Help have a process that i cant find info about on google

Discussion in 'Malware Help (A Specialist Will Reply)' started by gkizzle3622, May 16, 2005.

  1. gkizzle3622

    gkizzle3622 Private E-2

    hey i have a process called vlvpnn.exe on my computer i cant get rid of it no matter what i do plz help here is my hijcak this thx so much.


    Edit by chaslang: Unrequested, old version, inline log removed
     
    Last edited by a moderator: May 16, 2005
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read the announcement and sticky threads. HJT logs should only be posted when requested. HJT should also be run in normal boot mode. In addition, your version of HijackThis is way out of date.

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After completing the steps in my previous post run the steps below so we can find a bunch of hidden processes on your system.

    Follow the steps below:

    1 - Please EXTRACT all files from Qoologic Tool to its own folder - C:\Program Files\QoologicFinder . Then, DoubleClick Find-Qoologic.bat to run the tool. It should produce a log - Please attach that with your next post!

    2 - Please EXTRACT all the files form RKFiles Tool to its own folder - C:\Program Files\RKTOOL. Then, Please boot to SAFE MODE and DoubleClick rkfiles.bat to run the tool. Let it run and then, when it finishes, look for a log at C:\Log.txt and please attach that log after rebooting back to normal mode.

    After posting the above two logs, we will work up fix for your remaining problems.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download this tool too: ABIremover.zip

    Unzip it to a folder of it's own in a location that you can find later but do not run ABIremover.exe yet. We may use it later.
     
  5. gkizzle3622

    gkizzle3622 Private E-2

    ok i have started running the tutorial and ran Trend Micro's Online Virus Scan. it found aobut 38 trojans, i can post the virus log if u like. now for my question. the scan is still open, would u like me to delete them because they are non-cleanable? also would u like me to follow the trend micro's removal solution and delete the registry entries that trend micro tells me to for those viruses?
     
  6. gkizzle3622

    gkizzle3622 Private E-2

    sry i forgot to add this in the other post

    also i scanned twice i had 1 trojan that wuz only found in the first scan and 2 trojans that were found only in the second scan. also in the first scan only, i had a window that said "Clean Failed: TROJ_SMALL.AAL" but it doesnt appear on the list of trojans in either scan. (other TROJ_SMALL 's appear on the list but not that variant)

    i will start on the next tutorial scan as soon as i get this part cleared up
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just allow the scanners to fix everything they can fix and note (by file name and path) what they do not fix.

    Finish the remaining steps you had a lot of different problems.
     
  8. gkizzle3622

    gkizzle3622 Private E-2

    hey i cant run symantec security check it says

    "Unable to run Virus Detection

    In order to run Virus Detection you must be using Microsoft Internet Explorer 5.0 or higher with ActiveX and Scripting enabled."

    i followed the instructions for turning on activex and scripting, found they are already on and it still doesnt work. what would u like me to do now?
     
  9. gkizzle3622

    gkizzle3622 Private E-2

    also i was able to delete everything using trend micro's scanner accept one because it said it was in use in the memory or sumthin. here is what is was.

    TROJ_DLOADER.LT CanNotAccess C:\Windows\System32\winup2date.dll

    i am runnin trend micro again to see if it got everything
     
  10. gkizzle3622

    gkizzle3622 Private E-2

    for the symantec security check, could it be possible it doesnt run because i followed the tutorial and uninstalled my microsoft virtual machine in favor of teh sun java virtual machine? so far everything is gone on the trend mirco scanner. lookin good so wuts next
     
  11. gkizzle3622

    gkizzle3622 Private E-2

    ok just finished running McAfee AVERT Stinger, it found nothing.
     
  12. gkizzle3622

    gkizzle3622 Private E-2

    ok i just finished scannin with Ad-Adware SE Professional. attached is the log.
    one thing though, it used the VX2 cleaner plugin and it said "status:system clean" but when i ran the main scan it found some entries for VX2, i just erased those i believe. I couldn't erase 4 of them though:
    C:\Windows\System32\winup2date.dll
    C:\Windows\System32\tbtiggp.dll
    C:\Windows\System32\tbtiggp.dll
    C:\Windows\System32\tbtiggp.dll
    (yes it said it 3 times)
     

    Attached Files:

  13. gkizzle3622

    gkizzle3622 Private E-2

    nvm the VX2 never got removed but Spybot found no problems at all
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I left three messages with things to do. Please complete those steps 100% and then report back. I did not ask for an Ad-Aware log but I did ask for a bunch of other things to be done. Please follow directions. If you run into any problems along the way, just keep going and report the problems when you come back.
     
  15. gkizzle3622

    gkizzle3622 Private E-2

    ok i have run the tutorial 100% the only problems i had were:
    i coudln't run symantec online scan
    and the problems i listed earlier in this thread
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Keep going!
     
  17. gkizzle3622

    gkizzle3622 Private E-2

    keep going? wut do u want me to do know?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Finish the steps I gave you in those three messages.

    See messages 2, 3, and 4!
     
  19. gkizzle3622

    gkizzle3622 Private E-2

    ok here is my hijack this log and my qoologic finder log. i will get you the rkfiles log by tomorrow morning 7 AM (PST).
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't forget to run ABIremover.zip too.

    Your Qoologic scan did not run to completion. Or you posted the wrong log!
     
  21. gkizzle3622

    gkizzle3622 Private E-2

    u want ABI run in safe mode?
    o and for qoologic finder it says it finishes, but then it it like gives me the 16 bit program error.
     
    Last edited: May 19, 2005
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I do want ABIremover run in safe mode.

    Please give the full exact error message.
     
  23. gkizzle3622

    gkizzle3622 Private E-2

    ok this is teh error i get after the qoologic finder runs for about 20 secs

    16-bit MS-DOS Subsystem
    C:\WINDOWS\System32\cmd.exe
    C:\Windows\System32\Autoexec.nt The system file is not suitable for running MS-DOS and Microsoft Windows applications. Choose 'Close' to terminate the application.

    i also get anotehr message which pops up quickly then dissappears, i am gonna take a screen shot and get u that part tomorrow with the rkfiles
    i think the box tells me where the qoologic finder log is located but it is too fast too read and i am pretty sure it showed a temp directory
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    1.Click Start, click Run, type c:\windows\repair, and then click OK.
    2.Right-click autoexec.nt, and then click Copy.
    3.Click Start, click Run, type c:\windows\system32, and then click OK.
    4.Right-click anywhere in that folder, and then click Paste.
    5.Right-click the Autoexect.nt file that you just copied, and then click Properties.
    6.Click to select Read-Only, and then click OK.
    7.Repeat steps 1 through 6 to copy the Config.nt file.

    Then try the Qoologic scan again.
     
  25. gkizzle3622

    gkizzle3622 Private E-2

    ok here is the rkfiles log,i will run the qoologic finder later tonite
     

    Attached Files:

    • log.txt
      File size:
      1.5 KB
      Views:
      4
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can I assume you were able to do what I requested in message # 24?
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Before running Find-Qoologic.bat again, please boot into safe mode and run ABIremover. Then boot back to normal mode and run Find-Qoologic.bat .
     
  28. gkizzle3622

    gkizzle3622 Private E-2

    ok so i ran abi remover in safe mode just like u requested. ok qoologic worked after u gave me the those instruction which i followed to fix the error messag and it worked.

    ok i here is the qoologic finder log

    also if u dont mind, i want to install firefox for my new browser so if thats ok let me know unless u would rather have me install it after we fix the problems
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Wait until we are done fixing the current problems before installing Firefox. It is part of my finishing instructions anyway. I'm looking at your log now.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download Pocket Killbox and save it to its own folder where you can find it.

    Read thru the below steps and make sure you understand them before starting. Ask questions if you have any before starting.

    Run Killbox by double clicking on the killbox.exe file.

    Check the following boxes:

    Standard File Kill
    End Explorer Shell While Killing file

    Copy & paste (you must use copy & paste - typing will give an error) the full path of each of the files below (one at a time - see directions after the list) into the Full Path of File to Delete box.
    C:\WINDOWS\System32\BQBNOOC.EXE
    C:\WINDOWS\System32\VAVKNN.EXE
    C:\WINDOWS\system32\vlvpnn.exe
    C:\WINDOWS\system32\elitefmm32.exe
    C:\WINDOWS\system32\elitergn32.exe
    C:\WINDOWS\System32\PYPAV.DAT
    C:\WINDOWS\JVJOK.DLL
    C:\WINDOWS\system32\aqaka.dll
    C:\WINDOWS\system32\delfin.dll
    C:\WINDOWS\system32\goldnew2b.dll
    C:\WINDOWS\system32\pacis.exe
    C:\WINDOWS\system32\pop2.exe
    C:\WINDOWS\system32\pop317.dll
    C:\WINDOWS\system32\psoft1.exe
    C:\WINDOWS\system32\saie1108.exe
    C:\WINDOWS\system32\tdbOs.dlltmp
    C:\WINDOWS\RLUninstall.exe
    C:\WINDOWS\protector_update.exe
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ncnk.exe



    With the full path to the file name in the Full Path of File to Delete textbox. The filename will appear under the box in a blue color to indicate it was found. Now Click the Red X and for the confirmation message that will appear, you will need to click Yes. If the file is successfully delete you will get a message of confirmation. Just click OK!
    Do this for each of the files listed. Some may not be deleted. Make sure you keep a list of them.

    Now for any files not deleted properly above (the ones you wrote down), do the below (if all of them deleted, skip this step):
    - in Killbox select the option to Delete on Reboot
    - uncheck the option to End Explorer Shell While Killing file

    Copy & paste the full path of each of the files you could not delete above into the box and then click the Red X and for the confirmation message that will appear, you will need to click Yes. A second message will ask to Reboot now? You will need to click No (since you are not finished adding all related files in yet).

    When you do enter the last file name that needs to be deleted, click Yes on the last file.
    Note: Killbox will let you know if the file does not exist.

    Okay so now your PC should be reboot. If you get an error message about Pending Operations, just reboot your PC yourself.

    After reboot run HijackThis and select the following lines (if they still exist) but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\vlvpnn.exe
    O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)

    After clicking Fix, get a new scan from HJT and post it here as an attachment and tell me the results of the above steps.
     
  31. gkizzle3622

    gkizzle3622 Private E-2

    safe mode?
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! If we do not say safe mode, you should assume normal boot mode. We normally tell you when to be in safe mode. All other times you should assume normal boot mode.
     
  33. gkizzle3622

    gkizzle3622 Private E-2

    ok so i ran it and it worked like a charm xcept 2 files it could not find/didnt exist. & 1 file didnt dlete the first time so i tried again and it deleted. i ran hijack this and delted what u said. here is the log
     

    Attached Files:

  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That log looks clean! Are you having anymore problems? If not, you should follow the steps in the below thread to help keep you clean. You will see FireFox in one of the steps too.

    How to Protect yourself from malware!
     
  35. gkizzle3622

    gkizzle3622 Private E-2

    hey i need some recommendations from u, which anti virus should i get, i ahve norton 2003 i think but i dont wanna pay for the subscription bcuz norton sux and finds nothin so which would u reccommend, also which firewall would u also recommend? i am stickin wit sp1 just becuz i put sp1 on my laptop and it took forever to fix the problems with apps it casued

    alo for crap cleaner i didnt clean everythign becuz i wuz unsure if u could help me wit that if its ok wit u that would be great
     
    Last edited: May 21, 2005
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Recommendations are in the link I gave you. Any of the items listed are good. If you want to know what I prefer.... Avast and ZoneAlarm. ZoneAlarm can be rather resource hungry for some people so some prefer to use Sygate.

    If you do not get to SP2, you will continue to have more problems. If you have compatibility issues with software or hardware you need to get updates from the vendors.

    I do not understand what you are talking about with Ccleaner.
     
  37. gkizzle3622

    gkizzle3622 Private E-2

    ok i scanned for issues and got a lotbut not sure which to delte and which to leave bcuz i dont wana screw anything up so maybe u can help wit that
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We do not recommend that you use that Tab. In fact in the READ ME FIRST we specifically state:
     
  39. gkizzle3622

    gkizzle3622 Private E-2

    ok hey man thx for everything the computer is running like a charm and a lot faster 2 i might add. u defenietly worked wonders. anyways if i ever have any problems i know right where to go, many thx ,

    gkizzle
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     
  41. gkizzle3622

    gkizzle3622 Private E-2

    hey u told me to download those things ot protect me from malware, well i downloaded them and ran a scan using microsoft anti spyware in normal mode and found about 100+ things. i think some may be old and left from a while back but i dont know
     
  42. gkizzle3622

    gkizzle3622 Private E-2

    here is my log
     

    Attached Files:

  43. gkizzle3622

    gkizzle3622 Private E-2

    nvm u can take a look but i just deleted everythign cuz it all looked like spyware/adware
     
  44. gkizzle3622

    gkizzle3622 Private E-2

    also i downloaded the files u told me, but for avast i want to run it but it wont let me bcuz it says norton anti virus is running, how would i go about turnin it off wihtout delteing
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What I had you do did not add any problems to your PC. They are just helping you to find additional garbage that is still hanging around hidden from normal viewing.

    There are always many files that can be left hanging around on your PC that are due to malware but that are not easily visible in a HijackThis log. The same goes for literally hundreds of registry keys. Each spyware removal tool will almost always find things that another does not. That is one of the main reasons we have you run several of them.

    Did you tell MS Antisypware to fix what it found? Did it fix everything or did it have problems with any of them? Running it in safe mode sometime helps to make it easier to fix problems.

    If you now run SpySweeper, you may find even more items. You had a bunch of bad stuff on your PC. It is not unusal to have lots of junk like this found by running the additional scanners.
     
  46. gkizzle3622

    gkizzle3622 Private E-2

    hey i just checked my hijack this and i noticed that there is a new entry:

    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

    is that ok or should it be removed???
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds