SurfSideKick Romoval Problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by MsApril, Jun 26, 2006.

  1. MsApril

    MsApril Private E-2

    I am trying to remove SurfSideKick 3 from my PC and a load of other crap too...:eek: Anyway...I am following the instructions for removal that I found here on your site: http://forums.majorgeeks.com/showthread.php?t=74266

    Step 1: Stopping running processes C:\Program Files\Common Files\VCClient\VCClient.exe and C:\Program Files\Common Files\VCClient\VCMain.exe. Neither of these were present in Process Manager.

    Step 2: SurfSideKick 2, 3 were not present in add or remove programs.

    So I found C:\Program Files\SurfSideKick 3 and tried to delete it and it tells me that is cannot delete it because it is being used by another person or program.

    I went to Run typed "C:\Program Files\SurfSideKick 3\ssk.exe" /u

    It doesn't find anything with " /u on the end and if I type in C:\Program Files\SurfSideKick 3\ssk.exe it doesn't bring up anything for me to type the security code in.

    This isn't all that is wrong with my computer, but I am tackling one problem at a time. It also has win32.malum.erk that I cannot get rid of and it is barley running. I would appreciate any help that I can get on removing SurfSideKick 3.

    Thanks a bunch,
    April
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  3. MsApril

    MsApril Private E-2

    Thank you so much for your response. I was trying to get my computer in good enough running condition that I could do all of the steps in READ & RUN ME FIRST Before Asking for Support. But I can barley post a response here...I am acutally using another computer right now. I have ran: NoAdware, Adaware, and XoftSpy, I tried to run SpyBot S&D but it gets stuck when I try to download the updates. What should I do?

    Thanks again,
    April
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you purchase NoAdware and XoftSpy? If not, uninstall them because they are of no use to you unless you buy them.

    Skip to step 7 of the READ ME and get a HijackThis log and attach it. Based on it I will indicate the next steps. You will at some point have to run ALL steps in the READ ME to make sure you PC is properly cleaned. HijackThis does not show all problems.
     
  5. MsApril

    MsApril Private E-2

    NoAdware and XoftSpy are both purchased versions. They both detect SurfSideKick but neither have been successful at removing it.

    I have a feeling that there is a lot going on with my computer other than SurfSideKick. I had to restart it about 10 times before I was able to even run HJT. I couldn't even attach it on that computer because it would freeze up when clicked manage attachments. I do hope that you will be able to help me out.

    Attached is my HJT file.

    Thanks again,
    April

    P.S. I noticed that McAfee was listed on the HJT. I once upon a time had McAfee and it nearly crashed my system. I was never able to remove it - someone manually disabled it for me.
     

    Attached Files:

    Last edited: Jun 26, 2006
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since you paid for these programs you should contact them and ask for your money back and also ask for an explanation why they cannot remove SurfSideKick and also ask them why they did not report Qoologic and why they also did not remove it. What is the sense in buying programs that cannot detect the malware they are supposedly design to detect and even worse, if they detect it but cannot remove it, what good does it really do you. Any forum like this can tell you all of this for free and remove it for free too.

    I'll start working up a fix for you but you really should call both companies on the carpet for an explanation and also demand a refund.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you uninstalled McAfee (which it does appear to be incorrectly and incompletely uninstalled) then what are you using for an antivirus application.

    Let's start by doing another scan (not a fix, just a scan) for some hidden files related to Qoologic. I need this to work up a fix for Qoologic.

    Download FindQool by LonnyRJones
    • Extract the files and place the FindQool folder into root folder of your hard disk. This is usually C:\
    • Open the folder and run Qlocate.bat
    • attach the contents of the txt.log which will open when the scan is finished.
    FindQool is not a removal procedure. It is a scan that helps us to locate hidden files and registry keys so we can work up a fix for the Qoologic infection.


    Now let's start doing some other fixes. You have a load of other problems.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to McAfee.com McShield (if that is not found, look for the short name: aswUpdSv)... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Now repeat the above stop and disable for the following services:
    McAfee SecurityCenter Update Manager
    McAfee.com VirusScan Online Realtime Engine

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    McShield

    Now repeat the Delete NT Service steps for:
    mcupdmgr.exe
    MCVSRte
    If you receive any error messages just ignore them and continue.

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Look in Add/Remove Programs for the below and uninstall if found:
    NewDotNet
    eAcceleration or StopSign or Acceleration Software
    SoftwareOnline

    Make sure viewing of hidden files is enabled (per the tutorial).
    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\DOCUME~1\april\LOCALS~1\Temp\svchost.exe
    C:\WINDOWS\system32\RACLE~1\chkdsk.exe
    C:\Documents and Settings\april\Application Data\??crosoft\d?xplore.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:7900
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;127.0.0.1;<local>
    R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
    O3 - Toolbar: Search - {A32F5F7A-95FD-204C-D256-726729357BEA} - C:\WINDOWS\Qckxvdru.dll (file missing)
    O4 - HKLM\..\Run: [webscan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k
    O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
    O4 - HKLM\..\Run: [axdittgA] C:\WINDOWS\axdittgA.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [WindowsServicesStartup] C:\DOCUME~1\april\LOCALS~1\Temp\svchost.exe 1
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
    O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
    O4 - HKCU\..\Run: [SOProc_RegWxSzNn] rundll32 shell32.dll,ShellExec_RunDLL C:\PROGRA~1\SOFTWA~1\soproc.exe -pack RegWxSzNn
    O4 - HKCU\..\Run: [Sshl] "C:\WINDOWS\system32\RACLE~1\chkdsk.exe" -vt ndrv
    O4 - HKCU\..\Run: [Fcjg] C:\Documents and Settings\april\Application Data\??crosoft\d?xplore.exe
    O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
    O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll
    O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\april\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
    O16 - DPF: {18C3FD15-74F6-4280-9C98-3590C966B7B8} (SkillGam Control) - http://www.worldwinner.com/games/v46/skillgam/skillgam.cab
    O16 - DPF: {65FDEDF3-8ED9-4F5B-825E-18C2D44191A7} (OneCCCtl Class) - http://d.66.155.171.47.downloads.estara.com./as/OneCCDM.php?template=28029&sessionid=486817855_66.155.171.47_43283&=&req=1140489747198OneCC.cab
    O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
    O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
    O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} (Sol Control) - http://www.worldwinner.com/games/v44/sol/sol.cab
    O16 - DPF: {9E6C7461-FE4A-41A9-9D35-7468796CF9E7} (AVXControl Class) - http://threatlevel.pcsecurityshield.com/control/avxnew.dll
    O20 - AppInit_DLLs: repairs303169590.dll <--- ignore the error from HijackThis about fixing this and just continue

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    (if you do not find any of these or cannot delete them, DO NOT stop. Just continue and tell me about it later.)
    C:\Program Files\SoftwareOnline <--- delete the whole folder
    C:\Program Files\SurfSideKick 3 <--- delete the whole folder
    C:\Program Files\Acceleration Software <--- delete the whole folder
    C:\Program Files\outlook <--- delete the whole folder
    C:\Program Files\mcafee.com <--- delete the whole folder
    C:\Program Files\PartyGaming <--- delete the whole folder
    C:\Program Files\NEWDOT~1 <--- real name is probably NewDotNet or similar. Delete the folder
    C:\WINDOWS\system32\RACLE~1\chkdsk.exe <--- real name may be oracle or similar. Delete the oracle folder
    C:\Documents and Settings\april\Local Settings\Temp <--- delete all files and subfolder in this Temp folder
    C:\Documents and Settings\april\Application Data\??crosoft\d?xplore.exe
    C:\WINDOWS\axdittgA.exe
    C:\WINDOWS\Qckxvdru.dll
    C:\WINDOWS\system32\dmonwv.dll
    C:\WINDOWS\system32\repairs303169590.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  8. MsApril

    MsApril Private E-2

    You are absolutely right...it is so aggravating when you pay for something that promises to fix your problems and won't. Thank goodness for people like you who are willing to help otherpeople! You are all WONDERFUL!

    I will begin working on what you have given me. It might take a few since my PC is barley running. Will get back with you shortly.

    Thanks again,
    April
     
  9. MsApril

    MsApril Private E-2

    Okay....shew....I finally made it through everything that you listed-my computer is soooooooo Slow.


    NewDotNet
    eAcceleration or StopSign or Acceleration Software
    SoftwareOnline
    were not present in Add and Remove Programs. However, I did find Surf SideKick when I set it to show hidden files. I removed it.


    C:\Program Files\SoftwareOnline <--- was not present
    C:\Program Files\SurfSideKick 3 - I removed this in Add and Remove programs.
    C:\Program Files\Acceleration Software <--- was not present
    C:\Program Files\mcafee.com - I deleted two files in the folder but could not delete the last VSO file - or the folder itself. I checked to see if it was set to read only and it was.
    C:\WINDOWS\axdittgA.exe <--- was not present
    C:\WINDOWS\Qckxvdru.dll <---This was present but ended in .ini instead of .dll - I didn't delete it.
    C:\WINDOWS\system32\repairs303169590.dll <--- was not present

    I will have to send my FindQool and HJT scans to my email and attach them here on my other computer -this one freezes up when I try to attach.

    Thanks again,
    April


    I almost forgot I got the following error message when I rebooted from safe mode....
    Error loading C:\PROGA~\NEWDOT~\NEWDOT~2.DLL
    The specified module could not be found.
     
  10. MsApril

    MsApril Private E-2

    Here are my attached scans.

    Thank you,
    April
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you delete it now, or does it still block you?

    Delete the Qckxvdru.ini file too.

    This error occurs because you forgot to have HijackThis fix one of the O4 lines I gave you that mentions this file.

    We will fix it below. It does not look like FindQool ran completely. I will give you a fix to try but it may not work since your log really appears to be incomplete. Let's try anyway.

    Question: Is this SmartShopper program something you installed?

    Now download - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later to run it.

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click OK.

    Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.
    C:\WINDOWS\UNWN.EXE
    C:\WINDOWS\system32\kfsco.exe
    C:\WINDOWS\system32\ubagycu.exe
    C:\WINDOWS\system32\dmonwv.dll



    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself. However BOOT INTO SAFE MODE during this reboot and do not run anything but what I request. DO NOT open any browsers!


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\kfsco.exe
    F2 - REG:system.ini: UserInit=userinit.exe,ubagycu.exe
    O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4389/mcfscan.cab



    Now exit HJT
    Run Windows Explorer and double check to make sure the below files are all deleted (some we already got with killbox):

    C:\WINDOWS\UNWN.EXE
    C:\WINDOWS\system32\kfsco.exe
    C:\WINDOWS\system32\ubagycu.exe
    C:\WINDOWS\system32\dmonwv.dll


    Now reboot into normal mode and after reboot double check the same HJT entries I had you fix above and if any still remain, fix them again a second time.

    Now attach a new HJT log and a new log from FindQool

    Also tell me how things are working!
     
  12. MsApril

    MsApril Private E-2

    Quote:
    Originally Posted by MsApril

    C:\Program Files\mcafee.com - I deleted two files in the folder but could not delete the last VSO file - or the folder itself. I checked to see if it was set to read only and it was.

    Can you delete it now, or does it still block you? No, I cannot delete it. I checked read only and I keep getting the message "Cannot delete mcusshl.dll: Access is denied. make sure the disk is not full or write protected and that the file is not currently in use.
    I went to task manager and the following processes were running: (I was in Safe Mode)
    taskmgr.exe
    explorer.exe
    svchost.exe
    svchost.exe
    svchost.exe
    lsass.exe
    services.exe
    winlogon.exe
    csrss.exe
    smss.exe
    system
    system idle process

    I deleted Delete the Qckxvdru.ini file and I found the O4 lines you gave
    me that I missed fixing. This took care of the error message.

    I have ran findqool again and have attached the files, there are 4 so I will post another message with the 4th since I can only upload 3 of them to this message. You were right...it was incomplete *sorry about that*.

    I am having trouble downloading Pocket KillBox. I downloaded it to the desktop as fixme.reg with all files selected. When I double click nothing happens.

    I tried to download it to a folder and then extract it to the desktop but that didn't work either. It only gives me the option to "add to archives" "add to killbox.rar" "compress and email" "compress to Killbox.rar and email" "pin to start menu" and "scan for viruses".


    Thanks,
    April

    My computer is running a thousand times better already! Thank you so much for all that you are doing to help me.
     

    Attached Files:

  13. MsApril

    MsApril Private E-2

    Attached is the 4th file from the findqool scan.
     

    Attached Files:

    • tmp.txt
      File size:
      404 bytes
      Views:
      0
  14. MsApril

    MsApril Private E-2

    Since my computer is running better I am going through the step in Read and Run me first. If you would like I could post new HJT and FindQool scans when I complete that, along with the other scan reports requested in Read and Run me first. I thought that it may make your job easier if I did this first.

    Thanks,
    April
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


    See if you can rename the mcusshl.dll file. Right click on it and select Rename. Change the name to mcusshl.ddd If it let's you do this, then reboot and try to delete after reboot.

    There should only be two log files for you to attach. The one complete log from running FindQool. This is the file you attached named report.txt and the second attachment I requested is a new HijackThis log. I don't need those other files. They are temporary files FindQool makes inorder for it to make the final report.txt file. Don't do anything right now with HijackThis or the previous fix procedure. I need to create a new fix since I now have the full log from FindQool.

    First you must download it from the link I gave to you. This is an executable file download. After you download it to your Desktop, you can immediately double click on it to run it. The file is named killbox.exe. You don't need to extract it or do anything else to it. You also do not need to save it to your Desktop. You can download it to its own folder anywhere. We just suggest the Desktop to make it easy for you to find.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later to run it.

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click OK.

    Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.

    C:\Program Files\mcafee.com\mcusshl.dll <--- just incase you still could not delete or rename this McAfee file
    C:\WINDOWS\system32\dmonwv.dll
    C:\WINDOWS\UNWN.EXE
    C:\WINDOWS\system32\atqcb.dat
    C:\WINDOWS\system32\tvcxow.exe
    C:\WINDOWS\system32\kfsco.exe
    C:\WINDOWS\system32\adbygff.dll
    C:\WINDOWS\system32\ubagycu.exe
    C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\mdnyu.exe


    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself. However BOOT INTO SAFE MODE during this reboot and do not run anything but what I request. DO NOT open any browsers!

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\kfsco.exe
    F2 - REG:system.ini: UserInit=userinit.exe,ubagycu.exe
    O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...89/mcfscan.cab

    Now exit HJT
    Run Windows Explorer and double check to make sure the below files are all deleted (some we already got with killbox):

    C:\Program Files\mcafee.com <--- if the file was delete by Killbox, see if you can now delete the folder.
    C:\WINDOWS\system32\dmonwv.dll
    C:\WINDOWS\UNWN.EXE
    C:\WINDOWS\system32\atqcb.dat
    C:\WINDOWS\system32\tvcxow.exe
    C:\WINDOWS\system32\kfsco.exe
    C:\WINDOWS\system32\adbygff.dll
    C:\WINDOWS\system32\ubagycu.exe
    C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\mdnyu.exe


    Now reboot into normal mode and after reboot double check the same HJT entries I had you fix above and if any still remain, fix them again a second time.

    Now attach a new HJT log and a new log from FindQool

    Also tell me how things are working!
     
  17. MsApril

    MsApril Private E-2

    I was finally able to get through all of the steps on the Read and Run me First sticky.

    I have attached the Bitdefender scan and Panda Scan. I had to run Panda about 4 times before it run all the way through, The only difference I noticed is that it removed a virus on the first scan, but I don't know what it was.

    I have also ran a new HJT scan as I thought you may need it.

    Also, I would like to begin following the steps in the How to protect yourself from malware thread but I wasn't sure it I should wait until we are finished. I will wait for your answer before I begin.

    Thanks again,
    April
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't know why you are trying to run the READ & RUN ME procedure now. What you needed to do is what I gave you in message #16 and you still need to do this. Please complete those steps.
     
  19. MsApril

    MsApril Private E-2

    Well, I'll tell you why...lol! I didn't realize that I had to go to page 2 to see the most recent message. In other forums that I have been in the most recent message is always the bottom message. I was going through the Read and Run me first steps while I was waiting for your response. Soooooo, Now that I have figured out that all the complicated stuff :confused: , I will work on your fix.

    Again, Sorry about that!

    April
     
  20. MsApril

    MsApril Private E-2

    Okay...I have completed everything in message #16 and the requested files are attached.

    The computer seems to be running better, but it is still hanging some. Like when I click on IExplorer or My computer it takes a bit to pull it up.

    Thanks,
    April
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can changes your preferences by clicking Quick Links --> User Control Panel --> Edit Options. Scroll down to Thread Display Options . I display Linear - Newest First and I show 40 messages per page.

    Let's finish your malware fixes.

    Make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [tngpou] C:\WINDOWS\system32\tvcxow.exe reg_run
    O4 - HKCU\..\Run: [pkmrp] C:\WINDOWS\system32\tvcxow.exe reg_run
    O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone
    O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone
    O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    (it should already be gone! We are double checking!):
    C:\WINDOWS\system32\tvcxow.exe
    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  22. MsApril

    MsApril Private E-2

    Okay, I have run the requested fixes and have attached a new HJT log.

    My computer is still hanging. When I click on something to open it - IE, Mozilla, My computer, Recycle Bin, it takes 30 seconds to a minute to open. I am still getting some Not Responding windows - not as much as before but it is still happening, they begin to run again eventually. Also, when I restart the computer and log onto Windows it takes a few minutes before I can even move the mouse.

    Things are MUCH better than they were though.

    I have a question? I downloaded ZoneAlarm and I get a message when I restart that LEXPPS.exe is trying to act as a server. Should I deny or allow access...I have no idea what this is?

    Thanks,
    April
     

    Attached Files:

  23. MsApril

    MsApril Private E-2

    Something I forgot to mention. I keep getting a message from AntiVir that an unwanted program was detected Trojan Horse TR/Drop.Agent.YC.1. I have deleted each time I have gotten the message.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These remaining problems are not malware. I will give you some tips but this is not really a topic for the malware forum.

    Your problems are due to the items you are running. You need to go thru the stuff you have installed and decide which things you really need to use. Also one being resource hog is that you have the Microsoft Indexing Service running. I know this because cidaemon.exe is running. This service should really be stopped and set to manual mode.

    Uninstall things you don't use or really need. A couple examples may be:
    C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe

    Do you need all three of the below Messengers? The first should definitely be removed!
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe

    These next items are not even necessary to load at startup:
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe <--- only needed for ease of use
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    Stop playing all the Online Games and remove all the related O16 lines for the Games!

    This is a process for your Lexmark printer. If you need to share your printer over a network this will be necessary. You could start but blocking it from being a server and see how everything works for you. If you run into problems using the printer thru your network, then bring up ZoneAlarm and change the permission for the process to allow it.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is the file named and where is it located?
     
  26. MsApril

    MsApril Private E-2

    I didn't write that information down. But I am still getting these messages pretty often. These are what I have gotten so far.

    TR/Dldr.Qoologic.BJ.2
    c:\System volume information\...\A0032506.exe

    TR/Dldr.Qoologic.BJ.1
    c:\System volume information\...\A0031486.dll

    TR/Drop.Agent.YC.1
    C:\System volume information\...\A0033629.exe

    C:\System Volume Information\...\A0033631.exe
    TR/Drop.Agent.YC.1

    C:\!Killbox\KFSCO.exe
    TR/Dldr.Qoologic.bj.3

    C:\!Killbox\
    TR/Dldr.Qoologic.bj.2

    C:\!Killbox\
    TR/Dldr.Qoologic.bj.2

    C:\!Killbox\
    TR/Dldr.Qoologic.bj

    C:\System volume information\...\A0034633.exe
    TR/Dldr.Qoolog.bj.3

    C:\System volume information\...\A0034635.exe
    TR/Dldr.Qoologic.BJ.2

    C:\System volume information\...\A0034634.exe
    TR/Dldr.Qoologic.BJ.2

    C:\System volume information\...\A0034636.exe
    TR/Dldr.Qoologic.BJ

    I am deleting these as they pop up but I am not sure if they are being deleted.

    Thanks,
    April
     
    Last edited: Jul 1, 2006
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They are not problems! We just were not done with the final steps yet. The killox items are from what we were cleaning up using Pocket Killbox. You can just delete the whole !Killbox folder. The others are in System Restore which if you remember in step 0 of the READ ME we stated we needed to toggle when we were finished fixing malware. So that being said, do the below!

    It is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  28. MsApril

    MsApril Private E-2

    I will do that now.

    I just wanted to say thank you very much for all of the help that you have given me. I would've never been able to fix my PC without you.

    Thanks,
    April
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds