Sysnotifier.exe and much more!

Discussion in 'Malware Help (A Specialist Will Reply)' started by samara, Jul 26, 2008.

  1. samara

    samara Private E-2

    Hi, I'm having a problem with Sysnotifier.exe not deleting and also popping up in the corner of my screen. I noticed when I close explorer.exe, my programs move extraordinarily faster. In addition, I started getting messages like "explorer.exe has experienced an error and needs to close"

    note: this might be a repost, I'm sorry. I'm not sure if I clicked "post" last time :eek:

    err, but yea, here is what ComboFix had to say


    Any and all help is appreciated :)
     

    Attached Files:

    • CBF.txt
      File size:
      12.1 KB
      Views:
      3
    Last edited by a moderator: Jul 27, 2008
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Welcome to Majorgeeks!


    To fully rid your PC from malware its best for follow the full guide below and attach all the logs requested, as some scans will miss some important malware components so some tailored scans are needed.


    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide


    Note: If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    Starting your computer in Safe mode


    plus a guide on how to attach the logs HOW TO: Attach Items To Your Post
     
  3. samara

    samara Private E-2

    I'm going to attach the files to this reply. The Sysnotifier.exe was deleted twice, but has returned to annoy the hell out of me. In addition, now the system idles at 99% constantly, and has not abated.

    :cry
     

    Attached Files:

  4. samara

    samara Private E-2

    heres the last one
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Before we can get started, you need to put your system into Normal Startup mode with MSconfig as requested in step 1 of the READ & RUN ME where we warned you that this would delay getting help if not done.

    Now uninstall the below old software which was also requested in step 1:
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Viewpoint Manager (Remove Only)
    Viewpoint Media Player

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:
    • C:\MGlogs.zip
     
  6. samara

    samara Private E-2

    O_O sorry about that

    here is the updated MGtools log
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {CC628875-53FE-4DE3-9CA8-E61652820398} - C:\Program Files\Internet Explorer\SIGNUP\loeapi.dll
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. samara

    samara Private E-2

    whew, that's a lot to do!

    Well, so far, it's looking ok. The registry added successfully. The program sysnotifier.exe is still there when I searched, but as of now it has yet to pop back up. So far I've only gotten a message from Cisvc.exe that it had to close, I'm not sure if that has anything to do with it
     

    Attached Files:

  9. samara

    samara Private E-2

    I take it back, it just popped up again :(
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on the log from ComboFix, it does not look like you made the CFScript.txt file properly. ComboFix did not attempt to remove any of the files listed. Try it again and attach the same two new logs. If it does not work this time, we will use another tool.
     
  11. samara

    samara Private E-2

    Ok, it's definately moving a lot faster, and so far no evil demons have popped up. I'll notify you right away if something comes up. Here are the 2 newest logs.

    Thanks again :)
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the combo-fix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combo-fix folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds