"outerinfo" program removal failed

Discussion in 'Malware Help (A Specialist Will Reply)' started by Somemelvin1, Sep 5, 2008.

  1. Somemelvin1

    Somemelvin1 Private First Class

    I was following the clean up process in http://forums.majorgeeks.com/showthread.php?t=79754

    And I found a match on the list of programs that needed to be removed.
    After selecting "remove" under "Add or remove programs" for the "outerinfo" program I received the following message:

    Yazzle Uninstall window popped up
    "Download of uninstaller failed: resolving hostname. Please download and run the uninstaller from http://www.outerinfo.com/OIuninstaller.exe"

    I noticed that Yazzle was also a program on the remove list so I wasn't sure how to proceed.
    Thanks in advance for any insight.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    That uninstaller for OuterInfo and Yazzle will more than likely not even exist anymore. If you have these infections, it is quite possible you have others. Thus you should follow the instructions in the below link and attach the requested logs when you finish these instructions.



    READ & RUN ME FIRST. Malware Removal Guide
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:
    1. If you run into problems trying to run theREAD & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
    Last edited: Sep 6, 2008
  3. Somemelvin1

    Somemelvin1 Private First Class

    Thanks for the guidance. I started working through the instructions and when I selected MGtools.exe link to download it, I received the following messgae:
    Invalid attachment specified. If you followed a valid link, please notify the administrator.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try it again as it seems fine. Perhaps you were trying when it was being updated today.
     
  5. Somemelvin1

    Somemelvin1 Private First Class

    Here are the logs. One point to note:
    While running MGtools, I received the following:
    Processdll.exe - applicaion {window}
    "The application failed to initialize properly (0xc0000135)
    Click to terminate the application"
     

    Attached Files:

    Last edited: Sep 7, 2008
  6. Somemelvin1

    Somemelvin1 Private First Class

    ...and the 4th log
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It was explained in the Using MGtools instructions. ;)



    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O15 - Trusted Zone: *.gomyhit.com (HKLM)
    O15 - Trusted Zone: *.imageservr.com (HKLM)
    O15 - Trusted Zone: *.storageguardsoft.com (HKLM)

    After clicking Fix, exit HJT.

    Now delete the below files if they still exist:
    C:\WINDOWS\Temp\bca4e2da.$$$
    C:\WINDOWS\Temp\fa56d7ec.$$$
    C:\Documents and Settings\Parent\Local Settings\temp\pcf24.tmp

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:
    • C:\MGlogs.zip

    Are you currently having any malware problems?
     
  8. Somemelvin1

    Somemelvin1 Private First Class

    You wrote:
    Now delete the below files if they still exist:
    C:\WINDOWS\Temp\bca4e2da.$$$
    C:\WINDOWS\Temp\fa56d7ec.$$$
    C:\Documents and Settings\Parent\Local Settings\temp\pcf24.tmp

    I found the first 2 but not the 3rd one.
    When trying to delete the first 2, I received:
    Can not delete: It is being used by another person or program.

    I closed AVG and superAntispyware, but no luck deleting them.
    Should I close Zone Alarm too? I'm not sure what else is left.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay forget the previous procedure and let's do something different.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run this procedure: Running GMER to detect rootkits


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • GMER log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. Somemelvin1

    Somemelvin1 Private First Class

    I ran Combofix with CFscript.txt as requested. log is attached.
    I ran fixme.reg and received a success message.
    Tired to run Gmer. It crashed in the middle with blue screen. It says to run in safemode if you have problems, but it doesn't give instructions on how to get into safemode.
    I also ran Cclean.

    btw: "outerinfo" is not in the add/remove programs.
    However, the system still seems quite slow.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Use the below instructions to get into safe mode and try running GMER again. Attach the log if you get it to run.

    Starting your computer in Safe mode

    If you cannot get GMER to run then try the below instead:

    Using Sophos Anti-Rootkit
     
  12. Somemelvin1

    Somemelvin1 Private First Class

    I started the computer in Safemode. Ran GMER again. It started fine. When it was time to select SCAN, I was not able. The button was not active.
    I ran sarscan and it didn't find any hidden files. When I attempted to find the log per your instructions, a window popped up saying it couldn't find the file.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's just try something different.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  14. Somemelvin1

    Somemelvin1 Private First Class

    I executed the Avenger and it appeared to run fine.
    The fixme.reg executed successfully.
    CClean found and cleaned several files.
    When executing MGtools\GetLogs.bat, I received the following:
    Processdll.exe - application error
    The application failed to initialize properly (0xc000135)
    click ok to terminate.

    FYI: I found that the following files are still around:
    C:\WINDOWS\Temp\bca4e2da.$$$
    C:\WINDOWS\Temp\fa56d7ec.$$$

    another note: while waiting for your last response, I ran Adaware, which found purityscan (category: malware, TAI: 6) I mention this in case it is relevant.

    a final note: the CD drive does not work and hasn't worked for a long time. I didn't think it was related but wanted to mention this.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Put the below files into a ZIP file and attach it here. I'm wondering if maybe these are just valid temp files for something you are running.
    Code:
    "C:\WINDOWS\Temp\"
    bca4e2da.$$$  Sep 14 2008       46367  "bca4e2da.$$$"
    ed47fa.$      Sep 14 2008           4  "ed47fa.$"
    fa56d7ec.$$$  Sep 14 2008          45  "fa56d7ec.$$$"
    Neither are related. You should work you CD drive issue in the Hardware forum.


    Please run the below and attach the requested log:
    Using Dr.Web CureIt

    How is everything working at this time?
     
  16. Somemelvin1

    Somemelvin1 Private First Class

    You asked for 3 files in a zip file. Where is the zip utility?
    I ran curit and it found "backdoor.maosboot" on the first scan. then a window popped up:
    "to cure 1 or several infections a restart may be required. do you want to restart?"
    I selected yes and my system immediately restarted.
    I then initiated curit again to run through the 2 scans.
    I was not able to do the following 2 steps:
    "When the scan has finished, look if you can click next icon next to the files found:"
    "If so, click it and then click the next icon right below and select Move incurable as you'll see in next image: "
    I did save a report and attached DrWeb.txt.
    Then I "selected all" and "cure" and "move incurable". I then generated another report and attached, DrWeb2.txt

    Start up is quite slow: 5 min. Perhaps my settings for zone alarms and AVG 7.5 should be adjusted. If you have a link with advice on settings for these, please pass it along.

    When and how should I remove the programs that we have put on for Malware during this process?
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I just assumed you had one. You can use this: 7-Zip if the files are still there.

    Also run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the new C:\MGlogs.zip file


    Is the below Remote Administration tool something you installed?

    O23 - Service: PLSRemote Service (PLSRemoteSvc) - Unknown owner - C:\WINDOWS\SYSTEM32\PLSRemote.exe
     
    Last edited: Sep 16, 2008
  18. Somemelvin1

    Somemelvin1 Private First Class

    I do not recognize the Remote Administration tool you have asked about.

    When executing MGtools\GetLogs.bat, I received the following:
    Processdll.exe - application error
    The application failed to initialize properly (0xc000135)
    click ok to terminate.
    after clicking ok, this was the last statement on the screen:
    "could not find c:\documents and settings\parent\desktop\procdll.txt
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This error and fix were describe in theUsing MGtools link given in the READ & RUN ME.

    Let's remove that remote adminstration service.

    Open a command prompt window by clicking Start, Run, and enter cmd and click OK. If the window opens type each of the below commands in. Follow each by the enter key. Note there are spaces after the sc and after the stop and after the delete.

    sc stop PLSRemoteSvc
    sc delete PLSRemoteSvc

    Then reboot your PC. After reboot, delete the below file found
    C:\WINDOWS\SYSTEM32\PLSRemote.exe


    Also run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the new C:\MGlogs.zip file
     
  20. Somemelvin1

    Somemelvin1 Private First Class

    I could not stop or delete PLSRemoteSvc. Here is the message:
    [SC] Open Service Failed 1060:
    the specified service does not exist as an installed service.

    MGlogs attached.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't worry about PLSRemoteSvc! It was removed by Dr. Web CureIt


    Please download the following & save to your Desktop

    GMER's MBR.exe
    • Double click on the MBR.exe file to run it.
    • A log will be produced & saved to the desktop, called mbr.log.
    • Attach this log to your next message.
     
    Last edited: Sep 18, 2008
  22. Somemelvin1

    Somemelvin1 Private First Class

    MBR.LOG attached.
     

    Attached Files:

    • mbr.log
      File size:
      270 bytes
      Views:
      2
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now delete the currentmbr.log file and then run the below instructions.
    Click Start > Run and copy & paste the following text in the code box into the Run box and then click OK. You must copy and paste or type in this exactly. The quotes must be exactly as shown and there is a space before the -f
    Code:
    [B]"%userprofile%\desktop\mbr.exe" -f[/B] 
    Now double click on the mbr.exe file and attach the new mbr.log

    Then reboot and see if the below files still exist. If they do, then see if you can delete them.

    Also run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the new C:\MGlogs.zip file
     
  24. Somemelvin1

    Somemelvin1 Private First Class

    You wrote:
    Then reboot and see if the below files still exist. If they do, then see if you can delete them.
    Which files below are you referring to?

    I attached mglogs.zip. However, MBR.log could not be attached. the following is the error message I received:
    mbr.log:
    You have already attached this file in thread : "outerinfo" program removal failed


    Here is what mbr.log contains:
    Stealth MBR rootkit detector 0.2.4 by Gmer, http://www.gmer.net

    device: opened successfully
    user: MBR read successfully
    kernel: MBR read successfully
    user & kernel MBR OK
    malicious code @ sector 0x4476cc0 size 0x1fd !
    copy of MBR has been found in sector 62 !
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I was referring to the previous files we had mentioned. These
    Code:
    "C:\WINDOWS\Temp\"
    bca4e2da.$$$  Sep 14 2008       46367  "bca4e2da.$$$"
    ed47fa.$      Sep 15 2008           4  "ed47fa.$"
    fa56d7ec.$$$  Sep 14 2008         526  "fa56d7ec.$$$"
    See if you can delete them; however boot into safe mode to try this.
     
  26. Somemelvin1

    Somemelvin1 Private First Class

    The files were deleted.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Great!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  28. Somemelvin1

    Somemelvin1 Private First Class

    Can you provide advice on settings for zone alarms and AVG 7.5?
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The defaults work just fine.
     
  30. Somemelvin1

    Somemelvin1 Private First Class

    I had put Combofix.exe on the desktop; however, it is now in C:\documeents and settings\parent\doctorweb\quarantine. Should I use this directory name in the following statement:
    "%userprofile%\Desktop\combofix" /u

    Also, When Uninstalling Hijackthis 2.0.2, I received an uninstall error: An error occred while trying to remove hijackthis 2.0.2. It may have already been uninstalled. would you like to remove it from add or remove programs list?
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You could try that or you could move it back where it belongs and use the correct command.

    Just say yes.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds