Win32:Crypt-RQA [Trj]

Hi! Good night!!!

First of all, I apologize for eventual grammatical mistakes…

I’m facing a problem with what I obviously suppose to be a virus that try to open several pages variably, like Windows Store, variable websites, weather app, and any others. It’s like if someone else was trying to handle the mouse at the same time as me and started to open a lot of windows.

I ran avast scan several times, including boot scan, and the scan often found the virus "Win32:Crypt-RQA [Trj]" at the file “C:\System Volume Information\EfaData\SYMEFA.DB”. But whatever the option I choose, the AV never get to remove or fix the virus, it always show me a message saying something about “unavailable flags”. And even when I logon on Windows (using Administrator user) I have no access to this folder C:\System Volume Information, so I don’t have access to the file to try delete or remove it.

Well, I’ve read a topic that was posted by jjessen some days ago (on Jan 12nd, to be more specific), apparently about the same problem I’m facing, and after she/he post some log files, essexboy sent her/him a kind of a script that has to be saved in a file named fixlist.txt and, when executed, seems to help fix the issue. So, I’ve already downloaded and ran Malwarebytes Anti-Malware, FRST64.exe and aswmbr.exe. The logs files are attached!

So, can anyone help me?!?!

Hi inovox, :slight_smile:

My name is Valinorum and I will be the acolyte today. Before we proceed, please, acknowledge yourself the following(s):

[*]Please do not create any new threads on this while we are working on your system as it wastes another volunteer’s time. If you are being helped/have solved the issue/no longer wish to continue, notify me in your reply and I will quickly close this thread. Failing to comply will result in denial of future assistance.
[*]Please do not install any new software while we are working on this system as it may hinder our process.
[*]Malware removal is a complicated process so don’t stop following the steps even if the symptoms are not found. Keep up with me until I declare you clean.
[*]Please do not try to fix anything without being ask.
[*]Please do not attach your logs or put them inside code/quote tags. Do a Copy/Paste of the entire contents of the log file and submit it inside your post unless directed otherwise.
[*]Please print or save the instructions I give you for quick reference. We may be using Safe mode which will cut you off from internet and you will not always be able to access this thread.
[*]Back up your data. I will not knowingly suggest your any course that might damage your system but sometimes Malware infections are so severe that only option we have is to re-format and re-install the operating system.
[*]If you are confused about any instruction, stop and ask. Do not keep on going.
[*]Do not repeat the steps if you face any problems.
[*]I am not an omniscient. There are things even I cannot foresee. But what I know took years to learn and perfect the skill. This site is run by volunteers who help people in need in their own free time. I would ask you to respect their time and be patient as sometimes real life demands our time and replies to you can be delayed.
[*]Private Message(PM) if and only if I have not responded to your thread within three days or your query is offtopic and personal. Do not PM me under any other circumstances. Your thread is the only medium of communication.
[*]The fixes are for your system only. Please refrain from using these fixes on other system as it may do serious damage.


Do you use GbPlugin software for bank transaction?
Did you set the following proxy: ProxyServer: [S-1-5-21-1209147958-159855399-2761062323-1001] => 10.2.0.1:3128?


[*]Step #1 Uninstall Programs
I want you to uninstall the following program(s) listed below due to poor reputation we receive about them. To uninstall a program, go to Start > Control Panel > Uninstall a program or Start > Control Panel > Programs and Features. Wait for the list to fill up and double-click on the items I have listed below and follow the on-screen instruction to remove/uninstall them.

[b][color=navy][]Acrobat Reader Packages
[
]AppCloudUpdater


[*]Step #2 Fix with FRST
Make sure that you still have FRST.exe on your Desktop. If you do not have it, download the suitable version from here to your Desktop.
[*]Open Notepad.exe. Do not use any other text editor software;
[*]Copy and Paste the contents inside the code-box to your Notepad

Start
CreateRestorePoint:
CloseProcesses:
Emptytemp:
Task: C:\Windows\Tasks\AppCloudUpdater.job => C:\Users\Vanessa\AppData\Roaming\APPCLO~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
C:\Users\Vanessa\AppData\Roaming\APPCLO~1\
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-1209147958-159855399-2761062323-1001\...\MountPoints2: {da81f46e-183d-11e4-826f-fcf8ae1d17d4} - "D:\AutoRun.exe" 
AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => C:\PROGRA~2\SupTab\SEARCH~2.DLL File Not Found
AppInit_DLLs-x32: C:\PROGRA~2\SupTab\SEARCH~1.DLL => "C:\PROGRA~2\SupTab\SEARCH~1.DLL" File Not Found
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1209147958-159855399-2761062323-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1402586620&from=cor&uid=WDCXWD5000LPVX-55V0TT3_WD-WXB1AA3L9127L9127&q={searchTerms}
HKU\S-1-5-21-1209147958-159855399-2761062323-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1402586620&from=cor&uid=WDCXWD5000LPVX-55V0TT3_WD-WXB1AA3L9127L9127&q={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
CMD: bitsadmin /reset /allusers
End

[*]Click on File > Save as…
[list][*]Inside the File Name box type fixlist.txt
[*]From the Save as type drop down list, choose All Files
[*]Save the file to your Desktop;
[*]Re-run FRST.exe and click Fix;
[*]Note: If FRST advises there is a new updated version to be downloaded, do so/allow this.[]After the completion, a log will be produced;
[
]Attach the log in your next reply.[/list]


[*]Step #3 Fix with AdwCleaner
[*]Download AdwCleaner by Xplode to your Desktop from the following link.
[list][]Download Link #1
[
]Download Link #2
[*]Right-click on AdwCleaner.exe and choose Run as administrator;
[*]Click on Scan and let the program run unhindered;
[*]When done, click on Clean and allow the system to reboot after it is done;
[]A log will be opened automatically after the restart;
[
]Attach the log in your reply.[/list]


[*]Step #4 Fix with Junkware Removal Tool
Download Junkware Removal Tool by thisisu to your Desktop from the link below.
Download Link 1
Download Link 2
[]Disable your anti-virus to avoid potential conflicts. For more information please acknowledge yourself this article;
[*]Run the program either by double-clicking(Windows XP) or Right-clicking and choosing Run as administrator(Windows Vista and above);
[*]Please be patient as the tool cleans your system;
[*]After completion of the process a log named JRT.txt will automatically open and is save to your Desktop;
[
]Attach the log in your next reply.


[*]Required Log(s):
[]FRST Fix Log
[
]AdwCleaner Log
[*]Junkware Removal Tool Log

Regards,
Valinorum

Hey Valinorum!!

Tnks for your instructions. I will procedure as you recommended as soon as possible, I’m not in front of machine now…

Thanks for help!

I await your logs. :slight_smile:

Hello Valinorum!!! Good evening!

I proceeded as you requested in the 1st step: I’ve tried to remove Acrobat Reader Packages and AppCloudUpdater. The first one (Acrobat Reader Packages) isn’t shown on the list as you can see in the print attached. In the second I received the following message: “An error occured while trying to uninstall AppCloudUpdater. It may have already been uninstalled. Would you like to remove AppCloudUpdater from the Programs and Features list?”. Then I cliked “yes” and the program exit from the list.

The logs requested are attached. Thanks since then!!!

How is your system?

Is the same… I restart computer and after logon on Windows the virus starter to open several pages randomly again.

Is anything else to do?

I ran a new boot scan and now Avast didn’t accused any new virus, just some files that seems to be corrupted.

But the unblessed virus is stil here in somewhere (where I don’t know) cause the windows are still being opened ‘alone’ and on a mutable way and I can’t get control of the mouse because the cursor keep moving like crazy!

Post a fresh FRST scan log.

Hello!!!

Here it is!

ps.: I guess I might to tell you that my wife has tried to solve this problem by herself (she owners this computer) and she had installed Symantec AntiVirus. I really don’t know if this will make any difference, but I thought that I should notice you about this.

Thanks!

  1. You should not make any changes to the system as long as Valinorum is working on it … follow only his instructions
  2. Never install multiple AV. Now you have avast and Symantec endpoint

Why Using Multiple Antivirus Programs is a Bad Idea http://blog.kaspersky.com/multiple-antivirus-programs-bad-idea/

Listen to what Pondus says. Two resident av solutions on the same machine is a big no-no.
They are gonna detect each others signatures creating a big mess, just compare it to two watch dogs in front of the house starting to fight each other in stead of offering double protection all of your protection is gone.
A cleansing routine only creates the right results for a particular system and victim at a given moment, so you should trust the qualified removal expert to the dot. He has studied to be recognized as qualified everywgere online, so you could not be in better hands. These guys owe our mutual respect for what they do everyday here as volunteers out in the avast support forum trenches.

polonus

cause the windows are still being opened 'alone'
This is strange. Can you please post a screenshot?

Ok Pondus and Polonus, I’ll be attentive about your recomendations.

Valinorum, I think I can’t get a screenshot of this. I even think to record a video that would be better to show you what happens, but at this exact moment the virus seems to be “slepping” and the computer is running normally. But you should imagine something like two people handling two differents mouses on the same computer… I try to open the browser, for example, and the other person (the virus, in this case) moves the cursor of the mouse and open Windows Store; then I stop to move the mouse for some seconds and I “see” the computer opening several others pages like text editor, music players, browsers and others.

I still didn’t notice a kind of a standard… the pages are openned aleatory. Sometimes it stops, like now, and I can handle the computer normally; but after a couple of time, it starts again and I just can’t work on the computer while someone/virus keep trying to open a lot of other windows.

Okay. Give it a day and report me if it occurs. Let’s see if the virus awakes.