This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijackthis Log, Popup Problem(tryed Everything)

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Stick with the advice in this thread please Nokturnal. While your problem is similar to the other thread it is not the same. Allow me to finish analyzing this information and please don't take any other repair steps as that may complicate the issue. Thank You.
Once again, you will need to print these instructions as you will be booting into safe mode.
We'll concentrate on cleaning the malware, then we'll move on to the recycle bin and other problems.

First, download CWShredder. Save it to your desktop but do not run it yet.

Boot into safe mode.

Run CWShredder using the "Fix button"

It should fix your hosts file, if there are any errors then run it again and click the make report button, when the report comes up copy it to a notepad doc and post it in your reply here. No need for a report if it is sucessful.

Once CWShredder completes, navigate to
C:\windows\system32\drivers\etc\hosts.
Open the hosts file with notepad ("Open With" on the right click menu) and make sure none of the offending entries as seen in the HijackThis log are there. If they are not then close notepad, right click the hosts file, choose Properties and put a check mark in the "Read Only" box. Close the properties dialog box with the "OK" button.

Place a check mark in HijackThis next to each of the following (if they are still there).

Click "fix checked."

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchmiracle.com/sp.php
O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 58.dll
O4 - HKLM\..\Run: [kalvsys] C:\windows\system32\kalvndg32.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/0713a80718d8c4…ip/RdxIE601.cab

Delete the following
Folders
C:\WINDOWS\EliteToolBar
Files
C:\windows\system32\kalvndg32.exe Before you delete it, make a copy and send it to me please.

Create a folder on your desktop, name it "Backup"
Go to Start>Run and type in regedit then click ok.
In the registry editor, navigate to the following key (using the + beside each key name to expand it)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
Expand the services key and look for the following key names under it.
ISEXEng
ZESOFT
When you find them, highlight the name, right click and choose "Export"
Save each of them to the Backup folder you created as a .reg file.
Now right click each one again and choose "Delete" then say OK to the prompt.
Close the registry editor.

Make sure you have done this:

Show hidden files/folders
Go to Start>control panel (settings in win 9x)>folder options>view tab
Check mark "display the contents of system folders"
Select "Show hidden files and folders"
Uncheck "Hide extensions for known file types"
Uncheck "Hide protected operating system files (Recommended)
Click the [ok] button.

See if you can find either of these files, delete if found.
c:\windows\system32\angelex.exe
c:\windows\zeta.exe

Reboot normally, post a fresh HijackThis and ServiceFilter log along with the CWShredder log if it was necessary to make one.
What is the exact dll error that you get (name of file, error #, etc)?

If you have a browser other than IE that you can use, please do and do not run Inernet Explorer until we are done with repairs.
Alright im using firefox now and got the pop up i allways get asoon as i opened the browser.

No RUN DLL Error anymore.

Recycling Bin Still Screwed up.



This Log is of CWShredder in Safe Mode


**** Run Keys ****

RUN: [UpdReg] C:\WINDOWS\UpdReg.EXE
RUN: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
RUN: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
RUN: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe /s
RUN: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
RUN: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
RUN: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
RUN: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
RUN: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
RUN: [Steam]


**** Browser Helper Objects ****



**** IE Toolbars ****



**** IE Extensions ****

IEExt: [AIM] C:\Program Files\AIM\aim.exe


**** Hosts File Entries ****

HOSTS: ó


**** IE Settings ****

Default Page: http://www.microsoft.com/isapi/redir.dll?p…er=6&ar=msnhome
Default Search: http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Local Page: C:\WINDOWS\system32\blank.htm


**** IE Context Menu (Right click) ****



**** Layered Service Providers ****

LSP: NL MSAFD Tcpip [TCP/IP]
LSP: NL MSAFD Tcpip [UDP/IP]
LSP: NL RSVP UDP Service Provider
LSP: NL RSVP TCP Service Provider
LSP: MSAFD Tcpip [TCP/IP]
LSP: MSAFD Tcpip [UDP/IP]
LSP: RSVP UDP Service Provider
LSP: RSVP TCP Service Provider
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{C8ED6DAA-FCD7-4E64-BA51-51937BA62F75}] SEQPACKET 0
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{C8ED6DAA-FCD7-4E64-BA51-51937BA62F75}] DATAGRAM 0
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{169942F8-6E36-42DA-A438-1342162549F4}] SEQPACKET 1
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{169942F8-6E36-42DA-A438-1342162549F4}] DATAGRAM 1
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{A942E24B-5189-4C2A-B81A-3F4B9176B277}] SEQPACKET 2
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{A942E24B-5189-4C2A-B81A-3F4B9176B277}] DATAGRAM 2
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{6E11B332-81AF-4C0E-A917-2576131FF2DD}] SEQPACKET 3
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{6E11B332-81AF-4C0E-A917-2576131FF2DD}] DATAGRAM 3
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{827F85F9-A36D-4E0D-BE73-9D5904716116}] SEQPACKET 4
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{827F85F9-A36D-4E0D-BE73-9D5904716116}] DATAGRAM 4


**** Blocked Control Panel Items ****

BLOCKED: [ncpa.cpl] No
BLOCKED: [odbccp32.cpl] No


**** Downloaded Program Files ****

Microsoft XML Parser for Java [file://C:\WINDOWS\Java\classes\xmldso.cab]
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} [http://www.apple.com/qtactivex/qtplugin.cab]
{3334504D-9980-0010-8000-00AA00389B71} [http://download.microsoft.com/download/0/C/8/0C8EDFAB-30BC-4792-898E-2DABE27B2C4D/mp43dmo.CAB]
{5334504D-9980-0010-8000-00AA00389B71} [http://codecs.microsoft.com/codecs/i386/mpg4sdmo.cab]
{6414512B-B978-451D-A0D8-FCFDF33E833C} [http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1097456561584] C:\WINDOWS\System32\wuweb.dll
{74D05D43-3236-11D4-BDCD-00C04F9A3B61} [http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab] C:\WINDOWS\System32\mfc42.dll C:\WINDOWS\loadhttp.dll C:\WINDOWS\aucfg.ini C:\WINDOWS\tmupdate.ini C:\WINDOWS\runtsckl.exe C:\WINDOWS\patchw32.dll C:\WINDOWS\Downloaded Program Files\xscan53.ocx
{8AD9C840-044E-11D1-B3E9-00805F499D93} [http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab]
{A8658086-E6AC-4957-BC8E-8D54A7E8A790} [http://www.microsoft.com/security/controls/GDI/0/GDIChk.CAB]
{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA} [http://java.sun.com/products/plugin/1.3.1/jinstall-131_04-win.cab]
{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA} [http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab]
{D27CDB6E-AE6D-11CF-96B8-444553540000} [http://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab]


**** Custom IE Search Items ****

SEARCH: [SearchAssistant] http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
SEARCH: [CustomizeSearch] http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm


**** Complete IE Options ****

IEOPT: [NoUpdateCheck]
IEOPT: [NoJITSetup]
IEOPT: [Disable Script Debugger] yes
IEOPT: [Show_ChannelBand] No
IEOPT: [Anchor Underline] yes
IEOPT: [Cache_Update_Frequency] Once_Per_Session
IEOPT: [Display Inline Images] yes
IEOPT: [Do404Search]
IEOPT: [Local Page] C:\WINDOWS\system32\blank.htm
IEOPT: [Save_Session_History_On_Exit] no
IEOPT: [Show_FullURL] no
IEOPT: [Show_StatusBar] yes
IEOPT: [Show_ToolBar] yes
IEOPT: [Show_URLinStatusBar] yes
IEOPT: [Show_URLToolBar] yes
IEOPT: [Start Page] http://www.google.com/
IEOPT: [Use_DlgBox_Colors] yes
IEOPT: [FullScreen] no
IEOPT: [Window_Placement] ,
IEOPT: [NotifyDownloadComplete] yes
IEOPT: [Use FormSuggest] no
IEOPT: [AddToFavoritesExpanded]
IEOPT: [Error Dlg Displayed On Every Error] no
IEOPT: [Error Dlg Details Pane Open] no
IEOPT: [FormSuggest PW Ask] no
IEOPT: [Use_Combobox_DlgBox_Colors_Complete] 2
IEOPT: [Use_Combobox_DlgBox_Colors_Failed] 11
IEOPT: [Use_Combobox_DlgBox_Colors_Error] 10
IEOPT: [Save Directory] C:\Documents and Settings\Nokturnal\Desktop\
IEOPT: [Default_Page_URL] http://www.microsoft.com/isapi/redir.dll?p…er=6&ar=msnhome
IEOPT: [Default_Search_URL] http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IEOPT: [Search Page] http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IEOPT: [Enable_Disk_Cache] yes
IEOPT: [Cache_Percent_of_Disk]
IEOPT: [Delete_Temp_Files_On_Exit] yes
IEOPT: [Local Page] %SystemRoot%\system32\blank.htm
IEOPT: [Anchor_Visitation_Horizon]
IEOPT: [Use_Async_DNS] yes
IEOPT: [Placeholder_Width]
IEOPT: [Placeholder_Height]
IEOPT: [Start Page] http://www.microsoft.com/isapi/redir.dll?p…B_PVER}&ar=home
IEOPT: [CompanyName] Microsoft Corporation
IEOPT: [Custom_Key] MICROSO
IEOPT: [Wizard_Version] 6.0.2600.0000
IEOPT: [FullScreen] no
IEOPT: [Window Title]
IEOPT: [Enable Browser Extensions] yes





Logfile of HijackThis v1.98.2
Scan saved at 10:52:21 PM, on 12/3/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\M-Audio MobilePre\Install\MPInst.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe /s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: M-Audio MobilePre Control Panel Launcher.lnk = C:\Program Files\M-Audio MobilePre\MPTask.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097456561584
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab




The script did not recognize the services listed below.
This does not mean that they are a problem.

To copy the entire contents of this document for posting:
At the top of this window click "Edit" then "Select All"
Next click "Edit" again then "Copy"
Now right click in the forum post box then click "Paste"

########################################

ServiceFilter 1.1
by rand1038

Microsoft Windows XP Home Edition
Version: 5.1.2600 Service Pack 1
Dec 3, 2004 10:53:23 PM


—> Begin Service Listing <—

Unknown Service # 1
Service Name: MobilePreInstallerService
Display Name: MobilePre Installer
Start Mode: Auto
Start Name: LocalSystem
Description: …
Service Type: Own Process
Path: c:\program files\m-audio mobilepre\install\mpinst.exe
State: Running
Process ID: 412
Started: True
Exit Code: 0
Accept Pause: False
Accept Stop: True

Unknown Service #2
Service Name: SwPrv
Display Name: MS Software Shadow Copy Provider
Start Mode: Manual
Start Name: LocalSystem
Description: Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this …
Service Type: Own Process
Path: c:\windows\system32\dllhost.exe /processid:{423d5456-bbd1-4791-b252-59d643407d83}
State: Stopped
Process ID: 0
Started: False
Exit Code: 1077
Accept Pause: False
Accept Stop: False

—> End Service Listing <—

There are 80 Win32 services on this machine.
2 were unrecognized.

Script Execution Time: 0.9375 seconds.
Thanks for the file Nokturnal

Ok, that should take care of the unknowns and we can proceed with the Look2Me infection now that prvtect is gone.

Before you do the following, remove the check from the "Read Only" box on the hosts file if you set that.

Download Ad-Aware and install it.
On the right of that page is an add on called VX2Cleaner, download and install that also, according to the instruction on the page.
Run Ad-Aware and update it with the latest reference file using the Check for updates now link or the Globe icon at the top right.
Next, click the help button. In the help menu click "Getting started" then "Performing your first scan" and follow the directions there for setting up to scan (don't scan yet though).
Now do the following:
(instructions from http://www.lavasofthelp.net/submit/)
Go to “Add-ons”
Select the VX2 Cleaner add-on and click “Run Tool”
If your computer isn’t infected, click “Close”.

If your computer is infected (You should end up here)

Select “Clean System”
Reboot your computer
Scan your computer with Ad-Aware
Remove any VX2 objects detected
Reboot your computer again
Run a second scan to make sure the files have been removed from your computer

Once that is done, post a fresh hijackthis log and a summary of any problems you are still having.
Did you have adaware installed before we began repairs or did you just download and install it? If you had it installed before, please check the ignore list and make sure nothing is in there (under "Usage Statistics" on the Status screen) as one of the malware programs you had can add items to the ignore list. If you find anything there, remove it and rescan. If there are no items in the ignore list then try fixing these with hijackthis again (no need for safe mode) O1 - Hosts: 69.20.16.183 auto.search.msn.com O1 - Hosts: 69.20.16.183 search.netscape.com O1 - Hosts: 69.20.16.183 ieautosearch It is possible that one of the files we killed may have been protecting them so they might go now.
Ok, lets take another look for VX2.
Download VX2 finder and Pocket Killbox. Don't worry about killbox yet, that may be for later use.

Run vx2finder(126).exe, click the "click to find vx2.betterinternet" button.
Give it a few seconds to work, click the pink "make log" button.
Copy/Paste the log here.
Log for VX2.BetterInternet File Finder (msg126) Files Found— Additional Files— Keys Under Notify— crypt32chain cryptnet cscdll ScCertProp Schedule sclgntfy SensLogn ShellCompatibility termsrv wlballoon Guardian Key— is called: User Agent String— {712564B5-8817-46A3-9E29-BA19CD2A41CB}
Opening IE and having the problem reoccur indicates that a hidden dll is probably attached to IE. Lets check an area of the registry that can be used to do that.

Download and install reglite
Run reglite and paste the following into the address bar:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
In the right pane, double click "AppInit_DLLs"
Look to see if a filename or path is listed in the value box at the bottom, if there is , paste it in a reply here.
If no path or file is listed, right click the windows key in the left pane (represented by a blue folder) and choose export. Save as type "Win API hive files" and name it windows.txt. Save it to your desktop.
Open windows.txt with notepad (it will look like a bunch of gibberish) and paste the contents as a reply here.

—-
It is getting late here, I am going to bed. I will check on this tomorrow when I get up
regf       Pugf hbin  ¨ÿÿÿnk, ÊC)+3®Ä ÿÿÿÿ ÿÿÿÿÿÿÿÿ ° x ÿÿÿÿ 0  áG‹á Windowsáÿÿÿsk x x  Ô  „¸ È   ¤       !  €  !  ?          ?               Øÿÿÿvk  €   fùAppInit_DLLs֍æG h Ðÿÿÿvk  È   ÀUDeviceNotSelectedTimeoutðÿÿÿ1 5  x ðÿÿÿ9 0  ë=tÀÐÿÿÿvk  €'   zGDIProcessHandleQuota"þàÿÿÿvk  8   °ºSpooler2ðÿÿÿy e s Ñ_å h ˜ è  ` àÿÿÿvk  €   5swapdiskÐÿÿÿvk  Ø   . TransmissionRetryTimeoutàÿÿÿh ˜ è  ` € Ð Ðÿÿÿvk  €'   SqUSERProcessHandleQuota

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI