MajorGeeks Support Forums

Go Back   MajorGeeks Support Forums > ----------= PC, Desktop and Laptop Support =---------- > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.


Reply
 
Thread Tools Display Modes
  #1  
Old 02-23-07, 07:30
FAR451 FAR451 is offline
Private E-2
 
Join Date: Feb 2007
Posts: 14
Thanks: 0
Thanked 0 Times in 0 Posts
Default Unknown program - help required

Sirs,

I use Windows XP. When I shut the system down
a box appears telling me that the program
'kFKXBQ784VvnJFCDYGuMew24+de' is not responding
and do I want to close it now.
I have no idea what this is referring to. The program
does not appear on the list of programmes loaded and
Norton System Works doesn't pick it up as a problem
or virus. Neither does AOL spyware.
Is this a virus or spyware problem and what can I
do to either identify what it is or eliminate it
from my system?

I sent this query to pcreview, who suggested I send a report
re HiJackThis to you.

I have followed the instructions detailed on this site (and as I
am not an expert also purchased SpyOnThis to try to rectify the
problem.......this threw up a whole lot of stuff).

In safeboot mode I ran Ccleaner (it only identified SpyonThis
and MicrosoftSecurityCentre firewall and antivirus disabled as
problems - as I'm running Norton the above MS stuff is supposed
to be off as far as I understand it).
I ran Spybot - nothing found
I ran Counterspy - nothing found
I was unable to connect to the net whilst in safe mode so
haven't run bitdefender or panda.

I have the logs for HiJackThis, GetRunKey and ShowNew,
which I have attached.

This problem still persists and I am very concerned that the
unknown program is a major problem re secruity.

Any help you can give will be very gratefully received.
Thanks in advance for your assistance.

Regards
FAR451
Attached Files
File Type: log hijackthis.log (12.6 KB, 2 views)
File Type: txt runkeys.txt (26.8 KB, 2 views)
File Type: txt newfiles.txt (32.5 KB, 4 views)
Reply With Quote
Sponsored links
  #2  
Old 02-24-07, 15:06
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 46,417
Thanks: 430
Thanked 4,578 Times in 4,332 Posts
Default Re: Unknown program - help required

SpyOnThis 2.0 is a roque spyware program. Uninstall it!!

Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

Quote:
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SpyOnThisMonitor"=-

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
"SuperHidden"=dword:00000001
"ShowSuperHidden"=dword:00000001
"HideFileExt"=dword:00000000
Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

O4 - HKCU\..\Run: [SpyOnThisMonitor] "C:\Program Files\SpyOnThis v2.0\SpyOnThis.exe"

After clicking Fix, exit HJT.

Now attach new logs for:

* GetRunKey
* ShowNew
* HJT
Reply With Quote
  #3  
Old 02-25-07, 13:11
FAR451 FAR451 is offline
Private E-2
 
Join Date: Feb 2007
Posts: 14
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Unknown program - help required

TimW,

Thank you for taking the time to reply. Much appreciated. In order, this is what I've done.
1. I removed SpyonThis from the programs file. I then re-started the computer, but the SpyonThis returned. (How worried should I be that I downloaded this in the first place?).
2. I pasted the text you sent to notepad and allowed it to merge with the registry.
3. I ran HijackThis. There was no entry for O4 - HKCU\..\Run: [SpyOnThisMonitor] "C:\Program Files\SpyOnThis v2.0\SpyOnThis.exe" so I couldn't fix it.
There was a suspicious entry that relates to a supposed problem I had according to SpyonThis.......one of the things it purorted to find was a program called PC Police 2, which was placed at c:\windows\prefetch\MSMSGS.EXE.2B6052DE.pf.
I noted on the HijackThis log an entry for O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe"/background. I

Not sure if this is a problem in itself.

4. I've tried to delete an icon for SpyonThis. When I try to delete it I get a meesage box stating 'cannot delete SpyonThis: Access denied'.
I'm annoyed that I downloaded it in the first place!

5. Please find attached logs as requested.

I'm grateful to you for you help on this. Cheers..


FAR451
Attached Files
File Type: log hijackthis25feb.log (12.3 KB, 2 views)
File Type: txt newfiles.txt (32.6 KB, 2 views)
File Type: txt runkeys.txt (26.7 KB, 2 views)
Reply With Quote
  #4  
Old 02-25-07, 19:54
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 46,417
Thanks: 430
Thanked 4,578 Times in 4,332 Posts
Default Re: Unknown program - help required

Download and Install RogueRemover Free http://www.majorgeeks.com/RogueRemover_d5360.html

Run RogueRemover and select Scan and the program will walk you through the remaining steps.

Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

Quote:
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=-
Tell me how things are running.
Reply With Quote
  #5  
Old 02-26-07, 05:56
FAR451 FAR451 is offline
Private E-2
 
Join Date: Feb 2007
Posts: 14
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Unknown program - help required

TimW,

Thanks greatly to you for your help. I've followed your advice and so far all seems to be ok. I've also removed SpyonThis and have followed it up with a demand for a refund. Damn those rogue programs.

Thanks again.

Regards

FAR451
Reply With Quote
Sponsored links
  #6  
Old 02-26-07, 10:53
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 46,417
Thanks: 430
Thanked 4,578 Times in 4,332 Posts
Default Re: Unknown program - help required

If you are not having any other malware problems, it is time to do our final steps:

1. If we used Pocket Killbox during your cleanup, do the below
* Run Pocket Killbox and select File, Cleanup, Delete All Backups
2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
8. If you are running Windows XP or Windows ME, do the below:
* go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
* Then reboot and Enable System Restore to create a new clean Restore Point.
9. After doing the above, you should work thru the below link:
* How to Protect yourself from malware!
Reply With Quote
  #7  
Old 02-26-07, 12:31
FAR451 FAR451 is offline
Private E-2
 
Join Date: Feb 2007
Posts: 14
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Unknown program - help required

TimW,

Thanks again. I've followed the instructions and the only thing that may be a problem is MSMSGS.EXE-2B6052DE.pf. I've tried to delete this but it just keeps re-appearing, and it comes back almost instantly. It also returned following the re-boot.

Is this a problem or can I ignore this? (Googling gives references but they aren't conclusive).

Other than that all seems well with the system.

I am VERY appreciative of you're help once again.

Regards

FAR451
Reply With Quote
  #8  
Old 02-26-07, 13:15
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 46,417
Thanks: 430
Thanked 4,578 Times in 4,332 Posts
Default Re: Unknown program - help required

Windows Messenger is a program that has many vulnerabilities...
Also Kill the messenger

That should take care of it.
Reply With Quote
  #9  
Old 02-27-07, 05:46
FAR451 FAR451 is offline
Private E-2
 
Join Date: Feb 2007
Posts: 14
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Unknown program - help required

TimW,

Again, many thanks for your advice and time.

I followed your instructions but MSMSGS.EXE-2B6052DE.pf still
appears in the C:\WINDOWS\prefetch file. It was still there
after I'd run the uninstall and rebooted. Any suggestions?

Also, is EXPLORER.EXE-082F38A9.pf a problem? I've googled it but can't find a definitive answer on this one.

Many thanks in advance.

FAR451
Reply With Quote
  #10  
Old 02-27-07, 13:22
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 46,417
Thanks: 430
Thanked 4,578 Times in 4,332 Posts
Default Re: Unknown program - help required

Go to start / run / and type "prefetch" without quotes....it will give you a window with all the items in that folder. Select them all (Control + A) then delete them.

Then run CCleaner (both the cleaner and the issues - make the backup when prompted).

Tell me how things are running.
Reply With Quote
Sponsored links
  #11  
Old 03-01-07, 03:32
FAR451 FAR451 is offline
Private E-2
 
Join Date: Feb 2007
Posts: 14
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Unknown program - help required

TimW,

Your advice has been spot on. Thanks. All seems to be working very well now, apart from EXPLORER.EXE-082F38A9.pf, which still appears in c:\windows. Is this a problem or just part of the system that should be there?

Thanks again for your considered advice and time. Brilliant and well received.

FAR451
Reply With Quote
  #12  
Old 03-01-07, 13:28
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 46,417
Thanks: 430
Thanked 4,578 Times in 4,332 Posts
Default Re: Unknown program - help required

Are you unable to manually delete that file? It is possibly a remnant of our fixes.
Let me know.
Reply With Quote
  #13  
Old 03-05-07, 06:51
FAR451 FAR451 is offline
Private E-2
 
Join Date: Feb 2007
Posts: 14
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Unknown program - help required

TimW,

I have tried to remove EXPLORER.EXE-082F38A9.pf manually. Did delete and also emptied the recycle bin, but on re-boot it re-appears. Also, I tried to open it and then delete the contents but without success.

Any suggestions?

Thanks again for your great advice and time.

FAR451
Reply With Quote
  #14  
Old 03-05-07, 10:29
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 46,417
Thanks: 430
Thanked 4,578 Times in 4,332 Posts
Default Re: Unknown program - help required

One of the more difficult to get rid of, unfortunately.
Download and run CWShredder

You may have to run it twice.
Let me know.
Reply With Quote
  #15  
Old 03-07-07, 08:44
FAR451 FAR451 is offline
Private E-2
 
Join Date: Feb 2007
Posts: 14
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Unknown program - help required

TimW,

Thanks again for your time and help.

Unfortunately EXPLORER.EXE-082F38A9.pf keeps re-appearing, again after manually deleting. The wierd thing that also happened is that the program
'kFKXBQ784VvnJFCDYGuMew24+de' is not responding box came back when I closed the system down. It doesn't always appear but this is now causing me to think that someone has it in for my system!

I don't know how helpful the following is but when I look in CCleaner - Tools there are several programs listed that don't appear in add/remove programs. These are GdiplusUpgrade, Internet Worm Protection, MSRedist, NSW_DRM_Collection, Symnet and SPBBC. I think one or two of these may relate to Norton, which is the security software I use.

Please let me know your thoughts on this latest twist. I'm very grateful to you for this.

Regards

FAR451
Reply With Quote
Sponsored links
  #16  
Old 03-07-07, 10:26
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,122
Thanks: 61
Thanked 7,565 Times in 4,066 Posts
Default Re: Unknown program - help required

Quote:
Originally Posted by FAR451 View Post
Unfortunately EXPLORER.EXE-082F38A9.pf keeps re-appearing, again after manually deleting.
Explorer.exe is your Windows System Shell and is a valid process and you should see it in the Prefetch folder. You should not and do not need to delete it.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
Reply With Quote
  #17  
Old 03-08-07, 04:20
FAR451 FAR451 is offline
Private E-2
 
Join Date: Feb 2007
Posts: 14
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Unknown program - help required

chaslang,

Thanks for that. I'll leave it alone.

Any thoughts on the other stuff that I mentioned? Thanks in advance for your time and advice.

FAR451
Reply With Quote
  #18  
Old 03-08-07, 10:02
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,122
Thanks: 61
Thanked 7,565 Times in 4,066 Posts
Default Re: Unknown program - help required

Quote:
Originally Posted by FAR451 View Post
Any thoughts on the other stuff that I mentioned?
What other stuff? I saw no outstanding issues?
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
Reply With Quote
  #19  
Old 03-08-07, 10:57
FAR451 FAR451 is offline
Private E-2
 
Join Date: Feb 2007
Posts: 14
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Unknown program - help required

chaslang,

Sorry, the outstanding is also the original problem. When I shut the system down a box appears telling me that the program
'kFKXBQ784VvnJFCDYGuMew24+de' is not responding and do I want to close it now.
This appears every now and then on shut down, even after all the work we've done on the system. Is this merely an echo or is there likely to still be a problem?

As it is the computer is working well with no obvious slow down or problem.

Thanks again for your time and expertise.

FAR451
Reply With Quote
  #20  
Old 03-08-07, 19:55
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,122
Thanks: 61
Thanked 7,565 Times in 4,066 Posts
Default Re: Unknown program - help required

I doubt it has anything to do with malware. It is more than likely related to some application you have running.

Does it happen in safe mode? You will obviously have to try rebooting in safe mode whatever number of times is necessary to indicate to you that it either does or does not happen.

If it does not happen in safe mode, I suggest you use MSconfig for its intended debug purpose and disable various processes and services from loading at start up until you locate the problem. Note however it may also not be related to a startup process, it could be due to something else you periodically run/use on your PC and after it has been used and then you may get the shutdown error.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
Reply With Quote
Sponsored links
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Problem unknown, help required. XplicitFear Malware Removal 1 12-25-06 18:02
Need Help with unknown program pop ups capkr563 Malware Removal 2 10-19-06 23:47
Unknown Program Files avilo4u Software 1 01-03-06 21:31
Unknown program stealing focus Balbanebeoulve Software 7 02-11-05 02:42
unknown program bmw312lp Software 1 11-24-04 21:29


All times are GMT -5. The time now is 09:21.

MajorGeeks.Com Menu

MajorGeeks.Com \ All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ NEW! PC Games \ System Tools \ Macintosh \ Demonews.Com \ Top Downloads

MajorGeeks.Com \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds


Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger