Help..major problem after running Ccleaner

Discussion in 'Malware Help (A Specialist Will Reply)' started by BMCI, Dec 14, 2007.

  1. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay just get me the log from MGtools.exe as soon as you can. Do not run anything else except it?
     
  2. BMCI

    BMCI Private E-2


    I hope this works..the problem computer had difficulty uploading the file...so I saved it to a cd and the to the desktop of my other computer...if it is no good I will try again...as always, thank you for your help.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The log file looks okay but I see the below in your log:

    C:\Documents and Settings\Ashley\Local Settings\Temporary Internet Files\Content.IE5\2RG5OD89\MGtools[1].exe

    That means you ran MGtools.exe from the website rather than downloading it as requested. This is not a good thing to do. You are lucky it worked properly. I'm looking at your logs now. It appears that you have a lot of problems.
     
  4. BMCI

    BMCI Private E-2

    Thanks...I have no clue how that ran from the website....
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    While I continue to look thru your logs (there are a lot of things to remove), let's get you started doing a couple of things.

    Goto Add/Remove Programs and uninstall the below:
    Outerinfo
    Viewpoint Manager (Remove Only)
    Viewpoint Media Player



    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Ashley\Local Settings\Temp
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Instead of selecting Save you clicked Open.
     
  7. BMCI

    BMCI Private E-2

    Done..one item could not be deleted in documents and settings
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As you will see from below, you PC was very very badly infected which is more than likely why you had the initial problems getting started.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\lpcywinp.exe,C:\WINDOWS\system32\userinit.exe
    O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file)
    O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file)
    O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file)
    O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file)
    O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
    O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file)
    O2 - BHO: (no name) - {217144f4-1dd2-11b2-80c0-e9c4ec87d9a5} - C:\WINDOWS\azejkbmb.dll
    O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file)
    O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file)
    O2 - BHO: (no name) - {53C330D6-A4AB-419B-B45D-FD4411C1FEF4} - (no file)
    O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file)
    O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
    O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file)
    O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file)
    O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file)
    O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
    O2 - BHO: (no name) - {bb936323-19fa-4521-ba29-eca6a121bc78} - (no file)
    O2 - BHO: (no name) - {C0FD8F6F-40F7-4F20-D22E-3EE6078E5890} - C:\WINDOWS\system32\sxxrpcps.dll
    O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file)
    O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file)
    O2 - BHO: (no name) - {c5af2622-8c75-4dfb-9693-23ab7686a456} - (no file)
    O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
    O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file)
    O2 - BHO: egmulhxk.msdn_hlp - {E78B911A-6F68-4B84-8C19-EC417C9590E2} - C:\WINDOWS\system32\egmulhxk.dll
    O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file)
    O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file)
    O2 - BHO: (no name) - {F1D0BF19-6DC1-0A63-FF1E-09CB41B675A2} - C:\WINDOWS\system32\sxxrpcps.dll
    O4 - HKCU\..\Run: [Uaol] "C:\WINDOWS\ASEMBL~1\dvdplay.exe" -vt yazb
    O20 - Winlogon Notify: ivn4reg - C:\Documents and Settings\All Users\Documents\Settings\ivn4.dll
    O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/Ashley/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg

    After clicking Fix, exit HJT.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  9. BMCI

    BMCI Private E-2

    I continue to have some difficulty with uploading the logs...perhaps because of the improper way I ran it from the web... here is the Avenger info....
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No that has nothing to do with uploading of logs. Describe what problems you are having? Make sure you read messages in the Managing Attachments window. They are not real obvious.

    I need the new MGlogs.zip file to see where you are at.
     
  11. BMCI

    BMCI Private E-2

    Hopefully..this has what you are looking for ... I'm declaring this to be a Christmas Miracle. The computer is better than ever !!!!!!
     

    Attached Files:

  12. BMCI

    BMCI Private E-2

    The upload starts and gets about half way through (according to the green bar) and then just stalls..never making any additional progress...
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now I want you to run MSconfig and set your system for Normal Startup mode like we request in the READ ME. Do not reboot if it tells you it needs to. We will reboot further down.

    A bunch of items we were trying to fix with HijackThis are still in your log. Try fixing the below lines again:

    O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file)
    O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file)
    O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file)
    O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file)
    O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
    O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file)
    O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file)
    O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file)
    O2 - BHO: (no name) - {53C330D6-A4AB-419B-B45D-FD4411C1FEF4} - (no file)
    O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file)
    O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
    O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file)
    O2 - BHO: BndShell3 BHO Class - {875A1348-7674-42aa-ADAC-B4F36A004A2D} - C:\Program Files\QdrDrive\QdrDrive8.dll (file missing)
    O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file)
    O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file)
    O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
    O2 - BHO: (no name) - {bb936323-19fa-4521-ba29-eca6a121bc78} - (no file)
    O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file)
    O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file)
    O2 - BHO: (no name) - {c5af2622-8c75-4dfb-9693-23ab7686a456} - (no file)
    O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
    O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file)
    O2 - BHO: egmulhxk.msdn_hlp - {E78B911A-6F68-4B84-8C19-EC417C9590E2} - C:\WINDOWS\system32\egmulhxk.dll (file missing)
    O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file)
    O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file)

    MAKE SURE you close ALL browsers before clicking Fix checked.

    Now delete the below files:
    C:\WINDOWS\system32\ESHOPEE.exe
    C:\WINDOWS\kvnab.dll
    C:\WINDOWS\Temp\74ee3e7.dat

    Also delete all of the below .dat files in your Temp folder.
    Code:
    C:\Documents and Settings\Ashley\Local Settings\Temp\
    1120490e.dat  Dec 21 2007       16651  "1120490e.dat"
    1dac418.dat   Dec 21 2007       16441  "1dac418.dat"
    2962839a.dat  Dec 21 2007       16651  "2962839a.dat"
    3138773f.dat  Dec 21 2007       16651  "3138773f.dat"
    35628ab5.dat  Dec 21 2007       16441  "35628ab5.dat"
    3687afbc.dat  Dec 21 2007       16441  "3687afbc.dat"
    36fee10f.dat  Dec 21 2007      135660  "36fee10f.dat"
    37b81bc.dat   Dec 21 2007       96862  "37b81bc.dat"
    40645f9a.dat  Dec 21 2007       13898  "40645f9a.dat"
    52cf394c.dat  Dec 21 2007      135660  "52cf394c.dat"
    56eed422.dat  Dec 21 2007      135660  "56eed422.dat"
    5b9a4fda.dat  Dec 21 2007       16441  "5b9a4fda.dat"
    5c0c39a.dat   Dec 21 2007       16441  "5c0c39a.dat"
    620e1b00.dat  Dec 21 2007           0  "620e1b00.dat"
    664beecf.dat  Dec 21 2007       16651  "664beecf.dat"
    6a87b9.dat    Dec 21 2007       16441  "6a87b9.dat"
    6ba21c7d.dat  Dec 21 2007      135660  "6ba21c7d.dat"
    6baa4166.dat  Dec 21 2007       16441  "6baa4166.dat"
    6c1e586b.dat  Dec 21 2007           0  "6c1e586b.dat"
    704febab.dat  Dec 21 2007      135660  "704febab.dat"
    70b12812.dat  Dec 21 2007       14217  "70b12812.dat"
    70ebcd59.dat  Dec 21 2007       16651  "70ebcd59.dat"
    7293f4c.dat   Dec 21 2007      135660  "7293f4c.dat"
    76456b75.dat  Dec 21 2007        4097  "76456b75.dat"
    a1bce402.dat  Dec 21 2007      135660  "a1bce402.dat"
    a745d0d.dat   Dec 21 2007      135660  "a745d0d.dat"
    abf83be6.dat  Dec 21 2007           0  "abf83be6.dat"
    aca55784.dat  Dec 21 2007       16441  "aca55784.dat"
    b95d5024.dat  Dec 21 2007       16441  "b95d5024.dat"
    c4488df9.dat  Dec 21 2007       14409  "c4488df9.dat"
    c8bbe3c0.dat  Dec 21 2007        2785  "c8bbe3c0.dat"
    d2c9139d.dat  Dec 21 2007      135660  "d2c9139d.dat"
    d4f5dc64.dat  Dec 21 2007       20481  "d4f5dc64.dat"
    d6756f53.dat  Dec 21 2007       16651  "d6756f53.dat"
    da31b4e.dat   Dec 21 2007       16651  "da31b4e.dat"
    e2ed530.dat   Dec 21 2007       16651  "e2ed530.dat"
    e9f65437.dat  Dec 21 2007      135660  "e9f65437.dat"
    f6444ca1.dat  Dec 21 2007      135660  "f6444ca1.dat"
    f9dec5d.dat   Dec 21 2007      135660  "f9dec5d.dat"
    fc6ee3b2.dat  Dec 21 2007       16441  "fc6ee3b2.dat"
    fd2d7200.dat  Dec 21 2007       16441  "fd2d7200.dat"
    fd49c368.dat  Dec 21 2007       16441  "fd49c368.dat"
    fdfa76bf.dat  Dec 21 2007       16441  "fdfa76bf.dat"

    Now uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) 6 Update 2

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.
     
  14. BMCI

    BMCI Private E-2

    Hi...I followed the prior instructions... no problems although my inability to upload continues from the problem computer... so, again I am hoping I have transferred this info properly...thanks, as always.
     

    Attached Files:

  15. BMCI

    BMCI Private E-2


    For what it's worth...I just received this message from teh Trend Micro PC-illin ...
    Trend Micro PC-cillin Internet Security has detected a virus, spyware application, or other Internet threat, and performed the action specified.

    Infected file: C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP329\A0087084.exe
    Virus name: TROJ_VB.CXL
    User name: Ashley
    Scan action result: Quarantined.

    Thought I would pass it along as I received the message after performing all of the other tasks...
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thist does not appear to be a malware issue. It could be an issue with a setting on your PC. Possibly something with TrendMicro like in the firewall or similar. You should also try downloading and installing another browser like Mozilla FireFox and see if you can upload using it without a problem.


    This is just something in System Restore which my final steps will take care of.

    Now delete the below files:
    C:\WINDOWS\kvnab$.exe
    C:\WINDOWS\kvnab.exe
    C:\WINDOWS\wbeCheck.exe
    C:\WINDOWS\wbeInst$.exe

    Then reboot and make sure that they are still gone. If they are, then your logs will all be clean and you can continue on with the below.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  17. BMCI

    BMCI Private E-2

    Chaslang..just a quick note to express my sincere gratitude. The computer is running great..I went ahead and installed Mozilla as you suggested and have read through the Malware link...I cant thank you (and your colleagues) enough for the tremendous service you provide. Happy Holidays to you and all !!
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Happy malware free Holidays! ;)
     
  19. Matacumbie

    Matacumbie Rocky Top

    Man, great job on this one chas. ;)

    I have been kind of following along and thought for sure this one was hopeless and they would have to take drastic measures. I know they truely appreciate your efforts.

    You are the best my friend. :)

    Steve
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks Steve! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds