Error messages (ddccy.exe and gebby.dll) plus a really slow system...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by board, Jan 26, 2008.

  1. board

    board Private E-2

    Hi
    i think i've got a problem with my laptop. Everytime i boot the system up, 2 warnings pop up on the desktop. the first is:

    Could not run or load ‘C:\Users\jdhansom\appdata\local\temp\ddccy.exe’ specified in the registry. Make sure the file exists on your computer or remove the reference to it in the registry.

    and the second one is:

    Error loading C:\users\jdhansom\appdata\local\temp\gebby.dll. the specified module could not be found.

    After clicking o.k on these they don't come up again until i reboot the computer. I'm also sure my system is running pretty slow, and often when typing, letters are missed out..perhaps because the system can't keep up (and i'm not a fast typist..)
    I figured i may have malware or whatever so have ran Adaware, Spybot and norton...to no avail.

    If anyone has any advice to restore my laptop to its usual speeds and sort out the erro messages that would be great...

    I'm running Vista and will post a hijack this log here in a minute... my system appears to have frozen and it looks like i'll have to reboot.
    thanks
    Donald
     
  2. board

    board Private E-2

    here's the hijack this log...

    Edit by chaslang: Inline HJT log removed. READ & RUN ME sticky not followed.
     
    Last edited by a moderator: Jan 27, 2008
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  4. board

    board Private E-2

    Hi,
    o.k so i follwed the instructions and ran the various scans as advised. I still get the ddccy.exe but the gebby.dll error appears to have stopped. the system seems to be running slow and when i type letters still keep getting missed out...v.anoying. i'm also getting loads of pop-ups when on the net.

    I've also started getting a new error when in internet explorer:
    'Buffer overrun detected!
    program:c\windows\explorer.exe
    a buffer overrun has been detected which has corrupted the programs internal state. The program cannot safely continue execution and must now be terminated.'

    I'v attached the MGlogs.zip and the AVG log.

    any help would be great...
    thanks
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the requested log from ComboFix. It is at C:\combofix.txt

    Is your copy of Spyware Doctor a paid version or a free trial version? If free, uninstall it now. If paid, make sure your tell me.

    Now Disable Spybot's TeaTimer as requested in the READ & RUN ME
    • Run Spybot and click Mode
    • Select Advanced Mode.
    • Then click Tools and select Resident.
    • Now in the right window pane, uncheck TeaTimer.
    • Also while this is open, in the left column now select IE Tweaks
    • and then in the right pane make sure all the Miscellaneous locks are unchecked.
    • Now quit Spybot!
    Disable Windows Defender's realtime protection:

    Disable Windows Defender:
    • Open Windows Defender
    • Click Tools
    • Click General Settings
    • Scroll down to Real Time Protection Options
    • Uncheck Turn on Real Time Protection (recommended)
    • Close Windows Defender
    Once your log is clean you can re-enable Windows Defender Real Time Protection.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {3AB6CF00-6CDC-4942-A4E5-1FEE54326FF1} - C:\Users\jdhansom\AppData\Local\Temp\ddccy.dll
    O2 - BHO: (no name) - {EC5E2CAB-76AE-4E7A-9E14-F62B61FB9294} - C:\Users\jdhansom\AppData\Local\Temp\ddccy.dll

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a some files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    File::
    C:\Windows\eRy.exe
    C:\Windows\Temp\symlcsv1.exe
    C:\Users\jdhansom\AppData\Local\Temp\ddccy.dll
    C:\Users\jdhansom\AppData\Local\Temp\RtkBtMnt.exe
    C:\Users\jdhansom\AppData\Local\Temp\yccdd.ini
    C:\Users\jdhansom\AppData\Local\Temp\yccdd.ini2
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jan 31, 2008
  6. board

    board Private E-2

    Hi there...
    O.k so i followed u're instructions and disabled spybot's TeaTimer and windows defender. I then went to run C:\MGtools\analyse.exe to select and fix the specified registry entries:
    O2 - BHO: (no name) - {3AB6CF00-6CDC-4942-A4E5-1FEE54326FF1} - C:\Users\jdhansom\AppData\Local\Temp\ddccy.dll
    O2 - BHO: (no name) - {EC5E2CAB-76AE-4E7A-9E14-F62B61FB9294} - C:\Users\jdhansom\AppData\Local\Temp\ddccy.dll

    These were not present.... any ideas? I didn't continue with the other instructions...but i can...

    On a different note i'm getting a new error message:

    Error in C:\users\jdhansom\appdata\local\temp\cskrpbvf.dll
    missing entry:run

    Not sure what this is all about..also attached the combofix.txt this time..

    Cheers
    Donald
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just continue on with all instructions and ignore those O2 line in HijackThis. They may have renamed themselves or may have already been deleted. They were in your previous logs but malware can change names at each power down or reboot. After completing all instructions and attaching your new logs, DO NOT power down or reboot so we can avoid this problem.
     
  8. board

    board Private E-2

    Hi,
    o.k so i continued with the instructions....
    i pasted the quoted txt into notepad, named it as requested and dragged it onto the combofix.exe.
    This resulted in an error saying...
    'you cannot rename combofix as combofix please use another name'

    any ideas? i tried deleting combofix and downloading the combofix.exe file again and dragging and droppig the txt file ontop... same result...

    Donald
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are not doing something correctly. Just dragging the CFScript.txt (did you name it CFScript.txt) file ontop of ComboFix should cause it to run. It should not cause it to try and be renamed. Are you right clicking or left click with your mouse?
     
  10. board

    board Private E-2

    hi i'm dragging the txt file with the left mouse button and dropping it on the combofix.exe file. I just tried again and the program does try to run. I get a blue screen that looks a bit like DOS. The program then says
    'please wait,combofix is preparing to run' so i wait, not clicking or pressing any keys... it then says 'out of memory'
    and a windows box appears saying
    'freeware implementation of reg.exe has stopped working... a problem caused the program to stop working correctly. windows will close the program and notify you if a solution is available' with a 'close program' option...

    Donald
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is a different thing than what you said in your previous message.

    Since you are running Vista, it is critical that you have UAC disabled. Do you still have UAC disabled? This was covered in the Using MGtools link in the READ ME.

    It is also quite possible that any protection software you are running is interferring with ComboFix. Thus shutdown all protection software before trying the fix (like Spyware Doctor, AVG Antispyware, and Symantec). If you still have a problem after trying all of the above, boot into safe mode and try the fix.

    I previously asked you if Spyware Doctor was a paid or free version and you did not answer. If free, just uninstall it.

    Let me know the results.
     
  12. board

    board Private E-2

    Hi,
    o.k i tried what you suggested... still no luck. tried in safe mode also and that results in the same messages as mentioned previously. I did have a free version of spyware doctor but uninstalled it when you first suggested to remove it.
    I'm now having more problems however. For example at present when i opened a new tab in explorer i loose the task bar with the start menu etc so will have to go into task manager to shutdown. Also opening things like control panel to switch of UAC doesn't work...the window just flashes up then dissappears. very strange. The UAC is off now however, i had to go in through safe mode to do this.

    any thoughts?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try booting in safe mode and do the below:



    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines (or any similar lines will DLL files that are loading from your Temp folder) but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {3AB6CF00-6CDC-4942-A4E5-1FEE54326FF1} - C:\Users\jdhansom\AppData\Local\Temp\ddccy.dll
    O2 - BHO: (no name) - {EC5E2CAB-76AE-4E7A-9E14-F62B61FB9294} - C:\Users\jdhansom\AppData\Local\Temp\ddccy.dll

    After clicking Fix, exit HJT.

    Then locate the below files and delete them yourself:
    C:\Windows\eRy.exe
    C:\Windows\Temp\symlcsv1.exe
    C:\Users\jdhansom\AppData\Local\Temp\ddccy.dll
    C:\Users\jdhansom\AppData\Local\Temp\RtkBtMnt.exe
    C:\Users\jdhansom\AppData\Local\Temp\yccdd.ini
    C:\Users\jdhansom\AppData\Local\Temp\yccdd.ini2

    If any of them will not delete, reboot your PC back into safe mode and then try deleting them.

    Then no matter what happens while doing the above, come back here and tell me what happened while trying to do the above and then run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below log:
    • C:\MGlogs.zip
     
  14. board

    board Private E-2

    hi
    o.k i booted in safe mode, ran C:\MGtools\analyse.exe and deleted all lines with DLL files that were loading from my Temp folder, closed all winows and clicked fix. i then went about manually deleting the specific files mentioned.
    File C:\Windows\Temp\symlcsv1.exe was not present,
    the rest were all there, and were deleted except
    C:\Users\jdhansom\AppData\Local\Temp\ddccy.dll
    When i tried to delete this (both in safe mode and normally) i got the following message...
    'the action cannot be completed because the file is open in another program
    close the file and try again'
    At this point all other windows (and to my knowledge, programs) were shut down, so i couldn't figure out how this file was in use.
    Other than that, all else was fine.

    Donald
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to allow GetLogs.bat to run until it is finished. You closed to command prompt window before it was finished. See the snapshot on the Using MGtools download page that shows you what it will look like when it is finished.

    Attach a new log afterwards. Make sure that you have already disabled UAC and rebooted before you try to run GetLogs.bat and also make sure your use Run As Administrator as requested on the Using MGtools page for Vista users.


    We need to get ComboFix to run on your computer some how or we may not be able to fix your problems. The DLL files are in use because they are hooked in to Windows system processes that are running.
     
  16. board

    board Private E-2

    hi,
    ok so i disabled UAC rebooted and ran 'getlogs.bat'. attached is the MGLogs.zip file which is now updated.

    any ideas how i can get combofix to work??
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you are not using HijackThis's (analyse.exe) ability to filter processes or items from the logs. We need to be able to see everything and your HJT process list is not showing all Windows processes.

    Uninstall AVG Antispyware that was installed in the while doing the READ ME.

    I see you have Ad-Aware's Ad-Watch feature running. If you are going to use this you should not use Windows Defender otherwise they may conflict with each other. So either uninstall Ad-Aware 2007 or disable Windows Defender.

    In fact, Windows Defender has even been infected by the Vundo infection. The ddccy.dll file has hooked into Windows Defender and runs anytime that Defender is running. Also Ad-Aware 2007, Windows Defender and Symantec AV may be the reason for your problems with ComboFix so you may want to consider actually uninstalling Ad-Aware 2007 for now and then disabling Windows Defender. The reason for trying this is because if we cannot get ComboFix to work, you may have to do a reinstall to fix this problem since there are no other tools that support Vista that can help us to remove this Vundo infection.

    I will attempt to create another manual type fix below, but it is going to be long an tedious since the infection has hooked itself into many of your running processes. At last count it was hooked into 19 processes which is why you could not manually delete the files and is why it keeps coming back. Anytime any one of these process run, the infection is recreated. And in addition, there are dozens of other files related to the infection in your Temp folders.

    Continue by downloading Process Explorer which will we use to try and unhooked the Vundo DLL from your running processes.
    • Extract it to its own folder somewhere that you will be able to locate it later.
    • Make sure that one and only one Internet Explorer browser is opened up
    • Run Process Explorer
    • Below I will give a list of process that you will have to double click on (one at a time) to bring up a Properties form. On the Properties form you will click on the Threads tab at the top to show the Threads.
    • Once you see the Threads form, click on each instance of ddccy.dll or ddccy.exe (if found) and then click the kill button. Take care to look thru the list carefully to find these hooked ddccy files. You may only find the ddccy.dll file but make sure you look for both and look for multiple occurrences.
    • After you have killed all instances of any of the DLL under the process, click OK and move on to the next process (If you do not find the DLL, just continue on.)
    Here is the list of processes to perform the above procedure on:
    ERAGENT.EXE
    RtkBtMnt.exe
    ENMTRAY.EXE
    WZQKPICK.EXE
    BTTray.exe
    lsass.exe
    taskeng.exe
    iexplore.exe
    rundll32.exe
    wmpnscfg.exe
    winamp.exe
    sidebar.exe
    Explorer.EXE
    RtHDVCpl.exe
    EPOWER_DMC.EXE
    MSASCui.exe
    Dwm.exe
    ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
    WLLoginProxy.exe
    • After you have killed all instances of any of the ddccy.dll or ddccy.exe under all of the processes, just exit Process Explorer and continue.
    Now run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F3 - REG:win.ini: load=C:\Users\jdhansom\AppData\Local\Temp\ddccy.exe
    O2 - BHO: (no name) - {2106773A-C69D-411E-9F51-66729C0FEBFE} - C:\Users\jdhansom\AppData\Local\Temp\ddccy.dll
    O2 - BHO: {04a5a35f-c266-52c9-fc34-2f3ec919e6a9} - {9a6e919c-e3f2-43cf-9c25-662cf53a5a40} - C:\Windows\system32\clwrnegs.dll (file missing)
    O2 - BHO: (no name) - {F269E76F-AC5C-411A-86B5-619740F138AE} - C:\Users\jdhansom\AppData\Local\Temp\ddccy.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\jdhansom\AppData\Local\Temp\ddccy.dll,c

    After clicking Fix, exit HJT.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now delete the below file:
    C:\Windows\System32\aebnyxci.ini

    Now delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Windows\Temp
    C:\Users\jdhansom\AppData\Local\Temp

    If you have problems deleting any files, note the file name to try again later on and to tell me also.

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    You should print or save the below locally because it would be best that you do not open any browers or run anything except what is requested below when we boot into safe mode.

    Now reboot your PC into safe mode where we will repeat some of the above steps.

    Now while in safe mode continue with the below.

    Now delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Windows\Temp
    C:\Users\jdhansom\AppData\Local\Temp

    If you have problems deleting any files, note the file name and tell me when you come back.

    Now run ATF-Cleaner again.

    While in safe mode, also try to run ComboFix again!!! Just continue if you cannot.

    Now reboot in normal mode.

    Come back here and tell me what happened while trying to do the above and then run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below log:
    • C:\MGlogs.zip
    • also attach C:\ComboFix.txt if it ran.
     
  18. board

    board Private E-2

    hi,
    o.k so i uninstalled AVG and ad-aware. i then downloaded processes explorer and killed all the ddccy.exe and ddccy.dll threads.
    i ran C:\MGtools\analyse.exe and 'fixed' the specified lines. 2 of them however wern't there...
    'O2 - BHO: (no name) - {2106773A-C69D-411E-9F51-66729C0FEBFE} - C:\Users\jdhansom\AppData\Local\Temp\ddccy.dll' and
    'O2 - BHO: (no name) - {F269E76F-AC5C-411A-86B5-619740F138AE} - C:\Users\jdhansom\AppData\Local\Temp\ddccy.dll'
    I also merged the specified lines with the registry and deleted the contents of the files. Everything could be deleted o.k except ddccy.dll that was in the users temp file. tried deleting it in safe mode, and got the same message that it was being used by another program and couldn't be deleted. i also tried combofix in safe mode again...and got the same message 'out of memory'. I didn't do the ATF-cleaner as it said to only be used in windows xp and 2000...i have vista.
    on the up, when i booted my laptop up after safe mode i didn't get either of the original error messages.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the requested new MGlogs.zip file. If that DLL file did not delete you are still infected and it could be hooked into another running process which may be why you could not delete it. Even if you already created the new MGlogs.zip file, get a brand new one right now to attach. And then DO NOT power down or reboot your PC because power down/up or reboots can cause the infection to mutate or spread which would make your logs invalid for any fix I create after you post them.

    Strange, I thought we tested ATF-cleaner on Vista. I'll have to recheck.
     
  20. board

    board Private E-2

    hi,
    sorry forgot to run mgtools again...so thats done. attached is the new zip file... I'll leave the laptop on from now on...
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that DLL file is still hooked into some running processes. Until we get it unhook from all process, you will not be able to delete those ddccy.exe and ddccy.dll files. Let's try again a similar fix. Be very careful to find everything listed. Why I'm giving you is direct from the logs you just posted. So if you kept your PC running, these should all be found. However it is possible that just by running during this time frame that the DLL has hook into more process.

    • Extract it to its own folder somewhere that you will be able to locate it later.
    • Make sure that one and only one Internet Explorer browser is opened up
    • Run Process Explorer
    • Below I will give a list of process that you will have to double click on (one at a time) to bring up a Properties form. On the Properties form you will click on the Threads tab at the top to show the Threads.
    • Once you see the Threads form, click on each instance of ddccy.dll or ddccy.exe (if found) and then click the kill button. Take care to look thru the list carefully to find these hooked ddccy files. You may only find the ddccy.dll file but make sure you look for both and look for multiple occurrences.
    • After you have killed all instances of any of the DLL under the process, click OK and move on to the next process (If you do not find the DLL, just continue on.)
    Here is the list of processes to perform the above procedure on:
    lsass.exe
    iexplore.exe
    rundll32.exe
    explorer.exe

    • After you have killed all instances of any of the ddccy.dll or ddccy.exe under all of the processes, just exit Process Explorer and continue.
    Now run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F3 - REG:win.ini: load=C:\Users\jdhansom\AppData\Local\Temp\ddccy.exe
    O2 - BHO: (no name) - {BAD06BB2-D818-480F-9113-2D2E464A50AF} - C:\Users\jdhansom\AppData\Local\Temp\ddccy.dll
    O2 - BHO: (no name) - {C7FE111D-CF47-4D4A-8121-D27C464C2355} - C:\Users\jdhansom\AppData\Local\Temp\ddccy.dll

    After clicking Fix, exit HJT.

    Right now see if you can manually delete the below files ( if found):
    C:\Users\jdhansom\AppData\Local\Temp\ddccy.exe
    C:\Users\jdhansom\AppData\Local\Temp\ddccy.dll
    C:\Users\jdhansom\AppData\Local\Temp\fla121E.tmp
    C:\Users\jdhansom\AppData\Local\Temp\flaCD8F.tmp
    C:\Users\jdhansom\AppData\Local\Temp\TMP3D01.tmp
    C:\Users\jdhansom\AppData\Local\Temp\TMP59B5.tmp
    C:\Users\jdhansom\AppData\Local\Temp\TMPCB8A.tmp
    C:\Users\jdhansom\AppData\Local\Temp\yccdd.ini
    C:\Users\jdhansom\AppData\Local\Temp\yccdd.ini2
    C:\Windows\Temp\symlcsv1.exe


    If you get a message saying any of these are in use, go back up to the Process Explorer procedure and look one by one thru EVERY process shown running and look thru the threads for ddccy.dll and kill all instances of this DLL. Then try to delete the files again. Then even if it does not work, continue on but when you come back describe what happened to me.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run this procedure and attach the log when you come back: SUPERAntiSpyware - running & getting a log


    Now reboot your PC into safe mode where we will repeat some of the above steps.

    Now while in safe mode continue with the below.

    Now look for and try to delete any of the below files that still exist.
    C:\Users\jdhansom\AppData\Local\Temp\ddccy.exe
    C:\Users\jdhansom\AppData\Local\Temp\ddccy.dll
    C:\Users\jdhansom\AppData\Local\Temp\fla121E.tmp
    C:\Users\jdhansom\AppData\Local\Temp\flaCD8F.tmp
    C:\Users\jdhansom\AppData\Local\Temp\TMP3D01.tmp
    C:\Users\jdhansom\AppData\Local\Temp\TMP59B5.tmp
    C:\Users\jdhansom\AppData\Local\Temp\TMPCB8A.tmp
    C:\Users\jdhansom\AppData\Local\Temp\yccdd.ini
    C:\Users\jdhansom\AppData\Local\Temp\yccdd.ini2
    C:\Windows\Temp\symlcsv1.exe

    If you have problems deleting any files, note the file name and tell me when you come back.

    Now run Ccleaner.

    Now reboot in normal mode.

    Come back here and tell me what happened while trying to do the above and then run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below log:
    • C:\MGlogs.zip
    • SuperAntiSpyware log.
     
  22. board

    board Private E-2

    Hi...
    o.k i followed your instructions and deleted ddccy.dll or ddccy.exe threads in process explorer and then ran mgtoools analyse.exe and fixed the selected lines.
    I then went searching for the specific files to delete them. This was possible for all of them except
    -C:\Users\jdhansom\AppData\Local\Temp\ddccy.dll which said it was in use..
    -C:\Users\jdhansom\AppData\Local\Temp\fla121E.tmp
    C:\Users\jdhansom\AppData\Local\Temp\flaCD8F.tmp
    these last 2 wern't there, but all the rest were deleted...

    So i went back through process explorer checking for all ddccy.exe and ddccy.dll but found no new ones.
    I merged the reg. file, installed and ran superanti-spyware and rebooted in safe mode...
    Again went to delete the various specific files...This time none of the files (including C:\Users\jdhansom\AppData\Local\Temp\ddccy.dll, C:\Users\jdhansom\AppData\Local\Temp\fla121E.tmp, and C:\Users\jdhansom\AppData\Local\Temp\flaCD8F.tmp) wern't there so nothing was deleted.
    I then ran CCleaner and rebooted in normal mode and ran mgtools\getlogs.bat..

    Attached are the mgtools.zip and the superanti-spyware logs..
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like we got it this time!

    How are things working. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     
  24. board

    board Private E-2

    Dude thats awesome...
    thanks for your help...i would NEVER have figured that out by myself...

    cheers again..

    Donald
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Sometimes repetition with a little variation is required to take care of these malware infections. Note, it would have been a lot easier if ComboFix would run on your PC but on about 1% of all PCs it just will not run.

    Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds