Please help! Can't delete "xxyyywv.dll" (and other problems!)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by thedunnyman, Jul 8, 2007.

  1. thedunnyman

    thedunnyman Private E-2

    Hey guys,

    This is the first time posting on this forum. I've always run into problems and read the help and it has always worked. Now I've come across something I can't fix so naturally I thought, this is the best place for me!

    1.
    Anyway, I have a file: xxyyywv.dll I can't delete it no matter what. I've tried:
    • Tried deleting using HiJack This (in safe mode as well)
    • Tried deleting using 'Secure Delete' in System Optimizer
    • Tried deleting directly from recycle bin (it says it's currently being used)

    2.
    I also have another problem where Mozilla Firefox takes about 30 seconds to load. Initially I thought it was BitDefender running on real-time (as I just installed it). But upon removing it, I've realised it is still slow and therefore I'm using Opera at the moment.

    3.
    Also, with the services. I can't delete them with the newer version can I? I don't many of the items such as InCD. Is there another program I can use?

    Anyway, here is the log:

    Edit: Inline HJT log removed

    Cheers. Thanks in advance guys! :)
     
    Last edited by a moderator: Jul 8, 2007
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi and Welcome

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.




    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. thedunnyman

    thedunnyman Private E-2

    Okay, I've followed all the steps now. Sorry I skimmed the Read Me file! rolleyes

    Anyway, the 'xxyyywv.dll' is still there (apparently it's affected by VirtuMonde).

    Mozilla Firefox still takes 30 seconds to load. But other than that, the computer still works fine.

    I've attached the files too.
     

    Attached Files:

  4. thedunnyman

    thedunnyman Private E-2

    And the other files...


    And the BD one..I'm trying to convert from HTML because I forgot to save as text!!
     

    Attached Files:

  5. thedunnyman

    thedunnyman Private E-2

    And the remaining 2 files (sorry had to split)
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not need to convert anything. You just needed to follow the directions which said to renamed the file from a .html extension to a .txt extension so you could upload it as an attachment.

    You forgot to attach the log from CounterSpy. Do you have it? Did you fix what it found?

    You also need to do all of step 2 of the READ ME properly. You still have file extensions hidden.

    You did not rename HijackThis.exe as specified in step 7 of the READ ME. You must do this and then attach a new log. You have the exact kind of infection that makes this a necessity.


    Note FireFox can often be a little slow the first time you start it up. If you shut it down and open it again, is it still slow?

    You mentioned something about services that you don't want. If you don't want them, you need to uninstall the software related to them or disable that particular feature or the software (like InCD which is part of Nero). These are not malware.
     
  7. thedunnyman

    thedunnyman Private E-2

    Okay...I re-did it all again.

    So basically I think I have VirtuMonde and a few other malware on my computer.

    I've attached all the logs.

    I also ran VundoFix and the log is attached as well.
     

    Attached Files:

  8. thedunnyman

    thedunnyman Private E-2

    And the others....
     

    Attached Files:

  9. thedunnyman

    thedunnyman Private E-2

    And the HiJack This log..
     

    Attached Files:

    Last edited: Jul 14, 2007
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this Disable/Remove Windows Messenger to remove Windows Messenger.

    Uninstall the below software:
    Java(TM) SE Runtime Environment 6 Update 1
    Messenger Plus! Live <-- should have been uninstalled in step 0 of the READ ME. This is more than likely where you picked up your Virtumonde infection from.

    Also uninstall the CounterSpy trial now since we are finished with it

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {938A8A03-A938-4019-B764-03FF8D167D79} - C:\WINDOWS\system32\xlwmsmat.dll
    O2 - BHO: (no name) - {93DF53C2-CE6F-43B9-BD2B-6A525C0DDBC8} - C:\WINDOWS\system32\gebca.dll (file missing)
    O20 - Winlogon Notify: pmnnn - C:\WINDOWS\system32\pmnnn.dll (file missing)
    O20 - Winlogon Notify: sstqp - C:\WINDOWS\system32\sstqp.dll (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  11. thedunnyman

    thedunnyman Private E-2

    Thank you so much! It's all solved now. Spybot sees absolutely nothing at all! That's the first time I've seen that!

    Question:

    Regarding the uninstall of Messenger Live: I can't install it back can I? I like the way they keep logs - that's all.

    Here are the logs:
     

    Attached Files:

  12. thedunnyman

    thedunnyman Private E-2

    And Hi-Jack this:
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you also like the virtumonde infection that may have come from it? It is also the root cause of tens of thousands of people getting LOP infections. Software like this cannot be trusted. Every scanner detects it as a problem. It's your PC in the end so it will be your decision. If you do reinstall, be VERY CAREFUL to read the license agreement and make sure you DO NOT allow it to install any third party applications. The trouble is that you cannot trust what it might do during upgrades.

    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
    Last edited: Jul 18, 2007

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds