Spyware Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by nav88, Mar 5, 2005.

  1. nav88

    nav88 Private E-2

    We use WIndows XP and recently my wifes profile has become corrupted with SPYWARE. I followed your instructions "read me first" and below is my hijack this log. Hope you can help. She is unable ot get AOL to even respond anymore...

    Logfile of HijackThis v1.99.1
    Scan saved at 5:20:17 PM, on 3/5/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Edit by chaslang: Unrequested inline log removed
     
    Last edited by a moderator: Mar 5, 2005
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HijackThis is not the first step and we have guidelines about when and how to post logs.

    To help us to best help you, please follow the steps below closely and in the order given and do not skip anything. If you have any difficulty, please post back letting us know what steps you have completed, what you found while doing the scans if anything along with details about any problems you may have encountered in completing the steps. The more details you can provide the better. Don't be afraid to ask for additional help if you don't understand something!

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus RemovalMake sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download
    HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following: your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message.(Do NOT copy/paste the log into your post).
     
  3. nav88

    nav88 Private E-2

    My apologies for not following your format. I have followed the prerequisitie instructions and conducted the scans as requested. Still have many pop ups and it has corrupted the basic use of our WINdows XP system (will not allow programs to execute, i.e. AOL).

    The HIGHJACK THIS log file is attached.

    Thanks
    NAV88
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First you need to run ALL steps from the READ ME FIRST. You log show now signs of the online scans being run. So I have to wonder if you skipped anything else. Skipping steps will not help you resolve your problems faster. It will only delay getting your system properly fixed. You have a variety of problems. Run the online scans and anything else that you skip. Our READ ME is meant to be run in the order written, step by step to be most effective.

    Second you must extract HijackThis from the ZIP file and install it where requested. You are running it from:
    C:\DOCUME~1\Val\LOCALS~1\Temp\Temporary Directory 3 for hijackthis.zip\HijackThis.exe

    which is directly from the ZIP file. You will not get any backups this way. You must resolve this before continuing.

    You will need to download LSP - Fix and follow the directions given below

    NOW: Unzip it and run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the aklsp.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move aklsp.dll into the Remove section.

    Then, please do the same for dolsp.dll.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.

    After doing the above download and intall: Microsoft® Windows AntiSpyware
    Run a full system scan and allow it to repair what it finds.

    After doing the MS Antispyware scan reboot your system and then do the following steps.

    First Step:

    Please download the following tools and save them where you will be able to find them. I save stuff like this to a C:\downloads\Spyware-Stuff folder and I put each in their own subfolder. It makes it easy to find. Make sure you download them from the links below: And only run what I specify.

    L2MeFix Tool

    Generic Detection Tool - NT/2000/XP

    VX2.BetterInternet Finder XP/2k - Version Msg126

    Pocket KillBox

    Second Step:
    Extract all the files from the Generic Detection Tool into its own folder.
    Then run find.bat. Post the log it creates back here as an attachment (do it later when we reconnect).


    Third Step:
    Please move the L2MeFix Tool to your Desktop and DoubleClick l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix Folder on your Desktop. DoubleClick l2mfix.bat and Type 1 and ENTER to select Option #1 for Run Find Log . Allow it as much time as it needs to run until NotePad opens with a log.

    NOTE: Please do not run any other options or files in the l2mfix Folder!

    Fourth Step:

    Get a new HJT log and post it here along with the logs from find.bat and l2mfix.bat.
     
  5. nav88

    nav88 Private E-2

    First off, please allow me to extend my thanks for all your help to date. I have been extremely frustrated with the barrage of failures I have experienced suddenly due to this spyware problem. I have tried ot follow your directions whenever possible.

    Attached are the logs you requested. As I was rerunning some of the scans you should know that I was never able to complete step 4 of the TREND MICRO's scan (4 attempts, almost 3.5 hours..every time it got to step 4, the available action options did not show on my display so I was unable to select any action). Also, I only ran the spyware scan from Symantec, as I attempted to perform the VIRUS scan it stated I need to run Explorer 6.1 or higher. When I went to the MS website to download, it said I was already running a newer version. Otherwise, I have followed all the steps you detailed.

    I will place the HJT log in the following post.
    Thanks again
    APM
     

    Attached Files:

  6. nav88

    nav88 Private E-2

    Sorry , HJT log from 06 March was attached below. Here is teh L2mfix.bat report.

    APM
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have a rather bad case of this VX2 infection and you have some other nasty problems too. Here are your next steps.

    To begin, there are two file I wanted to have you remove back when we used LSP-Fix but I forgot to mention them. Please look for the below two files and delete them if found:
    c:\windows\system32\dolsp.dll
    c:\windows\system32\aklsp.dll

    Step 1:

    First I want you to uninstall Microsoft AntiSpyware and then reboot your PC.

    After reboot come here and re-download and install this version: Microsoft® Windows AntiSpyware during the install make sure you get any updates BUT BEFORE YOU START THE SCAN: Print or save these instructions locally now because you will have to be disconnected with no browsers open in the following steps.

    Please make sure ALL Browser Windows are Closed and also you should physically disconnect from the Internet by unplugging your cable. Do not reconnect or open a browser again until requested.

    Now allow the Microsoft Antispyware program to run a full scan. After it completes, reboot again in normal boot mode and continue the below steps.

    Step 2:

    Go to the L2MFix Folder on your Desktop and DoubleClick l2mfix.bat and type 2 and ENTER to select option #2 for Run Fix. Then, press any key to Reboot your machine.
    Your computer will go bazonkers (now there's a great technical term!) for a bit, but just let it run. It should eventually spit out another log in Notepad. Please attach that log later when the remaining steps are completed.

    Again, don't run any other files in the L2MFix folder.

    Step 3:

    Run "find.bat" from the Generic Detection Tool again!

    Okay after doing the above DO NOT REBOOT.

    Step 4:


    Now reconnect your cable to the internet (no browser yet) and get a new HJT log. Now open your browser and come back here and post as attachments the find.bat log, theth the L2MeFix Log, and the HJT log (it will take two messages to post all three attachments).
     
    Last edited: Mar 7, 2005
  8. nav88

    nav88 Private E-2

    Waiting to repost after I fully complete the steps. I am emailing from my laptop...A couple of questions..

    1) I deleted the dolsp.dll file as requested but the aklsp.dll file was located in the Windows/temp directory...I deleted that file as well.

    2) I am presently on my second run of the L2MFIX routine as you mention in step 2 below. During first run, the system shut down and then reboot wiht a teal green screen which showed Explorer and Rundll32.exe were killed. 1 file copied and then "Scanning first pass. Please Wait." Upon returning from work it said "Second Pass Complete." and then the phrase U MONITOR down the left margin repeating. No log was created so i figured there must have been an error. I am presenty two hours into the second attempt and I still have the teal screen with the "Scanning first pass. Please Wait!" Message

    Is there anything else I should be doing?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just wait for it to complete! Hopefully it will not be too much longer.

    Is it physically disconnected from the internet and are all browsers closed on that PC?


    Did MS Antispyware find anything and fix or not fix it?
     
  10. nav88

    nav88 Private E-2

    Yes everything is physically disconnected. Antispyware found 11 threats, ignored 4 and removed 7. UMONITOR saga continues..thanks for your continued support.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does it still sound like there is disk activity going on?

    Do you have a log from MS- AS?
     
  12. nav88

    nav88 Private E-2

    L2MFIX complete..now running the Generic Detection Tool. Will post results of these two runs and the HJT when it completes..

    MS-AS did not provide a log. I can access the summary page and cut a summary posting to Word if you think that would help. Not much information there except numbers of files and such.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I'll be waiting for the logs. How long did it take L2MFix to complete?

    As far as MS-AS, what I'm interested in knowing is what (by name) items it found and what it fix and could not fix. It's useful to know what tools can fix what.
     
  14. nav88

    nav88 Private E-2

    Okay...full report from my last assignment..
    1) Deleted the dolsp.dll file from the system32 directory and the aklsp.dll (however this was only found in the Windows/temp directory)

    2) MS-AS ran successfully. 11 threats. Here is a summary..
    Removed: PEPER (Trojan Downloader), Possible Browser Hijacker, SearchMircle.Elite Bar, Possible Hosts File Hijack, eXact.Downloader (trojan Downloader), BrowserAid. Quarantined Search n Click. Ignored MyWay Search Bar, BearShare, Grokster, and EDondkey2000.

    3) Ran the L2MFIX program. Took beteween 4 and 5 hours to complete. Log posted below.

    4) Could not complete the Generic Detection Tool (FIND.bat) scan. Let it execute for 4 hours and then a second time for another 7 hours with the same cues.

    Upon execution, a blue bordered box labeled "16 bit Ms-DOS Substem" appears. Inside the box it states
    C:\Windows\system32\cmd.exe
    C:\Windows\system32\autoexec.nt. System file not suitable for running MS-DOS and Micorosft Windows applications. Choose Close to terminate the application.

    I chose both the CLOSE and INGNORE buttons at different times to see if I could advance through the execution. Both resulted in the DOS alert within the WINDOWS\SYSTEM32\cmd.exe dos box "Beginning Strings.exe search..this portion can take several minutes, please allow it to run".

    I gave it plenty of time, appears to be hung up, especially in the light of the previous "not suitable" alert.

    5) HJT ran and log file attached.

    Attempted to reconnect to the INTERNET to send from PC. No connection obtained and I did not want to reboot. So I downloaded log files to disk and sending from the laptop.

    Hope this gets us back on track.
     

    Attached Files:

  15. nav88

    nav88 Private E-2

    Relating to Step 4 below:

    I found on the Microsoft website..steps to corret the MS DOS error I was receiving. Using the WIndow XP disk I replaced the critical files.

    Relaunched the Generic Detection Tool program..did not recieve the MS DOS error alert. It did produce the Beginning Strings.exe search (as I would assume is expected). Now we shall see how long it takes to run.

    As I have not powered down or rebooted. I will post the resulting log (hopefully) and then run the HJT as requested and post the log files.

    APM
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! L2Mfix took care of a load of bad files. I still see some stuff in your HJT log I expected MS-AS to fix.

    What version of MS Antispyware do you have running and also what version are the spyware definitions that it is using?
     
  17. nav88

    nav88 Private E-2

    MS-AS Beta1....and I loaded updates before I executed the scan..

    Updated definitions to version 5695

    Been an hour since I started the latest Find.bat scan ...still showing "Beginning Strings.exe search" alert...Is this normal or is it hung up?S
     
  18. nav88

    nav88 Private E-2

    The six MS-AS repairs I mentioned were the result ot the last scan. Current Spyware threats detected to date numbers 73.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is not the version number. Please look in the About MS Antispyware menu where the Definitions are also shown. The version number should look something like 1.0.509

    Tell me what you have!

    Have you tried running MS-AS in safe mode (with no networking)? If not, please do so.

    It does take awhile for the scans with these tools to complete. The duration it takes depends on how many files on your system, the speed of your PC, and whether you keep doing other stuff during the scan.

    Please download and run this too: EliteToolbar Remover
    And then post a new HJT log.
     
  20. nav88

    nav88 Private E-2

    Okay..I believe I am caught up on my tasks....

    1) The Generic Detection Fault scan is complete. Log File attached.

    2) I ran a HJT this file. I am not posting since I am running another one in the safe mode and will provide that one later in step #6.

    3) MS-AS version 1.0.501 is being run ( I did use the update feature). Spyware definition version 5695.

    4) Booted in the SAFE mode. Run another MS-AS scan. Detecting 7 threats..REMOVED 3 (eXactdownloader, Searchmiracle.elitebar, and Possible Hosts file) while IGNORING 4 (Bearshare Ad bundler, My Way Search Bar, eDonkey, and Grokster).

    5) Still in the SAFE mode, ran the Elite Toolbar Remover and it said it found suspected files and cleaned them.. Rebooted and ran again, Zero suspect files found.

    6) While Still in the SAFE mode, ran another HJT scan and that log file is also attached.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! So that's much better. Still some fixes to go and I will need a favor from you too.

    But first some of the links to the MS AS download are giving the older version which is what you have. You have 1.0.501 the latest is 1.0.509. I would uninstall, reboot, and then reinstall the new one. Download it from the below link:

    http://www.majorgeeks.com/downloadget.php?id=4466&file=1&evp=ce777b1c1a18760b1ff7da022361858a

    Here is the favor! Before fixing some of the remaining items I would like to see if I can get copies of the files. See if you can run Windows Explorer and located the three below files:
    C:\WINDOWS\system32\tguldndp.dll
    C:\WINDOWS\system32\cxvaotpd.dll
    C:\WINDOWS\system32\fdhstnmc.dll

    If so, tell me the file sizes for each one. We will need to put them into a ZIP file so you can send them to me (either as an attachment to the thread or via email if too large. Do you know how to use WinZip or similar to put files into a ZIP file.

    Now you still have a few problems left. Including a few left overs from the Look 2 Me VX2 infection. You were badly infected with multiple problems. Please run Step 2 from message number 7 again (that is l2mfix.bat and type 2) and post that log. I know it took a long time. Maybe it will not be as bad this time.

    Now download the below file to your computer where you can find it.

    RemV3.Zip

    Extract all the files to a folder (make it a folder for only these tools).
    Then boot into safe mode and run the remv3.bat file.

    Then reboot in normal mode. And post a new HJT log and the log from the above l2mfix.bat file.
     
    Last edited: Mar 9, 2005
  22. nav88

    nav88 Private E-2

    Most up to date version of MS-AS installed. Ran, found 24 threats including Vx2.ABetter INternet and Vx2.Zserv (50+ instances). Ran the cleaner part of the program and after removing the first of the 24 (WindUpdates Broswer Plug - in) the MS-AS program freezes up (NOT REPSONDING) while trying to remove the AproposMedia Browser Modifier threat.

    Should I uninstall MS-AS reboot and download again...or not perofrm the removal and proceed with the rest of the steps and post the requested logs?
     
  23. nav88

    nav88 Private E-2

    Okay..I uninstalled the MS-AS...uploaded a new copy..got the same result. Decided to try it in the safe mode (previous directions did not specify) and I was able ot advance through the complete removal process.




    Runnning the L2MFIX scan at this time
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Running in safe mode would have been my suggestion (like we do in the READ ME).

    Does your MS-AS now say it is 1.0.509 for version number?

    Post the logs from L2Mfix and also post the log from REMV3.BAT (I forgot to ask for that in my last message. It creates a file name log.txt in your drive C root folder (the c:\ folder). So upload c:\log.txt here as an attachment too.

    Also post another new HJT log (that will require a second message).
     
  25. nav88

    nav88 Private E-2

    Yes version 1.0.509 is running.

    Here are the L2Mfix and remv3 log files (attached)
     

    Attached Files:

  26. nav88

    nav88 Private E-2

    Finally, here is the most recent HJT log file (attached)

    I still have the 3 system 32 dll files requested..Tried to zip them but still too big a file...How do I email them to you?

    Related question..the "earth shattering" event that started our saga was AOL would not respond when executed on my wife's profile. Will that likely still be the case and should I plan on deleting AOL and reinstalling it when we get done fixing the spyare/malware issues?

    thanks again
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try making three separate ZIP files. Otherwise you will have to enable PMs and then I can send you an email address to mail to.

    The LM2Fix did not work properly. Can you please first run LM2Fix with option 1 and then follow it up by running it again a selection option 2. Post both of those logs. If this does not work, we will have to complete the final part of the cleanup using find.bat and some manual steps.

    I'm not sure about you AOL problem.
     
  28. nav88

    nav88 Private E-2

    Here are the first two zipped
     

    Attached Files:

  29. nav88

    nav88 Private E-2

    and now the third...
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those 3 files may be related to a porn dialer.

    Search your PC for each of the below files:

    ieloader.dll, coder.ini, coder.log

    You need to make sure you configure search properly. Follow the steps below.

    If you use Search, you need to do the following:
    Click Search and the Select "All files and folders"
    Enter the filename in the "All or part of the file name:" box, so enter ieloader.dll
    Now select "More advanced options"
    Make sure the following check boxes are checked:
    - Search system folders
    - Search hidden files and folders
    - Search subfolders
    Then click the Search button.

    Repeat the search part for each file and let me know what you find.

    Do you know how to use regedit (the registry editor)?
     
  31. nav88

    nav88 Private E-2

    L2MFix scans as requested..09March1 is option1 and 09March2 is option 2...

    Doing the search for the three files now....
     

    Attached Files:

  32. nav88

    nav88 Private E-2

    Search for ieloader.dll, coder.ini and coder.log found nothing.

    I have made regedit entries before so I feel comfortable doing so with the right guidance.

    Thanks again
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Just to be safe on the ieloader.dll stuff, got to this link:
    http://www.sophos.com/virusinfo/analyses/trojcoderda.html

    and click on the Description tab. Search thru your registry and see if you find any of the mentioned items. Do not do anything with them yet. Let's just see what we find first.
     
  34. nav88

    nav88 Private E-2

    Okay..I may have overrepresented my REGEDIT history...How exactly is the best way to search without typing in the whole string?
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    For some of them, just search for the numerical CLSID's like 67B15B0B-160C-4579-95AF-858169659092

    You could also just directly navigate to the specific key by expand the keys manually to find what we are looking for (regedit's search mechanism is very slow).

    For the other ietm you could search for IELoaderCtl
    or again just navigate to the key.

    Does that help or is searching still a problem for you?
     
  36. nav88

    nav88 Private E-2

    Searched for all 7 strings and found none of them
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Let's see if we can finish the baddies off:

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\system32\wupvlhla.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O2 - BHO: (no name) - {93233805-2E29-A344-0FDA-9A9C8822FCF3} - C:\WINDOWS\system32\tguldndp.dll
    O2 - BHO: (no name) - {D1F9E71A-51B7-C10C-D8E9-14FDC94410CB} - C:\WINDOWS\system32\cxvaotpd.dll
    O2 - BHO: (no name) - {FAE9A4C4-15F3-7985-BB29-95CD2E3873CE} - C:\WINDOWS\system32\fdhstnmc.dll
    O4 - HKLM\..\Run: [wupvlhla] C:\WINDOWS\system32\wupvlhla.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\tguldndp.dll
    C:\WINDOWS\system32\cxvaotpd.dll
    C:\WINDOWS\system32\fdhstnmc.dll
    C:\WINDOWS\system32\wupvlhla.exe
    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again.

    Now run Ccleaner that you installed while running the READ ME FIRST.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is one more problem in your log we will need to work on and that's the following:

    O23 - Service: lhrlkusypdlv (MsUpdate6) - Unknown owner - C:\WINDOWS\system32\msupd6.exe

    We may need to use a procedure similar to what is mentioned at Microsoft in the below link:
    http://support.microsoft.com/?scid=kb;en-us;894278
     
  39. nav88

    nav88 Private E-2

    When it came to deleting the 4 SYSTEM32 files in the Normal mode..the only one present in the directory was wvuplhla.exe file.

    Here is the HJT log.
     

    Attached Files:

  40. nav88

    nav88 Private E-2

    Thanks for all ur help so far.. I am getting ready ot leave for the airport, gone until Saturday..the machine appears ot be running fine although I deleted all copies of AOL and downloaded and reinstalled and it is still hanging up so I still have that problem.

    Please let me know if you think i have any more clean up to do.
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well now I would bet we will not be able to get rid of the line O2 - BHO lines where the files are missing. We have seen multiple cases of these where after removing the real problem (the exe file and the BHO files) that the O2 lines just will not stay gone. But let's try.

    Run HJT and put checks on the following lines but DO NOT click fix until you make sure all browsers are closed including the one you are reading write now:
    O2 - BHO: (no name) - {93233805-2E29-A344-0FDA-9A9C8822FCF3} - (no file)
    O2 - BHO: (no name) - {D1F9E71A-51B7-C10C-D8E9-14FDC94410CB} - (no file)
    O2 - BHO: (no name) - {FAE9A4C4-15F3-7985-BB29-95CD2E3873CE} - (no file)

    Then after clicking fix exit HJT and reboot. Get a new HJT log after reboot and see if the O2 lines are still gone. If so, open a browser and then close the browser. Get another HJT log! Are they still gone?

    I'll talk with you when you get back.
     
  42. nav88

    nav88 Private E-2

    No success...the BHO lines are still present after the scan and reboot.

    Here is the logfile for HJT....
     

    Attached Files:

  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As expected! Let's not worry about the BHO's. There is no known fix for these right now but the files are gone and they are more than like not causing a problem. We need to look at the msupd6.exe file.

    Can you see this file C:\WINDOWS\system32\msupd6.exe
     
  44. nav88

    nav88 Private E-2

    I have located the MSUPD6.exe file
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Try killing the process that is running using TaskManager and then try deleting the file. Does that work. Also do the below for another problem you have!

    Exit ALL applications especially browsers including the one you are reading in right now. (You may want to print or save this locally for reference).

    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:
    regsvr32 /u C:\WINDOWS\isrvs\mfiltis.dll
    then click OK. If a dialog box confirming this action appears, click OK.
    If you get an error message on this, just OK it and continue.

    Click START > RUN > regedit, please open the registry editor and navigate to the following:

    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{950238FB-C706-4791-8674-4D429F85897E}\InprocServer32

    Backup this key by clicking File, Export and then enter a File name (like mfiltis1.reg) and save it somewhere you can find it (if needed). Do the Export before doing the following:
    RightClick on the above registry key (the InprocServer32 one - make sure the bottom of the regedit window shows the full reg key as shown above in bold) and select DELETE.

    Now navigate to the following:

    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\mfiltis

    Backup this key by clicking File, Export and then enter a File name (like mfiltis2.reg) and save it somewhere you can find it (if needed). Do the Export before doing the following:
    RightClick on the above registry key (the mfiltis one - make sure the bottom of the regedit window shows the full reg key as shown above in bold) and select DELETE.

    When done, reboot and post a new HJT log.
     
  46. nav88

    nav88 Private E-2

    This key is not on my machine..

    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{950238FB-C706-4791-8674-4D429F85897E}\InprocServer32

    Therefore I stopped at that step of the process..
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just continue to the next one!
     
  48. nav88

    nav88 Private E-2

    MFILTIS folder deleted..

    HJT scan completed after reboot
     

    Attached Files:

  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay run HijackThis and fix the below lines (do not fix until browsers are closed).
    O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
    O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
    O23 - Service: lhrlkusypdlv (MsUpdate6) - Unknown owner - C:\WINDOWS\system32\msupd6.exe (file missing)

    Let me know if the O23 line comes back. If so, we will need to use a special procedure to fix it.
     
  50. nav88

    nav88 Private E-2

    yes..the O23 line came back
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds