XP Problems....

Discussion in 'Malware Help (A Specialist Will Reply)' started by RayM, Apr 28, 2008.

  1. RayM

    RayM Private E-2

    I'm having XP problems even after following all the instructions in the these two threads:

    1. http://forums.majorgeeks.com/showthread.php?t=35407

    2. http://forums.majorgeeks.com/showthread.php?t=139313

    After running all these programs I have removed countless Vundo variants, Trojan virus', malware's, etc...

    At first I was receiving this message upon stratup of my PC: "Error loading c:\WINDOWS\system32\twnudsbl.dll"

    Now after all the cleanups, I am receiving this message upon startup of my PC: Error loading C:\WINDOWS\system32\rsjeasbj.dll"

    I got whatever I got from trying to download something off of Pirates Bay. First and last time I ever try that.

    Here goes all the attachments with the logs. Thanks in advance for your help.

    -Ray
     

    Attached Files:

  2. RayM

    RayM Private E-2

    The other log attached.

    What my computer is doing now is giving me the error code as described above and every now and then my browser gets hijacked and takes me to some random signup page.

    Thanks again in advance for the help.

    Ray
     

    Attached Files:

  3. RayM

    RayM Private E-2

    I believe I attached the wrong ComboFix log. Here is the correct one.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Uninstall the below old versions of software:
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {A2860E6C-C291-4B7A-B158-6A335AEA85DD} - (no file)
    O2 - BHO: (no name) - {EC832291-BE24-4698-B0D8-2D1E80978C8B} - C:\WINDOWS\system32\tuVnlKDt.dll (file missing)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [644ab56d] rundll32.exe "C:\WINDOWS\system32\rsjeasbj.dll",b
    O20 - Winlogon Notify: DPWLN - C:\WINDOWS\system32\DPWLEvHd.dll
    O20 - Winlogon Notify: uRlKEvsR - uRlKEvsR.dll (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. RayM

    RayM Private E-2

    Thanks Chas. I'll let you know how it goes.

    Ray
     
  6. RayM

    RayM Private E-2

    I think my PC is running pretty strong now. I have attached the logs and please let me know what you think.

    The only hiccup I am finding is when I go to open MalwareBytes an installer popup occurs for ScanSoft PDF Professional 4. This happen to me before with this program when I would open Microsoft Word and I submitted a ticket and they had me add a registry key. Now they want $9.95 to open a ticket. I'll just deal with it or I may even delete the program all together.

    Lastly, if everything looks good to you, should I proceed with the toggle system restore instructions in the fix XP thread?

    Thanks again, as my machine is running pretty smooth right now.

    Ray
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You most likely have some kind of failed/incomplete install or uninstall which is also probably why I see Microsoft Installer running in your process list ( C:\WINDOWS\system32\msiexec.exe ). You should work in the Software Forum on this. Possibly by running thisWindows Installer CleanUp Utilityor by looking at your EventViewer/Application log you can find the problem.


    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    6. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work thru the below link:
     
  8. RayM

    RayM Private E-2

    Chas,

    Sorry for the delay in getting back to you. I un-installed all the programs and did the toggle system restore. All systems have been running smoothly and thanks for your help in cleaning up my machine and removing all the junk/viruses.

    The only thing that never went back to normal was the clock. It is still set to military time. Is there a quick fix I can apply to get it to read normally? Just in case, I did follow the instructions to the tee for the cf un-install. Please advise.

    Ray
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can fix your clock from Control Panel ->Regional and Language Options and then on the Regional Options tab click the Customize button then on the next form click the Time tab. Then change the Time format to what you want. It explains there what the lower case and upper case letters will do. Upper case H is giving you 24 hour clock settings.
     
  10. RayM

    RayM Private E-2

    Thanks. Got it. Keep up the good work. The world needs more people like you and your felllow admins here. Peace...
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds