More problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by pimpin72, Dec 27, 2006.

  1. pimpin72

    pimpin72 Private E-2

    Hi Chaslang, You have given me great advice in the past, and I have not had near the problems that I previously experienced. I have been back twice in 2 years to rerun the "read and run" page, and it has fixed my problems with no problems.

    I just went through that process again, and my computer is running much better, and the major problem is most likely gone for another year. However, I have an additional question.

    First, The Panda Software activescan shows almost 100 things to fix. I understand that most are cookies and probably harmless, but is it worth the money to download their software to clean up that stuff?

    Second, after my cleanup sessions using the scanners and cleaners and your cleaning process, I am still left with multiple listings on my startup list on msconfig. The list has gotten very long and, when I start in regular mode, I get about 4 different popups for rundll files, etc. that are no longer installed, but the trigger is still loaded. How can I thin out that list to just the items that are supposed to be starting up?

    I really appreciate the time and thought that you give, and I will be looking forward to your answer. Thank you for your time. Scott
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to complete the rest of the procedure and attach the other requested logs!
    • CounterSpy
    • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
    • runkeys.txt - the log from GetRunKey.bat
    • newfiles.txt - the log from ShowNew.bat
    Also note, that is not the correct way to get a Bitdefender log! It should be an HTML file that is just renamed to have a .txt extension. Don't worry about it now though, I don't need a new one.

    No you don't need to buy anything and yes it is true that you should ignore cookies.

    Why are you using MSconfig? This is one of the many reasons we specify that MSconfig should not be used.

    After we get the rest of the logs, we will see what we need to do to fix whatever you are mentioning.

    You actually have quite a few malware problems! In addition to the above mention logs, you need to run the below.

    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.
     
  3. pimpin72

    pimpin72 Private E-2

    I am sorry. I did the other scans, but I just did not post them. I didn't know if they were needed to answer my questions about the startup issues. I have attached the additional logs that you requested.

    As far as using msconfig, I would like to not use it, but it is the only way I know how to stop the popups that I get at startup. That is why I am asking about these things.

    The ones that popup are: "cannot open NvMcTray.dll"
    "cannot open NvCpl.dll"
    "cannot open MWSBAR.DLL"

    If I open msconfig and uncheck the items that I do not recognize on the startup page, these alerts will not popup when I start my computer. Thanks again for your help, and I'll await your instructions. -Scott
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I repeat! Stop using MSconfig! Attach logs from GetRunKey and HijackThis after MSconfig has been set to Normal Startup mode. You are getting "popups" because of the fact that you started using MSconfig to begin with and then uninstall or removed applications thus making it impossible for the applications to properly cleanup and thus leaving things in your MSconfig queue. Stop using it so we can fix the problems! This is requested multiple times in the READ ME.

    You also need to attach the log from either CounterSPy or AVG Antispyware.

    Note: GetRunKey has a newer version then you have now!
     
  5. pimpin72

    pimpin72 Private E-2

    Chaslang, thank you for the urgent goading. I was not clear in my last post. I was using msconfig, before I came to majorgeeks.com 4 days ago. Prior to this latest visit, the read me page did not mention anything about the usage of msconfig (on my previous visits about 8 months ago and about 16 months ago). It was the only way that I could find to keep the rundll popups from appearing.

    Since I used the read me first page on the 26th, I have set the msconfig program as instructed in the page. It does not come on at startup and, yes, the popups are back. This explains why I am inquiring on how to clear these items, so I can start my computer without getting popups. Prior to this visit, I had no idea that I wasn't supposed to use msconfig. All of the logs that I have sent were made as instructed on the read me first page and the startup setting was set to normal. Sorry for the miscommunication. I am attaching the HJT and Getrun logs again, along with the counterspy log which I had previously overlooked.

    Also, you mentioned there is a new getrunkey program available. I downloaded my copy 4 days ago from the link on the read me first page. Since you may have updated since then, I redownloaded from the same location, and reran the program. So the log that I am sending now is with the new download. If the new version of getrunkey is located somewhere else, you will need to tell me where, and I will get it done. Thanks again for all your help. Just let me know what to do next. -Scott
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not true!!!! It has always been in the READ & RUN ME bit previously was only mentioned in the section the HijackThis link was to be clicked. Now it is in step 0 of the READ ME and in the HijackThis link too.

    Also not really true. There are dozens of tools for controlling startups and quite a few antispyware programs also have that built-in to them too.

    Also not true. The below are from you runkeys.txt log obtained and posted on Dec 27th.
    Code:
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "MSConfig"="D:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe /auto"
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state]
    "system.ini"=dword:00000000
    "win.ini"=dword:00000000
    "bootini"=dword:00000002
    "services"=dword:00000000
    "startup"=dword:00000000
    The first Run item shows that MSconfig was being run at startup. The second item where bootini is set to dword 000000002 also indicates that you were not in Normal Startup which is what we ask you to be in. NOW your current log shows that you are in Normal Startup because both of the above have been corrected.


    It does not have to come up! Once you tell it not to warn me anymore, it no longer does. That is why the READ ME says run MSconfig and make sure Normal Startup is selected.

    As stated above, it was alwasy part of the instructions since I first got the READ & RUN ME and HijackThis instructions created more than 2.5 years ago.

    It is also important to always work from the online version of the READ & RUN ME before posting here. It changes frequently and tools are constantly updated too.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    NOTE: You are way out of date with your Windows updates. You need to get updated as soon as we remove all malware.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 5
    Mozilla Firefox (1.0.7)
    Outerinfo <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    D:\Program Files\?dobe\m?config.exe
    D:\PROGRA~1\SEMBLY~1\winspool.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    R3 - URLSearchHook: (no name) - {BAA25C21-E5BB-9219-E84E-EA6C541E09BE} - D:\WINDOWS\System32\buno.dll
    O2 - BHO: (no name) - {BAA25C21-E5BB-9219-E84E-EA6C541E09BE} - D:\WINDOWS\System32\buno.dll
    O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [My Web Search Bar] rundll32 D:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
    O4 - HKLM\..\Run: [Microsoft Windows Update] scvvhost.exe
    O4 - HKCU\..\Run: [Vchned] D:\Program Files\?dobe\m?config.exe
    O4 - HKCU\..\Run: [Swaa] "D:\PROGRA~1\SEMBLY~1\winspool.exe" -vt ndrv
    O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Alpy] D:\Program Files\Common Files\??crosoft\??erinit.exe
    O21 - SSODL: yLrmPDMPzFv - {13310B0C-B99B-A1A6-0559-27D8532E8858} - D:\WINDOWS\System32\chbdrb.dll (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    C:\from old computer\My Downloads\Dope Wars\DW22.EXE
    D:\Program Files\Common Files\{3C8511CB-086A-1033-0719-041112050001}\Uninst.exe
    D:\Program Files\Mozilla Firefox\chrome\m3ffxtbr.manifest
    D:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll
    D:\Program Files\àdobe\m?config.exe
    D:\Program Files\SEMBLY~1\winspool.exe
    D:\Program Files\Common Files\??crosoft\??erinit.exe
    D:\Program Files\MYWEBS~1\bar\1.bin\MWSBAR.DLL
    D:\WINDOWS\System32\buno.dll
    C:\Windows\System32\scvvhost.exe
    D:\WINDOWS\System32\chbdrb.dll
    D:\WINDOWS\system32\wtssvit.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folders and delete if found:
    D:\Program Files\Common Files\{3C8511CB-086A-1033-0719-041112050001}
    D:\Program Files\Common Files\{BC8511CB-086A-1033-0719-041112050001}
    D:\Program Files\Common Files\mqkw
    D:\Program Files\MYWEBS~1
    D:\Program Files\Outerinfo
    D:\Documents and Settings\Scott Waterman.HOMECOMPUTER\Application Data\FunWebProducts

    Also please delete the below folders? Note that the Questionmarks represent unprintable characters that were found during the scans, but they may appear to you as normal characters when you locate them using Windows Explorer. I will add comments in RED next to each item. Note the date of the folders which will help you to locate them:
    Code:
    "D:\Documents and Settings\Scott Waterman.HOMECOMPUTER\Application Data\"
    SEMBLY~1      Dec 26 2006              "??sembly"   [B][COLOR=red]<-- may look like Symbols[/COLOR][/B]
     
    "D:\Program Files\"
    àDOBE         Dec 10 2006              "àdobe"      [B][COLOR=red]<-- may look like adobe[/COLOR][/B]
    MBOLS~1       Dec 25 2006              "??mbols"    [B][COLOR=red]<-- may look like Symbols[/COLOR][/B]
     
    "D:\Program Files\Common Files\"
    MBOLS~1       Nov 21 2006              "??mbols"    [B][COLOR=red]<-- may look like Symbols[/COLOR][/B]
    [/color][/b]

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now! Tell me which popups warnings you are still seeing. These are probably due to the fact that you changed your PC hardware to boot from drive D and the drivers for your video card are not being found anymore or you may have changed video cards and don't even need them anymore. You tell me.


    Non-malware question:

    How are you getting the below to run on Win XP?
    Command & Conquer Red Alert 2
    Command && Conquer Red Alert 2 - Yuri's Revenge

    My son wants to play some of his old games on his new WinXP system! I cannot be bothered with games myself. Are you using compatibility mode or are there patches for the games?
     
  8. pimpin72

    pimpin72 Private E-2

    Ok, I went through these steps, and I will break results down for each step:

    I could not find the above processes listed on HJT.

    ok

    found and deleted

    found and deleted

    not found

    not found

    found and deleted

    found and deleted

    found and deleted

    found and deleted

    not found

    not found

    found and deleted

    found and deleted

    found and deleted

    I did this and appeared to go well

    I ran killbox and it appeared to run smoothly as well

    ok


    not found

    found and deleted

    not found

    found and deleted

    ok

    ok, I could only find the one listed above as adobe. There were two folders with that name, but one with that date. Nothing else even close for the other folders. I did an advanced search of my D drive and found the other three folders listed above, but the path was different. They were all listed under "D:\Qoobox\Purity\..." . Under that path was "documents and settings", "Program files", and "Windows" folders. Under each of these folders was a file named "from.txt" which had the path that you refered to above. Also, under the windows folder was another folder named "ICROSO~1" and under that folder was "netdde.exe". I recognized this file as a probable perp from the time I was having problems, so I deleted the whole "Qoobox" folder. Also, all folders appeared empty except for the "from.txt" files and the one "netdde.exe" file.

    They are attached

    Maybe a bit too thorough, but I don't want to miss anything.

    "error loading D:\windows\system32\NvMcTray.dll. The specified module could not be found"
    "error loading D:\windows\system32\NvCpl.dll. The specified module could not be found"

    Installed C drive when new using a SCSI adaptor card. It doesn't boot up like I think it should, but it seems to be working ok.

    I did add a video card about six months ago. It was an Nvidia card. Should I reload the drivers to replace the above mentioned dll files?

    It does seem to have cleaned up my system quite abit, but I still see some things that I don't like. For instance, there is a reference to ituneshelper on the HJT scan, but I have removed that program. Can I have HJT fix those ones that I recognize as ones that I don't need? Also, I have seven processes running in my taskbar (by the clock), and I don't want all of them running. How can I make them not come on at startup? You mentioned that there are a number of programs to do this...which would you recommend?

    I did download a patch a long time ago. Then loaded as usual. I just found the link below for the patch, but he recommends running 95 compatibility mode as well.

    http://www.dice.nl/Trouble/trouble_C&CRA.htm

    My son totally loves the games. I wish they would come out with new variations. Thanks again for your time and patience. I like to do most things myself, and it is very frustrating to mess with this malware stuff, because there are so many different things to look for and filter through. I just keep my fingers crossed that someday they make a program that will address all of the issues combined. Until then, I will try my best to follow the instructions that you provide. -Scott
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The Qoobox folder was from running Combofix earlier. These strange folder names are part of PurityScan and that was also part of what ComboFix was used for. We would have cleaned it up in my final steps (as you will see).


    Yes! That was my point. You need to put your drivers back where they belong. This was not due to malware.

    Yes HijackThis can be used to fix this:
    O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"

    However the O23 line
    may or may not go away. Give it a try with just HJT and let me know. Sometimes other steps are required to remove services.

    Give this one a try: Startup CPL But if you never want them to load (you have to determine this) you can just permanently stop the from loading using HJT to remove the startup entry.

    Thanks for the info! ;)



    Uninstall the CounterSpy trial software now!

    Your logs are clean! If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds