PnStsj.dll - what is this?

I am using Avast Free version on Windows 7. When I logged into my computer this morning, I received RunDLL message box that says “There was a problem starting C:\Users\MYPC\AppData\Local\PnStsj.dll. The specified module could not be found.”

This file was automatically sent to Avast Virus Chest. When The virus description for this file in virus chest has it as Win32:Malware-gen. So far everything is functioning well despite this file being sent to the virus chest.

Few things I wanted to know:

  1. I would like to know how I got this dll file on my computer and if it is associated with any of my installed programs.

  2. How can I get rid of the RunDLL message box everytime I log into my computer?

Any help will be appreciated. Thanks

Download DDS and save it to your Desktop from here:
http://download.bleepingcomputer.com/sUBs/dds.scr

Double click dds.scr to run the tool.

* When done, DDS will open two (2) logs:
     1. DDS.txt
     2. Attach.txt

Save both reports to your desktop. Post DDS.txt back to topic.

What is DDS and what exactly does it do?

See here for details : http://www.bleepingcomputer.com/download/anti-virus/dds

Please follow argus’s instructions.

DDS.txt attached.

Thanks

Download ComboFix from here and save it to your Desktop.
If you are unsure how ComboFix works please read this guide carefully.
note: ComboFix must be downloaded to your Desktop.

Temporarily disable your AntiVirus program.
If you are unsure how to do this please read this Instruction.

Run ComboFix.
ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.
ComboFix will display DISCLAIMER OF WARRANTY ON SOFTWARE.
Click Yes to allow ComboFix to continue.
If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.

When the tool is finished, it will produce a log report for you. (typical location: C:[b]ComboFix.txt[/b] )
Post log reports ( ComboFix.txt) back to topic.

ComboFix.txt attached.

Btw, after ComboFix rebooted my computer, in addition to previous RunDLL message, there is now a new RunDLL message box saying there was a problem starting okusuwule.dll. Not sure what’s happening.

Anyway I am attaching ComboFix.txt. See if you can help me. Thanks.

Open notepad and copy/paste the text present inside the code box below:

RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)

Save this as CFScript.

http://img213.imageshack.us/img213/1218/cfscript1.gif

Close all browser windows and refering to the picture above.
Drag CFScript.txt into Combofix.exe. ComboFix will re-run.

Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will now run. When finished, it will produce a log for you.
Copy/paste the contents of the log in your next reply. (typical location: C:[b]ComboFix.txt[/b] )

Could you tell me what does the above script do and what is it going to fix?

This is some restrictions created by the malware that we will unlock

Find the ComboFix.txt attached.

Your logs are clean and there is no traces of active malware.

Your system is clean. You do not have a malware.

Do you still have a problem?

Looks fine now.
Now when I restart my computer, I do not get RunDLL message boxes for PnStsj.dll and okusuwule.dll.

Thanks for your help!

I have few questions:
Could you tell me if PnStsj.dll and okusuwule.dll were part of the malware? If yes is it possible to know which program(s) caused these dll files to install?

How to figure out if my system is infected with malware using DDS and ComboFix? Can I run these tools anytime?

How to figure out if my system is infected with malware using DDS and ComboFix? Can I run these tools anytime?

No…

“You should not run ComboFix unless you are specifically asked to by a helper. Also, due to the power of this tool it is strongly advised that you do not attempt to act upon any of the information displayed by ComboFix without supervision from someone who has been properly trained. If you do so, it may lead to problems with the normal functionality of your computer.”


It is necessary to uninstall Combofix

Start >> Search >> Copy

Combofix /Uninsltall

Enter


On Windows Vista and Windows7 operating systems you must reset system restore manual.

ComboFix do it only on Windows XP.

http://windows.microsoft.com/en-US/windows7/Turn-System-Restore-on-or-off


The recommendation that you install this program MCShield

It will prevent infection by computer via USB flash drive, mobile phone or any memory card.
And not only will prevent infection, but will immediately clean Memory card or external HDD

Program is excellent.