Windows Antivirus Pro 2009: cannot remove

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by kyteach00, Aug 7, 2009.

  1. kyteach00

    kyteach00 Private E-2

    I have an especially tough case of Windows Antivirus Pro 2009. I have tried multiple suggestions from the forums and have tried working through the "Read and Run Me First" list; here are the results:

    I have Windows XP

    1. Step One is maintenance I do regularly
    2. Uninstall of any program cannot be accomplished. When I open the control panel and select "Add or Remove Programs" the following message appears: C:\WINDOWS\system32\rundll32.exe The parameter is incorrect.
    3. I cannot add/remove programs or access any of the antivirus or antispyware apps as they will not open. I was able to run ccleaner once (already had it on my machine) when I first had the virus but it did not clean/remove it.

    Note: Above steps have been attempted both in safe mode and normal mode.

    4. When I attempt to view hidden files, the only options under the tools tab are "map Network Drive, Disconnect Network Drive, and Synchronize.

    When I attempt to run MSconfig, I can see a nanosecond flash of the DOS command window, but it instantly disappears.

    4. Uninstall Malware: every antivirus program I run will attempt to start and scan for a bit then be shut down by windows. I have tried saving programs (Such as Malware Bytes and SpyBot S&D) to a CD from a clean computer and have tried to run with the same results as above. Note that when I even tried to save the programs to the system under a different name.

    5. I have tried every tool suggested in the Windows XP Cleaning Procedures and followed the step by step instructions and details for each. The programs will not open when double clicked, so I have tried right clicking and selecting "Run as" instead of just double clicking the programs. The result is an error message that says registy editing has been disabled by your administrator .

    Results by program:

    Malwarebytes: When the scan starts, the program closes.

    Super AntiSpyware: Will not open; dos window flashes then disappears . Resaved as SAS, when attempt to open receive a message that reads MSIEXEC: The parameter is incorrect.

    Combo Fix: Ran exact directions; program will not open. (The dos window flashes then dissapears.)

    MG Tools: log will be attached.
    RootRepeal: was able to open and run scan. Approximately one hour later I am still waiting for results and will attach if complete.
     
  2. kyteach00

    kyteach00 Private E-2

    The log from MG Tools is attached. I hope I have done it in the correct format.
     

    Attached Files:

  3. kyteach00

    kyteach00 Private E-2

    UPdate on RootRepeal: Left running overnight but did not get any results. There was a message in the bottom left corner that zero files were found. I tried to run again and receive a message "A device attached to the system is not functioning."
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You neglected to make the agreement to run HJT. Please do so then next time you are asked to run the MGTools program.

    Now, we have a lot to remove.

    Now download (use a different computer and transfer via cd) The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please Disable Spybot's TeaTimer

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!

    Please use add/remove programs to uninstall:
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME
    Viewpoint Manager (Remove Only)
    J2SE Runtime Environment 5.0
    PC Antispyware 2010

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    -
    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). Make sure you accept the agreement to run HJT!

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Now see if you can get the other scans to run and attach any logs you can get.
     
  5. kyteach00

    kyteach00 Private E-2

    Tim - thanks for getting to me so quickly!

    I need clarification: I cannot add/remove programs. (I receive a message stating c:\\WINDOWS\system32\rundll32.exe The parameter is incorrect.)

    Also, I cannot open and run Spybot - when I attempt to run this program a MS/DOS type windows flashes for approximately a half-second then disappears - nothing runs. I have tried right clicking on Spybot and selecting "Run As" and following the prompts, but I receive an error message stating, "A device attached to the system is not functioning."

    I will not proceed with Avenger until this is cleared up.

    Thanks so much for your help!
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I didn't ask you to run Spybot. Please just continue on with the instructions.
     
  7. kyteach00

    kyteach00 Private E-2

    Also, I cannot open and run Spybot - when I attempt to run this program a MS/DOS type windows flashes for approximately a half-second then disappears - nothing runs. I have tried right clicking on Spybot and selecting "Run As" and following the prompts, but I receive an error message stating, "A device attached to the system is not functioning."

    I figured out what was done incorrectly to receive this message, but the program still won't open.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please just do what I instructed you to do. We can deal with disabling Spybot later.
     
    Last edited: Aug 10, 2009
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now continue on with the fix.
     
  10. kyteach00

    kyteach00 Private E-2

     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Proceed with avenger.
     
  12. kyteach00

    kyteach00 Private E-2

    Avenger did open and I copied and pasted the script exactly. Received the following message: Error: Invalid registry syntax in command: "{HKEY CURRENT USER\Software\Microsoft\Windows|CurrentVersion|Run}|braviax" Only registry keys under the HKEY LOCAL MACHINE hiv e are accessible to this program. Skipping line. (Registry value deletion mode)
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * C:\MGlogs.zip
     
  14. kyteach00

    kyteach00 Private E-2

    I am receiving a message that says,

    "Registry editing has been disabled by your administrator."

    I am logged in as the administrator and have not disabled this; it appears to be a symptom of the malware.

    I still cannot run anything using the "run" command; I've tried to enable registry editing through gpedit.msc but receive a message that "Windows cannot find 'gpedit.msc.'
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I need to see where we stand so please download the latest version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. It should start on it's own, if not run the exe. Attach the new MGLogs.zip.
     
  16. kyteach00

    kyteach00 Private E-2

    Here is the log - hope it is again in the correct format.
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, its all back.

    We need to do this now.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now see if you can run either Combo and or RootRepeal and attach the logs if you can.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip
     
    Last edited by a moderator: Aug 25, 2009
  18. kyteach00

    kyteach00 Private E-2

    Results of the first two steps:

    Antivirus programs: I cannot disable the antivirus programs because I cannot open or run any program file on my computer - a DOS window appears for a microsecond then disappears - nothing else. I could not even open NotePad - I had to save the fixME.reg file to CD and then transfer it to the infected machine to use.

    Registry Editing: When I attempt to open the fixME.reg file, I receive a message that registry editing has been disabled by the administrator. I am logged in as administrator and it has been disabled by this virus - I cannot enable no matter what I try.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to remember that if something doesn't work, move on. Were you able to do the Avenger fix?
     
  20. kyteach00

    kyteach00 Private E-2

    When I ran Avenger and input the quote in the box, I received this response:

    Error: Invalid registry syntax in command:
    "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|Windows System REcover!"
    Only registry keys under the HKEY_LOCAL_MACHINE hive are accessible to this program.
    Skipping line. (Registry value deletion mode)

    When I close that window I receive one that says registry editing has been disabled by the administrator.

    Next, there is a message saying that the first step has been completed and the computer will be restarted.

    When the computer restarts, there is a window that says,

    "Choose the program you want to use to open this file: cleanup.exe

    Do do not see any appropriate selection on the list that could be used to execute a new program...I selected Notepad so I could continue with login.

    A message then popped up that rundll32.exe Application not found.
     
    Last edited: Aug 28, 2009
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you able to run RootRepeal?

    Choose the program you want to use to open this file: cleanup.exe --> not a valid file.

    Can you attach the Avenger log please.

    C:\Avenger.txt
     
  22. kyteach00

    kyteach00 Private E-2

    Both files are in txt format - hope this is correct. I cannot open my program to convert them to .zip files.
     

    Attached Files:

  23. kyteach00

    kyteach00 Private E-2

    I've now lost the ability to open/run Internet Explorer this morning. I have restarted multiple times without any success.
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you able now to run SAS or MBAM? If you can open SAS, then go to preferences/ repairs...and scroll down to repair broken internet connection and see if that works.

    I need you to run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  25. kyteach00

    kyteach00 Private E-2

    Cannot run SAS or MBAM; nothing happens at all when I double click. (Have Windows XP). Tried the right click and "run as" option (currently the only way I can run anything) and neither opens.

    I can run MG tools and produced the ZIP file. Since I cannot connect to the internet (Internet Explorer will not open), what would be the safest method to transfer the MGlogs file to another computer to upload?

    Thanks for all the efforts; perhaps if I could run .exe files or use the registry editor life would be easier!
     
  26. kyteach00

    kyteach00 Private E-2

    Update: Found a way to save and upload file. All information from the previous post still accurate.
     
  27. kyteach00

    kyteach00 Private E-2

    The new log is attached here. When I run MG Tools, I still receive a message that Registry Editing is disabled before the cycle begins.
     

    Attached Files:

  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download and the below file to the root folder of your Windows boot drive. Normally this would be drive C. If you do this correctly, you will then see C:\MGtools.exe and FixAVP.exe.

    FixAVP

    Now run the FixAVP.exe file by double clicking on it. This will attempt to automatically run Avenger (which you already have) and it should also try to reboot your PC so don't be alarmed when this happens.

    After Reboot, and if all goes well, a new scan by MGtools should automatically take place because Avenger will try to run C:\MGtools\GetLogs.bat which will begin all the scans again.
    When GetLogs.bat finishes running, there will be a new C:\MGlogs.zip file and now it will be time to attach it to your next message. Make sure that you allow GetLogs.bat to finish running. It will tell you when it is finished. Do not close the command prompt window on your own until it is finished.
     
  29. kyteach00

    kyteach00 Private E-2

    Downloaded the file to the root folder as directed. I cannot open/execute the file as it is an .exe file and the virus has rendered my computer still unable to open any .exe application. It appears that the primary reason none of the fixes are working is that the computer cannot execute .exe programs.

    When double clicked, here is the error message:
    Choose the program you want to use to open this file.

    I have tried right clicking and selecting "Run as." I choose "current user" leave the box checked that says, "Protect my computer and data from unauthorized program activity." I then receive a message that says, "A device attached to the system is not functioning.

    If I right click as described above and uncheck the box (which is how I have been able to open MGTools), it appears that the program attempts to open; a ms dos type window with black background flashes for a microsecond then disappears. (Apparently being automatically closed by Antivirus pro). It never opens.

    I am logged in as administrator and have tried this option in safe mode and while not in safe mode.

    If it weren't for the problem with the .exe files, I'm sure this would be taken care of.

    Thank you for the patience in tackling this painful infestation!
     
  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  31. kyteach00

    kyteach00 Private E-2

    The Win32K log is attached.

    I cannot do anything with the Inherit.exe - when I drag something on top, I receive a message that says "c:inherit.exe application not found." I have tried saving into the root folder and on the desktop. Also tried in safemode and during regular mode - both times logged in as administrator to no avail. It acts just like the other .exe applications I cannot open. Hopefully we'll find something in the log...
     

    Attached Files:

    Last edited: Sep 14, 2009
  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    • Please save Win32kDiag file to your desktop.
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished,
      there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    "%userprofile%\desktop\win32kdiag.exe" -f -r
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    NOTE: DO NOT POWER DOWN or reboot your PC from now on unless requested or one of the procedures automatically reboots it.

    First I have a question, do you have your Windows Boot CD?

    Okay let's try some manual cleaning steps which sometimes work.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now try to delete the below files. Tell me what happens. Don't be surprised if you cannot delete some or all. Just continue on.
    C:\Documents and Settings\All Users\Application Data\buqotu.dl
    C:\Documents and Settings\All Users\Application Data\byqu.ban
    C:\Documents and Settings\All Users\Application Data\ohifef.scr
    C:\Program Files\Common Files\fuwawedob.vbs
    C:\Program Files\Common Files\ugesa.dat
    C:\953914188
    C:\hcel.exe
    C:\niawndos.exe
    C:\p2hhr.bat
    C:\rcvbm.exe
    C:\stub.log
    C:\umoikchf.exe
    C:\WINDOWS\braviax.exe
    C:\WINDOWS\checkip.dat
    C:\WINDOWS\cru629.dat
    C:\WINDOWS\ipconfig.dat
    C:\WINDOWS\ppp3.dat
    C:\WINDOWS\ppp4.dat
    C:\WINDOWS\rumyqebu.ban
    C:\WINDOWS\svchast.exe
    C:\WINDOWS\uwusyqijo.dat
    C:\WINDOWS\vaxomuqyw._dl
    C:\WINDOWS\wipdate.log
    C:\WINDOWS\ygedira.bin
    C:\WINDOWS\SYSTEM32\azipcontmn.dll
    C:\WINDOWS\SYSTEM32\bennuar.old
    C:\WINDOWS\SYSTEM32\bincd32.dat
    C:\WINDOWS\SYSTEM32\braviax.exe
    C:\WINDOWS\SYSTEM32\cru629.dat
    C:\WINDOWS\SYSTEM32\dddesot.dll
    C:\WINDOWS\SYSTEM32\desot.exe
    C:\WINDOWS\SYSTEM32\gekesupih.lib
    C:\WINDOWS\SYSTEM32\hs7f3uhduhfukde.dll
    C:\WINDOWS\SYSTEM32\html.iec
    C:\WINDOWS\SYSTEM32\ibylyfuxu.sys
    C:\WINDOWS\system32\lphcrl0j0endt.exe
    C:\WINDOWS\SYSTEM32\nocuguvo.reg
    C:\WINDOWS\SYSTEM32\onhelp.htm
    C:\WINDOWS\SYSTEM32\sysnet.dat
    C:\WINDOWS\SYSTEM32\tapi.nfo
    C:\WINDOWS\SYSTEM32\wisdstr.exe
    C:\WINDOWS\SYSTEM32\_scui.cpl
    C:\WINDOWS\SYSTEM32\DLLCACHE\beep.sys
    C:\WINDOWS\SYSTEM32\DRIVERS\BEEP.SYS

    If you were able to delete the two braviax.exe files list above then we want to create folders with that name to try to block it from coming back. So create the below folders (yes folders not files) yourself. Name them exactly as shown with the .exe extension. If you don't know how to create folders, just use Windows Explorer to navigate to first the C:\Windows folder and right click in it. Select New and then New Folder. Do the same for the system32 folder.
    C:\windows\braviax.exe
    C:\WINDOWS\system32\braviax.exe

    Now also try to delete the below folders.
    C:\Documents and Settings\All Users\Application Data\11215004

    Delete all files and folders in the below folders. Don't be surprised if you cannot delete some or all. Just continue on.
    C:\WINDOWS\Temp
    C:\Documents and Settings\Administrator\Local Settings\Temp
    C:\Documents and Settings\Karen\Local Settings\Temp

    Now copy the below file:
    C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\scecli.dll

    to C:\scecli.dll

    To copy the file, just right click on it and select Copy. Then navigate back to the C:\ folder and right click in the window pane for the C:\ folder and select Paste. Make sure the file appears there before continuing with the below. Do not continue if you did not get this file copied. Just come back and tell us how all the above worked and what problems you had.


    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Sep 20, 2009
  34. kyteach00

    kyteach00 Private E-2

    The log is attached.


     

    Attached Files:

  35. kyteach00

    kyteach00 Private E-2

    This response may have to be in "parts" as I complete one step, then another so that I can enter all information.

    No, I cannot locate my boot CD.

    Results of executing the fixme.reg:
    First; let me state that I had to save it in Unicode; hope that was correct. Received a message that says "Information in c: \documents and settings\administrator/desktop/fixme.reg has been successfully entered into the registry.

    So we are making progress...

    Next I am now working on deleting these file; if there is a faster way to do it than manually finding and deleting each, please let me know.

    Will respond when the next steps are finished
     
  36. kyteach00

    kyteach00 Private E-2

    Deleting files: those in RED I could not delete because I could not find them at the locations

    IMPORTANT NOTE: c:windows/system32/occache.dll is present. When I tried to delete it I received a message "ACCESS IS DENIED. Make sure disk is not full or write protected..."


    Now try to delete the below files. Tell me what happens. Don't be surprised if you cannot delete some or all. Just continue on.
    C:\Documents and Settings\All Users\Application Data\buqotu.dl
    C:\Documents and Settings\All Users\Application Data\byqu.ban
    C:\Documents and Settings\All Users\Application Data\ohifef.scr
    C:\Program Files\Common Files\fuwawedob.vbs
    C:\Program Files\Common Files\ugesa.dat

    C:\953914188
    C:\hcel.exe
    C:\niawndos.exe
    C:\p2hhr.bat
    C:\rcvbm.exe
    C:\stub.log
    C:\umoikchf.exe

    C:\WINDOWS\braviax.exe
    C:\WINDOWS\checkip.dat
    C:\WINDOWS\cru629.dat
    C:\WINDOWS\ipconfig.dat
    C:\WINDOWS\ppp3.dat
    C:\WINDOWS\ppp4.dat
    C:\WINDOWS\rumyqebu.ban
    C:\WINDOWS\svchast.exe
    C:\WINDOWS\uwusyqijo.dat
    C:\WINDOWS\vaxomuqyw._dl

    C:\WINDOWS\wipdate.log
    C:\WINDOWS\ygedira.bin
    C:\WINDOWS\SYSTEM32\azipcontmn.dll
    C:\WINDOWS\SYSTEM32\bennuar.oldC:\WINDOWS\SYSTEM32\bincd32.dat
    C:\WINDOWS\SYSTEM32\braviax.exe
    C:\WINDOWS\SYSTEM32\cru629.dat
    C:\WINDOWS\SYSTEM32\dddesot.dll
    C:\WINDOWS\SYSTEM32\desot.exe
    C:\WINDOWS\SYSTEM32\gekesupih.lib
    C:\WINDOWS\SYSTEM32\hs7f3uhduhfukde.dll

    C:\WINDOWS\SYSTEM32\html.iec
    C:\WINDOWS\SYSTEM32\ibylyfuxu.sys
    C:\WINDOWS\system32\lphcrl0j0endt.exe
    C:\WINDOWS\SYSTEM32\nocuguvo.reg

    C:\WINDOWS\SYSTEM32\occache.dll
    C:\WINDOWS\SYSTEM32\onhelp.htm
    C:\WINDOWS\SYSTEM32\sysnet.dat
    C:\WINDOWS\SYSTEM32\tapi.nfo
    C:\WINDOWS\SYSTEM32\wisdstr.exe
    C:\WINDOWS\SYSTEM32\_scui.cpl
    C:\WINDOWS\SYSTEM32\DLLCACHE\beep.sys
    C:\WINDOWS\SYSTEM32\DRIVERS\BEEP.SYS

    If you were able to delete the two braviax.exe files list above then we want to create folders with that name to try to block it from coming back. So create the below folders (yes folders not files) yourself. Name them exactly as shown with the .exe extension. If you don't know how to create folders, just use Windows Explorer to navigate to first the C:\Windows folder and right click in it. Select New and then New Folder. Do the same for the system32 folder.
    C:\windows\braviax.exe
    C:\WINDOWS\system32\braviax.exe

    Created folders in locations as described.

    Now also try to delete the below folders.
    C:\Documents and Settings\All Users\Application Data\11215004 Successfully deleted

    Delete all files and folders in the below folders. Don't be surprised if you cannot delete some or all. Just continue on.
    C:\WINDOWS\Temp DONE
    C:\Documents and Settings\Administrator\Local Settings\Temp done
    C:\Documents and Settings\Karen\Local Settings\Temp Karen is not accessible; ACCESS DENIED

    Now copy the below file:
    C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\scecli.dll

    to C:\scecli.dll

    Followed these instructions to a "t." I could not right click on it to paste without first higlighting all the text. It appeared that the text was copied (this was a choice when I right clicked), but there was no option to paste when I opned the c:\ folder. I also tried Ctrl v with no success.

    DID NOT CONTINUE ON since I could not complete the step


    To copy the file, just right click on it and select Copy. Then navigate back to the C:\ folder and right click in the window pane for the C:\ folder and select Paste. Make sure the file appears there before continuing with the below. Do not continue if you did not get this file copied. Just come back and tell us how all the above worked and what problems you had.
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note: I'm removing the occache.dll file from my fix since that was a file I was supposed to edit out of the fix.

    I'm not sure that you are following the instruction properly. You are not suppose to be highlighting the text in my message to copy. You need to first navigate to the below folder on your hard disk:

    C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e

    Then you need to locate the scecli.dll file and right click on it and select Copy.

    Then you need to navigate back to the C:\ folder (the root folder) and right click in the window pane showing the root folder contents and select Paste to copy the file their.

    Does that help?
     
  38. kyteach00

    kyteach00 Private E-2

    My apologies; I was attempting to copy and paste from the forum, not the folder!

    I am now in the correct folder, but there is not a scecli.dll file located there. I do have files by that name located in the following folders:

    c:\
    c:\Avenger
    c:\I386
    C:\windows|system32
    c:\windows/servicepackfiles/\i386

    Would any of these be the one that I need?

    Thanks for being so patient with me. This has been a bear...
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    According to your last MGlogs.zip file which contains the newfiles.txt log, the below files existed which we could chose from. The one in bold is the one I suggested copying because it is the correct version of the file. The others are various older versions.

    "C:\i386\SCECLI.DLL" 174592 08/29/2002 06:00 AM
    "C:\WINDOWS\$NtServicePackUninstall$\scecli.dll" 174592 08/29/2002 06:00 AM
    "C:\WINDOWS\ServicePackFiles\i386\scecli.dll" 180224 08/04/2004 03:56 AM
    "C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\scecli.dll" 181248 04/13/2008 08:12 PM


    Read my comments in purple and red. :)
    If the scecli.dll file in C:\ is 181,248 bytes in size (right click and select Properties to see this info) then it is the correct file and you can just move to the rest of the fix.
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I see what happened. Back in msg # 17, TimW had you run Avenger and did the below as part of the fix:

    Files to move:
    C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\scecli.dll | C:\WINDOWS\SYSTEM32\scecli.dll

    This MOVED the file out of the folder I saw in your log and into the C:\Windows\system32 folder. If this actually worked properly then the C:\Windows\system32\scecli.dll file should be 181,248 bytes in size as previously mentioned. Just tell me what you see for file size of the C:\Windows\system32\scecli.dll file.

    In fact, do the below to get us a more current/up to date log since things seem to be out of sink.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Then attach the below log:
    • C:\MGlogs.zip
     
  41. kyteach00

    kyteach00 Private E-2

    The version in c:\is 180,224 bytes. I have a file sceli.dllmg in c:\mgtools\temp\sp3 that is exactly that size. Is it okay to just copy this or can it be edited to work?




     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The you have already run the new version of MGtools and the log you posted back in msg #27 is out of date. We need to see the new MGlogs.zip file before doing anything else. Please attach the C:\MGlogs.zip file now.
     
  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Wait.......! I see TimW had you run FixAVP. That is why you have those files in MGtools\temp\sp3

    You still need to download and run the new versio of MGtools as I requested a couple messages ago.
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It would be in your best interest to try and stay logged in for a while when we are trying to help you. Otherwise I will have to just let you wait until your turn in the queue comes up which means every 5 days or so to get an answer to each message. I was trying to expediate things but you keep logging out.
     
  45. kyteach00

    kyteach00 Private E-2

    There is some type of auto log-out that times out on me...working on the fixes now.
     
  46. kyteach00

    kyteach00 Private E-2

    THe new MGLogs file is attached. I'm assuming I was supposed to skip running Avenger for now. HOpe this was correct!
     

    Attached Files:

  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! I wanted to see what the real current status was since the previous log was out of date and not reflecting your current state. I'm looking at the logs now.

    In the meantime, repeat the below steps.

    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    C:\win32kdiag.exe -f -r
     
  48. kyteach00

    kyteach00 Private E-2

    I think we're getting somewhere at last!
     

    Attached Files:

  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes we have made some progress.

    No put your PC into normal startup mode with MSconfig as requested in the READ & RUN ME. Then continue.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    J2SE Runtime Environment 5.0
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) 6 Update 7
    Viewpoint Manager (Remove Only)
    Viewpoint Media Player

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now see if you can run ComboFix per the READ & RUN ME
    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  50. kyteach00

    kyteach00 Private E-2

    I made the msconfig change but am having to restart in safemode. When I logged in as admin in regular mode, I could not access internet explorer; I keep receiving the "Internet Explorer has encountered and error and needs to close message."

    Proceeding in safe mode with removal steps.
     
    Last edited by a moderator: Sep 21, 2009

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds