not wanting to make a mistake

Discussion in 'Malware Help (A Specialist Will Reply)' started by stevieink, Dec 13, 2007.

  1. stevieink

    stevieink Private E-2

    ok. first of all i downloaded spybot before i found this website and downloaded it to program files in C/ which is in docs and settings. as i was going through the steps, i read NOT to download to that, yet to a "root"(i think its called) which is C/"name of program". Is that the way its HAS to be done? Or am I ok? also when it says to "empty" quarantine, does that mean to delete, or restore so the program i'm running can decide? If spybot does have to be in a root file do i just delete it and re-install it? also, earlier in the steps i was told to remove malware from "add and remove" programs and i had two that it wouldn't let me get rid of. Kazaa 3.0 and it tells me "Install shield setup launcher encountered a prob. and needs to close, and web savings from ebates WJView error- could not execute main: the system cannot find the specified file. just need a little advice and direction of where to go from here. need to go eat 2 BC powders. this is driving me crazy. All of you rock for doing this everyday. Don't know how you do it. ANY help would be greatly appreciated!!! Thanks for reading.:confused
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Program Files is not in Documents and Settings. You have the below folders:

    C:\Program Files
    C:\Documents and Settings

    Where you DOWNLOAD and where you install are two different things. Do not DOWNLOAD to either of the above folders or any subfolder under them. But when you install software, you should install to the recommended default which is normally under C:\Program Files.

    We suggested that you download to a download folder where you can identify files by folder and file names. This is so you always know what they are rather than trying to guess later. An example could be C:\Downloads and under this download folder you can create sub-folders like AntiVirus, AntiSpyware, DiskCleaners....etc And under each of these folders you can create sub-folders to further categorize. Like:

    C:\Downloads\AntiSpyware\AVG Antispyware
    C:\Downloads\AntiSpyware\Spybot

    and so on.

    C:\ is the Root folder of drive C (note the colon is important, it is not C/ ) The only tool we asked you to DOWNLOAD to the root folder of your Windows boot drive was MGtools.exe


    It means delete or cleanup NOT restore. Most antivirus and antispyware programs create some kind of backup of what they remove. Some call it a quarantine, others call it a vault, and others may just call it a backup. We want them removed/delete to avoid detecting them during the scans. It will only confuse things and make scans take longer.

    See if you can use the CCleaner's Uninstall Tool under Tools (which you will see in the left column when you run Ccleaner). Then find them in the Programs to Remove list and select it, then click the Delete Entry button. Do this for the two you mentioned.
     
  3. stevieink

    stevieink Private E-2

    ok! first of all thanks for replying! went ahead and removed kazaa and other w/ Cclean. That worked great. no problems. then tried to run combofix and it went through the 38 or so stages and when it goes to deleting files all my desktop icons dissappear and i'm left w/ a desktop background and the autoscan window and a blinking cursor underneath. (which is what my computer has been doing when logging off IE) mouse still moves but not even ctrl+esc will work. Waited 20 min. Need i wait longer? should i try to run other 2 programs or do they need to run in order? Also am having these errors when booting up. dont know if it matters but just so you know ALL the info. RUNDLL error loading C:\windows\system32\NvCpl.dll and C:\windows\system32\xvbuypck.dll-specified module could not be found. also WJView error:could not execute main:the system cannot find the specified file. Thanks again!!:confused
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's what you will see while ComboFix is working. It terminates explorer.exe which is your Windows shell and is the program that will show your Desktop and icons. Than a while later ComboFix will attempt to reboot your PC which means Windows has to be shutdown. If your PC has problems that cause shutdown not to work, ComboFix may never be able to complete its process. You obviously cannot run anything else with your PC in this state. What did you do? How are you connecting here now? Do you kill the power? You are now talking about boot time errors. Does that mean that you already pulled the power?
     
    Last edited: Dec 14, 2007
  5. stevieink

    stevieink Private E-2

    just did it again when i finished reading your e-mail and hit home button to come to this website to reply. just leaves me with a pic of my daughter(my background) and a working mouse with nothing to click. All icons are gone. So yes, i unplug it and reboot and hope it dosent do that for good. (*I'm not sure if everyones computer does this but if i remember correctly my computer has ALWAYS had the icons dissappear for a split second when logging out of IE only to re-appear a split second later*) Because my desktop icons ALWAYS dissappear now for a split second only to return. Now, the icons return half the time, and if they dont return i'm forced to unplug. seems to do it when closing a program. Almost like its doing a "quick reboot". I dont know....I'm so computer illiterate. I'm sure my lack of knowledge is starting to frustrate you. OH, and it dosent seem have a problem shutting down that i know of when i use the correct shutdown method, but now half the time i have to unplug.one more thing.. in combofix and when closing IE, it LEAVES the desktop background, it only takes the icons. they dissappear but they dont come back. this help is priceless!!! THANKS:eek:
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't run ComboFix anymore. Also skip AVG Antispyware unless already finished with it. Move onto the step with MGtools and get me the log from it named C:\MGlogs.zip
     
  7. stevieink

    stevieink Private E-2

    ok here is the mglogs.zip file. just so you know, while running an error came up that said *Process DLL.exe-Application error--The Application failed to initialize properly (0xc0000135). Click OK to terminate the application. Didnt click ok yet waited till it looked done and just closed window. The zip file was there so hopefully it took. If not just let me know and i'll run again. thanks!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You only received this error because you are missing the Microsoft .NET Framework updates from Microsoft update.

    I'll take a quick look at your logs but I need to get to sleep real soon.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No wonder you are having so many problems!!! You are very badly infected.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to SymWMI Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteSymWSC into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: {81ec669c-3d59-faaa-53a4-8f39651b6110} - {0116b156-93f8-4a35-aaaf-95d3c966ce18} - C:\WINDOWS\system32\ftcnleeq.dll
    O2 - BHO: (no name) - {513CB345-A41E-47F0-8A24-3A237811BF4C} - (no file)
    O2 - BHO: (no name) - {A72F3AE9-61A0-4AE4-9D3D-BEACFF510931} - C:\WINDOWS\system32\mljjh.dll
    O2 - BHO: (no name) - {BBB05D9E-0297-404D-A6BF-D8F2876B84A6} - C:\WINDOWS\system32\rqrqolm.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [44abe178] rundll32.exe "C:\WINDOWS\system32\xvbuypck.dll",b
    O4 - HKLM\..\Run: [WebSavingsfromEbates] wjview /cp:p "C:\Program Files\WebSavingsfromEbates\System\Code" Main lp: "C:\Program Files\WebSavingsfromEbates"
    O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
    O4 - HKLM\..\Run: [updmgr] C:\Program Files\Common files\updmgr\updmgr.exe
    O4 - HKLM\..\Run: [KAZAA] D:\Program Files\Kazaa\kazaa.exe /SYSTRAY
    O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
    O20 - Winlogon Notify: rqrqolm - C:\WINDOWS\SYSTEM32\rqrqolm.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    After reboot, delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp\
    C:\Documents and Settings\STEVIE\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  10. stevieink

    stevieink Private E-2

    Me too. dead tired. Just let me know tomorrow or when you check them out. Appreciate all the help. Until tomorrow......
     
  11. stevieink

    stevieink Private E-2

    first of all..when my computer booted there was NO waiting. it just booted. much faster already and come to think of it NO popups on the way here. just had a couple more questions. are my folders still supposed to be showing hidden files or was i supposed to change that back before? the reason i ask is because on the steps you gave me "after reboot delete all files in below folders and a few files ending in .ill came up and said if deleted could harm my computer. so needless to say i didnt delete them. not gonna finish up till tomorrow anyway so let me know when you get a chance. NO POPUPS!!! unreal. thank you so much for all your time. with skills like that, i'm sure its valueable!!! i'll be sure to send you the logs when i finish up tomorrow. thanks again.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to finish my previous instructions and attach the follow up logs that were requested so we can be sure that everything worked properly.
     
  13. stevieink

    stevieink Private E-2

    here ya go! just let me know. thanks!!
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you actually use WinMXDownloadWinMX3.exe?

    Some items did not get fixed. We need to try again. This time shutdown as much of McAfee as you can before doing the below.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {1D842DE0-D532-478D-8D1B-C5CE6C07B7AA} - C:\WINDOWS\system32\mljjh.dll (file missing)
    O2 - BHO: (no name) - {BBB05D9E-0297-404D-A6BF-D8F2876B84A6} - C:\WINDOWS\system32\rqrqolm.dll (file missing)
    O4 - HKLM\..\Run: [msbb] c:\program files\180solutions\msbb.exe
    O4 - HKLM\..\Run: [AltnetPointsManager] C:\Program Files\Altnet\Points Manager\Points Manager.exe -s
    O20 - Winlogon Notify: rqrqolm - rqrqolm.dll (file missing)

    After clicking Fix, exit HJT.


    Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now please download the current version of MGtools from here: MGtools.exe
    • Save it to c:\MGtools.exe
    • Double click on MGtools.exe to run it and create a new C:\MGlogs.zip file.
    • Attach the new MGlogs.zip file.
    • Also attach then new log from Avenger.
    Make sure you tell me how things are working now!
     
  15. stevieink

    stevieink Private E-2

    No i do not use win mx. now that i load in NORMAL mode it loads up, is in the system tray and i have to exit out of it when i boot. My computer used to load in selective startup. I dont know why. Probably cause i went into startup and checked off boxes to load in startup because it used to take FOREVER to boot.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then have HijackThis fix the startup entry where it loads:

    O4 - Global Startup: WinMXDownloadWinMX3.exe

    Also delete the file. It is probably here:

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinMXDownloadWinMX3.exe
     
  17. stevieink

    stevieink Private E-2

    went ahead and tried to remove mcafee totally because it seemed to not let me disable and it wont let me delete. was planning on deleting anyway because your website says there is better and was just going to download one of those. but couldn't get rid. here are the logs. did the best i could with the disable of mcafee. hope it was OK! thanks.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're logs are clean.

    I still see McAfee. Did you remove it after getting the logs? Or are you saying you're having problems uninstalling McAfee. If having problems, see this: McAfee Consumer Product Removal Tool

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  19. stevieink

    stevieink Private E-2

    just wanted to say thank you to chaslang for helping me with my malware problem. i just finished my final steps of "prevention". All together it cleared up 2 gig of space, i have no popups and my computer runs like i just bought it. lightspeed it seems after all this. thanks for all your time and to everyone who adds info to this website. :cool

    STEVIEINK
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds