Windows File Protection? 60 Processes running.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by crazycat243, Dec 28, 2007.

  1. crazycat243

    crazycat243 Private E-2

    Recently infected with malware/trojans. I think AVG Free successfully removed, however the Sonic Update Manager starts every time I start windows. Also, Windows File Protection pops up and says that some versions of files are not recognized. The system is running extrememly slow, and running approx. 60 processes at any given time. I just ran ComboFix and MGtools today. Any support is greatly appreciated!
     
  2. crazycat243

    crazycat243 Private E-2

    OOps! here's they ComboFix and MG logs.
     

    Attached Files:

  3. abri

    abri MajorGeek

    Hi crazycat243!
    Welcome to Major Geeks!
    Still missing your AVG-Antispyware log and your MGlogs.zip

    The MGlogs.zip should be directly under C or whichever drive has your operating system in it. Your hijackthis log will be part of the zip file, not separate.
    abri
     
  4. crazycat243

    crazycat243 Private E-2

    I'm not sure if this is what you need from AVG. It is not creating logs for me to save.:confused
     

    Attached Files:

  5. crazycat243

    crazycat243 Private E-2

    Please help!
     
  6. abri

    abri MajorGeek

    Hi crazycat243!

    Do you have two resident antivirus programs running? If so, please uninstall one of them.

    Then continue as follows:

    1) Go to add/remove programs and uninstall the below:

    Viewpoint Media Player
    J2SE Runtime Environment 5.0 Update 6"
    Java 2 Runtime Environment, SE v1.4.2_03"
    Java(TM) 6 Update 2
    Java(TM) SE Runtime Environment 6 Update 1




    2) Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F3 - REG:win.ini: load=C:\WINDOWS\system32\ddcyx.exe

    After you click fix, just close hijackthis.


    3) Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Make sure you tell me how things are working now!


    4) Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.


    5) Please run C:\MGtools\GetLogs.bat and attach the fresh MGlogs.zip it generates along with the Avenger log.


    Let me know how things are running now?

    abri
     
    Last edited by a moderator: Jan 1, 2008
  7. crazycat243

    crazycat243 Private E-2

    Abri
    Wasn't able to work with my PC until this morning. AVG Antivirus Free detected the following during a scan overnight:
    Virus name: Virus found Lop filename: ptch[1]
    Trojan horse BackDoor.Agent.PTA filename: blsyniag.exe
    Virus found Lop filename: htcp[1]

    I quarantined them and don't plan on doing anything with them without your approval.

    I removed the old java apps. After this i started getting a bunch of popups.
    I also tried to remove MicroTrend, an antivirus software I received free from Dell, but it asked me for a password which I don't know, so I left it alone.

    I ran analyse.exe

    I also downloaded and ran Avenger. It didn't prompt me to reboot, so I rebooted myself. System is still full of processes (approx 60), Windows File Protection popped up on startup, and Sonic Update manager is dying to install an update from source '1'. Honestly I don't even use the Sonic programs, so I wouldn't mind getting rid of them. The problem is that it came with the PC from Dell, so I don't know if I will need a password to unlock the uninstaller.

    Since you wanted to know how things were working after this, I'm waiting for a response before beginning with ATF Cleaner.
     
  8. crazycat243

    crazycat243 Private E-2

    here's the MGlogs. For whatever reason, avenger did not create a log. Perhaps I need to run it again? it never prompted me that my computer needed to be rebooted after it was finished.

    -crazy
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That means it did not work properly. You need to repeat the procedure but first uninstall AVG 7 Free Antivirus since you cannot uninstall TrendMicro. Then shutdown as much of TrendMicro as you can before running the steps with Avenger. Be sure to copy ALL OF THE INFO inside the quote box. Make sure you recopy it because I made some changes to it.

    When finished, attach the Avenger log and a new MGlogs.zip file.
     
  10. crazycat243

    crazycat243 Private E-2

    Avenger still isn't doing anything. I input the script. click the traffic light. the whole program closes. thats it!
    -crazy
     
  11. abri

    abri MajorGeek

    Hi CrazyCat!

    Avenger is the best tool so I would prefer to get it to work if possible. If it simply won't work, I will give you another tool to use. First let me ask you if you downloaded the zip file to the desktop? If so, did you then extract the Avenger.exe and save it also to the desktop? And when you copied the contents of the box, did you include the words "Files to delete" and "Registry keys to delete"? The contents of the box have to be completely copied, not just the file. The above are the three main reasons why Avenger doesn't run properly.

    You can alternatively run the following:

    1) Download - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.


    2) Now copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Quote:
    REGEDIT4
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0092E95-78AE-4DDF-8CCF-54A71FFF7C63}]

    3) Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.

    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\drivers\lvuvc.hs
    C:\WINDOWS\system32\jpewocmz.ini
    C:\WINDOWS\system32\xycdd.ini
    C:\WINDOWS\system32\xycdd.ini2
    C:\WINDOWS\system32\RCX3A.tmp
    C:\WINDOWS\system32\RCX3B.tmp
    C:\WINDOWS\system32\RCX6A.tmp
    C:\WINDOWS\system32\ddcyx.dll
    C:\WINDOWS\system32\ddcyx.exe
    C:\WINDOWS\mrofinu72.exe.tmp
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    4) Please run C:\MGtools\GetLogs.bat and attach the fresh MGlogs.zip it generates
    That log is under C:\

    abri
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you download Avenger.zip as requested? Or did you try to run Avenger from the online link? Where exactly is the Avneger.zip file located on your PC. Where is the Avenger.exe file located on your PC?

    Abri, I doubt that Killbox will be of any use to you. If Avenger really will not run, then you will most likely have to use ComboFix.
     
  13. crazycat243

    crazycat243 Private E-2

    Here's a quick update. MicroTrend discovered Vundo after an update. I'm going to go through the removal procedures for it now. Maybe this is what has been plauging me the whole time?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Vundo is what we have been working on since the beginning and Trend Micro is not going to remove it. Only the manual steps we are giving you will. As I stated in message # 12, I don't believe Killbox will work. Either you have to get Avenger to work or a fix using ComboFix will have to be created.
     
  15. crazycat243

    crazycat243 Private E-2

    Oh! I didn't know that Vundo is what the problem was. I ran VundoFix found in the stickeys in the malware forum. Attached are the VundoFix and Hijack logs.
    I would like to also note that windows file protection didn't prompt after reboot! I did however receive an error message which after reporting, allowed me to download the fix from Microsoft. I'm also not getting popups at this time.

    In response to the questions about Avenger..
    Will Avenger work in safe mode?
    Avenger is located on my desktop as well as the zip.
    Yes I copied and pasted the quotes before and after chaslang's edit.
     

    Attached Files:

  16. abri

    abri MajorGeek

    crazycat,
    VundoFix isn't adequate to remove Vundo, but I can see from hijackthis that the infection is still there, which means, that VundoFix didn't remove it. It's because it's a difficult infection to remove, that certain procedures and tools are used in this forum which allow for its removal. It's a manual process which requires your assistance to us in providing the logs we request and in installing and implementing the tools in a way that they can work. To get your logs up-to-date, please run C:\MGtools\GetLogs.bat and attach the fresh MGlogs.zip. This will allow me to see if some of the files were removed by VundoFix and which ones still remain. The one which generates all the new files is still there, healthy and kicking.

    Thanks :)
    abri
     
  17. crazycat243

    crazycat243 Private E-2

    Sorry Abri. Here's the new zip.

    Upon reboot earlier I received the following... not sure if it will help you at all.

    RUNDLL
    Error loading C:\windows\system32\ckwcyraj.dll
    The specified module could not be found.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now run the C:\MGtools\VunFind.bat file by double clicking on it and be patient while it scans your whole hard disk.

    Then reattach the below C:\MGlogs.zip which will be updated with the results from Vunfind.bat.

    Note to Abri:

    This VunFind.txt log will be needed to create a full fix using ComboFix. Avenger and Pocket Killbox will not work. In fact for most of the current infections we see you can forget using Killbox completely.
     
    Last edited: Jan 5, 2008
  19. crazycat243

    crazycat243 Private E-2

    Here it is after running Vunfind
     

    Attached Files:

  20. abri

    abri MajorGeek

    Hi crazycat!

    Please copy the contents of the box below into Notepad and save the notepad file to the Desktop with the name Log.txt

    • Now using your mouse, drag Log.txt onto RenV.exe
    • When finished, RenV.exe will produce a new log. Attach the new Log.txt to your next reply.
    • Run ComboFix
    • Run C:\MGtools\GetLogs.bat by double clicking on it.
    • Attach the below new logs:
      • Log.txt
      • C:\ComboFix.txt
      • C:\MGlogs.zip
    abri
     
  21. crazycat243

    crazycat243 Private E-2

    What is RenV?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    LOL! Looks like Abri forgot something. ;)

    Are you going to be logged in for awhile? I would like to work on this right now to get some information collected, but I don't want to start posting if you have to leave.
     
  23. crazycat243

    crazycat243 Private E-2

    Here's the Log it created.
     

    Attached Files:

  24. crazycat243

    crazycat243 Private E-2

    Yes I'll be online for a while.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay did you do anything else from Abri steps! If not, don't.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also did you put RenV.exe on your Desktop? If not, it MUST be on your Desktop.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hello!!!! I need to have your attention here on this thread. DO NOT RUN ANYTHING ELSE!!! I need to know when you are back here paying attention and address my questions and concerns about where RenV.exe is located. DO NOT RUN COMBOFIX. I see you reading that thread.
     
  28. crazycat243

    crazycat243 Private E-2

    too late...=[ !! I'm online now. everytime i'm on it shows you are offline. I didn't see this thread before running combofix. i saved RenV.exe to the desktop.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then you need to attach the ComboFix log.
    You need to answer my question about RenV
    Attach a new MGlogs.zip file from running C:\MGtools\GetLogs.bat
    And a new Log.txt file from running RenV.exe

    And do not do anything else unless I ask you to.
     
  30. crazycat243

    crazycat243 Private E-2

    you want me to paste into RenV or just run it?
     

    Attached Files:

  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just run RenV first. I want to see what remains. We may be pasting the Log right back in but I need to see it first.
     
  32. crazycat243

    crazycat243 Private E-2

    here's the log from RenV
     

    Attached Files:

    • log.txt
      File size:
      189 bytes
      Views:
      3
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's what I thought was going to happen. The new version of ComboFix has removed many of the files that were being spawn by the infection. Your Log.txt file now shows no duplicate file names. Butt I do see some issues in your logs. While I look thru all of them, please run C:\MGtools\VunFind.bat and then attach a new the new MGlogs.zip file that will be updated by running VunFind. This will get the VunFind.txt log up to date in the file.
     
  34. crazycat243

    crazycat243 Private E-2

    vunfind update
     

    Attached Files:

  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good! VunFind also said the duplicate files are gone. Now we need to get answers to the below.

    You HJT log shows these processes with spaces in the EXE files. This was caused by the infection
    What I want to know is whether the valid files still exist. Check out the following.

    Go here: C:\Program Files\Common Files\InstallShield\UpdateService
    Does isuspm .exe exist or is it isuspm.exe
    What is the file size and date?

    Go here: C:\Program Files\QuickTime
    Does qttask .exe exist or is it qttask.exe
    What is the file size and date?


    Go here: C:\Program Files\MSN Messenger
    Does msnmsgr .exe exist or is it msnmsgr.exe
    What is the file size and date?
     
  36. crazycat243

    crazycat243 Private E-2

    isuspm.exe, 29 Dec 07, 244 kb
    qttask.exe, 03 Jan 08, 96kb
    msnmsgr.exe, 03 Jan 08, 5.41 mb
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you give me the sizes in bytes instead of Kbytes? You can get this by right clicking on them and selecting Properties.
     
  38. crazycat243

    crazycat243 Private E-2

    isuspm.exe 249,856 b
    qttask.exe 96,304 b
    msnmsgr.exe 5,674,352 b
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now I want to try using Avenger again since most of the infection is removed. If it still does not run, we will either use ComboFix to remove the indicated Files and Folder or we can do it manually.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  40. crazycat243

    crazycat243 Private E-2

    Ok! Avenger set up to run on restart this time. After restart it said can't find Avenger.txt. Do you wish to create? I clicked yes. It brought up a blank notepad. Since that seemed odd to me, I stopped to let you know. I haven't run CCleaner or getlogs yet.
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if you can find and delete the files and single folder I listed yourself. If you get them all deleted, then run the GetLogs.bat file to get the new log.

    Also tell me how things are running.

    Where is the Avenger.exe file on your PC?
     
  42. crazycat243

    crazycat243 Private E-2

    I deleted them. I could not find avexport.bat or ckwcyraj.dll.
    Also, when I deleted nqpisdfu.ini it gave me the 'system file' warning and told me a program may stop responding. All of the deleted items are in the recycle bin. Do you want me to empty the recycle bin or just get you the logs?

    Avenger.exe is located on the desktop.
     
  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just attach the new log first. Note if you ran CCleaner though your Recycle Bin would be empty so I assume you did not run it.
     
  44. crazycat243

    crazycat243 Private E-2

    I (just now, before getlogs.bat) ran CCleaner to empty all the temp files. I didn't run the registry scanner.
     

    Attached Files:

  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And you should not as it is not part of our instructions.

    You did not tell me how things are working.

    Your logs are clean.
     
  46. crazycat243

    crazycat243 Private E-2

    Things seem to be running much faster. Down to 45 proccesses. So do you think its all gone?
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes based on your logs it is gone.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    12. After doing the above, you should work thru the below link:
     
  48. crazycat243

    crazycat243 Private E-2

    Thank you so much! I want to ask also.. where did you learn how to do all of that?
     
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome from me and Abri.

    By using PCs for a long time at home and at work. And by reading alot! ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds