Too many viruses to name

Discussion in 'Malware Help (A Specialist Will Reply)' started by AVIS, May 25, 2006.

  1. AVIS

    AVIS Private E-2

    Hello,

    As the name of this thread suggests, my computer is infected with numerous viral entities! I just want you to know that as soon as the computer is clean, I will be updating to a new version of XP and I will be updating my anti-virus software. I have performed everything specified in the document "read and run me first before asking for support" but I know that there as still a number of bugs and would greatly appreciate your help. I have attached numerous logs including counterspy, panda scan, bit defender and hijack this.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run CounterSpy again and allow it to fix what it found. You told it to ignore all the bad Warez and P2P stuff it found. Then attach a new CounterSpy log.

    You also need to run the below and then attach the VundoFix log:

    Virtumonde aka Trojan Vundo Removal


    Then delete the below files if they still exist. You may need to boot into safe mode to delete them:

    C:\Program Files\Common Files\Companion Wizard <--- the whole folder
    c:\windows\STWSI <--- the whole folder
    D:\codecs_and_players\DivX\DivX Pro Codec\Gain_Trickler.exe
    C:\WINDOWS\Downloaded Program Files\turbo.inf
    C:\WINDOWS\System32\ssqpq.dll
    C:\WINDOWS\system32\sstqq.dll
    c:\windows\inf\biini.inf
    c:\windows\satmat.ini
    C:\WINDOWS\inf\satmat.inf
     
  3. AVIS

    AVIS Private E-2

    Hello,
    I re-ran counterspy and attached the log. I downloaded vundofix.exe. I checked "run vundofix as a task" but the program never re-opened. Any thoughts? I have also attached a new hijack this log. Cheers....
     

    Attached Files:

  4. AVIS

    AVIS Private E-2

    Oops. Forgot to delete the files you told me to delete...will do that now:)
     
  5. AVIS

    AVIS Private E-2

    I was able to delete everything you told me except for the following because the files were not there.

    C:\WINDOWS\Downloaded Program Files\turbo.inf
    C:\WINDOWS\System32\ssqpq.dll
    C:\WINDOWS\system32\sstqq.dll
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not according to you HijackThis log. This one is there (along with other related files) and you are still infected with VirtuMonde.

    O2 - BHO: InfoDocReader Object - {295BA105-3506-4D25-B0DD-54346320BDC5} - C:\WINDOWS\System32\ssqpq.dll
    O20 - Winlogon Notify: ssqpq - C:\WINDOWS\System32\ssqpq.dll

    You need to try running VundoFIx again. Try it in normal boot mode, safe boot mode, and and with no connection to the internet. You maybe having problems running it because your system is so far out of date. If it does not run, we may have to try manual steps.
     
  7. AVIS

    AVIS Private E-2

    Hello again,
    This post wont be very useful to you...sorry! I tried the Vundofix program again in all 3 recommended ways but the program just doesnt open up after it closes. Also, I ran Hijack this again and I see the files that you are talking about in the log but when i go into c-windows-system32 i do not see the files! What am I doing wrong?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not enable viewing of hidden and system files per the steps in the READ ME. But you will not be able to delete them right now even if you see them because the infection (that VundoFix is use to removed) is still in place.

    I'll post another fix to try but you must make sure you do the below while waiting for the fix:

    How to view hidden, system files & folders!
     
  9. AVIS

    AVIS Private E-2

    Hello,
    I did what you recommended and I have partial good news. I can now see ssqpq.dll but cannot delete it because it says that the program is being used by someone else. Also, I still cannot see the other 2 files that I was unable to delete previously...........
     
  10. AVIS

    AVIS Private E-2

    I jut re-read your post and I guess its the bug that is using the program...sorry a little slow........ :)
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This should have already been done when you first ran the READ & RUN ME. It is step 2.

    Okay let's use my older manual approach to fixing Virtumonde. Start by downloading two tools we will need:

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.
    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of ssqpq.dllonce and then click the kill button. After you have killed all of the ssqpq.dllunder winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of ssqpq.dlland kill it.

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: InfoDocReader Object - {295BA105-3506-4D25-B0DD-54346320BDC5} - C:\WINDOWS\System32\ssqpq.dll
    O20 - Winlogon Notify: ssqpq - C:\WINDOWS\System32\ssqpq.dll

    Copy the bold text below to notepad. Save it as fixVundo.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.

    C:\WINDOWS\SYSTEM32\qpqss.ini
    C:\WINDOWS\SYSTEM32\qpqss.ini2
    C:\WINDOWS\SYSTEM32\qpqss.bak
    C:\WINDOWS\SYSTEM32\qpqss.bak1
    C:\WINDOWS\SYSTEM32\qpqss.bak2
    C:\WINDOWS\SYSTEM32\qpqss.tmp
    C:\WINDOWS\System32\ssqpq.dll


    If you find any other files in this folder that begins withqpqss and ends with any other extension ( the .ini is an an extension) delete them to.

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now attach a new HJT log and tell me how the steps went. Doing this in normal boot mode does not always work. So we may have to retry again in safe mode.
     
  12. AVIS

    AVIS Private E-2

    Hello,
    All the steps seeme to go fine (in normal mode...i did not repeat them in safe mode). Here is the new hijack this log.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like we got rid of Virtumonde!

    Just have HJT fix the below two lines:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    R3 - Default URLSearchHook is missing

    Now exit HJT.


    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    How are things working now?
     
  14. AVIS

    AVIS Private E-2

    Things are working MUCH better! Thanks for all your help :) Now I can update my system. I am installing a newer version of XP but I was wondering if you had any additional suggestions?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Standard procedures after getting everything cleaned up are below.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds