Virus: Privacy Protector, Spyware & Malware Protection, Error Cleaner. Help?

By deepikaur
Apr 20, 2008
Topic Status:
Not open for further replies.
  1. Hello, everyone!
    Ok, sorry if this is posted in the wrong section. I just joined and need some serious help. Logged into my PC this morning and there were three new icons on my desktop:

    >Privacy Protector
    >Spyware&Malware Protection
    >Error Cleaner


    On top of that, there were these popups that kept coming up, and all these IE windows kept opening. And my Firefox windows kept crashing. Also, I am unable to open task manager.. Tried going to 'run', but even from there, I couldn't access my task manager. Also, several things from my desktop are missing, and I cannot afford to lose any of my data, but my computer keeps crashing, so I'm unable to back it up. I do run Symantec Antivirus regularly.

    I would greatly appreciate it if anyone could help me with this problem ASAP (considering I've got a major project due tomorrow)!

    If anyone needs to know, I use Windows XP, but am currently accessing the internet from my friend's laptop.
  2. kritius

    kritius TechSpot Guru Posts: 2,087

    Download and Run Malwarebytes' Anti-Malware
    Please download Malwarebytes' Anti-Malware to your desktop.
    • Double-click mbam-setup.exe and follow the prompts to install the program.
    • At the end, be sure a checkmark is placed next to:
      • Update Malwarebytes' Anti-Malware
      • Launch Malwarebytes' Anti-Malware
    • Then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select Perform full scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected.
    • When completed, a log will open in Notepad. please Attach the log into your next reply.
    • If you accidently close it, the log file is saved here and will be named like this: C:\Documents and Settings\<your username>\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt

    Download and Run ComboFix
    • Download this file to your desktop from either of the two below listed places :

      HERE or HERE
    • Then double click combofix.exe & follow the prompts.
    • When finished, it shall produce a log for you. Attach that log in your next reply
    WARNING: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

    HighjackThis Instructions
    • Make sure you have the LATEST version of HJT (currently v2.0.2) it can be downloaded from HERE
    • Run the HijackThis Installer and it will automatically place HJT in its own folder, usually C:\Program Files\Trend Micro\HijackThis. Please don't change the directory as it is necessary to create backups.
    • After installing, the program launches automatically, select Scan now and save a log
    • After the scan is complete attach the log into your reply.
    Do not attempt to fix any item yet.
    Do not add anything to the ignore list.
    Don't use the AnalyseThis button, its findings are dangerous if misinterpreted.
  3. deepikaur

    deepikaur Newcomer, in training Topic Starter

    unableo download ComboFix

    Thanks very much for the swift reply!

    Ok, I've completed the first step (the one involving Malwarebytes Anti-Malware), but I'm unable to download ComboFix for some reason.
    Every time I click either of the links, I get a message saying "You cannot rename ComboFix as ComboFix[1]!" even though I'm not attempting to rename it.

    Anywho, I've attached the first log. Please tell me what you'd like for me to do in place of the second step, if anything.
  4. kritius

    kritius TechSpot Guru Posts: 2,087

    : Download and Run DSS

    Download Deckard's System Scanner (DSS) to your Desktop. You must be logged onto an account with administrator privileges.
    • Close all applications and windows.
    • Double-click on dss.exe to run it, and follow the prompts.
    • When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<- this one will be minimized.
    • Attach the main.txt and the extra.txt in your reply.
  5. deepikaur

    deepikaur Newcomer, in training Topic Starter

    Thanks!
    I've attached both the main and extra as you've asked. =)
  6. kritius

    kritius TechSpot Guru Posts: 2,087

    Go to add/remove programs and unistall the following,

    Hijackthis 1.99.1
    HijackThis 1.99.1
    J2SE Runtime Environment 5.0 Update 2
    Viewpoint Media Player
    PowerReg Scheduler


    Please download the OTMoveIt2 by OldTimer.
    • Save it to your desktop.
    • Please double-click OTMoveIt2.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
    • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

      Code:
      [kill explorer]
      C:\WINDOWS\system32\geBSlLbx.dll
      C:\WINDOWS\system32\iifdawWN.dll
      C:\WINDOWS\dpevflbg.dll
      C:\Documents and Settings\All Users\Application Data\mzmxqzsf
      C:\Documents and Settings\Owner\Application Data\LimeWire
      C:\WINDOWS\system32\ksbaybgf.dll
      C:\WINDOWS\system32\kvkdyxsj.exe
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\b888e04b
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\cosjvceb
      C:\WINDOWS\wdpoefan.dll
      C:\WINDOWS\vadokmxt.dll
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\wdpoefan
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\vadokmxt
      purity
      [start explorer]
          
    • Return to OTMoveIt2, right click in the "Paste Standard List of Files/Folders to Move" window (under the light blue bar) and choose Paste.
    • Click the red Moveit! button.
    • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
    • Close OTMoveIt2
    Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

    Please download ATF Cleaner by Atribune.

    • Double-click ATF-Cleaner.exe to run the program.
      Under Main choose: Select All
      Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main menu to close the program.
    For Technical Support, double-click the e-mail address located at the bottom of each menu.

    Download RatsCheddar.zip
    It contains a program written by Rathat, and it is a Policy Controller.
    Save and extract this program to the desktop.
    Once extracted, click on the RatsCheddar.exe file.
    Enable everything, then click Exit
    Reboot your Computer.

    HighjackThis Instructions
    • Make sure you have the LATEST version of HJT (currently v2.0.2) it can be downloaded from HERE
    • Run the HijackThis Installer and it will automatically place HJT in its own folder, usually C:\Program Files\Trend Micro\HijackThis. Please don't change the directory as it is necessary to create backups.
    • After installing, the program launches automatically, select Scan now and save a log
    • After the scan is complete attach the log into your reply.
    Do not attempt to fix any item yet.
    Do not add anything to the ignore list.
    Don't use the AnalyseThis button, its findings are dangerous if misinterpreted.
  7. deepikaur

    deepikaur Newcomer, in training Topic Starter

    Alright, I did not find "PowerReg Scheduler" when I was removing and uninstalling the programs. The rest however, I've removed.

    The results from the OTMoveIt2 are:


    -----------------------------------
    Explorer killed successfully
    File/Folder C:\WINDOWS\system32\geBSlLbx.dll not found.
    File/Folder C:\WINDOWS\system32\iifdawWN.dll not found.
    File/Folder C:\WINDOWS\dpevflbg.dll not found.
    File/Folder C:\Documents and Settings\All Users\Application Data\mzmxqzsf not found.
    File/Folder C:\Documents and Settings\Owner\Application Data\LimeWire not found.
    File/Folder C:\WINDOWS\system32\ksbaybgf.dll not found.
    File/Folder C:\WINDOWS\system32\kvkdyxsj.exe not found.
    < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\b888e04b >
    Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\b888e04b not found.
    < HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\cosjvceb >
    Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\cosjvceb not found.
    File/Folder C:\WINDOWS\wdpoefan.dll not found.
    File/Folder C:\WINDOWS\vadokmxt.dll not found.
    < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\wdpoefan >
    Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\wdpoefan not found.
    < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\vadokmxt >
    Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\vadokmxt not found.
    < purity >
    Explorer started successfully

    OTMoveIt2 by OldTimer - Version 1.0.4.1 log created on 04222008_192805

    -----------------------------

    Working on the rest right now.
  8. kritius

    kritius TechSpot Guru Posts: 2,087

    Could you try it again with just this code?

    Code:
    C:\WINDOWS\system32\geBSlLbx.dll
    C:\WINDOWS\system32\iifdawWN.dll
    C:\WINDOWS\dpevflbg.dll
    C:\Documents and Settings\All Users\Application Data\mzmxqzsf
    C:\Documents and Settings\Owner\Application Data\LimeWire
    C:\WINDOWS\system32\ksbaybgf.dll
    C:\WINDOWS\system32\kvkdyxsj.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\b888e04b
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\cosjvceb
    C:\WINDOWS\wdpoefan.dll
    C:\WINDOWS\vadokmxt.dll
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\wdpoefan
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\vadokmxt
  9. deepikaur

    deepikaur Newcomer, in training Topic Starter

    Here are the results, using the second code:

    File/Folder C:\WINDOWS\system32\geBSlLbx.dll not found.
    File/Folder C:\WINDOWS\system32\iifdawWN.dll not found.
    File/Folder C:\WINDOWS\dpevflbg.dll not found.
    File/Folder C:\Documents and Settings\All Users\Application Data\mzmxqzsf not found.
    File/Folder C:\Documents and Settings\Owner\Application Data\LimeWire not found.
    File/Folder C:\WINDOWS\system32\ksbaybgf.dll not found.
    File/Folder C:\WINDOWS\system32\kvkdyxsj.exe not found.
    < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\b888e04b >
    Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\b888e04b not found.
    < HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\cosjvceb >
    Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\cosjvceb not found.
    File/Folder C:\WINDOWS\wdpoefan.dll not found.
    File/Folder C:\WINDOWS\vadokmxt.dll not found.
    < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\wdpoefan >
    Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\wdpoefan not found.
    < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\vadokmxt >
    Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\vadokmxt not found.

    OTMoveIt2 by OldTimer - Version 1.0.4.1 log created on 04222008_201335
  10. deepikaur

    deepikaur Newcomer, in training Topic Starter

    HJT log

    And here's my log from the HJT run. =]
  11. kritius

    kritius TechSpot Guru Posts: 2,087

    Can you run DSS again, I dont get why those files are saying not found when they are showing in the previous log.

    Does your computer have multiple user accounts?
     
  12. deepikaur

    deepikaur Newcomer, in training Topic Starter

    Sorry, my internet had been down yesterday..
    I ran the DSS, as you asked, but this time, only the "main" document opened. I've attached it.
    This PC only has the administrator and guest accounts, but nobody has been under guest for quite some time now.
  13. kritius

    kritius TechSpot Guru Posts: 2,087

    The extra should be in the deckards folder.

    Fix entries using HiJackThis
    • Launch HiJackThis
    • Click the Do a system scan only button
    • Put a check next to the entries listed below
    O4 - Startup: PowerReg Scheduler.exe
    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJxdm128MHUS

    • IMPORTANT: Do NOT click fix until you exit all browser sessions including the one you are reading in right now
    • Click the Fix checked button and close HiJackThis
    • Reboot HijackThis if necessary

    I would like you to do an online scan so that we can what else may be in your system,
    Run Kaspersky online scanner
    With the exception of Internet Explorer, which must be used for this scan, keep ALL programs closed
    Note: It is recommended to disable onboard antivirus program and antispyware programs while performing scans to speed up scan time and to make sure there are no conflicts.
    Do not go surfing while your resident protection is disabled!
    Once the scan is finished remember to re-enable resident antivirus protection along with whatever antispyware application you use.


    Do an online scan with Kaspersky Online Scanner in Internet Explorer. You will be prompted to install and run an ActiveX component from Kaspersky, Click Yes.
    Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75%. Once the licence accepted, reset to 100%.
    • The program will launch and then start to download the latest definition files.
    • Once the scanner is installed and the definitions downloaded, click Next.
    • Now click on Scan Settings
    • In the scan settings make sure that the following are selected:
      o Scan using the following Anti-Virus database:
      o Extended (If available, otherwise use standard)
      o Scan Options:
      o Scan Archives
      o Scan Mail Bases
    • Click OK
    • Under select a target to scan, select My Computer
    • The scan will take a while so be patient and let it run.
    • Please do not use your computer while the scan is running. Once the scan is complete it will display if your system has been infected.
    • Click the Save Report As... button (see red arrow below)

      [​IMG]
    • In the Save as... prompt, select Desktop
    • In the File name box, name the file
    • In the Save as type prompt, select Text file (see below)

      [​IMG]
    • Include the report in your next post.
  14. deepikaur

    deepikaur Newcomer, in training Topic Starter

    Attached.
    And about your previous question.. this PC doesn't have any other accounts, but a handful of people use it, not just myself.
  15. deepikaur

    deepikaur Newcomer, in training Topic Starter

    Oh, it'd probably be best to tell you...
    When I came home today and logged in, I saw several new icons on my desktop, but these were different. As soon as I deleted them, popups similar to the ones before started coming up. I ran RogueRemover to stop the popups and icons from showing up, but I think the new virus is still there. =(
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.