Author Topic: Help with removing Outerinfo  (Read 13853 times)

0 Members and 1 Guest are viewing this topic.

Viper666

  • Guest
Help with removing Outerinfo
« on: March 30, 2008, 11:20:08 AM »
Hello everyone,

I need some assistance removing Outerinfo pop-ups (aka PurityScan, Oinadserver or OIN). If you could help me out and walk me through the process, I'd appreciate it very much. It's been popping up like crazy and it's taken over my desktop screen. Rather annoying...

But thanks in advance if you could help me :).

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Help with removing Outerinfo
« Reply #1 on: March 30, 2008, 04:39:52 PM »
Hi

Please download
 OTMoveIt2 by OldTimer.


Save it to your desktop.

Please double-click OTMoveIt2.exe to run it.


Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):


purity



Return to OTMoveIt2, right click in the "Paste List Of Files/Patterns To Search For and Move" window (under the yellow bar) and choose Paste.


Click the red Moveit! button.

Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.

Close OTMoveIt2

If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

NOTE: If OTMOVEITE reboots, before you can get the ruslts they can be found here
 C:\_OTMoveIt\MovedFiles\********_******.log
(where "********_******" is the "date_time")

Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • When it has finished, dss will open two Notepads main.txt and extra.txt  -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.

Viper666

  • Guest
Re: Help with removing Outerinfo
« Reply #2 on: March 30, 2008, 06:05:42 PM »
I hope I did it right. It didn't look like much happened, but here are the results of OTMoveIt2:

[Custom Input]
< purity >
 
OTMoveIt2 by OldTimer - Version 1.0.21 log created on 03302008_090325

ETA: The dss txt pages were too long to post, so I'm going to attach them. Btw, thanks so much for your help once again :).
« Last Edit: March 30, 2008, 06:16:58 PM by Viper666 »

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Help with removing Outerinfo
« Reply #3 on: March 30, 2008, 06:23:01 PM »
You're welcome. When you said purity, I thought we could knock some out ahead of time. Give me a few minutes to look at the logs. BRB

Viper666

  • Guest
Re: Help with removing Outerinfo
« Reply #4 on: March 30, 2008, 06:38:57 PM »
Lol Good deal. I was just scared I didn't do it right. You're truly awesome for helping so many people out :D.

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Help with removing Outerinfo
« Reply #5 on: March 30, 2008, 07:08:16 PM »
Lot's of things here. You are using service pack 1. Do not attempt to install sevice pack 2 untill the machine is clean.

We'll start with this

* Download and run this removal tool for 180 Search

http://securityresponse.symantec.com/avcenter/Fix180Sh.exe


Please download ComboFix from Here or Here to your Desktop.

Do Not Run It Yet, we will run it a little differently.


**Note:  In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**


* Go to add remove programs and uninstall the following if present

Rabio
180Search assistant
Yazzle
QdrDrive
QdrModule



* Open HJT, run a system scan only, check mark these lines if present

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\System32\sbwltbxa.exe,
O2 - BHO: (no name) - {00000250-0320-4dd4-be4f-7566d2314352} - (no file)
O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
O2 - BHO: (no name) - {15651c7c-e812-44a2-a9ac-b467a2233e7d} - (no file)
O2 - BHO: (no name) - {3712b7f2-1dd2-11b2-a814-d414ee082346} - C:\WINDOWS\nkvchwjs.dll
O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
O2 - BHO: (no name) - {4e7bd74f-2b8d-469e-92c6-ce7eb590a94d} - (no file)
O2 - BHO: (no name) - {5929cd6e-2062-44a4-b2c5-2c7e78fbab38} - (no file)
O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
O2 - BHO: (no name) - {5fa6752a-c4a0-4222-88c2-928ae5ab4966} - (no file)
O2 - BHO: (no name) - {622cc208-b014-4fe0-801b-874a5e5e403a} - (no file)
O2 - BHO: BndBlock5 BHO Class - {82EA1A55-9CBC-404b-9D0C-E8BFB7EAAE9B} - C:\Program Files\QdrDrive\QdrDrive10.dll (file missing)
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: (no name) - {965a592f-8efa-4250-8630-7960230792f1} - (no file)
O2 - BHO: (no name) - {9c5b2f29-1f46-4639-a6b4-828942301d3e} - (no file)
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
O2 - BHO: (no name) - {fc3a74e5-f281-4f10-ae1e-733078684f3c} - (no file)
O2 - BHO: (no name) - {ffff0001-0002-101a-a3c9-08002b2f49fb} - (no file)
O4 - HKLM\..\Run: [pgdqjady] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\pgdqjady.dll"
 


Close all other browsers/windows, click fix, close HJT.

** Now for combofix

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.[/color]
    -----------------------------------------------------------
  • Close any open browsers.
  • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
  • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
  • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.


Open a new Notepad session (Do not use a Word Processor or WordPad). Click "Format" and be certain that Word Wrap is not enabled.

Copy and paste all the text in the quote box below into Notepad.

Click File, Save as..., and set the location to your Desktop, and enter (including quotation marks) as the filename: "CFscript.txt" . Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown at the bottom of this post.


Quote
File::
C:\WINDOWS\system32\sbwltbxa.exe
C:\WINDOWS\nkvchwjs.dll
C:\WINDOWS\bolgxafm.exe
C:\Program Files\Common Files\Yazzle1552OinAdmin.exe
C:\Program Files\QdrDrive\QdrDrive10.dll
C:\Program Files\QdrModule\QdrModule12.exe

Folder::
C:\Documents and Settings\All Users\Application Data\Rabio
C:\Program Files\QdrDrive
C:\Program Files\QdrModule


This will start ComboFix .Close  all browser/windows first. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HJT log.


Attaching the logs is fine. DSS should have install hijackthis for you.

Thanks


Viper666

  • Guest
Re: Help with removing Outerinfo
« Reply #6 on: March 30, 2008, 08:18:23 PM »
Okay, I've hit a major snag. I'm currently on my desktop instead. I did everything as directed so far. I made the CFscript.txt and dragged it onto the ComboFix icon, turned off my antivirus and all that other good stuff. Then ComboFix started to run, but it's stopped. It says (somewhat paraphrased here):

Scanning for infected files...
Scan time should take no more than 10 minutes
However, for badly infected systems it could easily double

ComboFix has changed your clock settings
Do not change it back, it will be restored later

Delete Files/Folders:
*blinking cursor*


It's stayed like this for some time now. And my desktop is gone; the taskbar, all of the icons. The wallpaper has restored itself though, and the nasty green screen from the malware is gone. Should I wait it out or are there other courses of action that I should take?
« Last Edit: March 30, 2008, 08:23:17 PM by Viper666 »

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Help with removing Outerinfo
« Reply #7 on: March 30, 2008, 09:01:41 PM »
If there is any type of hard drive activity, blinking light, sound from the hard drive, combofix is still running, Do not stop it  Give it about 40-50 minutes. if CF has stalled completely, reboot, all desktop items will come back.

Viper666

  • Guest
Re: Help with removing Outerinfo
« Reply #8 on: March 30, 2008, 09:10:02 PM »
It's definitely been an hour now, and it doesn't sound like anything is going on. No fan running, no crackles of it doing any work. I guess I'll reboot then. What should I do after that?

ETA: I tried running ComboFix again with the CFscript.txt and it still isn't doing anything. No blinking lights, nothing. Is there anything else I need to turn off or anything else I should do before running it?
« Last Edit: March 30, 2008, 09:58:39 PM by Viper666 »

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Help with removing Outerinfo
« Reply #9 on: March 30, 2008, 10:48:41 PM »
No don't re-run CF. Run DSS and post that log. There will only be a main log this time.

Thanks

Viper666

  • Guest
Re: Help with removing Outerinfo
« Reply #10 on: March 30, 2008, 11:23:34 PM »
Here it is. Thanks again for your help. I'd be completely lost right now.

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Help with removing Outerinfo
« Reply #11 on: March 30, 2008, 11:57:31 PM »
We'll just use a different tool for now. Delete combofix.exe from you desktop, we may get another copy later.


* Open HJT, run a system scan only, check mark these lines if present

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\System32\sbwltbxa.exe,
O2 - BHO: (no name) - {00000250-0320-4dd4-be4f-7566d2314352} - (no file)
O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
O2 - BHO: (no name) - {15651c7c-e812-44a2-a9ac-b467a2233e7d} - (no file)
O2 - BHO: (no name) - {3712b7f2-1dd2-11b2-a814-d414ee082346} - C:\WINDOWS\nkvchwjs.dll
O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
O2 - BHO: (no name) - {4e7bd74f-2b8d-469e-92c6-ce7eb590a94d} - (no file)
O2 - BHO: (no name) - {5929cd6e-2062-44a4-b2c5-2c7e78fbab38} - (no file)
O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
O2 - BHO: (no name) - {5fa6752a-c4a0-4222-88c2-928ae5ab4966} - (no file)
O2 - BHO: (no name) - {622cc208-b014-4fe0-801b-874a5e5e403a} - (no file)
O2 - BHO: BndBlock5 BHO Class - {82EA1A55-9CBC-404b-9D0C-E8BFB7EAAE9B} - C:\Program Files\QdrDrive\QdrDrive10.dll (file missing)
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: (no name) - {965a592f-8efa-4250-8630-7960230792f1} - (no file)
O2 - BHO: (no name) - {9c5b2f29-1f46-4639-a6b4-828942301d3e} - (no file)
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
O2 - BHO: (no name) - {fc3a74e5-f281-4f10-ae1e-733078684f3c} - (no file)
O2 - BHO: (no name) - {ffff0001-0002-101a-a3c9-08002b2f49fb} - (no file)
O4 - HKLM\..\Run: [pgdqjady] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\pgdqjady.dll"
O16 - DPF: {50BD5CDA-4BA8-4048-8FAA-763F222E41D8} (xpreload.xpreloader) - ms-its:mhtml:file://c:\\nores.mht!http://adxanet.net/code/chm/xpre.chm::/xpreload.oc




Close all other browsers/windows, click fix, close HJT.




Please double-click OTMoveIt2.exe to run it.


Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):


C:\Program Files\180solutions
C:\WINDOWS\system32\sbwltbxa.exe
C:\WINDOWS\nkvchwjs.dll
C:\WINDOWS\bolgxafm.exe
C:\Program Files\Common Files\Yazzle1552OinAdmin.exe
C:\Program Files\QdrDrive\QdrDrive10.dll
C:\Program Files\QdrModule\QdrModule12.exe
C:\Documents and Settings\All Users\Application Data\Rabio
C:\Program Files\QdrDrive
C:\Program Files\QdrModule
C:\Program Files\180search
C:\WINDOWS\voiceip.dll
C:\WINDOWS\stcloader.exe
C:\WINDOWS\swin32.dll
C:\WINDOWS\cdsm32.dll
C:\WINDOWS\mssvr.exe
C:\WINDOWS\mspphe.dll
C:\WINDOWS\bokja.exe
2C:\WINDOWS\System32\WER8274.DLL
C:\WINDOWS\System32\MSIXU.DLL
C:\WINDOWS\bjam.dll
C:\WINDOWS\2020search2.dll
C:\WINDOWS\2020search.dll
C:\Program Files\seekmo
C:\WINDOWS\180ax.exe
C:\WINDOWS\updatetc.exe
C:\WINDOWS\salm.exe
C:\WINDOWS\saiemod.dll
:\WINDOWS\System32\shdocpe.dll
C:\WINDOWS\System32\ntnut32.exe
C:\WINDOWS\shdocpl.dll
2C:\WINDOWS\shdocpe.dll
C:\WINDOWS\ntnut.exe
C:\Program Files\Sysmnt
C:\WINDOWS\winsb.dll
C:\WINDOWS\browserad.dll
C:\WINDOWS\aviwrap32.dll
C:\WINDOWS\avisynthex32.dll
C:\WINDOWS\avifile32.dll
C:\WINDOWS\autodisc32.dll
C:\WINDOWS\audiosrv32.dll
C:\WINDOWS\ati2dvag32.dll
C:\WINDOWS\ati2dvaa32.dll
C:\WINDOWS\athprxy32.dll
C:\WINDOWS\asycfilt32.dll
C:\WINDOWS\asferror32.dll
C:\WINDOWS\apphelp32.dll
C:\WINDOWS\changeurl_30.dll


Return to OTMoveIt2, right click in the "Paste List Of Files/Patterns To Search For and Move" window (under the yellow bar) and choose Paste.


Click the red Moveit! button.

Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.

Close OTMoveIt2

If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

NOTE: If OTMOVEITE reboots, before you can get the ruslts they can be found here
 C:\_OTMoveIt\MovedFiles\********_******.log
(where "********_******" is the "date_time")


Do this and post back the OTMOVEIT2 results while I look for more.


edit: a new DSS log too, please.



« Last Edit: March 31, 2008, 12:08:33 AM by oldman »

Viper666

  • Guest
Re: Help with removing Outerinfo
« Reply #12 on: March 31, 2008, 12:10:58 AM »
Okay, HJT stuff went just fine, but when I did the OTMoveIt2, it stalled when it was trying to move C:\WINDOWS\nkvchwjs.dll. Now it's frozen and the window for OTMoveIt2 is completely white/blank. I'm waiting to see if it can jump over this hurdle, but just fyi in case I need to do something about that.

ETA: 10+ minutes later and it still hasn't done anything since. Le sigh.
« Last Edit: March 31, 2008, 12:24:22 AM by Viper666 »

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Help with removing Outerinfo
« Reply #13 on: March 31, 2008, 12:28:12 AM »
ok, that may also be the file that stalled CF. Send me another DSS log so I can see what has been removed so far.

Thanks

Viper666

  • Guest
Re: Help with removing Outerinfo
« Reply #14 on: March 31, 2008, 12:36:08 AM »
That's what I thought too. Here's the new dss file.