exe"
     
  6. soler

    soler Private E-2

    Ok, I've done what you told me and -as one could expect- it worked.

    Just one explanation: to get the files that I attached previously, I double clicked directly on the unzipped *.bat files in the folders where I unzipped them; I didn´t double click inside the ZIP files. The problem was that I didn't do it using Windows Explorer (by the way, I think you should specify that point in your instructions at http://forums.majorgeeks.com/showthread.php?t=83087 and http://forums.majorgeeks.com/showthread.php?t=95941).

    Once again, thank you very much for your help.
     

    Attached Files:

  7. soler

    soler Private E-2

    And I forgot to tell that I didn't purchase Spyware Terminator, it was a free trial version.

    Thanks again.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then what were you running that you were using to find it and double click on it.


    I'm not sure what the below is! Is this from System Spyware Interrogator? Do you still have this installed?
    O23 - Service: SysEnforce - Unknown owner - C:\ARCHIV~1\TRISNA~1\SSI\SYSENF~1.EXE (file missing)


    Please download and install Registrar Lite Make sure you select a Majorgeeks download link and not the Authors!

    Run Registrar Lite navigate to the following key and take ownership of it (explained further down):

    HKEY_LOCAL_MACHINE\software\microsoft\mssmgr

    To take ownership of the key do the following:
    • Copy & Paste the registry key from above into the address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    • Click-on Security in the Menu
    • Select Take Ownership
    • Now leave RegistrarLite running and continue
    • Now run the REGISTRY PATCH below in this message.
    • Tell me the results. Any error messages?
    • Now in RegistrarLite click View and then Refresh
    • Now navigate to HKEY_LOCAL_MACHINE\software\microsoft\mssmgr
    • Does the above mssmgr key still exist! If so, right click on it and select Delete.
    Here is the Registry Patch

    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    After completing ALL of the above instructions, continue here!

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of winvcl32.dll once and then click the kill button. After you have killed all of the winvcl32.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    vturq.dll

    Next double click on explorer.exe and again click once on each instance of winvcl32.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    vturq.dll

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now (some of these may no longer be found if the uninstalls above worked):

    O2 - BHO: (no name) - {7B45FC4E-B8A2-4478-889B-2A00AA83F12F} - C:\WINNT\system32\vturq.dll
    O4 - HKLM\..\Run: [SpywareTerminator] "C:\Archivos de programa\Spyware Terminator\SpywareTerminatorShield.exe"
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O16 - DPF: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class) -
    O16 - DPF: {5CA3D70E-1895-11CF-8E15-001234567890} (DriveLetterAccess) -
    O16 - DPF: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class) -
    O20 - Winlogon Notify: vturq - C:\WINNT\system32\vturq.dll
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    After clicking Fix, exit HJT.


    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now click Start, Run, and enter cmd and click OK! This will open a command prompt window. In the command prompt window enter the below commands each followed by the Enter key.
    del %windir%\temp\win*.*
    exit

    If you get an error message while doing the above command prompt step, just ignore it and continue!

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    C:\temp\Archivos temporales de Internet\Content.IE5\1N7RPLGE\srvjgj[1].exe
    C:\WINNT\Downloaded Program Files\UWA6PY_0001_N91M2107NetInstaller.exe
    C:\WINNT\system32\byxwtrq.dll
    C:\WINNT\system32\vturq.dll
    C:\WINNT\system32\qrutv.ini
    c:\winnt\wininit.ini
    C:\WINNT\system32\winvcl32.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.


    Also after reboot, delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINNT\Temp\

    Now attach a new HJT log and tell me how the steps went.

    Also attach a new logs from ShowNew and GetRunKey.

    Make sure you tell me how things are working now!
     
    Last edited: Sep 14, 2006
  9. soler

    soler Private E-2

    I don't have this installed (actually i don't know where it comes from).


    Not really. During my first attempt I didn't copy the REGEDIT4 part and I got an error message, but I relized that I forgot a part, did it again and it worked.

    I killed all vturq.dll (3 under winlogon.exe, 4 under explorer.exe), but I didn't find any winvcl32.dll.

    Done

    Done

    No problems this time: it merged.

    No problem at all.


    Here there was a problem. I got a message saying: (I'm translating from Spanish which, as you noticed, is the system running language I'm using) Error 52: Wrong File name or number. I went on anyway.

    Everything seemed to go right. The message I got was "Verifying Registry Entries".

    Done.

    You can find them attached.

    I think some of the problems remain: I run a sneaky round of Panda and it started to find some stuff (but I didn't let it to finish), but, certainly, right now the Italian message saing that some program failed to connect to the phone line doesn´t show anymore.


    Once again, thank you very much for helping me out.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then we will fix it.


    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to SysEnforce ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    SysEnforce

    If you receive any error messages just ignore them and continue.

    Now exit HJT and reboot when it tells you it needs to.


    You should now have HJT fix the below two lines (since they are missing) but what did you do to cause these to be deleted since your last HJT log:
    These were valid BHOs.
    The first was for tfswshx.dll which is a module belonging Veritas and Sonic software and assists with media access for their range of products.
    The second was for ssv.dll which is part of Sun Java!



    You will have to be more specific if you are still having problems because I don't see any.
     
  11. soler

    soler Private E-2

    Firstly, let me tell you again how deeply grateful I am for your help and your patience (with my informatic clumsiness and my english babbling). Seriously, I think what you do is terrific.

    And, related to your instructions, I've done everything you told me without any trouble.

    Sorry for that. What I meant was that I don't notice any problem with my computer (the most important thing: no dialer program is trying to connect to the phone line), but I assume that something could be latent, since Panda detects some stuff (I'm attaching Panda log file).

    Once again, thank you very much.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Panda is only detecting stuff that you have in:

    - Killbox backups which you can simply delete
    - Recycle Bin which you should be emptying
    - VundoFix backups which you can simpley delete



    If you are not having any other malware problems, you should work thru the below link:

    How to Protect yourself from malware!
     
  13. soler

    soler Private E-2

    OK.

    Thank you very much again.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds