Spyware/Malware problems, not letting me post on forums

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Meister, Apr 2, 2006.

  1. Meister

    Meister Private E-2

    Well I typed out a thread about my problem, but the internet is timing out before I can post. All other sites work (including major geeks), but I can't seem to post a long message. I'm not even sure this message will work, I'm trying to post something short then edit.

    edit: So, I did the READ AND RUN ME FIRST thread, but parts of it didn't work and I'm still having problems. The first thing was that I couldn't install Windows Defender. Whenever I tried it said it had a problem accessing the .msi file and asked me to verify that it exists. I tried running it from the desktop and a Cleaning Tools folder I made in C:.

    edit 2:
    Also, the Panda ActiveScan didn't work for me. I opened it in Internet Explorer, but when I got to the step where you pick where to scan, it did nothing when I pressed the Local Disks button (I also tried all the buttons afterwards, and none of them did anything).
     
  2. Meister

    Meister Private E-2

    I did the CWShredder and Kill2Me steps just in case too.

    After that I went on to Alternative Scans because I was still getting spyware (pop-ups and processes which I'm blocking with the Sygate firewall, but which still take up RAM). I ran Spy Sweeper (it deleted some stuff but still didn't fix the problem). I also tried to run the avast! Virus Cleaner Tool and Blacklight Beta, but both said I didn't have sufficient priviledges. I only made one user account on this computer, mine, and I'm administrator (I check control panel, users, and it only shows my user account and shows me as administrator status. However, I noticed when I was starting the computer in SafeBoot that there were 2 users to pick, my name and "Administrator". Also, when I try to create a new user called Administrator, it says that there is already a user with that name.

    edit 3: Oh, and also I think I have TeaTimer running with Spybot. I've seen it in the processes a couple of times. How do you turn it off?
     
  3. Meister

    Meister Private E-2

    Logs added.

    edit: Sorry about the post in parts. Turns out the Sygate firewall wasn't letting me send any big posts. I had to turn it off for a few seconds to attach the logs.
     

    Attached Files:

  4. Meister

    Meister Private E-2

    Oh, and here is another HJT log. The one before I did right after I started my computer in normal boot mode with no restrictions. This one is after a ran a few more additional scans and closed all the little icons on the far right of the task bar (including firewall and other antivirus stuff).

    edit: now that I think about it, Pandascan might not have run because my java might be out of date (i went to the java site but it wouldn't download the update because my firewall was blocking everything, I think). I'll check that tomorrow.
     

    Attached Files:

  5. Meister

    Meister Private E-2

    When I try to install the Java update I get an error message saying there's a problem with Windows installer, just like when I try to install Windows Defender. Also, when my computer is really slow to startup now and I always get a .dll error.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please see step 3 of the READ ME and uninstall one of the two Antivirus applications.
    Also if the McAfee software you have includes a firewall (and it probably does), you cannot keep both McAfee and Sygate installed. You must only have one firewall. This could be part of your problems.

    So either completely uninstall ALL McAfee software or uninstall AVG and Sygate. The see if you can run PandaActiveScan.

    To disable TeaTimer, run Spybot and click Mode and select Advanced Mode. Then click Tools and select Resident. Now in the right window pane, uncheck TeaTimer.
    Also while this is open, in the left column now select IE Tweaks and then in the right pane make sure all the Miscellaneous locks are unchecked. Now quit Spybot!

    Now attach a new HJT log after correcting the multiple AV and multiple firewall issue.
     
  7. Meister

    Meister Private E-2

    Oops, by the time I had gotten to alternate solutions I had forgotten all about step 3, my bad.

    OK, I uninstalled McAfee (at least all the McAfee programs that were in add/remove programs), but Panda Scan still doesn't work. It still says Error on Page at the bottom left in the IE bottom bar. I also still can't run Windows Installers. Oh, and when my computer starts up I get an error message saying "Error loading w00alde7.dll
    Specified module could not be found". (This message was here before, forgot to mention it)
    I don't know if that's signficant, just thought I'd mention it. Anyways, here is the new HJT log.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should not even have gotten to step 4 without finishing step 3. ;) Steps are meant to be completed in the order given.

    Your problem with Panda could be related to the fact that you are not running a current version of Sun Java. You need to get updated from: http://java.com/en/

    You have the new for of Qoologic infection. Please run the tool below so we can locate a bunch of hidden files related to this infection. The we will be able to give you fix.

    Please download FindQool by LonnyRJones
    • Extract the files and place the FindQool folder into root folder of your hard disk. This is usually C:\
    • Open the folder and run Qlocate.bat
    • Post the contents of the txt.log which will open wen the scan is finished.
     
  9. Meister

    Meister Private E-2

    When I try to install the Java update I get an error message saying there's a problem with Windows installer, just like when I try to install Windows Defender.

    Anyways, I ran FindQool. Here's the report.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Well see where we are at with that problem when the malware is removed.

    FindQool does not seem to have run correctly. It does not seem to be showing all the missing files that are normally there. I going to try posting a fix but I doubt it will work. Let's find out!

    Downloading - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later to run it.

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.


    C:\windows\keyboard7.exe
    C:\WINDOWS\System32\w00a1de7.dll
    C:\WINDOWS\System32\OUGHYA~1.DLL
    C:\WINDOWS\System32\slk8x2peu.exe
    C:\WINDOWS\System32\e6tw76cpw.exe
    C:\WINDOWS\\System32\bimkfo.exe
    C:\WINDOWS\System32\rreof.exe
    C:\WINDOWS\System32\cmkspui.exe


    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself. However BOOT INTO SAFE MODE during this reboot and do not run anything but what I request. DO NOT open any browsers!

    Now run HijackThis and select any of the following lines (if they still exist) and then click Fix checked:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R3 - Default URLSearchHook is missing
    F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\rreof.exe
    F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,cmkspui.exe
    O2 - BHO: (no name) - {7B55BB05-0B4D-44fd-81A6-B136188F5DEB} - (no file)
    O2 - BHO: (no name) - {8729FE36-37EC-4B11-B916-47845D05FFF4} - C:\WINDOWS\System32\mfplay.dll (file missing)
    O2 - BHO: (no name) - {98DBBF16-CA43-4c33-BE80-99E6694468A4} - (no file)
    O2 - BHO: Yvakt Class - {BA3DDC15-3EF1-4DC7-B9B6-ED0403F9422A} - C:\WINDOWS\System32\OUGHYA~1.DLL
    O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)
    O4 - HKLM\..\Run: [winupdate] C:\Program Files\winupdate\winupdate.exe /auto
    O4 - HKLM\..\Run: [ayrcfm] C:\WINDOWS\System32\bimkfo.exe reg_run
    O4 - HKLM\..\Run: [CQ4d6] "C:\WINDOWS\System32\slk8x2peu.exe"
    O4 - HKLM\..\Run: [w00a1de7.dll] RUNDLL32.EXE w00a1de7.dll,I2 00013416000a1de7
    O4 - HKLM\..\Run: [keyboard] C:\windows\keyboard7.exe
    O4 - HKCU\..\Run: [wvxdg] C:\WINDOWS\System32\bimkfo.exe reg_run
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/0631ccf5b9fa43f55e22/netzip/RdxIE601.cab
    O18 - Filter: text/html - {D332110E-3EDB-417B-B8E2-297B61C074C6} - C:\WINDOWS\System32\OUGHYA~1.DLL



    Now exit HJT
    Run Windows Explorer and double check to make sure the below files are all deleted (some we already got with killbox):

    C:\windows\keyboard7.exe
    C:\WINDOWS\System32\OUGHYA~1.DLL
    C:\WINDOWS\System32\slk8x2peu.exe
    C:\WINDOWS\System32\e6tw76cpw.exe
    C:\WINDOWS\\System32\bimkfo.exe
    C:\WINDOWS\System32\rreof.exe
    C:\WINDOWS\System32\cmkspui.exe
    C:\WINDOWS\System32\w00a1de7.dll
    C:\Program Files\winupdate <--- the whole folder

    Then reboot into normal mode and attach a new HJT log and a new log from FindQool
     
  11. Meister

    Meister Private E-2

    Ack, sorry for the delay (lots of tests this week). I hope I didn't get any new spyware in the meantime :eek:

    Oh, when I booted up in safe mode after the killbox, I had to open the explorer to get to the HJT folder (I closed it after I opened HJT). I hope this didn't affect it.

    I also found C:\WINDOWS\keyboard71.dat while double checking the files at the end. I don't know what that is, just thought I'd mention it.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Delete that file too!

    You need to check that your xfire stuff is working okay. HijackThis indicates the below file may be missing.
    O10 - Broken Internet access because of LSP provider 'xfire_lsp_9996.dll' missing

    Check to see if the file is still installed. If not, you need to reinstall or we should fix your broken LSP chain (we need a special tool for that) to avoid problems with your connection to the internet.
     
  13. Meister

    Meister Private E-2

    OK, I deleted the keyboard71.dat and when I start up Xfire, it can connect to the internet, but I don't know if my LSP chain is fixed. Also, I've noticed that my computer takes an inordinate amount of time to start up (before I got the spyware it was relatively fast). I unchecked all the Startup commands in msconfig except for Sygate Firewall and RUNDLL32.EXE (I don't really know what that one is...) so I don 't know why it's taking so long.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now go back and select Normal Startup again using msconfig. While we are working on your PC, we do not want MSConfig used to control anything unless we ask you to use it. And we will only do that in rare case to track down a possible software conflict issue.

    What I asked you to do was to check to see if the xfire_lsp_9996.dll file was missing or not.

    Let's fix the broken LSP chain. Download LSP - Fix

    Run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the xfire_lsp_9996.dll file (in the “Keep” section) to select it.



    Then, Select the >> button to move xfire_lsp_9996.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.
    If it is already in the Remove section, just click Finish.

    When did you install Ewido and Spy Sweeper? Are they paid versions or the free trial versions?
    Do you have the Win XP SP2 firewall disabled?

    Now attach a new HJT log from normal boot mode and without msconfig controlling any startups. Also indicate if your PC is still slow to startup.
     
  15. Meister

    Meister Private E-2

    I installed Ewido and the sweeper for the R&R thread, so right before I made my first post. They're both the free versions. As for the Win XP SP2 Firewall, I don't know. I never downloaded anything like that, and it doesn't show up on the taskbar, but it may be hiding.

    Also, my computer is still slow to start up (I did it on normal boot this time like you said, so all the programs start up: Ewido, Spysweeper, Sygate Firewall, Quicktime, OpenOffice quicklauncher, Object Dock, and probably some others I'm forgetting about/don't show up on the task bar).

    Oh, and I also noticed that when the firewall is on normal mode, my internet becomes very slow. For example, as I said earlier in the thread, I can't attach logs with the Firewall on normal mode (even though firefox is set to allow).
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since they are only trials that will expire, uninstall Ewido and Spy Sweeper.
    Win XP SP2 firewall is part of Windows XP SP2. It is on by default and unless Sygate automatically disabled it (you must check to make sure), it could still be on and this will cause problems. See the info step 3 of the following link. It will help you check to make sure it is disabled: How to Protect yourself from malware!

    This should not be necessary. Sounds to me like something is not configured properly in your firewall. If you use Internet Explorer (with the Sygate enabled), can you attach files.

    But let's fix another problem (not malware) that you have. You have not updated your Sun Java version. Go here http://java.com/en/ and install the current Sun Java then uninstall all old versions (the current version is 5.0 update 6). This may help with some issues too.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Each of the below O4 lines can be fixed using HijackThis. They are not needed! This will stop them from loading at startup and this in turn will speed up your PC startup time and it will free system resources which improves overall performance.
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)

    Now the below items you have to decide whether you really need or want them to always run at startup. I would say they are not needed. But everyone has different needs and preferences. Some of these can probably just be run when you need them which I would assume is not all the time.
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
    O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup

    I'm not exactly sure what the below item from Dell is for but I deleted it from two Dells I have and I have never missed it.
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
     
  18. Meister

    Meister Private E-2

    I still can't install Java because I'm getting an error with Windows installer (specifically the error reads: "Error 1719. The Windows Installer Service could not be accessed. This can occur if you are running Windows in safe mode [I'm not], or if the Windows Installer is not correctly installed."

    My startup still seems slow (I timed it just to check that I wasn't insane. From the time I click restart to the time that everything is loaded up [and this is after I did you HJT recommendations, so only the absolutely necessary starts up] it takes 4 minutes 40 seconds.
    My computer specs are 2.4 GHz and 512 MB RAM.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like you have other problems with your PC not related to malware.

    Did you check to make sure the Windows firewall is disabled?

    Let's see what is in your current HJT log.


    You may want to consider downloading ZoneAlarmFree firewall and uninstalling Sygate which is no longer supported anyway since Symantec purchased the company. Then install ZoneAlarm and see how things work.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds