HELP! error cleaner,privacy protector virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by Randy Hernandez, Jan 17, 2008.

  1. Randy Hernandez

    Randy Hernandez Private E-2

    Dear Majorgeeks,

    My computer has acquired the error cleaner, privacy protector, spyware &
    Malware protection virus. I have followed the procedures listed on some of the
    related threads I found on this website and although I am able to what appears to be at first to clean the virus with combofix, ccleaner, spybot, avg antispware, mcafee antivirus etc. and even though I was careful to Toggle the system restore before rebooting my computer - I am still getting the virus and icons again after reboot. Please help! Attached is my mglogs zip file. (Please confirm if the zip file is attached. I'm new to majorgeeks and still getting comfortable with the website.) This virus was acquired by my computer about 3 days ago while trying to view a video that asked me to upload an activex control
    PS. THE SMITFRAUDFIX FILE IS BEING IDENTIFIED BY SPYBOT AS A SPYWARE AND BEING AUTOMATICALLY DELETED WHEN I TRY TO DOWNLOAD IT.
    Thank you!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the other logs requested in the READ ME. Attach the logs from ComboFix and AVG AntSpyware.

    Are you sure about this???? Spybot Search & Destroy does not actively detect anything unless Teatimer is running and we requested that you not run Teatimer in the READ ME. Are you sure it is not a McAfee issue?

    Or is it really due to the fact that you really meant to say SpywareBot is detecting SmifraudFix as a problem. You need to be more careful on what you call things!!!! Uninstall SpywareBot. It is not a program that you want to have installed. You did not install and run Spybot Search and Destroy as requested in the READ & RUN ME. Did you run all of the READ & RUN ME????
     
  3. Randy Hernandez

    Randy Hernandez Private E-2

    Dear Chaslang,

    Thanks for your advice. You were correct... I mistakenly dowloaded Spywarebot instead of Spybot search and destroy. I eliminated the former and installed the latter. I followed your procedures word for word in the "read me first" thread and the virus seems to have been eliminated. I shut down three seperate times and the virus is not re-spawning itself. I'm attaching the combofix log,AVG log & Mglogs zip file. Please let me know if I'm good to go. ** Also when my computer is booting up, I am now getting the following error message. " Error in C:\Windows\system32\spool\drivers\w32x86\3\DLCJTIME.DLL - missing entry: rundLLentry." This message was not popping up prior to the virus infection. What should I do about this? Can this be fixed by reinstalling Windows XP?
    I really appreciate your help!
     

    Attached Files:

  4. Randy Hernandez

    Randy Hernandez Private E-2

    Dear Chaslang,

    Further to the problems detailed in this thread......after following your "read me first" instructions to the letter and eliminating the virus referenced herein... I am now unable to perform windows updates. All of the updates are failing.
    My computer now has AVG antispyware, Spybot search and destroy, CCleaner, and the other programs you suggested downloading. Could these be preventing me from dowloading windows updates? Thanks for your help. * I still need you to check the logs I sent previously because there was a double click virus and ZLob virus that Spybot found again after I followed the read me first instructions and toggled system restore and rebooted etc.
    Thanks, Randy
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It has nothing to do with anything you did here. Perhaps it was broken when you ran SpywareBot. This is for your Dell printer not for Windows. If you need this, you will have to reinstall your Dell Printer software of just put the DLL file back into the proper folder.

    Also AVG Antispyware did not fix anything and neither did ComboFix, so I tend to doubt your problems with Windows Update are related to what you ran here. Let's finish removing your malware and then see where things stand.

    Now Disable Spybot's TeaTimer as requested in the READ & RUN ME
    • Run Spybot and click Mode
    • Select Advanced Mode.
    • Then click Tools and select Resident.
    • Now in the right window pane, uncheck TeaTimer.
    • Also while this is open, in the left column now select IE Tweaks
    • and then in the right pane make sure all the Miscellaneous locks are unchecked.
    • Now quit Spybot!
    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 3
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_03

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O3 - Toolbar: (no name) - {92162A1C-A9E3-4C0C-BCDC-2996E8406887} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\RunOnce: [SpybotDeletingA5117] command /c del "C:\WINDOWS\bmlvqkn.dll_old"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC9716] cmd /c del "C:\WINDOWS\bmlvqkn.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9726] command /c del "C:\WINDOWS\bmlvqkn.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9861] cmd /c del "C:\WINDOWS\bmlvqkn.dll_old"
    O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
    O21 - SSODL: bmlvqkn - {2DCD2F94-1A90-4539-80ED-A6C2384AC79E} - C:\WINDOWS\bmlvqkn.dll (file missing)
    O21 - SSODL: agrlmvp - {96A1F5A7-68F1-4A2A-A2A4-0ED9F0551091} - C:\WINDOWS\agrlmvp.dll

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt

    Also delete all files in the below folder except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Documents and Settings\Randy Hernandez\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  6. Randy Hernandez

    Randy Hernandez Private E-2

    Dear Chaslang,

    I followed your steps below..... attached are the logs you requested. I am still not able to do windows updates. I wrote to Microsoft about this... attached is a word document with Microsoft's reply. I don't necessarily trust the tech guys at Microsoft(India). Please take a look at there advice to see if it makes sense to you and your past experiences. Let me know if the new logs I'm sending had additional problems etc..
    Note: When I ran MGtools\analyse.exe - there were lines that you asked me to check that were not there... for example all of the 04 - HKLM Run once[spoybotdeleting} lines were not there and also 021 SSODL:agrlmvp
    Note: I was able to fix the RUNDLL entry error by reinstalling my printers drivers. Thank you for all of your help!:)
    Note: When I ran The Avenger I noticed the log said some of the files did not delete. I guess the log I'm sending will show you this.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are MANY MANY reasons for problems with Windows Update. We have also used fixes like they have suggested in the document you attached. We even have sticky links to some procedures. Here is one originally written in Nov of 2005.

    Fixing Windows Update Problems (Win 2K and XP)

    Sometimes they help, sometimes they do not. It depends on the real root issue. Sometimes the issue is as simple as you are blocking Windows Update in your firewall or with other protection software settings. You should make sure this is not your problem.

    You're logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     
  8. Randy Hernandez

    Randy Hernandez Private E-2

    Dear Chaslang,

    Just finished with the rest of your very latest instructions. Everything seems to be working fine. I just wanted to give you a big thumbs up for all of your help in the last 4 to 5 days. I don't believe I could have received the proper help from traditional sources. If you guys take donations let me know!

    FYI - The very first set of instructions Microsoft sent me.... - instructed me to register( start then run) the Windows update engine DLL files they provided, the list of files which was included on the word attachment I sent you. This fix worked ! It allowed me to update windows. I thought you would want to keep this information handy for others who may experience the same problem after removing malware.

    Best Wishes to MajorGeeks !!! ( I will certaintly tell my friends about you guys!) :wave
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Did you look at what was in the link I posted in my last message? We have used this for years. It is a more direct/abbreviated and to the point representation of what they gave you in the email. As I stated though, even this does not always work. It depends on the underlying problems.
     
  10. Randy Hernandez

    Randy Hernandez Private E-2

    I forget to click on your last link but thanks again for all of your help. :cool
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds