SpywareQuake and Trojans

Discussion in 'Malware Help (A Specialist Will Reply)' started by Feltes, Jun 2, 2006.

  1. Feltes

    Feltes Private E-2

    I completed the steps in the "SpywareQuake & SpyFalcon Removal Procedures" sticky.

    I removed SpywareQuake in add/remove programs. In safe mode, I found System32\wfkduei.dll, changed the extension to .ddd, then rebooted to normal mode and deleted it.

    I found, but was not able to delete the following files in either safe or normal mode.
    • System32\dcomcfg.exe
    • System32\hp100.tmp
    • System32\regperf.exe
    • System32\stdole3.tlb
    • System32\svcnt32.exe

    In addition to System32\dcomcfg.exe, Norton Antivirus found another Trojan - System32\atmclk.exe. I was not able to delete this in either safe or normal mode, either.

    My system is fairly stable and the annoying task bar messages have mostly gone away, but there are still Norton Antivirus warnings and an occasional popup.

    The smitfiles.txt is attached. PLEASE HELP! Thanks!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Try running the procedure again. Make sure you do not miss any of the filenames listed. The atmclk.exe file is in that list of files to delete too. For any file you run into that is not deleting, try using the renaming method on it. And then after another reboot, try deleting the renamed file.
     
  3. Feltes

    Feltes Private E-2

    Thank you.

    Same result. I can't delete these files or change the extension. Access to the file is denied because it's being used by another program.

    Also noteworthy - when windows starts, a program (WgaTray.exe; Windowns Genuine Advantage) try to access the internet. I deny it permission using Zone Alarm (firewall). This is not familiar to me, and could be part of the problem set. The seemingly related files in system32 are - WgaTray.exe and WgaLogon.dll)
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which files exactly do you see that cannot be deleted? Is it still the exact same list (including atmclk.exe)?

    Are you running the procedure exactly as indicated and getting into safe mode to run SmitRem? Did you run the fixquake.reg registry patch successfully?

    It has nothing to do with your infection. That is a valid Windows Process which you should not be denying. See: http://www.liutilities.com/products/wintaskspro/processlibrary/wgatray/

    If you still are having problems with the procedure, you could have other infections that are complicating the removal. Thus, I recommend you work thru the below.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  5. Feltes

    Feltes Private E-2

    Thanks! I beat you to the punch in running the "Read & Run Me First" (while I was awaiting your response). Reading other threads (that you were a part of), I've determined the WgaTray.exe and WgaLogon.dll files are Microsoft and should not cause concern.

    I THINK IT'S GONE!! After running Ewido (I'm telling you I was busy reading other material you've authored), I was magically able to either delete or rename/restart/delete every one of the SpywareQuake related files. Cheers Ewido.

    Here are the results from my adventure -

    Rebooted to safe mode
    Ran Ccleaner
    Ran Microsoft Windows Malicious Software Removal Tool (nothing found)
    Ran Ad-Aware SE (nothing found)
    Ran Spybot S&D (fixed a few minor threats, but couldn't fix dcomcfg.exe - access denied, of course)
    Ran Microsoft Windows Defender (wouldn't run in safe mode)

    Rebooted to normal mode
    Ran Microsoft Windows Defender (wouldn't run in safe mode)
    Ran BitDefender (nothing found, but I screwed up and didn't save the log! STUPID! It took forever!)
    Ran PandaScan (found a few things, I have the log)
    Ran Ewido!!! (found 8 items, one of which was atmclk.exe. It wouldn't delete in safe mode, but i re-ran in normal mode and it was gone, which allowed me to either delete or rename/restart/delete the other files on your bad guy list. Unfortuneately, it would not allow me to view or save the log :(

    After all of this, I decided the HJT may be an unecesary step. I ran CCleaner, emptied the Norton Protected files, and disabled system restore, . I'm 95% sure everything is gone and my music recording studio is back in order.

    HERE'S A HUGE SHOUTOUT TO CHASLANG, MAJOR GEEKS, and EWIDO'S FREE TRIAL! The spoils of war are mine, major, but take with you satisfaction knowing you saved my computer in 3 days, and re-formatting and installing my studio is at least a 20-day project.

    Let me know if you think you should still look at an HJT log. If so, I'll do my best to follow the steps correctly, as outlined.

    P.S. If you are curious, I currently reside in Bath (not England, Pennsylvania :) )
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! As long as everything is okay now, no we do not need to see the logs.


    If you are not having any other malware problems, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds