This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Help with AV System Care

10 min read

This thread's last reply is from September 29, 2007, 3:43 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

    Hello, and welcome to the forum.

    My name is Simon V., and I'll be glad to help you with your computer problems.

    HijackThis logs can take some time to research, so please be patient with me. I know that you need your computer working as quickly as possible, and I will work hard to help see that happens.
    I am currently looking over your log. As I am a trainee, everything that I post to you must be checked by an Admin or Moderator. Thus, there may be a tiny bit of a delay between posts, but it shouldn't be too long. I will post back shortly with a potential fix.

    Please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
    Hi :)

    Download and Run Blacklight

  • Download F-Secure Blacklight (fsbl.exe) to your desktop from here.
    • Open it and click Accept Agreement.
    • Click Scan.
    • After the scan is complete, click Next, then Exit.
    • It will create a log on the desktop named fsbl-xxxxxxx.log (the xxxxxxx will be the date and time of the scan).

    Make an Uninstall List
  • To access the Uninstall Manager you would do the following:

    1. Start HijackThis
    2. Click on the Config button
    3. Click on the Misc Tools button
    4. Click on the Open Uninstall Manager button.
    5. Click on the Save list... button and save the file to a convenient location. When you press Save, Notepad will open with the contents of that file.

    Report Back
  • Please post the report from Blacklight and the Uninstall List, along with a new HijackThis log in your next reply.
    Hi :)

  • There is quite a bit to do in this post, and it would probably be a good idea to print these instructions, because you will be rebooting your computer and won't have internet access during Safe Mode.
  • Important: Before anything else, please move fsbl.exe from your desktop to your C:\ drive. To do this, right-click on fsbl.exe and choose Cut. Then double-click on My computer, and double-click on your C: drive. Then right-click anywhere and choose Paste.
  • Download BFU.zip from here.
    • Right click on BFU.zip and click Extract all.
    • Extract it to C:\BFU.
    • Right click here and choose Save Link as to download EGDACCESS.bfu by Metallica.
    • Save it to C:\BFU as EGDACCESS.bfu.


[*]Copy and paste the following quote box into a new notepad (not wordpad) document. Make sure that wordwrap is turned off.

@echo off
If exist temp.reg del /q temp.reg
echo REGEDIT4 > temp.reg
echo.>> temp.reg
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\qleeegkrf] >> temp.reg
echo.>> temp.reg
echo [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] >> temp.reg
echo "qleeegkrf"=- >> temp.reg
echo.>> temp.reg
regedit /s temp.reg
attrib -r -s -h %windir%\prefetch\qleeegkrf.*
attrib -r -s -h %windir%\system32\qleeegkrf_navps.*
attrib -r -s -h %windir%\system32\qleeegkrf_nav.*
attrib -r -s -h %windir%\system32\qleeegkrf.*
attrib -r -s -h %windir%\system32\qleeegkrf_m2s.*
attrib -r -s -h %WINDIR%\qleeegkrf*.pf
del /q %windir%\prefetch\qleeegkrf.*
del /q %windir%\system32\qleeegkrf_navps.*
del /q %windir%\system32\qleeegkrf_nav.*
del /q %windir%\system32\qleeegkrf.*
del /q %windir%\system32\qleeegkrf_m2s.*
del /q %WINDIR%\qleeegkrf-*.pf
del /q temp.reg


[*]Save this as “Naviclean.batâ€
    Hi :)

    Word Wrap

  • You have Word Wrap turned on, this is making your logs difficult to read.
    • Run notepad.
    • Go to Format and untick Word Wrap.

    Run Kaspersky Online Scan
  • Please do an online scan with Kaspersky WebScanner

    Click on Kaspersky Online Scanner

    You will be promted to install an ActiveX component from Kaspersky, click Yes.
    • The program will launch and then begin downloading the latest definition files:
    • Once the files have been downloaded click on NEXT
    • Now click on Scan Settings
    • In the scan settings make sure that the following are selected:
      • Scan using the following Anti-Virus database:

        Extended (if available otherwise Standard)

      • Scan Options:

        Scan Archives Scan Mail Bases
    • Click OK
    • Now under select a target to scan:
        Select My Computer
    • The program will start and scan your system.
    • The scan will take a while so be patient and let it run.
    • Once the scan is complete it will display if your system has been infected.
      • Now click on the Save as Text button:
    • Save the file to your desktop, and post it here, along with a new HijackThis log (make sure Word Wrap is unchecked!)
    Hi :)

    That’s looking good, although there is one file I’m worried about.

    Upload File to Virustotal

  • Please visit Virustotal
    • Click the Browse... button.
    • Navigate to the file C:\588e64e565e05b9ba1\iexplore.exe
    • Click the Open button.
    • Click the Send button.
    • Copy and paste the results and post them back here, along with a new HijackThis log.
    Hi :)

    ATF Cleaner

  • Please download ATF Cleaner.

    Double-click on ATF-Cleaner.exe to start the program.
    Under the Main tab, put a check next to 'Select All'.
    Click the 'Empty Selected' button. (Note: if you select cookies, automated login at forums and sites will be disabled. If you do not want this, uncheck 'Cookies')

    If you use the Firefox browser:
    Click on Firefox at the top and put a check next to 'Select All'.
    If you would like to keep your saved passwords, click No at the prompt.
    Click the 'Empty Selected' button. (Note: if you select cookies, automated login at forums and sites will be disabled. If you do not want this, uncheck 'Cookies').

    If you use the Opera browser:
    Click on Opera at the top and put a check next to 'Select All'.
    If you would like to keep your saved passwords, click No at the prompt.
    Click the 'Empty Selected' button. (Note: if you select cookies, automated login at forums and sites will be disabled. If you do not want this, uncheck 'Cookies')
  • To free up resources, you can disable a few items from starting up when Windows loads. All these programs can be started when you need them, but if you want to keep one of them loading at startup, don’t check it in HijackThis. The optional entries are marked in blue.

    Fix Entries with HijackThis
  • Open HijackThis, perform a scan and put a check next to the following items (if present):

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" –atboottime

    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 –k
    O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun –nosplash
    O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
    O4 - HKLM\..\Run: [MMTray] C:\PROGRA~1\MUSICM~1\MUSICM~1\mm_tray.exe
    O4 - HKLM\..\Run: [Avvenu Access n Share Update] "C:\Program Files\Avvenu\Avvenu_updater.exe"
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKCU\..\Run: [Road Runner PhotoShow Media Manager] C:\PROGRA~1\ROADRU~1\ROADRU~1\data\Xtras\mssysmgr.exe
    O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
    O4 - HKCU\..\Run: [MsnMsgr] ~"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - Startup: Utility Tray.lnk = C:\WINDOWS\SYSTEM32\sistray.exe
    O4 - Global Startup: Avvenu Connector.lnk = C:\Program Files\Avvenu\Avvenu_agent.exe
    O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
    O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
    O4 - Global Startup: Virtual Assistant.lnk = C:\Program Files\Virtual Assistant\bin\matcli.exe
    O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Engine\ymetray.exe


    Close all programs except HijackThis and click on Fix checked.
  • Reboot your computer.
  • In your next reply, post a new HijackThis log and tell me how your computer is running.
    Hi :)

    If you are using an email program, like Outlook, you should check if all settings are correct (check with your internet provider), I can't help you with that.

    Prevention

  • Congratulations, your log looks clean. Please advise of any problems you are still experiencing, or follow these simple steps to keep your computer clean in the future:
    • Delete Tools - You can now delete the following files/folders:
      • fsbl.exe
      • C:\BFU\, BFU.zip
    • Rehide your System Files
      • Double-click My Computer.
      • Click the Tools menu, and then click Folder Options.
      • Click the View tab.
      • Put a check next to Hide file extensions for known file types.
      • Under the Hidden files folder, select Do not show hidden files and folders.
      • Check Hide protected operating system files.
      • Click Apply, and then click OK.
    • Disable and Enable System Restore - If you are using Windows ME or XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.
      • Turn off System Restore.
      • On the desktop, right-click My Computer
      • Click Properties
      • Click the System Restore tab
      • Check Turn off System Restore
      • Click Apply, and then click OK
      • Reboot.
      • Turn on System Restore.
      • On the desktop, right-click My Computer
      • Click Properties
      • Click the System Restore tab
      • Uncheck Turn off System Restore
      • Click Apply, and then click OK

      NOTE: only do this ONCE, NOT on a regular basis!
    • Make your Internet Explorer more secure
      • From within Internet Explorer click on the Tools menu and then click on Options.
      • Click once on the Security tab.
      • Click once on the Internet icon so it becomes highlighted.
      • Click once on the Custom Level button.
        • Change the Download signed ActiveX controls to Prompt.
        • Change the Download unsigned ActiveX controls to Disable.
        • Change the Initialise and script ActiveX controls not marked as safe to Disable.
        • Change the Installation of desktop items to Prompt.
        • Change the Launching programs and files in an IFRAME to Prompt.
        • Change the Navigate sub-frames across different domains to Prompt.
        • When all these settings have been made, click on the OK button.
        • If it prompts you as to whether or not you want to save the settings, press the Yes button.
      • Next press the Apply button and then the OK to exit the Internet Properties page.
    • Update your Anti-Virus Software - It is very imprtant that you update your Anti-Virus software at least once a week (even more if you wish). If you do not update your Anti-Virus software then it will not be able to catch any of the new variants that may come out.
    • Visit Microsoft's Update Site Frequently - It is important that you visit http://update.microsoft.com/ regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
    • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option.
      This will provide real-time spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an anti virus software. A tutorial on installing & using this product can be found here:
      Instructions for - Spybot S & D and Ad-aware
    • Install Ad-Aware - Install and download Ad-Aware. You should also scan your computer with the program on a regular basis just as you would an anti virus software in conjunction with Spybot. A tutorial on installing & using this product can be found here:
      Instructions for - Spybot S & D and Ad-aware
    • Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. An article on anti-malware products with links for this program and others can be found here:
      Computer Safety on line - Anti-Malware
    • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

      Follow this list and your potential for being infected again will reduce dramatically.
    • Stand Up and Be Counted!

      Please take the time to tell us what you would like to be done about the people who are behind all the problems you have had. We can only get something done about this if the people that we help, like you, are prepared to complain. We have a dedicated forum for collecting these complaints Malware Complaints, you have to be registered to post after registering just find your country room and register your complaint.
      The infection you had was Navipromo.
    • >> Here << you can see how you can help us.
You're welcome :) Happy surfing and stay safe!
Glad we could be of assistance.

This topic is now closed. If you wish it
reopened, please send us an email to 'admin at malwareremoval.com' with a link to your thread.


You can help support this site from this link :
Donations For Malware Removal

Do not bother contacting us if you are not the topic starter. A valid,
working link to the closed topic is required along with the user name used.
If the user name does not match the one in the thread linked, the email will be deleted.