Strange system service names YQDASL and BOPRVULM?

Discussion in 'Malware Help (A Specialist Will Reply)' started by dinogeek, May 26, 2008.

  1. dinogeek

    dinogeek Private E-2

    I am having some blue-screen trouble after starting a HW update from Windows Update for my Soudblaster Audigy. In researching how to get back to square one with that, I noticed two very strange "services: in MSCONFIG Services tab. The names are just YQDASL and BOPRVULM.

    Does anyone have any idea what these are? Google doesn't and searhing these forums hasn't turned up anything either. Are these malware items?

    Any info appreciated.

    dinogeek
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not. Make sure that you follow the instructions in step 1 for putting MSconfig in Normal Startup mode, otherwise I will just be asking you to do it again before we get started on trying to take any further steps.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. dinogeek

    dinogeek Private E-2

    OK, I've just done that whole process last week so I am familiar with it. I will do it again but it will be quite a while until it's done. This machine has a boatload of software loaded so the scans take a long time.

    I'll be back when it's done. Thanks for the advice.

    dinogeek
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then you should have attached the logs at that time if you were having a problem.
     
  5. dinogeek

    dinogeek Private E-2

    At the time I did not have a problem anymore. The virus or trojan or whatever it was no longer had my machine by the throat. It started again this morning after an MS update from Win Update pages for a sound driver (SB Audigy).

    Now I have a worse problem. After running CCLeaner on primary userid and one of three secondary userid's, I now get a bluescreen STOP X'0000007E' on any regular boot. I can boot to safe mode or safe mode with networking, but not any regular boot. No driver is mentioned as the source of the X'7E' stop problem.

    Where do I go from here? Spyware scans in safe mode?

    Any advice greatly appreciated.

    dinogeek
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can try that but some of your problems are not sounding like malware.
     
  7. dinogeek

    dinogeek Private E-2

    OK, I'm up to some research and RTFM, but please tell me where to start.

    dinogeek
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All I can help you with here is malware, but you need to be able to boot your PC to do that. Can you boot up? In either safe mode or normal mode?

    When you ran CCleaner exactly what did you do with it? Please be specific.
     
  9. dinogeek

    dinogeek Private E-2

    I ran CCLeaner in my primary userid exactly as specified in the instructions, windows tab only, no changes to the options. Then I logged off and ran it in the second userid, then I logged off and got a bluescreen before I could login to the third userid. I rebooted and got the STOP X'7E' bluescreen every time since them on a regular boot.

    I booted into safe mode and ran CCLeaner in the Administrator userid and then in the third regular userid (also in safe mode).

    I can boot into safe mode or safe mode with networking. I am currently running Superantispyware on my primary userid in safe mode with networking, with the network connection unplugged.

    dinogeek
     
  10. dinogeek

    dinogeek Private E-2

    I am going to let the Superantispyare run overnight, I am falling asleep and need to get to work in the morning. I will post again in about 18-20 hours with an update when I get home from work.

    Thanks for your prompt responses. Talk to you again soon.

    Peter
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And this occurs before the Windows Login forum even appears?

    Okay we will see you some time tomorrow. ;)
     
  12. dinogeek

    dinogeek Private E-2

    Yes. It turns out the bluescreens were caused by a bad re-install of the sound drivers for my SB Audigy2 LZ sound card. I have uninstalled them again and now I can do a normal boot. No sound, but I can boot.

    It's not a coincidence that this whole mess started with an MS Update change to a "sound driver" (kb/920872) that I blindly allowed to be applied.

    While in Safe mode w/networking last night I did run Superantispyware (unplugged from the network, as instructed, but it found nothing) and Spybot S&D this morning before work (found only old RegClean logs and Windows Security turned off by Norton 2008).

    Now that I have a regular boot back I'm going back to step one and will run SAS again in normal mode overnight. I'll report back after I finish the rest of the read-me steps.

    The reason I think I still have a malware problem is that before the bluescreens started, when I logged into the second userid on this system to run CCLeaner, I could not run Win Task manager. I got the same message that I got a few weeks ago when I was first infected: "Task Manager has been disabled by your administrator". I certainly didn't do that, so I'm thinking it's more malware.

    I'll post my logs if I can't find and fix whatever this is.

    Thanks again for the help and advice, and for the well-written instructions.

    Bye for now.

    dinogeek
     
  13. dinogeek

    dinogeek Private E-2

    Attaching first three log files, fourth to follow.

    dinogeek
     

    Attached Files:

  14. dinogeek

    dinogeek Private E-2

    Fourth log file.

    Will reboot and check secondary userid's while you look at these logs.

    Again, many thanks for your patience and help.

    dinogeek
     

    Attached Files:

  15. dinogeek

    dinogeek Private E-2

    Both secondary userid's on this machine have the "Task manager disabled by your administrator" problem. They also take an extraordinarily long time to get the internet connection activated. Taskbar has a solid hourglass and cannot be accessed until the connection is activated.

    Internet connection is wired ethernet to router to cable modem.

    Primary userid does not seem to have these problems.

    Minor problem: The AM/PM time format was not restored after Combofix, I have to go to regional settings to restore it.

    I will await your reply and will not try to restore the sound drivers (which caused those bluesceeen problems earlier) until I have heard back from you.

    Thanks for your help.

    Peter
     
  16. dinogeek

    dinogeek Private E-2

    I found some registry entries with the names mentioned in the title of this post (though I mis-spelled one, it is really YPQDASL not YQDASL).

    Text file of registry entries attached for your review. It looks like at least YPQDASL was at one time an executable in my LocalSettings/temp directory, if that means anything. It is no longer there.

    dinogeek
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 4
    Java 2 Runtime Environment, SE v1.4.2_06
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {bc97b254-b2b9-4d40-971d-78e0978f5f26} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKCU\..\Run: [Sonic RecordNow!] "C:\Program Files\Messenger\msmsgs.exe" /background
    O23 - Service: Windows Action Script - Unknown owner - C:\WINDOWS\system32\scvhost.exe (file missing)
    O23 - Service: YPQDASL - Unknown owner - C:\DOCUME~1\Peter\LOCALS~1\Temp\YPQDASL.exe (file missing)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  18. dinogeek

    dinogeek Private E-2

    Sorry about missing the Viewpoint uninstall, I guess my eyes just glazed over it.

    I can and will uninstall the J2SE Runtime Environment 5.0 Update 4 (I should have installed 6.0 already anyway), but I can't uninstall the Java 2 Runtime Environment, SE v1.4.2_06 because I also use this machine for my employer's work, and they have said in the past that software I must use for work that they supply won't work with any more recent version. I haven't checked with the company PC support folk recently though, so I'll check with them tomorrow if I can uninstall it. Unlike you and I, they don't work nights... :(

    I'll get to the rest of your steps this evening and post the logs later.

    Thanks for all your help.

    dinogeek
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Old versions of Java, especially these real old 1.4 versions are very susceptible to Virtumonde and other infections. It is dangerous to keep these old versions installed and in use. Someone needs to update their scripts to the current versions of Java. If they value the security of their PC network and know what they are doing, they should have already done this.
     
  20. dinogeek

    dinogeek Private E-2

    That's a *great* argument for me to make when I speak to them, so thanks for that.

    I didn't get to the other steps you gave me yet because I had a nasty BSOD to get around first. It turned out to be a failed sound card. When I pulled that card I could boot to normal mode again. It's now late night again and I have to go to work in the morning, so I will run through your instructions tomorrow evening and send back the logs.

    Thanks once again for your patient and generous help.

    Bye for now.

    dinogeek
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just attach the new logs when you finish up and make sure you tell me how things are working.
     
  22. dinogeek

    dinogeek Private E-2

    New logs attached. The registry update was successful, but I haven't tried the secondary userid's yet.

    Last remaining problem is that the wired internet connection takes an *extraordinarily* lo-o-o-ong time to come up. Like 10-15 minutes or more. I have to walk away from the machine and come back later, so I don't have exact timings, but it's a *long* time. All the other taskbar tasks come up reasonably quickly (under 3 minutes).

    I'll report back again after I check out the secondary userid's.

    dinogeek

    [Edit] The secondary userid's still cannot run Task Manager, only the primary userid. It takes about 5 minutes (it really did seem longer than 5 mins on the primary userid, I'll re-verify that in a minute) for the wired internet connection to come up on the *first* user to login after power-up, but for subsequent logoff/logins to any other userid the connection comes up quickly (under 2 mins).
     

    Attached Files:

    Last edited: May 30, 2008
  23. dinogeek

    dinogeek Private E-2

    Sorry for the double post, but the site wouldn't let me edit the prior message again.

    Primary userid only takes 5 minutes to bring up the wired internet, consistent with the other userid's. I guess time is relative when you're staring at a screen waiting for something to happen.

    So the last remaining problem seems to be the inability to run task manager on the secondary userid's. This worries me. Should I be worried or not?

    dinogeek

    P.S. -- I'm about ready to uninstall that old Java release regardless of my employer's needs and deal with the consequences later. If that's your advice, I will do it.
     
  24. dinogeek

    dinogeek Private E-2

    Another problem seems to have cropped up. I cannot plug in a USB-key drive and have it recognized, and the system doesn't recognize any of the partitions on the external USB drive that I use to boot (the boot is a Linux grub boot, defaulting to WinXP for the prmary OS on the internal SATA drive). Since I can boot, I know the hardware is working. There are several FAT and FAT32 partitions on that external drive.

    The HW device USB Mass Storage is also not working in the Hardware Manager, device driver USBSTOR.SYS.

    Ths only USB-connected "drive" that is seen is the media-card reader integrated into my printer (HP Photosmart 1218).

    Did any of these procedures modify or delete a file or service that would disable regognition of USB drives? I'm especially curious about the "svchost" that was deleted, was that relevant to this USB problem?

    dinogeek
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should read this sticky: Don't Bump! It Only Hurts You!!! Each additional post you made still bumps you whether intentional or not and cost you more than a day of additional waiting time.

    This is most likely not a malware issue. Are you referring to the time it takes after you boot up until the time you can get a browser to connect or are you referring to something else? ....... Okay I see from below you are referring to the time it takes after boot and also for subsequent logins. This may just be due to what you are running.



    You will have to run the cleaning procedure on this user account after we are finish with the first account (which I believe we are since your logs are clean and remaining issues are not malware).


    I suggest that you try two test uninstalls to see what impact they have:
    1. Uninstall your Roxio Software it has been shown to slow down PCs quite a lot
    2. Uninstall Symantec - it has always been a resource hog
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not related to any malware that you had. You may need to reinstall some drivers.

    No this is not related. We did not remove anything related to USB drives and the file name was scvhost.exe not svchost.exe. scvhost.exe is this http://www.sophos.com/security/analyses/viruses-and-spyware/w32agobots.html
     
  27. dinogeek

    dinogeek Private E-2

    You're right, I should have read that first. I was just trying to provide information, not bump. I'll wait for a response in the future.

    OK, it's good to know the first account is clean, but do I understand you correctly -- I need to run the whole READ ME process again on both of the secondary userid's on this machine?

    I will give that a try after the cleanup of the other accounts. Please let me know soonest if I understand you correctly about the cleanup process.

    dinogeek

    [Edit] Thanks also for the answers to my other questions. I won't reply separately to that one so that I don't bump myself. [/Edit]
     
    Last edited: Jun 2, 2008
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is best to work on only one user account at anytime to avoid confusion. Thus if you have two others, pick one to start with and we will work on it until it is declared clean and then we will start the other. As far as running the whole READ ME, no it is not necessary at this time. Here is what you should do.

    • reboot and login to the other account ( DO NOT use Switch User! Make sure you reboot and then login to only that account)
    • run Malwarebytes and save a log
    • run C:\MGtools\GetLogs.bat
    • attach the MBAM log and the new C:\MGlogs.zip file.
    • Along with the logs, tell me what problems this user account is currently having
     
  29. dinogeek

    dinogeek Private E-2

    Logs for second user of three attached.

    Things not right with the second user:

    1) It took literally 30 minutes to activate the wired internet connection tonight. I *think* this is mainly due to many non-working parts of the sound system (lots of yellow triangles in the Hardware Manager). I suspect but can't yet prove that the system's trying and retrying those drivers delays the wired internet connection extensively.

    2) Obviously, no sound available (primary user doesn't have any either).

    3) Cannot run Task Manager ("... disabled by your administrator").

    4) Internet Explorer screen scrolling is quite "jerky", not smooth like it was before the malware infection and cleanup (same problem with primary user as well).

    5) When turning off the system, "Stand By" is greyed out and cannot be selected. Only "Turn Off" and "Restart" can be selected (primary user also has this problem).

    One other item I forgot to mention yesterday is that after the last cleaning of the primary user, now Windows Explorer comes up every time the primary user logs on, displaying the C:\Windows\system32 directory. I can just close it without any further problems, but it's really quite annoying, and just a little worrisome. Is something evil trying to start itself, or perform some other bad thing?

    Thanks again for all of your help.

    dinogeek
     

    Attached Files:

    Last edited: Jun 4, 2008
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These logs are all free from malware, so I suggest that you post in the Software or Hardware Forum for you issues with getting your internet connection fixed. Based on the yellow triangles you are reporting, sounds like you have driver issues to fix.

    • Download SeDebug-Restore
    • Save to the Desktop or this user account.
    • Now double click to run.
    Did this help?

    While it is possible that malware may have instigated some issues, there is no remaining malware that is causing this. You should resolve your hardware driver issues first and then continue to work this in the Software Forum if necessary.

    This could be disabled due to your driver issues. If a card is not able to support standby (possibly due to drivers), the feature may be disabled by Windows.

    This is not malware. Normally this happens when a startup registry key is not properly setup and it can cause the system32 folder to open at startup. You could experiment with MSConfig (this is the kind of debug it was designed for) by disabling various startup entries a few at a time to see if you can locate which entry may be cause this.
     
  31. dinogeek

    dinogeek Private E-2

    Thank you, it is good to know that it isn't more malware. I will address the driver issues separately.

    No, I got this result when I ran it:

    '\cscript.exe' is not recognized as an internal or external command,
    operable program or batch file.

    Please reboot your machine

    Press any key to exit

    Thanks again for your advice on all three of those issues and for your help with this infection. I will indeed address the driver issues and proceed from there.

    dinogeek
     
  32. dinogeek

    dinogeek Private E-2

    Followup about SeDebug-Restore.exe -- the messages seemed to indicate it did not work, but in fact I *can* now bring up Task Manager on the secondary userid, so whatever it did actually worked.

    Thanks again for your help

    dinogeek
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Great! ;)


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    9. Go to add/remove programs and uninstall HijackThis.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    12. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds