the Malware...

Discussion in 'Malware Help (A Specialist Will Reply)' started by TsarveK, Apr 28, 2007.

  1. TsarveK

    TsarveK Private E-2

    Hi all

    I'm Tsarvek, Obviously I'm new here.
    I'm Here because of the malware that has infested my machien:( .

    As per the instruction at the "no hijack this log before reading and run this "

    thread. I am requesting help with the hjt log.

    I have run everything as near as i could to the instructions (took about 8 hrs total) and now have the required log files to attach.
    It should be noted that I could not run counter spy in safe mode, so I ran The Avg anti-spyware in normal mode.
    I also could not run the online scans in safe mode.

    Am attaching said logs to this and the next post

    my symptoms include, still getting popup advertizing, redirects of destinations ( dosen't matter where i'm going).
    I was also getting Buffer Overrun warnings,and freezups, but they seem to have stoped.

    OOps, while I was entering this thread the computer froze up again. and the mouse pointer dissapierd.

    and since i rebooted, Winpatrol reports that a "vtusrq.dill" wants to attach its self as a ie addon. I Just tried again as i was typing this. I keep refusing it. but this is the 6TH time it has tried in the last 15 minutes or so.



    I could use some help.:tired

    T'sarveK
     

    Attached Files:

  2. TsarveK

    TsarveK Private E-2

    part 2

    here are the rest of the logs.
     

    Attached Files:

  3. TsarveK

    TsarveK Private E-2

    Part 3

    Hi all,
    I thought the buffer overruns were gone, they are not.
    just had 4 in about 20 minutes, 3 one after the other (imeadiatly)

    And the WINPATROL keeps telling me that vtusrq.dll is till trying to install itself, about once every 3 minutes.

    This is really annoying. With the return of the overrun messages from the C++runtime, I am exactly back where i started.

    I even know how this stuff got here, that was Flashget downloads. (not mine )

    any Ideas on how to get rid of this crap??

    T'sarveK
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    First please re-run AVG Antispyware and this time don't Ignore the problems. Have it Delete the malware it is finding. Save a new log and attach it.

    Please run this Virtumonde aka Trojan Vundo Removal and then perform and additional reboot and then run the VundoFix procedure again. After running the full procedure a second time, attach the requested log from VundoFix.

    Then also attach new logs from ShowNew and HijackThis so we can finish the cleanup that the above will more than likely not complete.

    Thus you should be attaching four new logs:
    • AVG AntiSpyware
    • VundoFix
    • ShowNew
    • HijackThis
     
    Last edited: Apr 28, 2007
  5. TsarveK

    TsarveK Private E-2

    Will do now
    T'
     
  6. TsarveK

    TsarveK Private E-2

    part 4

    Just finished the required scans as stated in last email.
    logs are attached .
    Have installed sunbelt Kirio personal firewall.
    Have Mozilla instaler on disk. not installed yet, let me know what is next
    let me know what is next.
    G'nite
    T'sarveK
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still Ignored things with AVG. You must physically select Delete. Or did you attach the wrong log? Based on the date in the log you just posted, it looks like it is the same as the previous log.

    If you have the new log from AVG Antispyware attach it. If you do not have the new log, are you sure you ran it again and Deleted the malware????

    Also you forgot the new log from ShowNew!
     
  8. TsarveK

    TsarveK Private E-2

    HI,
    The last 2 times I ran avg, as requested and I manualy sellected delet for the action to be tacken.

    so I must have grabed the wrong log.,

    But I assure you the action tacken was deletion.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but you still did not attach the requested log from ShowNew. I cannot continue without it. This is the third time I'm asking for it.
     
  10. TsarveK

    TsarveK Private E-2

    Your Right, i forgot to attach it .
    Since I have been out on the net,(with a fire wall), I am going to run the procedure once more, so it will be a while, will probably have for you late tonight ,early tomarrow.

    However, the symptoms have dissapieared. That does not mean that I think the paracite is gone.
    but thanks for the releife any how.

    will send the reports as soon as I have them.

    T'sarveK
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't need to run all of the READ ME again. Just download the new version of GetRunKey which was just updated.

    Then attach the below NEW logs:

    - GetRunKey
    - ShowNew
    - HijackThis

    If you do not attach ALL of these, I cannot help you.
     
  12. TsarveK

    TsarveK Private E-2

    the logs.
     

    Attached Files:

  13. TsarveK

    TsarveK Private E-2

    the last 2
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note: You have QuickTime improperly installed into the folder for K-Lite Codec Pack. This is a very bad practice. You should uninstall QuickTime and install it properly into its own default folder as suggested by the installation program.


    Now let's continue with your malware removal!


    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Windows Server Management Services
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteWSMSPSVC into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    If CounterSpy is the free trial version from the READ ME, uninstall it now since we are finished with it!

    Now look in Add/Remove programs for Windows Safety Alert and uninstall it if found.

    What is in the below folders in the root of drive C
    Code:
    C:\
    {00002~1      Apr 19 2007              "{00002A3A-0000-0000-20BA-973FBED59AFE}"
    {00002~2      Apr 22 2007              "{00002A3A-0000-0000-6108-B923FB95EE04}"
    {00002~3      Apr 25 2007              "{00002A3A-0000-0000-9A8E-37E892CD8719}"
    {00004~1      Apr 19 2007              "{000040AC-0000-0000-49D4-FAAC49B53172}"
    {00004~2      Apr 25 2007              "{000040AC-0000-0000-4FBB-4B382CAE6D1E}"

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINNT\system32\ntbcpwec.dll (file missing)
    O2 - BHO: (no name) - {52896693-27C7-4D8C-8D91-B5E70381EB1B} - C:\WINNT\system32\vtsqr.dll (file missing)
    O2 - BHO: (no name) - {975F9F36-613F-4A40-AB90-E598EC16A65e} - C:\WINNT\system32\qvwjeuys.dll (file missing)
    O2 - BHO: (no name) - {A711FD5C-62E9-4FAD-91AE-640F611E2D11} - C:\WINNT\system32\pmnlk.dll (file missing)
    O20 - Winlogon Notify: awtsqrp - awtsqrp.dll (file missing)
    O20 - Winlogon Notify: ddcdbya - ddcdbya.dll (file missing)
    O20 - Winlogon Notify: efcawvu - efcawvu.dll (file missing)
    O20 - Winlogon Notify: efcccdb - efcccdb.dll (file missing)
    O20 - Winlogon Notify: pmnlk - C:\WINNT\system32\pmnlk.dll (file missing)
    O20 - Winlogon Notify: vtusssp - vtusssp.dll (file missing)
    O20 - Winlogon Notify: vtuvsrq - vtuvsrq.dll (file missing)
    O22 - SharedTaskScheduler: grassily - {4233ac08-a2c4-4742-a0b4-83719613d62c} - C:\WINNT\system32\ilmpjy.dll (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    C:\WINNT\system32\awtsqrp.dll
    C:\WINNT\system32\ddcdbya.dll
    C:\WINNT\system32\efcawvu.dll
    C:\WINNT\system32\efcccdb.dll
    C:\WINNT\system32\pmnlk.dll
    C:\WINNT\system32\vtusssp.dll
    C:\WINNT\system32\vtuvsrq.dll
    C:\WINNT\system32\atjqcmek.dll
    C:\WINNT\system32\dmwywsxv.dll
    C:\WINNT\system32\fkddrhsk.dll
    C:\WINNT\system32\(null)id.tmp
    C:\WINNT\system32\dojlgngx.ini
    C:\WINNT\system32\kemcqjta.ini
    C:\WINNT\system32\kshrddkf.ini
    C:\WINNT\system32\vxswywmd.ini
    C:\WINNT\temp\_pccchkdll.log
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But if you do get this message, please let me know!)

    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  15. TsarveK

    TsarveK Private E-2

    Hi chaslang,

    did as requested...
    I DID get the Pending renaming prompt from Killbox.

    Attached are the 3 logs.

    Behavior report:
    I have Pest Patrol. It sounds an allarm every time a pest hits the computer.
    while I was posting this responce, I had 4 hits. do not yet know what the were/are, will run PP and see what it says. let you know.

    As for behavior for the day in general, no freizes, no popups,no redirects, no buffer overun warnings. 2 IE has made an error and needs to call home, but nothing else.


    Hmmm. cannot attach to this responc, will try with a fresh responce, see next post.
    T'sarveK:cool
     
  16. TsarveK

    TsarveK Private E-2

    Ah thats better,
    further notes on behavior.
    Pages on web coming up faster, access time from msn mail to actual viewing of said mail, at least 50% faster.

    T'sarveK
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still see some of CounterSpy trying to load. Did you get any errors while trying to uninstall it? If the below lines still appear in HJT, see if you can fix them:
    O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
    O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Unknown owner - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe (file missing)


    I also notice that you did not reinstall QuickTime properly yet! You really should correct this!


    Okay, due to this error, some of the files did not get deleted. Boot into safe mode and use Windows Explorer to delete the below files manually.

    C:\WINNT\system32\atjqcmek.dll
    C:\WINNT\system32\dmwywsxv.dll
    C:\WINNT\system32\fkddrhsk.dll
    C:\WINNT\system32\(null)id.tmp
    C:\WINNT\system32\dojlgngx.ini
    C:\WINNT\system32\kemcqjta.ini
    C:\WINNT\system32\kshrddkf.ini
    C:\WINNT\system32\vxswywmd.ini


    Then attach new logs from ShowNew and HJT.
     
  18. TsarveK

    TsarveK Private E-2

    Hi,

    All Items found and removed.
    I did find that Killbox has kept copies of said items. remove them too?

    Quick time unistalled, will reistall later to its proper place.

    yes there was a problem with the Sunbelt deinstall..
    About half way through, there was a power surge, and my protecters shut down both mylaideys and my computers.
    (Utillities are working golden time to replace stormdamaged power poles, some times there is a slip.)

    When things were back up, the emblem for the sunbelt counterspy was not ine the ad/remove programs page. I thought it was gone.

    T'sarveK
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These are always taken care of in my final steps. And since your logs are clean, here are those steps.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  20. TsarveK

    TsarveK Private E-2

    HI Chasling
    final system behavior ;
    All seems to be clear now.
    net access much improved,
    no crap.

    Thanks again.

    T'sarveK
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds