Immortal(e-Group Instant Access)bug

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by rayzur, Oct 12, 2005.

  1. rayzur

    rayzur Private First Class

    :confused: e-Group Instant Access & Magic Control Agent bugs keep coming back after I run through removal procedures. I am PC beginner so I don't know all of the terminology yet. However I have followed all of the procedures in the Read& Run me first to the best of my knowledge. My system is a windows 98, I ran the bitdefender online AV scan (clean) then the Trojan scan it found (malware-dialer) I knew the e-Group bug was in there from previous Spybot S&D runs last week. Now with scans run I've disconnected cable (phone line) & rebooted into safe mode. Ran Ccleaner w/ default on windows tab, ran Ad-aware fix all it finds (found 13 e-Groups). Next I ran Spybot S&D (no tea timer) & it found( Connect MFC Application-e-Group Instant Access & Magic Control Agent) I fixed them & immunized. I finished with cw shredder,Kill2Me,& Stinger- all were clean. I did all this rebooted & went back to Read & Run to follow up on prevention and was taken over by some porn page before I could even get support forum loaded. :( Next I downloaded & ran A-square personal from Trojan Scan & it found (malware-dialer) again as it did on the online scan, clicked fix & all seemed to be okay. I ran through all procedures again & I still can't get rid of it. I had breif communication with one of the staff members through e-mail & they suggested that the problem might be in my start up(msconfig) items. Remember I am a beginner , I'm not sure how or where to approach the start up items. Any input & guidance would be greatly appreciated. I'm not ready to give up yet! ;)
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. rayzur

    rayzur Private First Class

    I can't say for sure, I mainly just looked at the common name & quantity of test results before I closed each test. If I had I would not have known what it meant. There has also been numerous entries of (slagent).
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I was asking if you had gone to those links and tried the procedures related to MagicControl.Agent
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  6. rayzur

    rayzur Private First Class

    Okay I'm back again, I tried to install " Ewido "but was unable to. I have windows 98 & it required 2000. As far as the other sites http:/www.spy-bot.net & http:/www.2-spyware.com they seem like they may have the answer. I wil confess though, they seemed a little intimidating to me-(a PC beginner). Also now it seems that I'm having to reset my password to enter the forum now. Any other options before I start deleting items that I'm not sure about through the two sites above.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay, I forgot that you indicated you had Win 98 in your first message. Just run the last part of my previous message (the steps for using and posting a HijackThis log). Do not do anything else yet. Not even the stuff in those links I referred you to.
     
  8. rayzur

    rayzur Private First Class

    ;) I'm still in the fight! Okay Chas, I created the C:\ Program Files\ HJT. Did the HJT scan (got the MD5 Calc. under control) but I'm not sure if I saved the log right. It wound up in my word pad, but I got that to my WinZip file w/out any problem. Heres what happened, (In step 3 of "Running HJT & Posting..." it says ...-save your log file to the default .log extension type. The only option I saw after the scan was just( save log ). After clicking save log a file direction window came up & I got the log to my new HJT folder. I never found any type of " Manage Attachments" button. I'm windows 98 remember & beginner also, please bear with me if my terminology is not proper. Bottom line is that I have the log saved & awaiting further directions for it. HAVE NEW INFO. also, I right clicked start/explore/C;/Program files and found a file in their called (Instant Access) would'nt you know it! In addition to that in C:\Unzipped Files I found e-Group. I dumped & shredded both of them, ran Window Washer by webroot. Thought maybe I was on my way out of this mess & ran Spybot S&D for grins. It found (Magic Control Agent , MFC application, e-Group & Spy Hunter ) I went back to start menu and the Instant Access file had regenerated itself. Let me know if I saved my HJT log right. I think were closing in on the lil rats! :p
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As long as you have saved the HJT log file to a .log or a .txt file extension, that is fine. We really do not want Wordpad or MSWord files uploaded for logs. They would have .doc extensions. Win98 was different than current OS's. I believe they do not associate .log files to notepad and you have to do the association youself.

    Manage Attachments is here on MGs when you are writing your message. Look under your message window for Go Advanced and click it. Then scroll down to see Manage Attachments. If you do not see Go Advanced, you are already in advanced mode.

    Have you looked in add/remove programs for Instant Access, E-group and Spy Hunter and tried to uninstall them?
     
  10. rayzur

    rayzur Private First Class

    Heres the latest, I was able to go into add/remove programs to locate & remove (Instant Access). It had 25 different files in it's folder. Now with the e-Group problems gone I ran Spybot S&D again just to see what was it would find. The only thing it found was (Magic Control Agent) & it seems that it is causing most of the problems. Just as I was coming in here to post, I was again taken over by the Crazy Girls page. I ran the HJT & even though word pad put it in my HJT folder ,it was a .log file . I know that on your last reply you said ("I believe they (win98) do not associate .log files to notepad and you have to do the association yourself.) I know also that you really do not want Wordpad uploaded for logs. I did a practice run through the Manage Attachments & was able to get my Wordpad HJT .log on there but didn't send. What sould I do , can you coach me on .log files to notepad? Should I send Wordpad? :confused:
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not need to use Wordpad to upload it. So as long as it was saved to a .log file (which should be a text format) just upload it. If you are having problems uploading it, edit the log file and look for a line in the process list to see if anything like the below appears.
    c:\windows\cmd.exe
    c:\windows\system\cmd.exe
    c:\windows\system32\cmd.exe

    If any of those appear just delete the cmd.exe part (put a note on the line in the log saying command exe deleted) and save the log. Then upload it. If you still cannot upload it, use copy and paste to put the log directly into your message.
     
  12. rayzur

    rayzur Private First Class

    Here is the HJT log file
     

    Attached Files:

    Last edited by a moderator: Oct 14, 2005
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why did you put the log in a ZIP file? It was not necessary. I reattached it as a log file.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\SYSTEM\YFCBTG.EXE

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O4 - HKLM\..\Run: [yfcbtg] c:\windows\system\yfcbtg.exec:\windows\system\yfcbtg.exe
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/265f154ed0bcfbe2fd19/netzip/RdxIE601.cab
    O16 - DPF: {C6760A07-A574-4705-B113-7856315922C3} - http://akamai.downloadv3.com/binaries/IA/sysnetsvc32_EN.cab
    O16 - DPF: {01BE5BD7-B2DD-48B3-A759-59265A91E787} - http://akamai.downloadv3.com/binaries/EGDAccess/EGDACCESS_1064.cab
    O16 - DPF: {E114CD5B-17CE-4807-890E-7B1EDF9F2E5E} - http://scripts.downloadv3.com/binaries/EGDAccess/EGDACCESS_1066.cab

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\SYSTEM\YFCBTG.EXE

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.


    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now let's look for more of MagicControl.

    Open a DOS command prompt window by clicking Start, Run and entering cmd and click OK.
    Now enter the following below commands each followed by the enter key. Some of them may fail to work or they may give an error message. Just OK your way out of the message and continue. Don't forget to put the quotes where I use them.
    cd "%WinDir%\System32"
    regsvr32 /u msegcompid.dll
    attrib -r -s -h msegcompid.dll
    regsvr32 /u "..\mc\MagicControl.dll"
    regsvr32 /u "..\wintrim\MagicControl.dll"
    regsvr32 /u "..\wintrim\EGPing.dll"
    regsvr32 /u "..\wincomp\2_wincomp.dll"
    regsvr32 /u "..\wincomp\3_1,0,0,5_wincomp.dll"
    regsvr32 /u "..\wincomp\2_1,0,2,9_winmgts.dll"
    regsvr32 /u "..\wincomp\3_1,0,0,6_winmgts.dll"
    del msegcompid.dll

    exit

    Now reboot your PC into safe mode and look for the below folders and delete if found:
    c:\windows\mc
    c:\windows\wintrim
    c:\windows\wincomp

    Also tell me whether you see the below folder or not:
    c:\Program Files\iexplore
     
  15. rayzur

    rayzur Private First Class

    Okay Chas, back again. Sorry about that zip file, I have that 2nd HJT log file & will load from Word Pad . Things are looking good :) On the list of items to fix in your log anaylisis the last item to fix was ( 016-DPF:{E114CD5B-17C-4807-890E-7B1EDF9F2E5E} Five lines up from it I noticed another entry that ended the same way as the last item. It was not on your list to fix, but it had the same definition after all the numbers as the last item. It was ( 016-DPF:{A1C39A2-B274-46DB-89BE-1FBD476B9393} & I checked it to fix also, It looked like part of the same group with ( EGDAccess ) in it. No harm appears to be done by my decision to fix it. As far as performance goes, System is working faster than ever & things seem to be working very well. No sign of the Rats & the Crazy Girls have gone home ;) . It seems that I have had a lot of error notices popping up whenever I close some programs, I don't think it's related to our current issue, just more info. for you. Web settings have been reset & homepage has been set to MajorGeeks(something useful- I agree!). Your next post-" Now let's look for more of MagicControl"--- I opened the DOS promt window & entered all items w/ quotes in place. One said "file missing", all others said "bad command or file name" - then I entered "exit". I was not really sure what I was doing , but I did it even though :rolleyes: I rebooted into safe mode to look for the(c:\windows\mc) -(c:\windows\wintrim) & (c:\windows\wincomp) folders, did not find any of them nor did I find the (c:\Program Files\iexplore ). Heres the 2nd HJT log. Private Amatuer Geek is awaiting orders Sir! :cool:
     

    Attached Files:

  16. rayzur

    rayzur Private First Class

    I saw that the HJT #2 log was encrypted, I have not quite got the hang of this file moving business just yet. Let's try again, I'll call it HJT#3 this time. Just the same , here is the second log. :)
     

    Attached Files:

  17. rayzur

    rayzur Private First Class

    New Info., I've just ran the Zone Alarm online spyware scan & it reported Navpmc-Hacker Tool -- Registry Key-HKEY_CURRENT_USER\Software\mc I'm sure that the (mc) at the end stands for MagicControl right. I remember that when I went to the MC removal sites you referred me to in pg.#2 (your 1st reply to me) that I saw Navpmc as one of the items listed. As far as pg#14("Now let's look for more MagicControl) that's where things are getting unclear for me in using the command prompt window. After entering the items & then entering exit the window just closed. What am I looking for, what is my goal in this step?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The purpose of the steps in message # 14 was to use the command prompt to unregister some DLLs (if they exist) and to delete some files too. Exit is supposed to close the window. I'm not sure it matters now though since you did not find any of those folders. But let's double check to make sure the folders do not appear anywhere else. Look for the below:

    c:\windows\system\mc
    c:\windows\system\wintrim
    c:\windows\system\wincomp

    c:\windows\system32\mc
    c:\windows\system32\wintrim
    c:\windows\system32\wincomp


    Also try using Windows Search to look for each of the below files. Let me know if you find them and where they are found (the asterisk is a wildcard that will match anything so *wincomp.dll means match anything ending with wincomp.dll):

    msegcompid.dll
    MagicControl.dll
    EGPing.dll
    *wincomp.dll
    *winmgts.dll
     
  19. rayzur

    rayzur Private First Class

    Okay Chas, I found ( msegcompid.dll ) in c:\ Program Files by using Windows Search & deleted it. Did not find any of the( c:\windows\system\ mc's or win's) by using the Command Prompt. After both of these steps I ran Spybot S&D to see what was going on & found ( Connect MFC Application ,1-entry ) & ( Magic Control Agent, 3-entries ). I rebooted into Safe Mode & repeated everything again ( No Files Found this time ) & Spybot S&D found 1-entry of Magic Control Agent , which seems to be the problem now. It looks as if the file that I found may be a remnant of the e-Group bug which seems to be taken care of. I guessing this because of the _ _(eg) _ _ _ _ .dll in it. Any thoghts on a new approach to Magic Control? :confused:
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Post the Spybot log! I want to see what information they are providing on it.
     
  21. rayzur

    rayzur Private First Class

    Heres the Spybot log.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is not the log I want to see. I want to see what the scanner is finding that it says is bad.

    Use HJT's process manager to Kill the below process if found running:
    C:\WINDOWS\SYSTEM\EJAMCILTVH.EXE

    Now have HJT fix the below line

    O4 - HKLM\..\Run: [ejamciltvh] c:\windows\system\ejamciltvh.exec:\windows\system\ejamciltvh.exe

    And then boot into safe mode and delete the below file:
    c:\windows\system\ejamciltvh.exe <--- note the date of this file and also look for other new files and tell me what you find in this folder.


    Reboot in normal mode and post a new HJT log.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also tell me if you see the below file. Don't do anything with it! Just look:

    c:\windows\system\yfcbtg.exe
     
  24. rayzur

    rayzur Private First Class

    Yes , it showing that it is there. But I can't open it up, it acts like an empty file. We killed it w/ HJT through your instructions on pg#13. I found & treated everything according to all your instructions on pg#22. FYI- When I was running through HJT again, I noticed that the items that had been fixed were going into backup via default settings. Reading in the tutorial I found out that it is possible for spyware scans to pick up those items. I have since deleted them to eliminate this possibility & knowing that we could refer back to my posted logs if we needed any past info. New HJT log below.
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you notice that the below is now back:
    O4 - HKLM\..\Run: [yfcbtg] c:\windows\system\yfcbtg.exec:\windows\system\yfcbtg.exe

    See if you can find and delete this file in safe mode. Also look for and delete:
    c:\windows\system\ejamciltvh.exe

    Tell me what other files names you see in the c:\windows\system folder with similar file creation dates.
     
  26. rayzur

    rayzur Private First Class

    :eek: HEADLINE NEWS: WE HAVE LOCATED THE IMMORTAL INTRUDERS!! In c:\windows\system - I found the whole (yfcbtg) family- (yfcbtg.exe)-(yfcbtg_nav.dat)-(yfcbtg.dat)-(yfcbtg_navps.dat) THEY REFUSE TO BE DELETED !! Also in c:\windows\system- I found, (ejamciltvh.dat) and (ejamciltvh_navps.dat) I've deleted them and it appears to have worked. Ready & Waiting for your thoughts on the next action to take. Have one question for you also, My Zone Alarm Pro trial period ends tommorrow. Should I let it roll into the free standard version or is there another free firewall that you prefer to ZA. :)
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After deleting the ejamciltvh family of files could you delete the yfcbtg stuff. If not, you probably need to kill the process that is running first. Make sure you look for other files (not just with similar names) with similar creation dates. Make sure you reboot after deleting these. Try safe mode delete if necessary. Reboot in normal mode and post a new HJT log.

    Personally I like ZoneAlarm.
     
  28. rayzur

    rayzur Private First Class

    :) Things are lookin good now, it seems that I was able to delete all of the (yfcbtg) stuff after the (ejamciltvh) was gone. As far as looking for other files with similar creation dates, I'm not quite sure how to go about that. If you still think it's neccessary after reviewing the new HJT log you might need to help me understand exactly what I'm looking for. It appears that the files are gone & I assume the dates are gone with them. Unless there in the previously posted log files. See what you think, BY THE WAY - I really appreciate your help & your patience with me through all of this . It has been a good learning experience for me.
     
  29. rayzur

    rayzur Private First Class

    Forgot the HJT log, here it is. Thanks again, Rayzur
     
  30. rayzur

    rayzur Private First Class

    I guess it had problems uploading , lets try again here . If not, I'll get back later.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Still no success. Watch the messages in the Attachments window. You may be getting an error message or it may not be completing. If it never completes, the problem could be that you have a line like c:\windows\system32\cmd.exe in the log. The vB system that Majorgeeks uses, seems to have a problem with this line for some reason. Post your log inline if necessary and I will attach it.
     
  32. rayzur

    rayzur Private First Class

    Yes I was getting an error message, I will try it again. If it does'nt go through , explain how to post my log inline with your next reply. I am also going to try to attach a Spybot log that I think you need to see. It may not be the right one, but it does have the search results in the opening paragraph. How do I locate something like -HKEY_USERS\.DEFAULT\Software\LanConfig or HKCU\Software\mc. These are just two of 5 or 6 of them. Let me see if I can get it to you.
     

    Attached Files:

  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is Spybot finding? Is it stuff like below:

    HKEY_CLASSES_ROOT\TypeLib\{5630B768-1C09-4105-9E03-E35985E36B0B}

    C:\WINDOWS\SYSTEM\msegcompid.dll

    HKEY_CLASSES_ROOT\Interface\{510C3373-4842-4944-8729-0AFF6725A132}

    C:\WINDOWS\mslagent\

    HKEY_USERS\.DEFAULT\Software\mc\SA

    HKEY_USERS\.DEFAULT\Software\LanConfig
     
  34. rayzur

    rayzur Private First Class

    I can't get the Spybot log to upload, but here are some of the items it found. Magic Control Agent- ( HKEY-USERS\.DEFAULT\Software\LanConfig)--Magic Control Agent-(HKEY-USERS\.DEFAULT\Software\mc\SA) --Magic Control Agent-(c:\windows\system\msegcompid.dll) I have looked for this last one since I knoe how to search by clicking Start\Explore\c:\windows etc. but I did not find it there. It was one we deleted a couple of days ago. Don't know why it showed up on todays Spybot scan. In addition the scan found Connect MFC Application-(HKEY-USERS\.DEFAULT\Software\livesvc) How do I approach thes HKEY or HKCU entries ?
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why can't you upload the Spybot log?

    Some of those lines are what I said you would find in my previous message.
     
  36. rayzur

    rayzur Private First Class

    I was getting vM error notices on them , even though they were .txt files and I even tried to use a .zip file. I was able to send one a few days ago even though it was not the one you wanted. What about this posting inline bus. ,how does that work? And if You can tell me how the Spybot log works I can make sure you get the one you want.
     
  37. rayzur

    rayzur Private First Class

    Let's see if you get this Spybot log.
     

    Attached Files:

  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After Spybot completes its scan. Right click in the Window and select Save Results to file ....
    The default filename is SpybotSD.Results.txt and it is normally saved in an Application Data path for Spybot (but you can choose to save it anywhere - like your Desktop - to make it easy to find). Otherwise the default may be something like:

    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Logs\SpybotSD.Results.log

    There is another option to save full report that has a load more detail but we should not need that.
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to get your updates for Spybot. You are out of date. Always check for updates for any programs like this before scanning.
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ooops! Forgot you are running Win98! Yours will not be in the above folders.
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those logs show different results. Are they from the same time? Are they old or new scans because I see the below which you said you deleted:

    yfcbtg (yfcbtg)
    uninstall cmd: c:\windows\system\yfcbtg.exe -uninstall

    Get your Spybot updated and run a new system scan (in safe mode) and post the new log.


    I also wonder what the below is that shows in your log:

    Located: HK_LM:Run, wilrptns
    command: c:\windows\system\wilrptns.exe
    file: c:\windows\system\wilrptns.exe
    size: 236084
    MD5: 48b4722437cf3db0ba8a4f513748adb8
     
  42. rayzur

    rayzur Private First Class

    Okay Chas, I got my updates on Spybot S&D. Ran the scan, no sign of Connect MFC Application this time. Still got that stinking Magic Control Agent though. Heres is the log.
     

    Attached Files:

  43. rayzur

    rayzur Private First Class

    There may have been an old log in there. I have just purged all of the old logs as you were replying. Log posted below is fresh.
     
  44. rayzur

    rayzur Private First Class

    Opps, I missed the safe mode part on that fresh spybot s&d scan. Now heres the updated Spybot S&D with fresh scan in safe made. I just went into c:\windows\system\... to check once more for that (yfcbtg) & there was no sign of it. Now about that new item you were wandering about! Let me print out that page w/ my printer & I look around while waiting for reply. I just tried to attatch the safe mode Spybot log. Manage attatchments says that it is already in this thread. I tried to rename it five differtent ways, I guess it's reading the content as it's uploading & knows that it has it , no matter what I call it. I going to sit tight for a while & let you evaluate the situation ;)
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes if the content is the same, it will stop the upload even if you rename the file.

    While I'm not sure the below is going to work (I seem to remember doing this once before and it kept coming back), let's try anyway:

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixMC.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixMC.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
     
  46. rayzur

    rayzur Private First Class

    New Info! Our (yfcbtg's) may have turned into ( wilrptn's) that you were wondering about on your pg. 41 . What I have now in c:\windows\system\.. is (wilrptns.dat)-(wilrptns_navps.dat)-(wilrptns_nav.dat) & there very unstable, they sit there & flicker.
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Boot in safe mode and make sure you have no connection to the internet by unplugging your cable. Also make sure no browsers are open. Then run HJT's process manager and kill wilrptns.exe if found running. Then try to delete all the associated files.

    Now if that all works! Pull the power plug to your PC. I want to create a non-graceful shutdown because I suspect this malware may be spawning at normal shutdowns or reboots.
    After your PC is off for a minute, power back up and check to see if any new forms of this have appeared. Sort the files in your Win Explorer window by dates ( you may need to click View and select Details first to see this option). All you have to do is then click the Date Modified text (this is actually a button) and it will sort by Date Modified.

    Did you do that registry patch in msg # 45 yet?
     
  48. rayzur

    rayzur Private First Class

    No I have not done the patch in #45 yet, I wanted to update you first before going any further. I'll wait to for your reply on which one to do, pg.45 or pg.47. I would guess 47 , but I'm waiting for confirmation ;)
     
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the registry patch from msg 45 but do not merge it in until you boot into safe mode as in msg 47. Then just continue with the rest of 47. Make sure you hunt around for other possible file with fairly new dates.
     
  50. rayzur

    rayzur Private First Class

    " Magic Control.Agent is out of Control " is what the title of this thread should have been! Let me start by telling you what I did & then what is happening now. In response to your mssg.#49, I created the (fix.MC.reg) patch & put it on desktop. I followed mssg.#47 to the Tee,(wilrptns.exe was not found running by HJT) and I was able to delete all of the (wilrptns') in c:\windows\system. I Pulled The Plug on my PC for that hard shutdown & when I repowered, I went straight to HJT scan & fix(ed) (c:\windows\system\wilrptns.exe) Whether one should have been done before the other I'm not sure. Regardless everything was cleaned up & I had clean Spybot & HJT scans. Went back to windows explore loking for traces of the (wilrptns) w/ none to be found. I went into Add/Remove just to see what was going on there & I found dead files of (ejamciltvh)-(yfcbtg)&(wilrptns) I seem to remember seeing the (yfcbtg) when I was in ther removing "Instant Access" but that was last week & my untrained eye didn't notice it as bogus! Now heres is were it gets sticky, I have just ran secondary Spybot & HJT scans for precautionary measures & Spybot greeted me with (MagicControl)&(Connect MFC Application) again :rolleyes: Big Sigh, I went to HJT & guess what is sitting right where all the others were...(HKLM\..\Run\ (cnjukvps) thats right ! this sucker is spawning & its sitting in my Add/Remove right now also. Magic Control is out of Contrl- I'm sending both my scans, I'm sure you will want to see them. Time to pull out the BIG GUNS!
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds