infecection suspected: profile keeps getting corupted

Discussion in 'Malware Help (A Specialist Will Reply)' started by dkvinnie, Apr 17, 2008.

  1. dkvinnie

    dkvinnie Private E-2

    I'm suspecting something may belurking on my system. Twice one of the accounts on our XP system have become corrupted. When trying to logon it would take forever and then fijnhally get a message that the local profile could not be located and was in use by another anothter user.
    Other reasons I think something is amuck is that the HD will start spinning at times when I know scheduled scans are not running.

    I had been running SPybot and AD Aware, and windows defender for a long while before this occurred.

    I have tried root kit revealer too but nothing seems to be found.

    I've followed your process completely and none of the malware scans found anything. Maybe there is something in the HJT log orthe CF logs.

    I 've attached all the logs except SAS since it didn't find anything.

    Hoping you can provide some help to get to the botton of this.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you install this:
    VPN Client

    It may be the cause of your issues so I am going to give you a fix and want you to uninstall VPN Client first.

    * Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    * On the page that opens, scroll down to ADVYU
    * then right click the entry, select Properties and press Stop Service.
    * When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    * Now do the same for:
    CRYIM
    EKAR
    FICYHFBIFY
    GRBBYOOP
    HIZKZLMW
    LQIGRWY
    MJZKCIT
    NVYCL
    OENDIMDLT
    POOQ
    RSZLAGNO
    VFG
    XJ
    YQVSAZCIGKO
    * Click OK until you get back to Windows.

    * Next, run C:\MGtools\analyse.exe, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    * At the lower right, click on the Config button
    * Then click the Misc tools button
    * Select Delete an NT Service
    * Copy/paste
    into the box that opens, and press OK
    * If you receive any error messages just ignore them and continue.
    * Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Now re-Run C:\MGtools\analyse.exe and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Go back to services.msc and make sure those services are gone.....then tell me how things are running.
     
  3. dkvinnie

    dkvinnie Private E-2

    Thanks for the quick response!
    I sucessfully deleted all the services as listed. I did notice those after I sent off the logs.

    WRT the VPN client; yes I did install that. One may have been the Cisco VPN client and the other was the F5 SSL VPN clinet. I can use both for access to our corporate network. I ran the uninstall for the Cisco one since I never use it. But I do use the F5 one associated to uroam.progress.com so I did not delete the O16 lines associated with the F5 except for the one for the user kel. I will be deleting that user since it was a tempoary fix when of the other user profiles became corrupt.

    Things seem a bit better. I can logon using all the profiles and my logon doesn't seem to cause the disk to churn as it did before.

    Do you haven any idea as to what was the specific issue was?

    Are there things I did following your instructions to send you the initial post that I need to undo? e.g. Enable teatimer, reconfigure SAS?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No I don't....though I am leery of all those services and how they got there....you did check each profile, right?

    Would you please run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file so I can double check them.
     
  5. dkvinnie

    dkvinnie Private E-2

    :confused
    How do yo mean check each profile?
    I've logged on tea each since the cleaning and I ran ccclaeaner ans SAS under each profile. But not the MGtools stuff.

     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That was exactly what I meant .....and your system looks good. You can keep what you like as far as the anti-spyware programs are concerned. And re-enbale TeaTimer if you like.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    2.
    * Click START then RUN
    * Now type "%userprofile%\Desktop\cf" /u in the runbox and click OK.
    * Note: The space between the cf and the /U, it must be there.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds