Spyware and Slow Computer

Discussion in 'Malware Help (A Specialist Will Reply)' started by mrali20, Mar 22, 2005.

  1. mrali20

    mrali20 Private E-2

    I have read and followed the instructions on the Basic Spyware Tutorial. I attempted to complete the online virus scans but on both the Trend Micro's Free Online Scanner and the Symantec Security Check, about 16 Trojans were found but when I tried to clean them, it would not allow me to do so. All running programs were already closed so that was not an issue. Also, I proceeded to use the anti-spyware programs and all those seemed to work fine, except that SpyBot could not remove a Global Internet Money Search adware. I then tried to download HijackThis but every time I tried to unzip the zip file, the folder which I unzipped them to was empty. I followed the instructions on the HijackThis tutorial and created it's own folder and it still did not work. I also tried downloading the .exe file directly from merijn but when I tried to run it, I received a message that the file had been renamed, deleted or moved. Also, I downloaded StartUpList and have a list of files and processes that run upon startup because my computer has been extremely slow as of late. I have the startuplist text available if anyone would like me to paste it in a thread. Any help anyone can give me to help out my computer would be very much appreciated!! Thank you.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run the online scans in safe mode?
    What OS do you have and what program are you using to unzip HijackThis? You need to make sure you are unzipping to the folder that you think. Many times the unzipping could be defaulting to a temp folder somewhere. Are you sure you selected Extract?

    You could have a piece of malware blocking your use of HijackThis. Try downloading the hijackthis.exe file from Merijn again. But do not run until you first rename it to myhjt.com. See if that works. If so, post a log. Otherwise post your StartupList log (as an attachment please! Do not paste it into the thread!).
     
  3. mrali20

    mrali20 Private E-2

    Yes, I did run the online scans in safe mode. I have Windows XP Professional and I am using WinZip to unzip HijackThis. I double checked the unzipping folder and it was correct. I was also sure to select extract. I tried your suggestion of changing the file name but once again when I tried to run it, it said the file did not exist and was renamed, moved or deleted. I am attaching my startuplist log as an attachment. Thanks for your continued support.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hopefully you can run Task Manager. If so, use it to end the following processes (just the .exe part of the file name will show - like stcur.exe):

    C:\WINDOWS\System32\msupd6.exe
    C:\WINDOWS\msagent\CHARS\crmc.exe
    C:\WINDOWS\System32\stcur.exe
    C:\WINDOWS\System32\stcur.exe
    C:\WINDOWS\System32\stcur.exe
    C:\WINDOWS\System32\uzocmjse.exe
    C:\WINDOWS\System32\ebbuaevj.exe

    Now try to run HijackThis! And post a log if possible.
     
  5. mrali20

    mrali20 Private E-2

    Still no luck. I tried to stop all the processes you suggested but everytime I tried to close crmc.exe it would keep on popping up. I tried to keep on ending the process many times but it kept coming back. It would leave for a few moments and then I'd try to download the file but still no luck. I am using Firefox as my browser if that makes any difference.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No browsers should be open when doing this! Did any of the process end? If so, which ones?
     
  7. mrali20

    mrali20 Private E-2

    Even with the browser closed, crmc.exe still popped up. It disappeared for a bit but I still had no luck with the HijackThis file. All the other processes closed without a problem.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the following. Make sure you report back on all results.

    Look in Add/Remove programs for the below and uninstall them if found:
    CasinoOnline
    WeatherBug

    Make sure you have enabled viewing of hidden files and unchecked the Hide extensions for known file type option as mentioned in step 3 of the READ ME FIRST.

    Physically disconnect from the Internet now (unplug your cable) and Exit all browsers.

    Click Start > Run > type services.msc and Click OK

    Locate a seemingly randomly named service that also contains (MsUpdate6) as part of the name and RightClick on it to bring up the Service Properties Window.
    First: Stop the service by clicking the Stop Button.
    Next: Disable it by changing the Startup Type to Disabled and click Apply

    If you have the correct service you will see a reference to the follow file in the Path to executable box: C:\WINDOWS\system32\msupd6.exe

    Now boot into safe mode with no network connection

    Run Task Manager and end any of the following if found (if they do not end just continue):
    C:\WINDOWS\System32\msupd6.exe
    C:\WINDOWS\msagent\CHARS\crmc.exe
    C:\WINDOWS\System32\stcur.exe
    C:\WINDOWS\System32\stcur.exe
    C:\WINDOWS\System32\stcur.exe
    C:\WINDOWS\System32\uzocmjse.exe
    C:\WINDOWS\System32\ebbuaevj.exe

    Exit Task Manager!

    Run Windows Explorer. Find and delete the following:
    C:\WINDOWS\System32\msupd6.exe
    C:\WINDOWS\msagent\CHARS\crmc.exe
    C:\WINDOWS\System32\stcur.exe
    C:\WINDOWS\System32\uzocmjse.exe
    C:\WINDOWS\System32\ebbuaevj.exe
    C:\WINDOWS\Config\abrsrv.exe
    C:\WINDOWS\System32\sesask.exe
    C:\WINDOWS\System32\qsykgzfd.dll
    C:\Documents and Settings\alir\Local Settings\Temp\cmrc.dat
    C:\WINDOWS\System32\bzimqqfg.dll
    C:\WINDOWS\System32\nbymdgvp.dll

    Let me know which ones you find and can delete. Also which one not found? Also which ones were found but could not be deleted. If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again.

    Try running HijackThis in safe mode. Safe a log if you can.

    Now reboot normal mode and reconnect your cable. See if you can run HJT now and save a second log from normal boot mode. Post both logs as attachments when you come back.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I should have noted that you will need to print or save my previous instructions locally since you will be offline and disconnected while running them. It should be obvious but I usually mention it.

    Also when you come back run the below tool and let me know if it reports anything:

    Symantec's new removal tool: Symantec Trojan.Vundo Removal Tool

    I believe you have this problem present!
     
  10. mrali20

    mrali20 Private E-2

    I tried step one of your suggestion and while I did not find a CasinoOnline I did find WeatherBug. When I tried to uninstall Weatherbug I got the following error message: "Windows cannot find 'unwise.exe'. Make sure you typed the name correctly, and then try again. To search for a file, click the start button and then click search."

    I figured I should let you know about this before I follow through with the rest of your suggestions. Thanks for your continued patience with this.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's okay! If you have not started the steps yet! Run message number 9 first. And report. Then run message number 8's steps.
     
  12. mrali20

    mrali20 Private E-2

    I ran the Symantec Vundo remover after disconnecting from the internet but after the scan was completed it said that the Trojan Vundo was not found on my computer. I found this odd because I seem to recall that this specific trojan appeared while doing the Trend Micro online scan. Please advise what to do from here. Note: I have not done the instructions in message 8 yet and will not do so until further communication. I also have a log from the FixVundo scan if you would like me to attach that to my next post.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes continue with message # 8. Sometimes the Symantec tool does not find or fix the problems even though they are there. We may have some work cut out for us as these can be quite annoying to remove. Time for me to get some sleep. I'll get back to you tomorrow. Let me know the results of executing the steps in msg # 8.
     
  14. mrali20

    mrali20 Private E-2

    I performed all I could from message 8. The results of which are posted below.

    Look in Add/Remove programs for the below and uninstall them if found:
    CasinoOnline (not found)
    WeatherBug (found but not removed)
    (I was unable to do this because of previous error alert)

    Locate a seemingly randomly named service that also contains (MsUpdate6) as part of the name and RightClick on it to bring up the Service Properties Window. (not found)

    Run Task Manager and end any of the following if found (if they do not end just continue):
    C:\WINDOWS\System32\msupd6.exe (not found)
    C:\WINDOWS\msagent\CHARS\crmc.exe (ended and did not seem to come back)
    C:\WINDOWS\System32\stcur.exe (not found)
    C:\WINDOWS\System32\stcur.exe (not found)
    C:\WINDOWS\System32\stcur.exe (not found)
    C:\WINDOWS\System32\uzocmjse.exe (not found)
    C:\WINDOWS\System32\ebbuaevj.exe (not found)

    Run Windows Explorer. Find and delete the following:
    C:\WINDOWS\System32\msupd6.exe (found and deleted)
    C:\WINDOWS\msagent\CHARS\crmc.exe (not found)
    C:\WINDOWS\System32\stcur.exe (found and deleted)
    C:\WINDOWS\System32\uzocmjse.exe (found and deleted)
    C:\WINDOWS\System32\ebbuaevj.exe (found and deleted)
    C:\WINDOWS\Config\abrsrv.exe (not found)
    C:\WINDOWS\System32\sesask.exe (not found)
    C:\WINDOWS\System32\qsykgzfd.dll (found and deleted)
    C:\Documents and Settings\alir\Local Settings\Temp\cmrc.dat (not found)
    C:\WINDOWS\System32\bzimqqfg.dll (found and deleted)
    C:\WINDOWS\System32\nbymdgvp.dll (found and deleted)

    Try running HijackThis in safe mode. Safe a log if you can. (HijackThis finally worked in safe mode and a log is attached!)

    Now reboot normal mode and reconnect your cable. See if you can run HJT now and save a second log from normal boot mode. Post both logs as attachments when you come back. (Unfortunately the success was shortlived because the .exe file for HijackThis disappeared when I came back to normal mode. The safe mode log is attached.)

    I'm also going to get some sleep right now. Thanks again for all your help and I'll be back on the forum tomorrow night and any more help you could offer me would be wonderful.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Some more of your problems are now showing. You have a combination of some nasty stuff in here. One is Stopguard/Virtumondo as mentioned already and you also have a new form of the about:blank hijacker (the se.dll type). To top it off you have a bunch of items classified as unknown trojans and some bad Browser Helper Objects.

    I think we are going to have a difficult time repairing this because your OS and IE are severly out of date. In addition you do not appear to have an antivirus application or a firewall installed which makes it even more difficult. We have to hold off on doing Windows Updates right now as it is not a good idea to try certain updates while infected. But please go to this next thread below and install an antivirus application (try Avast) and a firewall (try ZoneAlarmFree).

    How to Protect yourself from malware!

    Let me know when you complete that or if you have any problems trying to do that.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also do the below after complete my previous message.


    1) go here and download Registrar lite and install it: http://www.majorgeeks.com/download469.html
    2) Run it, copy and paste this line to reglite's address bar:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
    3) Click the "go" tab
    4) Find: "AppInit_Dlls" value on the right side panel.
    5) DoubleClick on AppInit_Dlls and tell me exactly what you see in the Value field:
     
  17. mrali20

    mrali20 Private E-2

    I downloaded both Avast and ZoneAlarm and they are up and operational. I also downloaded the Registrar program, followed your instructions and here is what I found in the value field: C:\WINDOWS\System32\mshdgm.dll

    I feel like the first steps toward a fully functioning computer have been made! Hopefully a virus-free and spyware-free computer is in the makings. Thanks for any continued help!
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay do the following:

    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:
    regsvr32 /u C:\WINDOWS\System32\mshdgm.dll
    then click OK. If a dialog box confirming this action appears, click OK.

    Run Registrar Lite again but this time do the following:
    - copy the following into the address bar or expand the same key by hand:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
    - Rename the Folder Windows to NotWindows (in the left hand pane of reglite)
    - Double Click "AppInit_DLLs" again and clear the data value:
    C:\WINDOWS\System32\mshdgm.dll < delete this line , 'Apply' and 'ok' to set.
    - Rename the NotWindows folder back to its original name Windows

    Now just to be sure, exit Registrar Lite and then restart it and look at that same registry key now. Is it blank?

    If so, see if you can delete the C:\WINDOWS\System32\mshdgm.dll file.

    Now post a new HJT log and do not reboot your PC after this?
     
  19. mrali20

    mrali20 Private E-2

    I tried your suggestion but for the first part I received the following error message: LoadLibrary("C:\Windows/System32/mshdgm.dll") failed - The specified module could not be found.

    Because of this message I did not proceed with the rest of your recommendations.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's okay! Continue with the other steps! And tell me the results.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What's happening.....? Did you run into some kind of problem? It should not be taking this long to complete those few steps. Hopefully you just took a food break! ;)
     
  22. mrali20

    mrali20 Private E-2

    Haha.. actually just stepped outside for a bit but I completed all your steps. I was able to clear the data value and it stayed clear even after reopening the application. I was not able to find the file to delete it however. HijackThis did work and I saved a logfile!! It is attached to this post.
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.ezfastsearch.com/index2.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\alir\LOCALS~1\Temp\se.dll/sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\alir\LOCALS~1\Temp\se.dll/sp.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {47B1991F-7BFC-E0B8-A7B2-89D8FBF660BB} - C:\WINDOWS\System32\qsykgzfd.dll (file missing)
    O2 - BHO: (no name) - {710AFDA5-A01F-45E3-AE0E-CECA42EEEE57} - (no file)
    O2 - BHO: (no name) - {B0A388D4-0DB0-C97A-8EC5-61D3C95B7D47} - C:\WINDOWS\System32\bzimqqfg.dll (file missing)
    O2 - BHO: (no name) - {C5621C16-3D79-4993-BC8F-25E7F75A6DA9} - C:\WINDOWS\System32\pambdab.dll
    O2 - BHO: (no name) - {EB04333C-9B8F-B176-783F-8984A66D18D6} - C:\WINDOWS\System32\nbymdgvp.dll (file missing)
    O4 - HKLM\..\Run: [Remndr] "C:\Program Files\CasinoOnline\CsRemnd.exe"
    O4 - HKLM\..\Run: [CSV10P70] C:\Program Files\CSBB\CSv10P070.exe
    O4 - HKLM\..\Run: [p4mX37l] stcur.exe
    O4 - HKLM\..\Run: [AutoLoaderpz5r1JYTXJIX] "C:\WINDOWS\System32\stcur.exe" /HideDir /HideUninstall /PC="CP.FHB" /ShowLegalNote="nonbranded"
    O4 - HKLM\..\Run: [AutoLoaderpz5d1JYTXJIX] "C:\WINDOWS\System32\stcur.exe"
    O4 - HKLM\..\Run: [uzocmjse] C:\WINDOWS\System32\uzocmjse.exe
    O4 - HKLM\..\Run: [ebbuaevj] C:\WINDOWS\System32\ebbuaevj.exe
    O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\alir\LOCALS~1\Temp\se.dll,DllInstall
    O4 - HKCU\..\Run: [Y357RXJ7g] sesask.exe
    O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297C} - http://download.weatherbug.com/minibug/tricklers/AWS/minibuginstaller.cab?
    O18 - Filter: text/html - {FB7A7C23-6994-4A1A-85B4-1AB24EA72BF0} - C:\WINDOWS\System32\pambdab.dll
    O18 - Filter: text/plain - {FB7A7C23-6994-4A1A-85B4-1AB24EA72BF0} - C:\WINDOWS\System32\pambdab.dll
    O23 - Service: mbwjkuishveq (MsUpdate6) - Unknown owner - C:\WINDOWS\System32\msupd6.exe (file missing)
    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\CasinoOnline <--- the whole folder
    C:\Program Files\CSBB <--- the whole folder
    C:\WINDOWS\System32\stcur.exe
    C:\WINDOWS\System32\uzocmjse.exe
    C:\WINDOWS\System32\ebbuaevj.exe
    C:\WINDOWS\System32\sesask.exe
    C:\Documents and Settings\alir\Local Settings\Temp\se.dll
    C:\WINDOWS\System32\pambdab.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file. Tell me how these deletions go!!!!

    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Please run HijackThis click on the "Open the Misc Tools Section" button on the open page. Then select "Delete an NT service" on the left-hand side. A "Delete a Windows NT Service" window will pop up. Try entering the following into the box and then click OK:

    mbwjkuishveq

    If that does not work try entering the short name: MsUpdate6

    Now reboot in normal mode and post a new HJT log. And get ready for a lot of work ahead of you to cleanup the pile of Virtumundo problems. That's our next step assuming the above all worked properly.
     
    Last edited: Mar 24, 2005
  24. mrali20

    mrali20 Private E-2

    I followed your instructions for the first part but had a few questions before proceeding. I followed your suggestion to go to "open the Misc Tools Section", selected "Open process manager" on the left-hand side. However, none of the processes you suggested were in the list when I looked. They were in a different format. The ones you suggested I end are on the main list page where I am given an option to check the box beside them and click fix selected. Am I looking for certain parts of the names in the processes or should I just click beside the entries and click 'fix selected'?
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    My fault! Hang on a second I'll correct that line. The directions are wrong!
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Read it thru now to make sure you follow all of it. It is best if you stay off line and do not run any browsers while doing these steps until the end for a post of your new log.
     
  27. mrali20

    mrali20 Private E-2

    Everything worked except that C:\Program Files\CSBB <--- the whole folder is the only folder/file I could find or delete in safe mode. However, I have encountered a new problem in that my internet would not reconnect once I got back into normal mode. I am currently typing this from my roommates computer who is connected through the same router and I have tried a different ethernet cord and also reconnected the wires several times and tried different slots on the router. I think perhaps something happened when we reset the internet options. It keeps saying the network cable is unplugged even when it is plugged in. Also the light on the back of my computer by the ethernet card is out when the cable is plugged in, Any help you could give me on this would be much appreciated so we can continue with the fix. Thanks!
     
  28. mrali20

    mrali20 Private E-2

    I managed to run a Hijack scan, save it to disk and upload to the website through my roommate's computer. It is attached. Good night and I'll talk to you tomorrow.
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please verify the following

    Right Click Start.
    Select Explore
    Select the Tools menu and click Folder Options.
    Select the View Tab.
    Under the Hidden files and folders heading select Show hidden files and folders.
    Uncheck the Hide extensions for known file types option.
    Uncheck the Hide protected operating system files (recommended) option.
    Click Apply.
    Click OK.

    Let me know if those three items in bold were already set as above.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure why you cannot access the internet now. Reboot and try again. Do you see any error messages while booting?

    Perhaps when of the bad items we had to remove was some how tied to internet access. But we still also have a bunch of bad stuff from Virtumundo to fix.

    Please do the below:

    1. At the command prompt, start your computer in Safe mode. To do this, follow these steps:
    a. Restart your computer.
    b. As your computer starts, press the F8 key repeatedly (one time per second).
    c. This will display the Microsoft Windows Advanced Startup Menu options.
    d. Use the UP ARROW and the DOWN ARROW keys to select Safe mode with Command Prompt, and then press ENTER.

    2. Click Start, click Run, type cmd, and then click OK.

    3. At the command prompt, type CD %windir%\system32\drivers, and then press ENTER.

    4. Type Dir /ah, and then press ENTER.

    Copy back here the list of files & dates you get. It will look something like:
    Code:
     Directory of C:\WINDOWS\system32\drivers
     
    01/11/2005 09:18 AM			 13,824 gbqxmhia.sys
    			 1 File(s)			13,824 bytes
    			 0 Dir(s)	 961,425,408 bytes free
    All I need are the complete lines that look like:
    Code:
     01/11/2005 09:18 AM			 13,824 gbqxmhia.sys
     
  31. mrali20

    mrali20 Private E-2

    In the folder options everything was right except the "Uncheck the Hide protected operating system files (recommended) option." I have now unchecked this. Should I go back and do the steps you recommended before, prior to continuing with the new instructions? Still no internet access after rebooting.
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Now you see the need to be following directions properly? :) (I'm not yelling! I'm just making a point for everyone reading this thread.) This is why you have not been finding files all along and why a keep asking about viewing of hidden files.
     
    Last edited: Mar 24, 2005
  33. mrali20

    mrali20 Private E-2

    I followed your previous instructions with the proper boxes unchecked but still could not find any of the files in safe mode. I'm thinking perhaps they got deleted through some previous action we took? Anyhow, I followed your most regest suggestion and here are the results.

    02/05/2005 02:45 PM 13,824 mhvxtusx.sys
    03/23/2005 03:30 AM 13,824 ddihssju.sys
    03/11/2005 11:42 PM 13,824 .sys
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's do the below

    1. Click Start, click Run, type cmd, and then click OK.

    2. At the command prompt, type CD C:\windows\system32\drivers, and then press ENTER.

    3. Type Attrib –s –h mhvxtusx.sys and then press ENTER.

    4. Type Attrib –s –h ddihssju.sys and then press ENTER.

    5. Type Attrib –s –h .sys and then press ENTER.

    6. Type Ren mhvxtusx.sys mhvxtusx.old and then press ENTER. This renames the file.

    7. Type Ren ddihssju.sys ddihssju.old and then press ENTER. This renames the file.

    8. Type Ren .sys junk.old and then press ENTER. This renames the file.



    Now reboot your PC. And tell me if you are still having any problems and what they are.
     
  35. mrali20

    mrali20 Private E-2

    I followed the instructions but after rebooting the computer I still get the computer icon in the tray with the x over it and when placing the mouse over the icon I get the message "A network cable is unplugged." I rechecked all the connections and everything is connected securely.
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Look at the point where you plug the network cable into your PC. Are there any lights (LED's)? There normally are. And one typically is labeled Link . When there is connectivity this will normally be green. If you unplug the cable and then plug in the cable, do you see any change in status of the LED when it is unplug versus plugged in?
     
  37. mrali20

    mrali20 Private E-2

    The light is off when plugged and unplugged. When the internet worked the LED back there was green when the cord was plugged in.
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then it sounds like one of a few things are wrong:

    1) the other end of your cable is not plugged into anything or it is plugged into a piece of equipment where you need a cross over cable to talk properly

    2) or you are using a crossover cable and should not be

    3) your Network Interface Card (NIC) is not functioning. Look in Device Manager to see that your device is correctly configure and the drivers are loading
     
  39. mrali20

    mrali20 Private E-2

    I don't believe there is anything wrong with the connection since I have been using the same configuration for several months and it has worked fine. When I looked in device manager I found two drivers under the subheading Network Adapters. My NIC card was working properly and the second driver (WAN Network Driver) had an X over it.
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you saying there are two NIC interfaces in your PC? Are you sure you plugged yourself back into the correct one?

    If you double click on the one with an X, what does the Device status box have in it?
    And also what does the Device usage: box at the bottom say?
     
  41. mrali20

    mrali20 Private E-2

    There is only one NIC interface on the back of my computer. The WAN Network Driver is disabled. It is the driver installed by AOL and I no longer use AOL. My ISP told me to disable the driver previously. Even so, just to check, I enabled it just now and nothing changed as far as connectivity (still disconnected). I could just keep on proceeding with the fix and talk to my ISP technicians tomorrow and see if they can help me get it up and running.
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have ADSL or Cable? You said you were using your roomates PC before. Does their PC working if you plug this same cable into it? Does their NIC card LED come on? I know earlier you said you were using a router but you also said something about changing the NIC card. Are sure this NIC card is good?

    Doing a Reset of Web Settings like we did earlier will not impact your physically connectivity. If your LED is not coming on then as I said before, your NIC card is bad, the cable you are using is bad or is a crossover. It could also be the port on your router but you did say you swapped ports.

    If your roomates PC works, this problem is not related to your ISP.
     
  43. mrali20

    mrali20 Private E-2

    I finally got the internet back on my computer!! Turns out the card was messed up and I just installed a new one and I'm up and running again. If you could help me continue with the fix on my computer whenever you can I would really appreciate it. Thank you.
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! But update me on your current status! What probles are you having?
     
  45. mrali20

    mrali20 Private E-2

    I was just going off of what you had told me before. Should I post a new Hijack log?
     
  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That would be a good idea and also tell me of any apparent problems that you have?
     
  47. mrali20

    mrali20 Private E-2

    The problems I have are that the computer is very slow starting up and also very slow when starting applications such as browsers and MS Word.
     

    Attached Files:

  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have a preference for which antivirus program you prefer? Avast4 or AVPersonal?
    You need to uninstall one of them now!
     
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Step 1:

    Look in this folder C:\WINDOWS\msagent\CHARS for all filenames beginning with the following crmc and cmrc (any of the following file name extensions may be found .ini, .exe, .dat, .bak,etc...). Delete what you can.

    You should also run a search of your machine for crmc and cmrc and see where else they may be hiding out (Prefetch folder, etc...) and try to remove them. Make sure you set up windows search propery. See my instructions below:

    Configuring Win Xp Search:
    Click Search and the Select "All files and folders"
    Enter the filename in the "All or part of the file name:" box, so enter crmc (without the extension so you get all matches)
    Now select "More advanced options"
    Make sure the following check boxes are checked:
    - Search system folders
    - Search hidden files and folders
    - Search subfolders

    Then click the Search button. Write down all filenames with full path info that you find matching. For example the below are fullpath and filenames:
    C:\Documents and Settings\alir\Local Settings\Temp\cmrc.dat
    C:\WINDOWS\msagent\CHARS\crmc.exe

    Now repeat the search using cmrc.

    Now repeat all of the above while looking for the below:
    abrsrv.exe and .ini, .dat, .bak, etc also look for vrsrba
    baknut.exe and .ini, .dat, .bak, etc also look for tunkab
    mp3tcp.exe and .ini, .dat, .bak, etc also look for pct3pm
    vssras.exe and .ini, .dat, .bak, etc also look for sarssv

    Report back everything that you find for all of the above. I know this is alot of work but this is the only what to remove this stuff when tools like the Symantec scan do not work. And if you do not get all of it, it spreads and can get worse.

    NOW:
    Copy and paste the information below to notepad. Save it to your Desktop as type "all files" and name it fixmundo.reg We will use this later so just save it for now.


    NEXT:
    Make sure you are completely disconnected from the Internet.

    Then, run CCleaner that you installed while running the READ ME FIRST.

    Then doubleClick on the fixmundo.reg file you made and follow the prompts to allow it to add entries into the registry.

    Please boot to Safe Mode.

    Open a command prompt by clicking Start, Run, and enter cmd and click OK.
    Please enter the following lines in the command prompt window and follow each with the enter key (at any prompts you get just answer yes! Make sure you enter the commands correctly, don't miss the spaces):

    cacls C:\WINDOWS\msagent\CHARS\crmc.exe /g Everyone:f
    cd C:\WINDOWS\msagent\CHARS
    attrib -r -h -s crmc.exe
    del crmc.exe

    cacls C:\WINDOWS\Config\abrsrv.exe /g Everyone:f
    cd C:\WINDOWS\Config\abrsrv.exe
    attrib -r -h -s abrsrv.exe
    del abrsrv.exe

    cacls C:\WINDOWS\AppPatch\baknut.exe /g Everyone:f
    cd C:\WINDOWS\AppPatch
    attrib -r -h -s baknut.exe
    del baknut.exe

    cacls C:\WINDOWS\Drivers\mp3tcp.exe /g Everyone:f
    cd C:\WINDOWS\Drivers
    attrib -r -h -s mp3tcp.exe
    del mp3tcp.exe

    cacls C:\WINDOWS\addins\vssras.exe /g Everyone:f
    cd C:\WINDOWS\addins
    attrib -r -h -s vssras.exe
    del vssras.exe

    exit

    The exit command will close the command prompt window!

    Empty your Recycle Bin and your C:\windows\Prefetch folder.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: CATLEvents Object - {73529697-D46A-4F7D-8A93-01378FCAEDA4} - C:\DOCUME~1\alir\LOCALS~1\Temp\cmrc.dat (file missing)
    O4 - HKLM\..\Run: [abrsrv] C:\WINDOWS\Config\abrsrv.exe
    O4 - HKLM\..\Run: [*abrsrv] C:\WINDOWS\Config\abrsrv.exe
    O4 - HKLM\..\Run: [*baknut] C:\WINDOWS\AppPatch\baknut.exe
    O4 - HKLM\..\Run: [*mp3tcp] C:\WINDOWS\Drivers\mp3tcp.exe
    O4 - HKLM\..\Run: [vssras] C:\WINDOWS\addins\vssras.exe
    O4 - HKLM\..\Run: [*crmc] C:\WINDOWS\msagent\CHARS\crmc.exe

    After clicking Fix, exit HJT.

    Reboot to normal windows and tell me how things went. If you received any error messages along the way, let me know!
    Post a new HJT log.
     
  50. mrali20

    mrali20 Private E-2

    I followed your instructions and here are the results:

    While doing the searches I found and deleted the following two files:
    C:\WINDOWS\Prefetch (crmc.exe)
    C:\WINDOWS\DRIVERS (pct3pm.tmp)

    The registry entry worked fine.

    The command prompts had some problems however. When I gave the initial command (cacls....) the error message I received was "The Cacls command can be run only on disk drives that use the NTFS file system." I received this error message for each set of command prompts. Also, when I tried to follow the next steps for each set of prompts the files could not be found and thus not be deleted.

    I ran hijackthis in safe mode and successfully fixed all the lines you asked me to.

    I have rebooted into normal mode and a hijackthis log is attached. The computer is still very slow in booting up.
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds