SpywareQuake Is Still On My Computer!

Discussion in 'Malware Help (A Specialist Will Reply)' started by JLuv3k7, Apr 24, 2006.

  1. JLuv3k7

    JLuv3k7 Private E-2

    ok so i did the instructions that the spywarequake thread told me. and it didnt work.
    none of the file references that are listed in the removal thread were on my computer. not a single one. but as the thread said, i proceeded anyway. so i ran RunThis.bat and it looked as if it found something. however, when i rebooted i still had the damn spywarequake!
    any help?

    -JLuv
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please rerun the SpywareQuake Removal Procedure sticky thread. I just updated it a little while ago for the new form that you have.

    Attach a new log and let me know the results.
     
  3. JLuv3k7

    JLuv3k7 Private E-2

    sweet.
    worked like a charm.
    thanks.

    -JLuv
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Make sure you work thru the below before you go.

    How to Protect yourself from malware!
     
  5. JLuv3k7

    JLuv3k7 Private E-2

    DAMMIT!! ITS STILL HERE!
    i tried to get rid of spywarequake again today to no avail. this is the 3rd time in 2 days i've had to try to get rid of this. any help?
    i attached my latest smitfiles.txt and hijackthis log.
    any help?

    -JLuv
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No!!!!! You picked up a new version that just came out. You need to be careful where you are surfing. You got the two newest versions within a 24 hr period. Where have you been surfing.

    The SpywareQuake Removal Procedure has been updated tonight for the new form.

    Make sure you re-download the fixquake.reg registry patch since it has changed and also re-download SmitRem.exe just incase it has changed.

    Attach the new file. You may want to consider running our full cleaning procedures after fixing the above. You may have other issues that could be at the root of why you keep getting re-infected. Consider running the below:

    READ & RUN ME FIRST Before Asking for Support
     
  7. JLuv3k7

    JLuv3k7 Private E-2


    ok i followed the "RUN ME FIRST" link and did everything it said then ran through the spywarequake removal. i had a cpl problems tho. Microsoft Defender wouldnt update its definitions. whenever i tried, i got an error. also, CCleaner would spit an error at me when i tried to run it in Safe Mode. so those two programs were out of the door. the other ones worked great and i also added Webroot Spysweeper to the list b/c i have a subscription to it.

    ok i think i got rid of spywarequake. however, i now think that the problem lies elsewhere. as soon as i got rid of spywarequake i rebooted into normal mode and reconnected my cat5 to come here and post. almost immediately, my Symantec AV auto-protection detected at dialer (which i've also been gettin ever since i've had spywarequake) called "Dialer.DialPlatform" and once i opened IE6 i noticed my homepage had been hijacked (despite the fact that i had went in and set it manually when i rebooted). then i noticed my hdd spinning for about 3 min straight with only hijackthis and firefox, open. i hope thats of no importance. i then ran hijackthis and fixed a few things (very carefully i might add) according to the hijackthis guide.

    also, i think i'll mention that i noticed winlogonhook in one of my scans. so i'll go through that procedure also right after i post this.

    any other suggestions?

    -JLuv
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must run ALL steps in the READ & RUN ME and they must be run before using HJT. You completely skipped step 6. Did you skip anything else? You are also using MSconfig to control startups which we specify not to do in the instructions in step 7.

    What is the below and why is it running at all let alone 4 times:
    C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe
    C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe
    C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe
    C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Even though you were running msconfig which may have hidden some stuff we needed to see, here is an attempt at a fix anyway.


    Download - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later to run it.
    Run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click OK.

    Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.

    C:\WINDOWS\system32\dcomcfg.exe
    C:\WINDOWS\system32\vtstq.dll
    C:\WINDOWS\SYSTEM32\winsgf32.dll

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself. However BOOT INTO SAFE MODE during this reboot and do not run anything but what I request. DO NOT open any browsers!

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O20 - Winlogon Notify: vtstq - C:\WINDOWS\system32\vtstq.dll (file missing)
    O20 - Winlogon Notify: winsgf32 - C:\WINDOWS\SYSTEM32\winsgf32.dll


    Now exit HJT
    Run Windows Explorer and double check to make sure the below files are all deleted (we already deleted them with killbox but we are double checking):

    C:\WINDOWS\system32\dcomcfg.exe
    C:\WINDOWS\system32\vtstq.dll
    C:\WINDOWS\SYSTEM32\winsgf32.dll


    Now reboot into normal mode and after reboot double check the same HJT entries I had you fix above and if any still remain, fix them again a second time.

    Now attach a new HJT log

    Also tell me how things are working!
     
  10. JLuv3k7

    JLuv3k7 Private E-2

    ok, i *think* i'm ok :knock on wood:.
    all of this got really really frustrating so i used linux for a few days b/c the spyware was just plain annoying! but i came back with a vengence...
    i went through the special steps for Winlogonhook, then SpywareQuake, then the long READ ME FIRST, then Alternative Scans.
    winlogonhook seemed to work, my second scan in Webroot came out clean as a whistle.
    i followed all steps this time for SpywareQuake and it seemed to work. i dont think i had any problems.
    the READ ME FIRST part had a cpl hurdles. again, MS Defender wouldnt update at all. and Counterspy installed fine the 1st time, but when i went to update it i got an error (sry for the lack of specific errors). and everytime i tried to update Spybot i got "bad checksum". even on diff servers. but all of my other definitions and programs updated fine. almost all scans came out clean except spybot. which has a recurring find of "SexList". Bitdefender online scan came out clean and i totally forgot to save the logfile. panda found some stuff but i couldnt save the log due to horrible screen resolution that safe mode wouldnt let me change. i couldnt see any of what it found not could see any buton to press to continue after the scan.
    the Alternatice Scans section was a failure. none of the software on that page would install on my computer. almost every single download ran into an error. however, i did manage to get a-squared which returned a clean scan.
    i did not follow the instructions that are posted in this thread about Pocket KillBox but i'll do that also when time permits.
    i ran hijackthis and i had it fix an R3 that said "URLSearchHookIsMissing" and i am skeptical about the O9 bdoscandel.exe. i googled it and no results mentioned it as harmful so i left it alone. and there are also a few O20's that say Winlogon. is that something from Winlogonhook??
    and as for "YahooWidgetEngine.exe". its nothing to worry about. i have 3 Yahoo! Widgets running at all times and they start at start-up. i guess the 4th instance of that is just the engine in general that runs in my taskbar.
    thanks for all your help.
    and if i forgot to attach somethin let me know.

    edit: just fixed the Yahoo! link.
     

    Attached Files:

  11. JLuv3k7

    JLuv3k7 Private E-2

    dammit!!
    Symantec AV just popped up telling me about somethin called "Adware.PurityScan". its been poppin up for a cpl days and gets quarantined by Symantec everytime. do u know what this is?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still need to see the logs from step 6 of the READ ME. Run both of them in normal boot mode this time and then attach both logs but make sure you follow the directions in step 6 on how to attach them or you will get the Bitdefender log wrong.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds