Laptop issues (spyware, etc.)

Discussion in 'Malware Help (A Specialist Will Reply)' started by stejampzy, Oct 4, 2007.

  1. stejampzy

    stejampzy Private E-2

    Hello. I've completed the first few steps of the "Read Me First" thread and downloaded all of the necessary software (CCleaner, GetRunKey, ShowNew, Spybot, CounterSpy), however the bug that is in my system won't allow me to install Spybot for some reason. I click on the program icon (to install it) and get a buzzing/vibrating sound from my speakers and nothing happens.

    Before coming to this site, I also downloaded SpySweeper and AdAware and haven't been able to successfully run the programs more than once -- again, I click on the program and get a 2 second buzzing/vibrating sound and the program doesn't open. I don't think this is good. :(

    Any suggestions on where to go from here?

    Thank you!
    -Steve
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please just continue on trying to complete all steps. Note you can also see if you can install Spybot in safe boot mode. If you cannot complete a step, just continue on to the next step. I would expect that you should at least be able to get the logs from GetRunKey, ShowNew, and HijackThis since they do not need to be installed. It is possible that you are not having malware problems. Do other programs on your PC run okay?
     
  3. stejampzy

    stejampzy Private E-2

    No. My IE window closes by itself after a couple of minutes and I can't access my Quicken information. I used Firefox to access this forum and it seems to be working OK, but I have had a couple of random pop-ups and monitor switches with it (I use two monitors).

    Also, my computer seems to be running much slower than it did a few days ago (before the problem started). I also had an audio advertisement (good ol' Wilford Brimley and his diabetes info) playing from "nowhere". I had no IE or Firefox windows open, and an advertisement just started playing over my speakers all of a sudden.

    Thanks a bunch for your help. I'll follow your other suggestions, as best I can in safe mode, when I get home this evening. In the meantime, I took out my wireless card and that computer is no longer connected to the internet.

    -Steve
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just attach the logs when you complete the other steps. Hopefully you can get us the logs from the below at a minimum:
    • GetRunKey
    • ShowNew
    • HijackThis
     
  5. stejampzy

    stejampzy Private E-2

    Hello again. OK, I got most of the READ ME FIRST stuff done (with the exception of the Panda scan, which wouldn't work for some reason). Here are three logs with two more to follow on the next reply.

    I hope I did this right!
    -Steve
     

    Attached Files:

  6. stejampzy

    stejampzy Private E-2

    2 more logs. Thanks again!

    -Steve
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is your copy of Spy Sweeper a paid version or free trial?

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2

    Continue by downloading a tool we will need

    - Process Explorer

    Extract it to its own folder somewhere that you will be able to locate it later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    Make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of any of the below DLL files (if found) and then click the kill button.
    tuvww.dll
    ssqoomn.dll
    xxyxxuv.dll

    After you have killed all instances of any of the above DLLs under winlogon click ok.
    (If you do not find these DLLS, just continue on.)

    Next double click on explorer.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button.
    tuvww.dll
    ssqoomn.dll
    xxyxxuv.dll

    After you have killed all instances of any of the above DLLs under Explorer click ok.
    (If you do not find these DLLS, just continue on.)

    Next double click on iexplore.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button.
    tuvww.dll
    ssqoomn.dll
    xxyxxuv.dll

    After you have killed all instances of any of the above DLLs under iexplore click ok.
    (If you do not find these DLLS, just continue on.)

    Now just exit Process Explorer.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F3 - REG:win.ini: load=cfilvxad.exe
    O2 - BHO: (no name) - {0F83CC0F-6DB6-4BD6-929F-2169380A1B11} - C:\WINDOWS\system32\tuvww.dll
    O2 - BHO: (no name) - {373324C4-3575-4B6A-9A46-9D9C77830B15} - C:\Program Files\Windows NT\potedy4444.dll
    O2 - BHO: (no name) - {4A6E655C-37DA-43A5-B55D-875A6657A710} - C:\Program Files\Windows NT\potedy83122.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {C3352FCD-CFE5-4F35-831A-19C68DDB7CF4} - C:\WINDOWS\system32\ssqoomn.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\DOCUME~1\CARRIE~1\LOCALS~1\Temp\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\bedemosk.dll",sitypnow
    O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
    O15 - Trusted Zone: *.imageservr.com
    O15 - Trusted Zone: *.imagesrvr.com
    O15 - Trusted Zone: *.imageservr.com (HKLM)
    O15 - Trusted Zone: *.imagesrvr.com (HKLM)
    O20 - Winlogon Notify: ssqoomn - C:\WINDOWS\SYSTEM32\ssqoomn.dll
    O20 - Winlogon Notify: xxyxxuv - C:\WINDOWS\SYSTEM32\xxyxxuv.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  8. stejampzy

    stejampzy Private E-2

    RE: Spy Sweeper. I paid for a 1-year subscription shortly before coming back to this site for help.... thinking I could do it on my own. :eek:

    I'll run the other steps this evening. Thanks for the help.
    -Steve
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then you may want to just shut down Spy Sweeper before starting the procedure just to make sure it does not get in your way.
     
  10. stejampzy

    stejampzy Private E-2

    Thanks again. Here are my first 3 logs, with the last one to follow. Everything seems to be running more smoothly (and faster) with the exception of my external monitor. This is possibly an indepedent issue, but my laptop monitor is burned out so I use an external monitor as my only viewing source (Fcn+F8) to use the secondary monitor. For some reason, the info on my external monitor is slowly stretching horizontally... now it's almost to the point that I can't even see my Start button on the left, or the system clock on the right!

    Any advice? Thank you!
    -Steve
     

    Attached Files:

  11. stejampzy

    stejampzy Private E-2

    HJT log. :)
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I cannot help you with this. It sounds like you have major hardware issues. You should backup any necessary data really soon before you cannot do it anymore. Your graphics card could be going. You can post questions like this in the Hardware Forum.


    We still have a bunch of malware things to fix!

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    F3 - REG:win.ini: load=qvabbfkl.exe
    O2 - BHO: (no name) - {637A61DB-D3BA-4536-8D2A-76B18FAB0D5D} - C:\WINDOWS\system32\tuvww.dll (file missing)
    O2 - BHO: (no name) - {89AD4D75-2429-462e-BD4E-443F233F6033} - C:\WINDOWS\system32\gbxpdfcs.dll
    O2 - BHO: 0 - {D8D695EB-3D90-4268-99B4-F46F7B97A1A0} - C:\Program Files\Sony Corporation\saguwilo.dll (file missing)
    O4 - HKCU\..\Run: [DDC] C:\WINDOWS\system32\kbjqvyym.exe
    O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
    O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\kbjqvyym.exe (file missing)

    After clicking Fix, exit HJT.


    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  13. stejampzy

    stejampzy Private E-2

    Hi. Here are some fresh logs. Everything is running smoother than it was, although I have a bunch of extra .sys and .sqm files in my C:\drive -- most of which have the icons faded out, if you know what I mean.

    Thanks again for your help.
    -Steve
     

    Attached Files:

  14. stejampzy

    stejampzy Private E-2

    4th fresh log. HJT. Thanks.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have a lot more bad stuff to cleanup. It has probably been spreading each time you reboot your PC. There are many new bad files to delete.

    I don't know what files you are referring too. I don't see any of these. You will have to be much more specific. Also note that Windows Live Messenger creates files ending with .sqm.

    I'll be posting another fix in my next message.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F3 - REG:win.ini: load=nlkfywuo.exe

    After clicking Fix, exit HJT.

    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT
    Make sure you tell me how things are working now!

    DO NOT REBOOT AFTER ATTACHING YOUR LOGS - rebooting is causing the malware to mutate and spread. You will have to leave your PC running until I can get back to you which will not be until late Sunday night. If you cannot leave your PC running, please tell me and do not get any new logs until Sunday night. But also note that if you are still infected, rebooting will make all of the above work a waste of time.
     
  17. stejampzy

    stejampzy Private E-2

    Here's a screenshot of what I'm talking about. Logs and more info to follow. I'll be happy to remove Windows Live Messenger if you think it'll help.

    Thanks,
    Steve
     

    Attached Files:

  18. stejampzy

    stejampzy Private E-2

    I had some problems running Avenger. It gave me several error screens after entering the info from the Quote box.

    "Sytax error in line --- does not appear to be a valid registry path. Line will be ignored."
    [pushed 'OK']

    Error code: 0
    Line:
    [pushed 'OK']

    Error: HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows | load
    [pushed 'OK']

    Error: could not create zip file.
    [pushed 'OK']

    Here's the log, although it doesn't say much. Avenger wouldn't run completely without restarting... which I did NOT do.
     

    Attached Files:

  19. stejampzy

    stejampzy Private E-2

    The other three updated logs.

    Thank you,
    Steve
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those files are all normal. The .sys files are required system files and the .sqm files are part of Windows Live as I stated. If you don't want these .sqm files to appear, you can disable the Customer Experience Improvement Program feature of Windows Live Messenger and the delete all the sqm files.

    The previous fix did not work properly because you did not get Avenger to run properly. Due to this the infection may have spread and it could require addition steps to remove. I will post a new fix now with similar steps and also so new items to remove since the infection mutated because the Avenger fix was unable to run.


    Shut down your antivirus, AVG AntiSpyware and Spy Sweeper programs before starting the fix since they could have interferred with Avenger.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [lbffrxml] C:\aovtqxrr.bat
    O4 - HKLM\..\Run: [sckxikwp] C:\oaalntqy.bat
    O4 - HKLM\..\Run: [xwnnsvcv] C:\gtservrh.bat

    After clicking Fix, exit HJT.
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT
    Make sure you tell me how things are working now!

    DO NOT REBOOT AFTER ATTACHING YOUR LOGS - rebooting is causing the malware to mutate and spread. You will have to leave your PC running until I can get back to you which will not be until late Sunday night. If you cannot leave your PC running, please tell me and do not get any new logs until Sunday night. But also note that if you are still infected, rebooting will make all of the above work a waste of time.
     
  21. stejampzy

    stejampzy Private E-2

    I shut down Spy Sweeper and AVG Antispyware, and have no other virus scans running that I know of (only Windows Firewall).... and still couldn't get Avenger to work properly. I ran the Avenger scan and got the same 4 errors that I listed previously. Here are three new logs, with a 4th to follow.

    Thanks much,
    Steve
     

    Attached Files:

  22. stejampzy

    stejampzy Private E-2

    New HJT log.
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The logs are of no use until Avenger runs! Let's try a different method.

    Uninstall (yes uninstall) AVG Antispyware and Spy Sweeper as the are probably getting in the way of the malware removal even when shutdown because the services are still running.


    Start by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.


    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F3 - REG:win.ini: load=jmqqupsa.exe
    O4 - HKLM\..\Run: [sqshbhht] C:\sjcsmhaw.bat
    O4 - HKLM\..\Run: [buiycnrj] C:\sxpfphic.bat

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\sjcsmhaw.bat
    C:\sxpfphic.bat
    C:\aovtqxrr.bat
    C:\oaalntqy.bat
    C:\gtservrh.bat
    C:\Documents and Settings\xydwkjcc.txt
    C:\vilgvkpy.txt
    C:\zip.exe
    C:\WINDOWS\SYSTEM32\nlkfywuo.exe
    C:\WINDOWS\SYSTEM32\jmqqupsa.exe
    C:\WINDOWS\SYSTEM32\qvabbfkl.exe
    C:\WINDOWS\SYSTEM32\adkrdfmt.dll
    C:\WINDOWS\SYSTEM32\cfilvxad.dll
    C:\WINDOWS\SYSTEM32\cjyegmfk.dll
    C:\WINDOWS\SYSTEM32\dhqzaemu.dll
    C:\WINDOWS\SYSTEM32\fazsqkix.dll
    C:\WINDOWS\SYSTEM32\gdowiozg.dll
    C:\WINDOWS\SYSTEM32\hexeawor.dll
    C:\WINDOWS\SYSTEM32\ikdwlrjc.dll
    C:\WINDOWS\SYSTEM32\iodmaogp.dll
    C:\WINDOWS\SYSTEM32\iyojimqa.dll
    C:\WINDOWS\SYSTEM32\jtixisgu.dll
    C:\WINDOWS\SYSTEM32\mctkbrhy.dll
    C:\WINDOWS\SYSTEM32\nlkfywuo.dll
    C:\WINDOWS\SYSTEM32\oerakqkt.dll
    C:\WINDOWS\SYSTEM32\ofcauuro.dll
    C:\WINDOWS\SYSTEM32\ouwnmmiu.dll
    C:\WINDOWS\SYSTEM32\pzkreoyi.dll
    C:\WINDOWS\SYSTEM32\qalcqiyp.dll
    C:\WINDOWS\SYSTEM32\qvabbfkl.dll
    C:\WINDOWS\SYSTEM32\skxgtpbk.dll
    C:\WINDOWS\SYSTEM32\swakjmpd.dll
    C:\WINDOWS\SYSTEM32\udbjoxyg.dll
    C:\WINDOWS\SYSTEM32\usoliffb.dll
    C:\WINDOWS\SYSTEM32\uuuupsww.dll
    C:\WINDOWS\SYSTEM32\vmkmovgw.dll
    C:\WINDOWS\SYSTEM32\wcydejjn.dll
    C:\WINDOWS\SYSTEM32\auwlexdv.dll
    C:\WINDOWS\SYSTEM32\dhqzaemu.dll
    C:\WINDOWS\SYSTEM32\fwsocxoj.dll
    C:\WINDOWS\SYSTEM32\gdowiozg.dll
    C:\WINDOWS\SYSTEM32\huiwkxkx.dll
    C:\WINDOWS\SYSTEM32\iyoodshp.dll
    C:\WINDOWS\SYSTEM32\lqzxfktu.dll
    C:\WINDOWS\SYSTEM32\miewxgqw.dll
    C:\WINDOWS\SYSTEM32\pfavqgau.dll
    C:\WINDOWS\SYSTEM32\qjogyqto.dll
    C:\WINDOWS\SYSTEM32\scnaocud.dll
    C:\WINDOWS\SYSTEM32\uqvwbbfg.dll
    C:\WINDOWS\SYSTEM32\vmkmovgw.dll
    C:\WINDOWS\SYSTEM32\haywwpmj.dll
    C:\WINDOWS\SYSTEM32\jmqqupsa.dll
    C:\WINDOWS\SYSTEM32\roprrspu.dll
    C:\WINDOWS\SYSTEM32\wkclylhp.dll
    C:\WINDOWS\SYSTEM32\wvupfdcb.dll
    C:\WINDOWS\SYSTEM32\RCXC.tmp
    C:\WINDOWS\SYSTEM32\RCX14.tmp
    C:\WINDOWS\SYSTEM32\DRIVERS\dmpyxeuj.sys
    C:\WINDOWS\SYSTEM32\DRIVERS\ktl^syrr.sys
    C:\WINDOWS\SYSTEM32\DRIVERS\lsyxkggk.sys
    C:\WINDOWS\SYSTEM32\DRIVERS\bylnhhyf.sys
    C:\WINDOWS\SYSTEM32\DRIVERS\pf^puysd.sys
    C:\Documents and Settings\Carrie Ann Pzynski\Local Settings\Temp\Apoint.exe
    C:\Documents and Settings\Carrie Ann Pzynski\Local Settings\Temp\hkcmd.exe
    C:\Documents and Settings\Carrie Ann Pzynski\Local Settings\Temp\igfxpers.exe
    C:\Documents and Settings\Carrie Ann Pzynski\Local Settings\Temp\igfxtray.exe
    C:\Documents and Settings\Carrie Ann Pzynski\Local Settings\Temp\SsAAD.exe
    C:\Documents and Settings\Carrie Ann Pzynski\Local Settings\Temp\RCX11.tmp
    C:\Documents and Settings\Carrie Ann Pzynski\Local Settings\Temp\RCX1A.tmp
    C:\Documents and Settings\Carrie Ann Pzynski\Local Settings\Temp\RCX41.tmp
    C:\Documents and Settings\Carrie Ann Pzynski\Local Settings\Temp\TMP3B.tmp
    C:\Documents and Settings\Carrie Ann Pzynski\Local Settings\Temp\TMP3D.tmp

    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But if you do get this message, please let me know!)

    If Killbox does not reboot just reboot your PC yourself.
    Now run CCleaner
    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    DO NOT REBOOT AFTER ATTACHING YOUR LOGS - rebooting is causing the malware to mutate and spread. You will have to leave your PC running until I can get back to you which will not be until late Sunday night. If you cannot leave your PC running, please tell me and do not get any new logs until Sunday night. But also note that if you are still infected, rebooting will make all of the above work a waste of time.
     
  24. stejampzy

    stejampzy Private E-2

    Hi. Everything went smoothly, and my computer seems to be running much faster now than it has in the last two weeks. Here are my 3 logs.

    Thank you,
    -Steve
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. While Pocket Killbox delete some of the files, it did not delete them properly. We will have to try deleting these with manual steps. If you have problems deleting files in normal boot mode, boot into safe mode and try again.

    Right click Start and select Explore to open up Windows Explorer. Type C:\windows\system32 into the address bar and hit Enter. This will get you into the system32 folder. Now scroll thru the file list and locate each of the below files. When you find it, right click on it and select Delete.


    C:\WINDOWS\SYSTEM32\qvabbfkl.exe
    C:\WINDOWS\SYSTEM32\haywwpmj.dll
    C:\WINDOWS\SYSTEM32\jmqqupsa.dll
    C:\WINDOWS\SYSTEM32\nlkfywuo.dll
    C:\WINDOWS\SYSTEM32\qvabbfkl.dll
    C:\WINDOWS\SYSTEM32\roprrspu.dll
    C:\WINDOWS\SYSTEM32\wkclylhp.dll
    C:\WINDOWS\SYSTEM32\wvupfdcb.dll
    C:\WINDOWS\SYSTEM32\RCX14.tmp

    Now navigate to the C:\WINDOWS\SYSTEM32\DRIVERS folder and delete the below file.
    C:\WINDOWS\SYSTEM32\DRIVERS\pf^puysd.sys

    Then if you are in safe boot mode reboot to normal mode.

    Now run Pocket Killbox and select File, Cleanup, Delete All Backups
    Now exit Pocket Killbox!

    Now attach a new log from ShowNew.
     
  26. stejampzy

    stejampzy Private E-2

    Here is my fresh ShowNew log.

    Even in safe mode, and as Administrator, I wasn't able to delete:

    C:\WINDOWS\SYSTEM32\jmqqupsa.dll
    C:\WINDOWS\SYSTEM32\nlkfywuo.dll
    C:\WINDOWS\SYSTEM32\qvabbfkl.dll

    and when I deleted:

    C:\WINDOWS\SYSTEM32\qvabbfkl.exe

    it showed up again right away. (Disappeared and reappeared)

    When I tried to delete the files, I got an error message that said "Cannot delete ["file name"]: Access is denied. Make sure the disk is not full or write-protected and that the file is not currently in use."

    This is some crazy stuff! Thanks for hanging with me.
    -Steve
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This means that there are additional processes locking the files making them impossible to delete. This is the reason we use Avenger. It can normally (when it runs) get around those problems and delete all the bad files at once. We will need to work up a new procedure using Avenger but I want to run some other steps first.

    First run HijackThis and have it fix the below lines:

    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe

    Then exit HijackThis.


    Download this file - combofix.exe
    1. Double click combofix.exe & follow the prompts.
    2. When finished, it will produce a log ( C:\combofix.txt ) for you. Attach this log to your next reply See: HOW TO: Attach Items To Your Post
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run this procedure: Using MGtools and attach the requested C:\MGlogs.zip file afterwards. This is an automated version for running many things including GetRunKey, ShowNew, and HijackThis (already renamed) and a couple other tools. And it will automatically put all of the logs into the ZIP file for easy uploading.

    Please do not power down or reboot your PC after posting the above logs or it could cause problems to mutate or spread. This would render useless any fixes I would propose.
     
  28. stejampzy

    stejampzy Private E-2

    Hi there. New logs from the most recent instructions. This is *almost* getting fun... in the treasure hunt sort of way. ;)

    Thanks,
    -Steve
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    If Avenger does not run properly, boot into safe mode and attempt to manually delete each of the above mentioned files names. If you cannot delete any of them, try right clicking on the file and select rename and then change the file name by just adding a .BAD to the end of it.

    Now run Ccleaner!

    Now re-run ComboFix.

    MGtools did not install and run how we want it to run.

    Please move the MGtools.exe file that you downloaded from your Desktop to the root folder of drive C. That is, put it here: C:\MGtools.exe
    Then re-run the MGtools.exe file by double clicking on it.
    Then attach the new C:\MGlogs.zip file
    Also attach the new ComboFix log.
     
  30. stejampzy

    stejampzy Private E-2

    Here are my two latest logs. MGTools ran, and then after the HJT log popped up I saved it, then closed the notepad window and HJT... then I got an error message. I'm not sure if it ran completely or not.

    Thanks. I hope you had a nice weekend,
    Steve
     

    Attached Files:

  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It appears that you did not do the Avenger procedure or that it did not run properly. Shutdown your antivirus and any other protection software and please do the Avenger procedure again. Attach the requested log from Avenger.

    Yes something is missing. Can you try again (but see below on what to do) and this time tell me the exact word for word error message you are getting. It looks like it had a problem running procdll.exe and creating the log. What I want you to do is just go into the C:\MGtools folder with Windows Explorer ( right click Start and select Explore) and then just double click on GetLogs.bat which will run all the scans and will create a new MGlogs.zip file for you to attach.
     
    Last edited: Oct 22, 2007
  32. stejampzy

    stejampzy Private E-2

    Here is the error message:
    -----
    ProcessDll.exe - Application Error

    "The application failed to initialize properly (0xc0000135). Click on OK to terminate the application."
    -----

    Zip log to follow.
     
  33. stejampzy

    stejampzy Private E-2

    FYI: I still had the same error message when running GetLogs.bat directly. Do you still want to see a log? Thanks.
     
  34. stejampzy

    stejampzy Private E-2

    Hi. I'm not trying to bump my thread, but I haven't heard a response in three days... so I figured I'd see if you had any new advice. Thanks chaslang.

    Also, my latest Avenger log was completely blank. It had no info and was essentially a blank Notepad page.

    -Steve
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry for the delay! Somehow you got lost in the shuffle with all the activities going on in the forum and behind the scenes (I'm working on a whole bunch of new tools.)
    This could be failing because you do not have the Microsoft .NET Framework software installed on your PC which is available from Microsoft Update. You can try installing the below to see if ProcessDll.exe will then run.

    http://www.microsoft.com/downloads/details.aspx?familyid=262D25E3-F589-4842-8157-034D1E7CF3A3&displaylang=en


    Also please download the current version of MGtools.exe to your C:\ folder, but do not run it yet. First I want to rerun the fix from message # 29 but only up to the point of running CCleaner. Do not run ComboFix or the old version of GetLogs.bat. Shutdown all unnecessary applications before running the Avenger fix. Then run the new MGtools.exe file to create new logs and then attach the log from Avenger (C:\Avenger.txt) and the C:\MGlogs.zip file. If the Avenger procedure does not run properly, tell me what happens but run MGtools.exe anyway and attach the new log.
     
  36. stejampzy

    stejampzy Private E-2

    Hello! Avenger and MGTools logs attached. Thanks. Everything is running smoothly and MGTools ran better after installing the .NET framework.

    -Steve
     

    Attached Files:

  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps below. Step 11 includes a link to get your properly protected. You must make sure you follow those steps.
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  38. stejampzy

    stejampzy Private E-2

    Great! Thanks for your help and consistent follow-up. I've been reviewing the tips for protecting myself going forward. Thanks for the great website!

    -Steve
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds