trying to clean up my system...

Discussion in 'Malware Help (A Specialist Will Reply)' started by mobes32, Apr 25, 2006.

  1. mobes32

    mobes32 Private E-2

    Excellent step by step instructions guys! I followed steps 1 through 7 and have attached the Bitdefender and Panda ActiveScans along with my HJT logfile.

    I've been having serious problems with pop ups and virus notifications, with firefox as my primary browser. Please review the attachments and let me know if there is anything else I need to take care of. Thanks!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You have a couple problems! One of them is a Qoologic infection. We need to run another tool to locate some hidden files. This will help us so we can work up a fix.

    Download FindQool by LonnyRJones
    • Extract the files and place the FindQool folder into root folder of your hard disk. This is usually C:\
    • Open the folder and run Qlocate.bat
    • attach the contents of the txt.log which will open when the scan is finished.
    I see some WildTangent stuff installed. Do you play WildTangent games? Do you need this because we normally have all WildTangent stuff removed.

    Also we highly recommend against using KazaaLite which is a illegal clone of Kazaa. All P2P sites are dangerous and cause thousands of problems for people per month.
     
  3. mobes32

    mobes32 Private E-2

    The FindQool logfile is attached.

    I don't play the wildtangent games but since they came installed on the computer I usually just leave them alone (even when a program wants to remove them), if you think they should be removed I'm more than happy to do it.

    I have tried repeatedly to get rid of all traces of Kazaa and KazaaLite, but it seems that there are always folders or shortcuts somewhere that I find later. I will definitely give up P2P programs, I actually think that Limewire caused all my current problems.

    Also, after going through steps 1 - 7 initially, when I reboot I get a couple of RUNDLL errors, and I always have between 40 and 50 processes running in the background (seems excessive?).
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you should remove them if you don't play them. Just because the PC manufacturer put them there does not mean they are good or wanted. They get kick backs from all the junk software they put on PCs. The first thing I do when new PCs come is remove all the crud they put on (like AOL - which is where Wild Tangent come from too).

    Please attach one more quick log. I saw a load of stuff in your Panda log and want to check for any install programs related to them.

    Let's get an installed programs list from HijackThis!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
     
  5. mobes32

    mobes32 Private E-2

    Here's the program list from HJT...

    Thanks for the quick responses, I might not be able to post again for a few hours...
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay uninstall the below:
    Java 2 Runtime Environment, SE v1.4.1_02 <-- old version not neeeded anymore
    WildTangent GameChannel (remove only)

    Do you know what the tookit item is in Add/Remove programs?

    Do you know what the below is for?
    C:\Program Files\Livvices\ace.dll
     
  7. mobes32

    mobes32 Private E-2

    Successfully removed Java 2 using Add/Remove programs in control panel. Error removing WildTangent, said it might have already been uninstalled (I'm pretty sure it hasn't). Is there another way to remove it?

    Also, I don't recognize the toolkit item and I don't know what the ace.dll file is for.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later to run it.

    Run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click OK.

    Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.

    c:\GatorPatch.log
    C:\markavr.chm
    C:\markavsp.chm
    c:\w.exe
    C:\Program Files\Windows Media Player\wmplayer.exe.tmp
    C:\WINDOWS\system32\mwinqrag.exe
    C:\WINDOWS\system32\gtsdf.exe
    C:\WINDOWS\system32\rpyhpsg.exe
    C:\WINDOWS\system32\tjipf.dll
    C:\WINDOWS\system32\ZICORN002.exe

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself. However BOOT INTO SAFE MODE during this reboot and do not run anything but what I request. DO NOT open any browsers!

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\gtsdf.exe
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe,rpyhpsg.exe
    O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe
    O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
    O4 - HKLM\..\Run: [sys] regedit -s sys.reg
    O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\bridge.dll",Load
    O4 - HKLM\..\Run: [KAZAA] "C:\Program Files\Kazaa Lite K++\kpp.exe" "C:\Program Files\Kazaa Lite K++\KazaaLite.kpp" /SYSTRAY
    O4 - HKLM\..\Run: [BullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exe
    O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
    O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe

    Now exit HJT
    Run Windows Explorer and double check to make sure the below files are all deleted (some we already got with killbox, we are double checking):
    c:\GatorPatch.log
    C:\markavr.chm
    C:\markavsp.chm
    c:\w.exe
    C:\Program Files\DNS <--- the whole folder
    C:\Program Files\WildTangent <--- the whole folder
    C:\Program Files\Livvices <--- the whole folder
    C:\Program Files\Windows Media Player\wmplayer.exe.tmp
    C:\WINDOWS\system32\F?nts\n?lookup.exe <-- be careful! This is not the system32\Fonts folder. It may look like it but it is not. Tell me what you find.
    C:\WINDOWS\system32\mwinqrag.exe
    C:\WINDOWS\system32\gtsdf.exe
    C:\WINDOWS\system32\rpyhpsg.exe
    C:\WINDOWS\system32\tjipf.dll
    C:\WINDOWS\system32\ZICORN002.exe
    Now reboot into normal mode and after reboot double check the same HJT entries I had you fix above and if any still remain, fix them again a second time.

    Now attach a new HJT log and a new log from FindQool

    Also tell me how things are working!
     
  9. mobes32

    mobes32 Private E-2

    Okay, I used killbox on all ten files listed, and rebooted into safe mode (I noticed the file C:\!killbox was still in explorer after reboot).

    These were the only files found in my HJThis scan:

    F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\gtsdf.exe
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe,rpyhpsg.exe
    O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\bridge.dll",Load
    O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe

    I checked these and fixed them, also there were three others that began with "O4 - Global Startup" but I left them alone.

    When I checked Windows Explorer for the files you listed, all were gone except:

    C:\Program Files\DNS
    C:\Program Files\Livvices

    ... and I didn't see the F?nts file anywhere.

    After I rebooted in normal mode, I ran HJThis and the files I fixed were still gone. I didn't have time to mess around with my computer that much after that but I did notice that it booted up slower than it did before. Attached are the HJT and FindQool logs.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is a backup folder that Killbox creates when it deletes files. You can safely delete the folder.

    Your logs are clean! I'm not sure why your system would boot slower. It should be faster now with this malware removed. What is your reference point? Don't forget that MS Windows Defender will have an impact on boot up, but you need the protection!!
     
  11. mobes32

    mobes32 Private E-2

    I rebooted and everything seems to be back up to speed!

    I really appreciate your help chaslang.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds