Help Virus wont go away

Discussion in 'Malware Help (A Specialist Will Reply)' started by TheTick, Jan 4, 2007.

  1. TheTick

    TheTick Corporal

    Hey guys

    I have blueyonder antivirus software which updates everyday and is good, but it keeps picking up these two viruses in my machine and says that it cannot delete them straight away, it will have to delete them on the next reboot, but it never does.

    I have tried everything you suggested

    turned off sys restore and opened up hidden files then ran the anti virus and lava soft adware.

    I have tried bit defender as well using the same precedure as before but it says it cannot delete the file

    CCleaner as well.

    The file in question is these three
    C:\WINDOWS\TEMP\WIN26.TMP.EXE
    C:\WINDOWS\TEMP\WIN3C9.TMP.EXE
    C:\WINDOWS\TEMP\WIN2D.TMP.EXE
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. TheTick

    TheTick Corporal

    Here are the attachments for you to have a look at cheers by the way.

    Soz for it being late my comp crashed a few times then my monitor died so i have given up for the min.

    The problem is that my virus software keeps picking up the viruses and says it will delete after the next reeboot, but it does not, it also asks me to scan for viruses after it picks up a virus which i do but nothing is found. Then when i turn my PC back on the viruses have been picked up again
     

    Attached Files:

  4. TheTick

    TheTick Corporal

    here are the final files that need to be attached to the message

    I could not run panda scan at the min

    Cheers for this guys
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why couldn't you run Panda? And more importantly why did you do the steps out of order? The logs from GetRunKey and ShowNew should have been obtained after all the other scans were run and jsut before HijackThis. The were run before you even ran CounterSpy. You must follow steps in the order written.

    You also did not uninstall the below malware bundlers as requested in step 0 of the READ ME. Uninstall them now.
    Morpheus 5.3 (remove only)
    Morpheus Toolbar
    SelectRebates

    It also looks like you skipped step 2 of the READ & RUN ME and did not properly enable viewing of hidden files.

    You also need to go back and re-run CounterSpy. You had it ignore all the malware it found. This time Quarantine everything. Attach a new log from CounterSpy.


    Also attach new logs from GetRunKey and ShowNew after doing all of the above.

    You also did not install and rename HijackThis as requested in step 7 and you also got your log from Safe Boot mode which we do not want. Please install and rename HijackThis as specified and then attach a new log from Normal Boot mode.
     
    Last edited: Jan 9, 2007
  6. TheTick

    TheTick Corporal

    Hi i know i am probably bothering you by now but what are Select Rebates. I am kind of new to all this spyware and trojan virus stuff so can you bare with me

    Cheers
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you don't know what it is then you probably did not install it nor do you want it. From what I know, it is adware or is a bundler of adware/malware or it comes from another bundler of malware (possibly Morpheus)

    It may also be related to http://www.shopathome.com/TermsAndConditions.aspx
     
  8. TheTick

    TheTick Corporal

    Virus wont go away part 2

    hi i posted a few days ago and go a mini lecture off one of the experts lol.

    Well i am back and have followed all of the cleaning procedures to the letter so hear goes.

    A Brief description

    My anti virus S/W keeps saying it is picking up viruses and tells me it cannot delete them, it will only do it after the next reboot. And the next reboot the same thing happens.

    I followed the cleaning procedures right through this time. and it keeps popping up with one rather annoying one.

    I will attach the txt files that i ran for you to have a look at

    Cheers for the help guys

    PS if the txt files are posted out of order thats cause i dont really know what order theyt go in, but be sure they were run in the correct order.
     

    Attached Files:

  9. TheTick

    TheTick Corporal

    Re: Virus wont go away part 2

    here are more txt files
     

    Attached Files:

  10. TheTick

    TheTick Corporal

    Re: Virus wont go away part 2

    Also after all of this cleaning which took me ages in safe mode this certain pop up keeps coming up and it is really annoying. I took a screen dump of it so you can take a look, i dont know if it will be much use
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Virus wont go away part 2

    And now another one! Please remain in one thread for your current malware problem! There was no reason to start a new thread and lose the history of what was going on. I'm merging your threads back together.

    Are you referring to the minor issue you posted a snapshot of. That is nothing and can simply be removed by emptying your Temp folder which running CCleaner should do too (assuming you ran it while logged in as Adam).

    You need to run CounterSpy again and have it Quarantine what it finds. I also told you this in message # 5. You can Ignore WeatherBug if you installed it and really need it but you must fix the other items. Attach a new log after Quarantining all the problems!


    Continue by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)
    Also make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of winuqw32.dll once and then click the kill button. After you have killed all of the winuqw32.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of winuqw32.dll and kill it. (If you do not find the dll, just continue on.)
    Next double click on iexplore.exe and again click once on each instance of winuqw32.dll and kill it. (If you do not find the dll, just continue on.)


    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - (no file)
    O3 - Toolbar: (no name) - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - (no file)
    O4 - HKLM\..\Run: [Explorer] C:\WINDOWS\iexplore.exe
    O4 - HKLM\..\RunServices: [winlog] winlog.exe
    O4 - HKLM\..\RunServices: [virtual-ie] winlogi.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O16 - DPF: {FF3F0F03-0F01-131A-A3F9-08F02B23E0CC} - http://66.117.37.13/dba2161.exe
    O20 - Winlogon Notify: winuqw32 - C:\WINDOWS\SYSTEM32\winuqw32.dll
    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    C:\Program Files\Common Files\{1D3114DA-068B-2057-0820-02101502002c}\Update.exe
    C:\WINDOWS\system32\stickrep.dll
    C:\WINDOWS\iexplore.exe
    C:\WINDOWS\SYSTEM32\winuqw32.dll
    C:\WINDOWS\SYSTEM32\winlog.exe
    C:\WINDOWS\winlog.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.
    After reboot locate the below folders and delete if found:
    C:\Program Files\Common Files\{1D3114DA-068B-2057-0820-02101502002c}
    C:\Program Files\Common Files\{3D3114DA-068B-2057-0820-02101502002c}

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp\
    C:\Documents and Settings\Adam\Local Settings\Temp\

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Jan 11, 2007
  12. TheTick

    TheTick Corporal

    Man your cool

    The steps in the last post went fairly smoothly. There was one problem with Counterspy, it will not update with the new info it needs, i did not want to risk it missing anything so i ran that AVG anti spyware, and followed all the instructions there, i quarantined (Soz bout the spelling) all of the spyware and other stuff. I dont know if you need it but i will add the AVG file too.

    Other than that the steps went smoothly.

    I will mention that my computer has started to run slower than it was a week ago, i put it down to the viruses but it has not speeded up. Any tips?

    As of yet the anti virus S/W has not picked up any viruses but it might after the next reboot, if it does i will let you know

    Dont suppose you can tell me in lemans terms what i just did to my comp can you

    One other thing can you reccomend any good pop up blockers
     

    Attached Files:

  13. TheTick

    TheTick Corporal

    AVG Log

    cheers for this
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Now that we are finished with CounterSpy and also AVG Antispyware, uninstall both of them now. This will speed things up.

    Also don't run things that you don't need. For example, you can have HJT fix the below unnecessary line:
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot


    The easiest way to put it with getting too complex is that you fixed a load of malware (Virtumonde, Winlogonhook, Maxifiles, and many more misc trojans).

    Use FireFox. A popup blocker is built-in. Adding an additional specific program to do popup blocking will just slow your PC down more. I don't really find popup blockers that necessary and I don't consider popups themselves to be malware (unless they install malware).
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay we need to continue with some more fixes! You picked up some new infections on Jan 10th. And it appears that you did not delete some of the stuff I asked you to delete. Make sure you do every step one at a time in the order written. Also make sure you have uninstall CounterSpy and AVG Antispyware before doing the below.

    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Documents and Settings\Adam\Desktop\Morpheus.exe
    C:\Program Files\Common Files\Yazzle1162OinUninstaller.exe
    C:\WINDOWS\system32\tmnoudff.dll
    C:\WINDOWS\system32\ddcyv.dll
    C:\WINDOWS\system32\ffduonmt.ini
    C:\WINDOWS\system32\vycdd.ini
    C:\WINDOWS\system32\hmkfpvcj.ini

    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.
    After reboot locate the below folder and delete if found:
    C:\Program Files\Morpheus
    C:\Program Files\Sunbelt Software
    C:\Program Files\Ipwindows
    C:\Program Files\VSAdd-in
    C:\Program Files\Common Files\{3D3114DA-068B-2057-0820-02101502002c}
    C:\Program Files\Common Files\{1D3114DA-068B-2057-0820-02101502002c}
    C:\Program Files\Common Files\{1D3114DA-068C-2057-0820-02101502002c}
    Make sure you locate and delete the above. If you have any problems finding these tell me. They have been showing in your newfiles.txt log from ShowNew. Check you ShowNew log before posting and see if these still appear. If so, delete them and then get a new log.
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  16. TheTick

    TheTick Corporal

    Hi the processes from your last post went ok

    The combofix.exe went well. I dont really know alot about it so if something went wrong the i would not know, but everything seemed to go well.

    Pocket KillBox also went well and deleted the files before the reboot and rebooted successfully

    I did have trouble with the locating and deleting the files i could not find certain files
    C:\Program Files\Sunbelt Software
    C:\Program Files\Common Files\{3D3114DA-068B-2057-0820-02101502002c}
    C:\Program Files\Common Files\{1D3114DA-068B-2057-0820-02101502002c}
    C:\Program Files\Common Files\{1D3114DA-068C-2057-0820-02101502002c}

    The deletion of the file from your second to last post i did but i was unsure about it.

    was this the only file to be deleted or was there anymore?
     
  17. TheTick

    TheTick Corporal

    For some reason it would not let me post my attachments so here they are.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Many of the fixes are not working properly. This normally means one of three things

    1) fixes are not being performed properly

    2) malware is blocking the fixes and reinfecting you

    3) protection software is blocking our fixes instead of blocking the malware.

    Right now I'm going to assume it in number 3. Can this PC Guard stuff you have installed be shutdown completely? If not, we may need to uninstall it while doing fixes.

    Also I noticed the Morpheus.exe on your Desktop came right back. This could also be a sign of number 3. If you drag the file on your Desktop to the Recycle Bin, does it get removed from your Desktop. If so, is it still gone after a reboot?

    Let's do another single fix! There are alot more that need to be done but I want to take this slower since we seem to be having problems. And I need an answer about PC Guard being stopped!!


    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to COM+ Messages
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteCOM+ Messages into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJTand reboot when it tells you it needs to.

    Now goto Add/Remove Programs and uninstall the below:
    IE Host R3
    Outerinfo
    SelectRebates

    Now attach new logs from ShowNew and HJT and be sure to answer my question!
     
  19. TheTick

    TheTick Corporal

    To answer your first question i could not find a way to disable blue yonder so i uninstalled it.

    I deleted morpheus in to the recycle bin and it stayed there after the reboot.

    The scans went well and did not have any problems, though that COM+ Messages thing was already stopped so i just disabled it.

    The uninstalls went well but i did find this program Dealio toolbar which i cant remove at all even when i was doing the house keeping

    I have also attached the getrunkeys file just incase.

    I think that is all you asked

    Cheers Mate
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not according to your log from ShowNew. It shows the below:

    Dealio Toolbar <--- I assume this is the one you are having a problem with?
    PCguard advisor 1.3.22 <--- looks to me like you did not uninstall the BlueYonder stuff
    PCguard <--- looks to me like you did not uninstall the BlueYonder stuff
    SelectRebates <--- looks to me like you did not uninstall this last time. Did you get an error message.


    If you re-installed PCguard, you need to leave it uninstalled until we fix your problems!

    You need to attach new logs after uninstalling PCguard so I can work up a new procedure. But it is showing in your HJT log as running now so it would be a waste of my time to post another fix now.
     
  21. TheTick

    TheTick Corporal

    I dont know where the select rebates thing is i looked in the add remove programs thing and it was not there what does it come under cause it aint there. is there another way i can find it.

    The PC Guard thing i am sure i uninstalled but as you say it has re appeared. but windows says that it is not running and i am un protected. I Tried to un install it again but a fatal error keeps popping up and it wont uninstall.

    Yes i am having trouble with the dealio thing

    It might take me time to get PC guard off my machine and post the logs you need, any tips on how to get it off would help cheers

    I will post as soon as i can

    Thank you
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see it in the newfiles.txt log at the end in the Uninstall progams list. This means it still has a registry entry which was not completely removed.

    Try installing this: Your Uninstaller! 2006

    Then run it and see if it can deal with SelectRebates, PCGuard and Dealio. If not, we will remove them manually.
     
  23. TheTick

    TheTick Corporal

    ok here we go

    i am not sure if it worked or not but i will try and post and let you have a look and tell me if the stuff your looking for is still running.

    I uninstalled PC Guard and the advisor as much as i could but it is still in the start, programs menu, however when i click on it nothing hapens,it does not appear in the add/remove programs or on the Your Uninstaller.

    The dealio toolbar has gone i used Your uninstaller and it seemed to ahve worked

    The Selectrebates i cannot find i have searched everywhere in add/remove programs the your uninstaller and i have searched the C: but i came up with nothing, i am out of options. Could it be another program that goes under a different name?

    i have attached the latest logs for you to look at

    Soz if there wrong but i tried
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First use Add/Remove programs or Your Uninstaller to uninstall Cursorbar

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: (no name) - {16E26862-F6EF-4D88-89A3-2A25C519BD97} - C:\WINDOWS\system32\ddcyv.dll
    O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - (no file)
    O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\hcyqstsw.dll",setvm
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O20 - Winlogon Notify: winuqw32 - winuqw32.dll (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • Select File, Cleanup, Delete All Backups
    • Select Tools , Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\Downloaded Program Files\ebraryRdr.ocx
    C:\WINDOWS\system32\cjsalrok.exe
    C:\WINDOWS\system32\hcyqstsw.dll
    C:\WINDOWS\system32\ddcyv.dll
    C:\WINDOWS\system32\vycdd.tmp
    C:\WINDOWS\system32\wstsqych.ini
    C:\WINDOWS\system32\vycdd.ini
    C:\WINDOWS\system32\ffduonmt.ini
    C:\WINDOWS\system32\vycdd.ini2
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot use Windows Explorer to look for the below files and if any are found delete them. They should be gone already if Killbox worked!
    C:\WINDOWS\system32\cjsalrok.exe
    C:\WINDOWS\system32\hcyqstsw.dll
    C:\WINDOWS\system32\ddcyv.dll
    C:\WINDOWS\system32\vycdd.tmp
    C:\WINDOWS\system32\wstsqych.ini
    C:\WINDOWS\system32\vycdd.ini
    C:\WINDOWS\system32\ffduonmt.ini
    C:\WINDOWS\system32\vycdd.ini2

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT

    Make sure you tell me how things are working now!

    If any of these files come back or do not delete this time, we are going to use another program to delete them instead of Pocket Killbox.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  25. TheTick

    TheTick Corporal

    Hi

    The steps went smoothly and my computer seems to be running faster now, and i have had no messages saying i am being attacked by viruses latley. just annoying pop ups

    In your steps i did the fixme.reg thing but forgot to merge it with the system before i went on to the next step, as soon as i rebooted the computer i merged it them repeated the next steps as requested. Will this have an effect on what we just did?

    i still had to manually delete some of the files that pocket kiibox did not get. And i got the PendingFileRenameOperations error message i hope you know what it means

    Cheers
    Adam
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It means that the fixes did not work properly! You are still infected and some of the files renamed themselves.

    Let's try this one more time with the longger procedure using Processs Explorer. Be very careful and make sure you do all steps exactly as written. Do not skip anything and do not do them out of order. If this does not work, we will need to try another method of removal.


    Make sure you have rebooted in Normal Mode (do not open any other processes)
    Also make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of ddcyv.dll once and then click the kill button. After you have killed all of the ddcyv.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    hcyqstsw.dll
    winuqw32.dll
    vsjsmlds.dll
    exibrfhp.dll
    kbpoflvf.dll
    tbdrrcfj.dll
    tmnoudff.dll

    Next double click on explorer.exe and again click once on each instance of ddcyv.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    hcyqstsw.dll
    winuqw32.dll
    vsjsmlds.dll
    exibrfhp.dll
    kbpoflvf.dll
    tbdrrcfj.dll
    tmnoudff.dll

    Next double click on iexplore.exe and again click once on each instance of ddcyv.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    hcyqstsw.dll
    winuqw32.dll
    vsjsmlds.dll
    exibrfhp.dll
    kbpoflvf.dll
    tbdrrcfj.dll
    tmnoudff.dll

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: (no name) - {29EF269B-0A82-48D5-8842-0331A6F54281} - C:\WINDOWS\system32\ddcyv.dll
    O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - (no file)
    O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\kbpoflvf.dll",setvm
    O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\hcyqstsw.dll",setvm
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O20 - Winlogon Notify: ddcyv - C:\WINDOWS\system32\ddcyv.dll
    O20 - Winlogon Notify: winuqw32 - winuqw32.dll (file missing)

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\vsjsmlds.dll
    C:\WINDOWS\system32\exibrfhp.dll
    C:\WINDOWS\system32\hcyqstsw.dll
    C:\WINDOWS\system32\kbpoflvf.dll
    C:\WINDOWS\system32\tbdrrcfj.dll
    C:\WINDOWS\system32\tmnoudff.dll
    C:\WINDOWS\system32\ddcyv.dll
    C:\WINDOWS\system32\vycdd.ini
    C:\WINDOWS\system32\fvlfopbk.ini
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew - please download the new version first
    3. HJT


    Make sure you tell me how things are working now!
     
  27. TheTick

    TheTick Corporal

    Hi

    The steps went well and i think that i managed to delete all of the files that you asked me too, unless i have gone blind and missed a few.

    Things seem to be working ok at the min

    But i could not find some of the files from hijack this tho

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - (no file)

    And i think there was one more but i forgot what it was sorry.

    The other steps went smoothly however no problems.

    There was no PendingFileRenameOperations. my computer just rebooted as usual

    I also downloaded shownew but i am unsure whether it is the new version or not

    Cheers
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    A new baddie showed up! Delete the below with Pockey Killbox:

    C:\WINDOWS\system32\vjfhhlpg.dll

    Make sure it gets deleted. Look to see that it appears in the C:\!Killbox backup folder after reboot.

    Part or my registry patch did not work back in message # 24. Let's try the below to address this.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Let's also get some protection in place. It may help to stop these infections from constantly coming back.

    Download, install and update: AVG Free Edition then run a full scan and fix any problems it finds.

    Now download and install ZoneAlarmFree

    Attach new logs from ShowNew and HJT now.

    Is everything still working okay?
     
  29. TheTick

    TheTick Corporal

    I delete that file that popped up using killbox.

    I also adjusted my reg as you told me to

    AVG found 8 problems and deleted them successfully

    and zone alarm is running well

    My computer is working well now still a little slow but other wise ok

    It all went smoothly

    I am attaching the logs as you requested
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not Malware! Possibly just due to non-malware stuff install or not uninstalled properly. I see things like Window Washer from Webroot and Borlands VisiBroker programs trying to load but yet the software does not seem to be installed. Are these programs still installed? Do you need them?

    I also see PC Suite. Is this from Nokia?

    PCGuard and SelectRebates are still not gone. We are going to need special steps to remove them. It would appear that you have some how lost ownership of the registry keys and cannot remove them for some reason.

    Also I have requested that you fix the below line a few times, but it still seems to be there. This is an unnecessary startup process that wastes systems resources. Are you getting any error messages when trying to fix this line?
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    The below is also an unnecessary startup and big waste of system resources and you are loading it twice! You should fix these lines too.
    O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

    Please run the below procedure and attach the requested C:\GetUnKey.txt log:

    Getting Uninstall Programs List From The Registry
     
  31. TheTick

    TheTick Corporal

    Hey

    i did as the procedure asked and used hijack this to try and remove those stubborn files.

    I dont get an error when trying to fix that line it just says it is fixing them
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    I also downloaded that getunkeys thing and i will attach it to this message

    The webroot and borland thigs i dont need and have no idea what they are but i cant find them to uninstall them. i also cannot find the PC Suite thing niether i think it was from nokia yes

    thats it so far hope i got everything right
     

    Attached Files:

  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well now it is one but the qttask.exe from QuickTime came back. Neither of these are malware. They are just totally unnecessary to load at startup and waste system resources which in effect slows your PC's performance.

    Okay the below should fix all of these and the others we have been trying to fix.


    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Visibroker Activation Daemon
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below two Services (if you do not find them or get any errors, just continue):
      • VisiBroker Smart Agent
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste oad into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below two Services (if you do not find them or get any errors, just continue):
      • osagent
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\Washer <--- the whole folder
    C:\Program Files\Borland\vbroker <--- the whole folder
    C:\Program Files\Cursorbar <--- the whole folder

    Now run Ccleaner.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  33. TheTick

    TheTick Corporal

    Hi

    I followed the procedure that you sent me.

    The visbroker Activation Deamon and the visbroker smart agent i looked at but they were already stopped so i just disabled them. Was this right?

    The hijack this went smoothly and there was no problems and the fixes went ok.

    The safemode went ok but i could not find borland/vbroker so i searched for it using search for files and came up with borland shared in C:/programfiles/commonfiles/borlandshared and deleted that was that correct?

    I fixed the registry like you said then the ccleaner ran well

    All the steps went as smoothly as they could apart from the problems mentioned.

    Cheers
     

    Attached Files:

  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Everything you did was fine. Your logs are clean now!

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  35. TheTick

    TheTick Corporal

    hi

    Well i think i am now malware free thanks to you, i bow down and worship the ground you walk on

    cheers

    I did the last message and deleted all the unnecessary programs and looked at the protection from malware. like i downloaded firefox

    My comp does run a little slow on start up, i assume that is the zone alarm and the AVG S/W loading is it?

    Also will these programs be enough to protect myself i also have lava soft and ccleaner. I dont want to download unnecessary programs that are going to clog up my system

    Once again
    Cheers :) :p
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that will happen! A necessary evil while the hook into your system to protect you.

    No solution is perfect. As the how to protect thread tells you, YOU are the biggest threat to your security. You should install SpywareBlaster given in the How to steps and enable all protection. It does not use any system resources. Ad-aware does not provide any protection unless you use the paid version. You do need one realtime antispyware blocking tool which you don't have yet. You could try this Spyware Terminator which is free and provides blocking.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds