Dll errors that dont exist! Helllp!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by meloney, May 1, 2008.

  1. meloney

    meloney Private E-2

    Hi Iv done a search and cant find the erros on my pc, iv tried to use ad-aware but it just gets stuck.

    I have enclosed a word doc, and 2 reports for the problems I have..

    I wonder if you can help??
     

    Attached Files:

  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    As you have noticed some random files and errors, its possible that those are malware, but to be fully sure just single scans and logs as attached will not locate the malware, you do need to fully follow the guide below and attach the logs requested.

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. meloney

    meloney Private E-2

    :hyper:wine

    Hi did what you said.. and here are the results.. its stopped doing funny things now and has started moving much faster.. Found a few bugs.. not sure if i did it correctly one hundred percent but its looking good. thank you .. please look at my results, and if you feel i need to do other things let me know..

    moo moo in London, after a few glasses of red wine.. over and out>>xxx God u guys are so cleaver!!. xx Thank youx
     

    Attached Files:

    • log.zip
      File size:
      532.1 KB
      Views:
      3
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please only attach the logs that are requested in the procedures. You need to attach the logs from SUPERAntispyware and Malwarebytes Anti-Malware.

    Is the below something you installed?
    O4 - Startup: Babuki.lnk = C:\Program Files\Babuki\Babuki.exe


    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_15
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O20 - Winlogon Notify: wvUlijKd - C:\WINDOWS\SYSTEM32\wvUlijKd.dll

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. meloney

    meloney Private E-2

    Hello

    I got a good result, and iv enclosed the reports. Do i uninstall all the programs we used?? I dont know if they read ok now the reports??

    Thank you very much... xx:cloud9

    That was a right task! I wonder what caused it..
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We'll get to this in final instructions. But first load the below file into notepad and paste back here what you see in it:

    C:\WINDOWS\system32\Days5.ini
     
  7. meloney

    meloney Private E-2

    Enclosed...
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks harmless. Probably a file for date/time exceptions for a recurring calendar component.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. meloney

    meloney Private E-2

    Thank you very much for your time.. Its much appreciated...
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  11. meloney

    meloney Private E-2

    Serious Error??!

    Hi i received a message about a serious error, iv enclosed it in the zip file.

    Also I now have de activated xp firewall and using armor.

    The anit virus I have is AVG 8.0 pro..

    Do I need anything else on my pc to combat bugs, only i tried to download ad-aware and it said my system would not allow it.


    Meloney:confused
     

    Attached Files:

  12. meloney

    meloney Private E-2

    blue screen and shutting down!

    Hi its now occasionaly going to a blue screen saying it has to close and shutting down. Then re boots with the enclosed error??
     
  13. meloney

    meloney Private E-2

    now a blue screen!

    Here is the error
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: now a blue screen!

    Why are you attach files with a docx extension? If you are creating Word files, why are you using this form which is not compatible with many PCs. It is unique to Office 2007. Just make valid MS Word documents. In reality it would just be much much better if you just attach JPG files made with a window or area of a window capture tool like Fastone Capture. ( see: http://www.faststone.org/ )

    However, I doubt the errors you are having are related to malware. You will need to use FastStone to capture only a snapshot of the error message popup (do not copy your whole Desktop) and paste it into a message in the Software Forum. You should also get a copy of your EventViewer logs and attach that too (someone will probably ask for it) since it may show what application is causing the crash. See this: http://support.microsoft.com/kb/308427

    Everything you need I already gave you in the How to protect yourself link Ad-Aware is not something you need. It is really quite inadequate with todays malware which is why it does not appear in the READ & RUN ME nor is it in the How to protect youself thread.
     
    Last edited: May 4, 2008

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds