Weird icon in system tray + Boot Problems

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Teapot, Dec 12, 2004.

  1. Teapot

    Teapot Private E-2

    A few weeks ago, a weird and unclickable icon appeared in my system tray. I usually don't turn off my computer, but today I restarted it after installing iTunes for a second time. When the computer booted up again, everything was essentially just as it was two weeks ago. So.. I think this spyware/virus is overriding my Windows load process. I can't boot in safe mode, and I can't do a system restore because it always gets overriden by this "thing."

    Anyone heard of this or know what it is? I glanced at my process and looked a few up in the process library, but I couldn't find anything.

    I really need to figure this out because I spent a lot of my weekend working on a big project which I can't access now.

    Thanks!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should attempt to follow all the steps in this Sticky thread < READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal >

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    If still having a problem after the above, you should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log file as an attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    Make sure you have HJT version 1.98.2 and follow the guidelines on where to install it and how to post a log as an attachment.
     
  3. Teapot

    Teapot Private E-2

    Note: I couldn't boot in safe mode to finish the rest of the inital spyware scan. Whenever I try to do a system restore or boot in safe mode, it doesn't work and just starts my computer back up to it's state of two weeks ago. I hope someone can help me!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The procedure clearly stated that if you cannot run in safe mode (for whatever reason) to run the steps in normal boot mode.

    We did not ask you to do a system restore. We asked you to disable system restore.
     
  5. Teapot

    Teapot Private E-2

    Oh yeah, and the picture is a screenshot of that ugly blue process which I think is causing my problems. Speaking of system toolbars.. I can't acces the date/time either because it says I don't have the proper administrative privledges. I do, however; I checked in the Command Prompt.

    http://www.white-wahpah.net/Random/systembar.bmp
     
  6. Teapot

    Teapot Private E-2

    I did run the steps in normal boot mode (that's all I can do), and I disabled system restore, but I still need to preform one because of the files that disappeared. The random blue process disables me from being able to boot in safe mode and do a system restore to get to what I want. That's why I thought it was a virus and that's why I ran the log...
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You said " I couldn't boot in safe mode to finish the rest of the inital spyware scan."
    Which meant to me you did not finish the scans. I do not see any sign of the online scans being run, so that still means they were not run.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are you running msconfig at startup? Are you using it to do a selective startup? If so, you should let everything run normally so we can see all of the items that would normally load. You could be hiding problems we need to see. I'm talkin about this line in your log.
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

    Is this ProxyServer something you have setup and need?
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=cache1.midco.net:3128


    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Look for the below process(es) and if found, End them:
    ?ttrib.exe


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {42D86F7A-BA1C-59CF-8407-6D5504F5733C} - C:\WINDOWS\system32\qiid.dll (file missing)
    O2 - BHO: (no name) - {81C2F84F-7860-FF73-60B8-AA9A17ADA690} - C:\WINDOWS\System32\vrslotvb.dll
    O2 - BHO: (no name) - {DB9F9735-00FE-282A-D13B-04C5367E45B0} - C:\WINDOWS\system32\juhesfii.dll
    O4 - HKLM\..\Run: [igcjjlcf] C:\WINDOWS\wnaznrgi.exe

    O4 - HKLM\..\Run: [sfikcblswk] C:\WINDOWS\system32\bslrqr.exe

    You should uninstall SpywareKilla. It is on a list of rogue/suspect spyware removal tools. See this link: http://www.spywarewarrior.com/rogue_anti-spyware.htm
    O4 - HKCU\..\Run: [SpywareKilla] "C:\PROGRA~1\SPYWAR~1\SpywareKilla.exe" /s

    O4 - HKCU\..\Run: [Ease] C:\Documents and Settings\Administrator\Application Data\oesb.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    m.cab
    O16 - DPF: {4C226336-4032-489F-9674-67E74225979B} (OTXMovie Class) - http://www.otxresearch.com/OTXMedia/OTXMedia.dll
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/19bd54c724f9afb48922/netzip/RdxIE601.cab
    O16 - DPF: {65E7DB1D-0101-4100-BD66-C5C78C917F93} - http://install.wildtangent.com/bgn/partners/aolim/install.cab
    O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundler/CAB/RealArcadeRdxIE.cab


    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\vrslotvb.dll
    C:\WINDOWS\system32\juhesfii.dll
    C:\Documents and Settings\Administrator\Application Data\oesb.exe

    Empty your C:\Windows\Prefetch folder and your Recycle Bin

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  9. Teapot

    Teapot Private E-2

    After glancing at my hijack.log, I've come to the conclusion that the perpetrator is the frzstate.exe file which is some super-admin program that's overriding all of my "powers". I have no idea how to get rid of it though.. any ideas? This description would explain why I'm having so many problems:

    Deep Freeze from Hyper Technologies. "Freezes" the current software configuration so that an a re-boot all changes made refer back to their original settings. Not required for most users - more likely to be used by system administrators, for example
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I thought it was something you installed. That's why I skipped it. You have other problems though. See my post below of things that need to be fixed.

    Look in Add/Remove program for something relating to HyperTechnologies or Deep Freeze.
    If found, uninstall it. If that does not work, we will use HJT to remove it. Let me know.
     
  11. Teapot

    Teapot Private E-2

    I followed all of your Hijack This instructions, but I don't really think they did anything, because, lo and behold, when I rebooted everything was back to normal and they popped up again in the log. So.. yeah.. it's definitely that deep freeze program.

    I can't find it in the add/remove list or anything like Hyper Technologies.

    When I get that taken off, I'll go back through and follow your Hijack instructions again.

    Thanks for the help so far! Sorry if I'm technically inept and making this difficult.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does the system tray icon for Deep Freeze allow you to disable it?
     
  13. Teapot

    Teapot Private E-2

    Nope, it allows no right click of any sort, and double clicking doesn't do anything.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try bringing up Task Manager and right click the below processes and select End process tree.
    DfServEx.exe
    FrzState.exe

    Does that work?
     
  15. Teapot

    Teapot Private E-2

    Both showed up in the process list but both were unable to be stopped.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  17. Teapot

    Teapot Private E-2

    I tried killing the system tree, and the system process in that program for both processes but neither worked.

    I'm beginning to wonder how this ever got on my computer..
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    According to what I have read this is a program that people install themselves. Normally installed by an Administrator. It is not considered malware in anything I have read. It's rather strange that you cannot kill it or uninstall it. Are you logged in as the Administrator?
     
  19. Teapot

    Teapot Private E-2

    I know I never installed it; I would have no reason too. Yeah, I only have two accounts on this computer-- one default guest, and one admin that I always use. Windows wants me to have admin capabilities and it says that I do everywhere except this freeze program overrides it all.

    Maybe I have a really evil friend who put it on here. Either way, I need it off really badly. There has to be some way to get it removed permanently.. I know that I killed it in the system tray once, somehow, but it obviously came back.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That may be the start of the problem with removing it. I have read that if you don't end the program first before trying to remove certain items, it will respawn and now you have no way to remove it.


    What is showing in your Startup list? You can Generate a StartupList log using HijackThis.

    Run HJT, select Config on lower right. In the next window first select 'List also minor sections (full)' and then choose 'Generate StartupList log' and save it to a .txt file so you can post it back here as an attachment.
     
  21. Teapot

    Teapot Private E-2

    Well.. that would really suck if I couldn't get it off. My computer would essentially be worthless, as far as I can see it.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Start, Run, and enter Services.msc then look thru the list of services. Do you see this stuff in the services list?
     
  23. Teapot

    Teapot Private E-2

    DfServEx.exe shows up but FrzState.exe doesn't
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must stop it by right clicking on it then select stop. Now disable it by right clicking on it and selecting Properties. Then in the General tab see the area that says "Startup type: " click on the pull down arrow and change it to Disabled.

    Now let's see what happens. Try ending the running processes now with ProcessExplorer.
     
  25. Teapot

    Teapot Private E-2

    Okay, this is kind of weird.

    I tried stopping it once, and right away it said I couldn't do it on "Local Computer". Then I tried to stop it again, and it took longer, and said it couldn't stop it, yet, the only option on it now is "Start" so you would assume it's stopped. Should I continue onto the next steps?
     
  26. Teapot

    Teapot Private E-2

    By the way, you are SO incredibly helpful. I don't think that I can ever express how grateful I am for all of this. Thank you!!!!
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, see if it can be disabled.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! But in a couple minutes I have to get some sleep! It's 2:30 am here and my eyes are getting blurry and my fingers are getting tired ;) . It's been busy here tonight.
     
  29. Teapot

    Teapot Private E-2

    Well, the DfServEx.exe disappeared completely from the process list but FrzState.exe is still there and it's still unable to be stopped.

    :( I'm so disheartened! I hope it just dies. Somehow, I doubt that will happen.

    Oh yeah, and now it's running under the "Windows Explorer" tree (in the blue section, but right outside of it-- if that makes sense). But, I have no idea what that means, if anything.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay try rebooting your PC and see what happens. The service we killed may be the thing that starts everything up. Without the service starting, the other program may not even run anymore. On the otherhand, they may all reload after reboot. If so, we may need to have something like Pocket Killbox try to delete those files upon Windows startup. Let's see.

    I'm signing off now. Talk with you later tomorrow (today).
     
  31. Teapot

    Teapot Private E-2

    Thanks! It's really nice to hear that we haven't exhausted every option...

    But, it didn't work. Both processes reappeared.

    My computer is insisting that I died November 27 (the day it keeps becoming everytime I restart). All of my emails end that day, after all. Oh wow.. I just realized something. If I'm using Outlook as my external mail client, and it receives mail from someone-- when I restart, they're gone forever? Because it takes them off my server...

    This just keeps getting worse. Looking forward to your assistance tomorrow. Again, THANK YOU!!!
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I know you said you tried System Restore, but did you try going to a restore point before Nov 27th?
    Also, before doing that Stop & Disable the service again.
     
  33. Teapot

    Teapot Private E-2

    I tried doing a system restore, but the only available date that came up was today. I guess it does an automatic system restore when I restart. But this means that I lost my one last restore point when I reinstalled iTunes before it went back to being November 27.

    This is kind of weird, because last night I had plenty of other restore dates. I just want my stuff from yesterday and Saturday back! :(

    Should I still try to do that one available system restore date?
     
  34. Teapot

    Teapot Private E-2

    Wow-- I don't know if this means anything, but if you hold shift and doubleclick the icon in the system tray you get a box asking for a DeepFreeze password.

    Too bad I have no idea what it would be.
     
  35. Teapot

    Teapot Private E-2

    I found these files that make up deep freeze in another forum post. Do you think if I stopped the one process and tried to delete all of these, that it would wor

    depfrzlo.sys : kernel driver
    depfrzhi.sys : filesystem driver
    dfserv.exe : the service it installed
    frzstate.exe : the password app
    persis00.sys : password file (replace with one that uses a known password if you lost yours... also contains the information to tell it at boot time in what mode to boot frozen/thawed)
    (I'm not sure where it keeps it's mirrored copy of the HD or whatever information)
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is all too strange. How did this application get installed on your PC without your knowledge? Thi s does not sound like malware that would do that. Someone had to install it. Was this always your PC?

    Check to see if the password is just empty (just hit return). You may need to get in touch with this company to find out how to recover from a lost password and how to uninstall it.
     
  37. Teapot

    Teapot Private E-2

    I think someone put it on here. It's always been my computer, and I usually put it in sleep mode when I'm not around.

    I've contacted the company but I don't think they'll help me since they have no way of knowing whether my case is legitimate, or whether I'm some random kid who wants to crack their school computers.
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That maybe true. And for that matter, I don't know that either.
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds