Annoying messages on bootup.

Discussion in 'Malware Help (A Specialist Will Reply)' started by bigblueshoe777, Mar 10, 2008.

  1. bigblueshoe777

    bigblueshoe777 Private E-2

    I followed all the instructions in the READ AND RUN THIS FIRST thread, and it seems to have gotten rid of my original problem (it was a vtutr.dll thing). But ever since I get a few problems when I boot up my computer.

    First, I get two error messages telling me about two missing files, these files are "tsyylpnu.dll" and "aimqyjjf.dll."

    The other problem is that an installer always starts called "Sonic Activation Module Installer" and wants me to insert a disc to install it, but I don't have any Sonic program, I'm pretty sure. When I try to cancel out of the installer, it restarts itself multiple times. Eventually it stops, but it's pretty annoying.

    I've attatched the logs from the scans, hopefully someone can tell me whats up and how to fix it. :confused
     

    Attached Files:

  2. abri

    abri MajorGeek

    Hi bigblueshoe777,
    Welcome to Major Geeks!

    There are still some things wrong with your computer. I will post you a set of instructions after looking through your logs. This takes time, so thanks for being patient.

    abri
     
  3. abri

    abri MajorGeek

    Hi bigblueshoe!

    Please do the following:

    1) Please disable your guest account if this has not already been done.

    2) Open your Windows Live Messenger, go to Help -> Customer Experience Improvement Program and turn it off. That will stop you getting all those sqm files.

    3) If you do not use Windows Messenger (not to be confused with MSN Messenger!!) I would like you to run Disable/Remove Windows Messenger

    4) And now I would like to ask you to rename the following files by adding zzz to the end of each one as follows:

    C:\WINDOWS\system32\Chip.dll -----> Chip.dll.zzz
    C:\WINDOWS\system32\drivers\hcccwtshxbvs.sys ----> hcccwtshxbvs.sys.zzz
    C:\WINDOWS\system32\5FE5F8649B.sys ----> 5FE5F8649B.sys.zzz
    C:\WINDOWS\system32\628E1A1F50.sys ----> 628E1A1F50.sys.zzz


    5) Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Apps\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [3c098e36] rundll32.exe "C:\WINDOWS\system32\aimqyjjf.dll",b
    O4 - HKLM\..\Run: [BM3f3abdaa] Rundll32.exe "C:\WINDOWS\system32\tsyylpnu.dll",s

    After you click fix, just close hijackthis.


    6) Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    7) Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.


    8) Please run C:\MGtools\GetLogs.bat and attach the fresh MGlogs.zip it generates along with the Avenger log.


    Let me know how things are running now?

    abri
     
  4. bigblueshoe777

    bigblueshoe777 Private E-2

    Alright, I did what you told me and the two missing .dll errors went away on bootup, but I'm still getting the Sonic install thing going on.

    Along with the logs you requested, I've also attached a .zip of three .png pics of the error. The first occurs on bootup, the second after the bar finishes loading, and the third after I click cancel on the second. The cycle then repeats itself until I cancel it during the first pic a few times in a row.

    Thanks for your help. :cool
     

    Attached Files:

  5. abri

    abri MajorGeek

    Hi bigblueshoe,

    To address the Sonic problem please see this article at Dell. There's a hotfix and if that doesn't work, you can run the Windows Installer Cleanup Utility. I advise trying the hotfix first. The problem you have is known, so this may be the easiest solution to try.

    http://support.dell.com/support/top...d=098D85DDBAC783B2E0401E0A55175844&l=en&s=bsd

    Look first at "Download and Run the Isum Hotfix" link and see if that works.


    As far as your logs go, your logs are clean except for the files I had you rename. If those don't cause any issues in the next week or two, I would just go ahead and delete them. There is also one tmp file I'm concerned about, but I need to get back to you about whether it should be removed or not. I'll go ahead and post the final cleanup instructions for you in the box below.
    • abri
     
  6. abri

    abri MajorGeek

    Hi bigblueshoe,

    Please go to Windows Explorer and delete the following file if it is still in C:\

    C:\27F.tmp

    How are things going with your computer?
    abri
     
  7. bigblueshoe777

    bigblueshoe777 Private E-2

    Everything seems to be back to working condition! Thanks a bunch for your help. :D
     
  8. abri

    abri MajorGeek

    Hi bigblueshoe!
    I'm happy to hear that!
    Happy computering!
    abri
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds