Help!!aeagrr.exe, slmrx.exe, qnrur.exe hijack problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by runuts, May 31, 2006.

  1. runuts

    runuts Private E-2

    Hi all,
    I just encounter a problem that hijackthis couldn't be done. It actually started from E2Give. I spend over 2 days working on this and still couldn't get it to be remove. I've try deleting ever string by possible in the regedit, and starting from safe mode cleaning everything first. Avenger, hijackthis, adaware se, spyware doctor,... etc.. Only thing I haven't try is running norton yet. Would anyone let me know how they get this off? Seemingly, I went through a search in google and yahoo with nothing related to this. I am sure this is much of a newer hijack. It works the same way other hijack attempts, except that I can't even clear this one off. Msconfig would still be the same even if I clear it off from start up and removing it from the startup regedit that it duplicate itself very fast. I must be missing some strings which i didn't delete in order for it to run. Please let me know if anyone encounter this problem. I am to a point that even log in from main screen would go back to logging off itself. Thanks..

    PS, files that shows... aeaqrr.exe, qnrur.exe, cixxy...sometghing.exe, slmrx.exe. ... Most problem seems like is the slmrx.exe which is starting up everytime. And qnrur.exe dll is just running. Can't even unregister that.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    If you have E2Give problems, did you run our sticky removal procedure for it?

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  3. runuts

    runuts Private E-2

    Thank you for the reply. I am currently at work now, therefore I can't give you a log file. My main concern is getting the startup file not to load at all. But is being pop up even after i deleted it off at regedit. Very very wierd. With everything done at safe mode, it shouldn't have pop back up, but once again it did.
    Is there any possible experience with this related matter you can address me with so I can give it a try? I did all the scan as your requirment for the post has prior into bumping into this site. I eliminited the E2Give issue, appearingly. I got an access denied from safe mode command prompt trying to delete the file at windows32\aeaqrr.exe, and windows32\slmrx.exe.
    I stoped the service before actually deleting it. So does that mean there much be a rogue hiding somewhere that i didn't catch? Once again, I have used spyware doctor, hijackthis, search and destroy, adaware se to clear off anything that it sees. Logs shows clean... very clean, except for hijackthis, and knowing that from msconfig something is still running.
    The other issue that i saw was , when i restart the computer, a pop up would appear stating some sort of dll not running afterward, which was a qnrur.exe file I found to be running in the background.
    :confused: :confused: please lend me a hand here to expand my thoughts on how to clear that from common startup in the regedit. Maybe bootdisk at command prompt? I haven't try that yet. Or have a working clean primary hardisk, and clean the secondary(which is now)?
    Cwas running overnight on the scans, before I headed off to work, and rebooted the system, I couldn't be able to log back in. It tries for the first time, and logs me back off.. What is the correct way to delete an "access denied" file from the system32 folder would be the main question for now? Many thanks.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please just complete ALL the steps I gave you in message number 2 and then attach the three requested logs. Also if you ran the E2Give Removal sticky, attach the avenger.txt log that was requested from that procedure.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds