This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Popups - Can't get rid of whatever the source is

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey, if you've got other ideas, I'm game. But I'll try it tomorrow night - I've got a splitting headache right now. (I wonder why! :blink: ) Beverly
OK, here's the FindIt log. The C:\Windows\System dll's listed in the log are the NicTech dll's I've been referring to. File properties on every one of them shows NicTech Networks in the digital signature list. The number of these files continues to grow over the days. Of them, only MZC70 has entries in the registry. It has an InprocServer32 entry at the following keys: HKEY_CLASSES_ROOT\CLSID\{48DF3BF0-30FB-4E7A-A412-14F51EFEC879} HKEY_LOCAL_MACHINE\Software\CLASSES\CLSID\{48DF3BF0-30FB-4E7A-A412-14F51EFEC879} When I boot in safe mode to a command prompt, I cannot see the files in the directory. I was also working this past weekend to get rid of these dll's. I had a different batch of them. I only found entries in the registry for one of them, and I deleted the registry entries in safe mode. Then I attempted to delete all of the dll's and was able to do so for all but one. I couldn't delete it - said it was being used by Windows. The next time I booted the machine, those registry entries I deleted for the file were back. And the next day, I noticed the files had morphed into a new set, this one, with a new date/time stamp. I was able to delete the dll's from the first set. But now MZC70 appears to be the ringleader in that it has the registry entries and I can't delete the file (tried last night). I keep seeing new copies of these dll's appearing in C:\Windows\System each day. Warning! This utility will find legitimate files in addition to malware. Do not remove anything unless you are sure you know what you're doing. ——- System Files in System Directory ——- Volume in drive C has no label Volume Serial Number is 07CF-070E Directory of C:\WINDOWS\SYSTEM MKPWL32 DLL 226,592 06-18-05 8:25p MKPWL32.DLL DRLAY DLL 226,592 06-18-05 8:25p DRLAY.DLL CVFG95 DLL 226,592 06-18-05 8:25p CVFG95.DLL NPDLL DLL 226,592 06-18-05 8:25p NPDLL.DLL MXPWL32 DLL 226,592 06-18-05 8:25p MXPWL32.DLL SCACE DLL 226,592 06-18-05 8:25p Scace.dll MZC70 DLL 226,592 06-18-05 8:25p mzc70.dll MHXMLA DLL 226,592 06-18-05 8:25p MHXMLA.DLL PIPD32 DLL 226,592 06-18-05 8:25p PIPD32.DLL QJV DLL 226,592 06-18-05 8:25p QJV.DLL MJCONF DLL 226,592 06-18-05 8:25p MJCONF.DLL CTMCAT DLL 226,592 06-18-05 8:25p CTMCAT.DLL RUBOEX32 DLL 226,592 06-18-05 8:25p RUBOEX32.DLL IHCVID DLL 226,592 06-18-05 8:25p IHCVID.DLL 14 file(s) 3,172,288 bytes 0 dir(s) 1,120.73 MB free ——- Hidden Files in System Directory ——- Volume in drive C has no label Volume Serial Number is 07CF-070E Directory of C:\WINDOWS\SYSTEM HPF71T13 GID 16,826 11-11-00 9:32p HPF71t13.GID HPF71H13 GID 8,628 10-17-00 10:36p HPF71h13.GID FOLDER HTT 13,122 07-14-99 1:51a folder.htt DESKTOP INI 266 07-14-99 1:51a desktop.ini 4 file(s) 38,842 bytes 0 dir(s) 1,120.72 MB free —————- User Agent ———— REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] "{AE9CE44A-8023-E39A-C590-81600D23D52A}"="" —————— Locate.com Results —————— C:\WINDOWS\SYSTEM\ mkpwl32.dll Sat Jun 18 2005 8:25:22p ..S.R 226,592 221.28 K drlay.dll Sat Jun 18 2005 8:25:22p ..S.R 226,592 221.28 K cvfg95.dll Sat Jun 18 2005 8:25:22p ..S.R 226,592 221.28 K npdll.dll Sat Jun 18 2005 8:25:22p ..S.R 226,592 221.28 K mxpwl32.dll Sat Jun 18 2005 8:25:22p ..S.R 226,592 221.28 K scace.dll Sat Jun 18 2005 8:25:22p ..S.R 226,592 221.28 K mzc70.dll Sat Jun 18 2005 8:25:22p ..S.R 226,592 221.28 K mhxmla.dll Sat Jun 18 2005 8:25:22p ..S.R 226,592 221.28 K pipd32.dll Sat Jun 18 2005 8:25:22p ..S.R 226,592 221.28 K qjv.dll Sat Jun 18 2005 8:25:22p ..S.R 226,592 221.28 K mjconf.dll Sat Jun 18 2005 8:25:22p ..S.R 226,592 221.28 K ctmcat.dll Sat Jun 18 2005 8:25:22p ..S.R 226,592 221.28 K ruboex32.dll Sat Jun 18 2005 8:25:22p ..S.R 226,592 221.28 K ihcvid.dll Sat Jun 18 2005 8:25:22p ..S.R 226,592 221.28 K 14 items found: 14 files, 0 directories. Total of file sizes: 3,172,288 bytes 3.02 M ———— Strings.exe Qoologic Results ———— C:\WINDOWS\VPTNFILE.693: TROJ_QOOLOGIC.G C:\WINDOWS\VPTNFILE.693: TROJ_QOOLOGIC.C C:\WINDOWS\VPTNFILE.693: TROJ_QOOLOGIC.B C:\WINDOWS\VPTNFILE.693: TROJ_QOOLOGIC.A C:\WINDOWS\LPT$VPN.693: TROJ_QOOLOGIC.G C:\WINDOWS\LPT$VPN.693: TROJ_QOOLOGIC.C C:\WINDOWS\LPT$VPN.693: TROJ_QOOLOGIC.B C:\WINDOWS\LPT$VPN.693: TROJ_QOOLOGIC.A C:\WINDOWS\hosts.bev.txt: 127.0.0.1 www.qoologic.com C:\WINDOWS\hosts: 127.0.0.1 www.qoologic.com ————– Strings.exe Aspack Results ————- C:\WINDOWS\vsapi32.dll: ASPACK EXE C:\WINDOWS\vsapi32.dll: ASPACK2 EXE C:\WINDOWS\vsapi32.dll: ASPack 1.08.04 C:\WINDOWS\vsapi32.dll: ASPack 1.08.03 C:\WINDOWS\vsapi32.dll: ASPack 1.08.02b C:\WINDOWS\vsapi32.dll: ASPack 1.08.01 C:\WINDOWS\vsapi32.dll: ASPack 1.08 C:\WINDOWS\vsapi32.dll: ASPack 1.07b C:\WINDOWS\vsapi32.dll: ASPack 1.61 C:\WINDOWS\vsapi32.dll: ASPack 1.05b C:\WINDOWS\vsapi32.dll: ASPack 1.03 C:\WINDOWS\vsapi32.dll: ASPack 1.02 C:\WINDOWS\vsapi32.dll: ASPack 1.01 C:\WINDOWS\vsapi32.dll: ASPack 1.00 —————– HKLM Run Key —————— ————– Strings.exe Umonitor Results ————- REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ScanRegistry"="c:\\windows\\scanregw.exe /autorun" "TaskMonitor"="c:\\windows\\taskmon.exe" "SystemTray"="SysTray.Exe" "LoadPowerProfile"="Rundll32.exe powrprof.dll,LoadCurrentPwrScheme" "ccApp"="\"c:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\"" "Symantec Core LC"="C:\\Program Files\\Common Files\\Symantec Shared\\CCPD-LC\\symlcsvc.exe start" "IS CfgWiz"="c:\\Program Files\\Common Files\\Symantec Shared\\cfgwiz.exe /GUID NIS /CMDLINE \"REBOOT\"" "URLLSTCK.exe"="c:\\Program Files\\Norton Internet Security\\UrlLstCk.exe" "AVG7_CC"="C:\\PROGRA~1\\GRISOFT\\AVGFRE~1\\AVGCC.EXE /STARTUP" "AVG7_EMC"="C:\\PROGRA~1\\GRISOFT\\AVGFRE~1\\AVGEMC.EXE" "AVG7_AMSVR"="C:\\PROGRA~1\\GRISOFT\\AVGFRE~1\\AVGAMSVR.EXE"  Beverly
Download Pocket Killbox version 2.0.0.175
http://www.atribune.org/downloads/KillBox.exe
If you already have Killbox first ensure it is this version !.

Start Killbox, Use standard file kill.(default settings).
Copy this whole list into the windows clipboard, all the Bolded below.


C:\WINDOWS\SYSTEM\mkpwl32.dll
C:\WINDOWS\SYSTEM\drlay.dll
C:\WINDOWS\SYSTEM\cvfg95.dll
C:\WINDOWS\SYSTEM\npdll.dll
C:\WINDOWS\SYSTEM\mxpwl32.dll
C:\WINDOWS\SYSTEM\scace.dll
C:\WINDOWS\SYSTEM\mzc70.dll
C:\WINDOWS\SYSTEM\mhxmla.dll
C:\WINDOWS\SYSTEM\pipd32.dll
C:\WINDOWS\SYSTEM\qjv.dll
C:\WINDOWS\SYSTEM\mjconf.dll
C:\WINDOWS\SYSTEM\ctmcat.dll
C:\WINDOWS\SYSTEM\ruboex32.dll
C:\WINDOWS\SYSTEM\ihcvid.dll


Back in Killbox go > file > paste from clipboard, now click the red X
that looks like a stop sign, wait until a success message appears.
Repeat those same step's until each file has been deleted.


Note: if a file cannot be deleted [x] check delete on reboot, then go back to
standard file kill for the next file in the list.

When finished exit Killbox and restart your PC.
Run another:Find.bat. It will run for a minute, then produce a log. Copy and paste the log here.
I think that got it LD. Here's a new FindIt log. I am not seeing the popups now. :D Thank you so much for your help and for your perseverance in sticking with me through this! Warning! This utility will find legitimate files in addition to malware. Do not remove anything unless you are sure you know what you're doing. ——- System Files in System Directory ——- Volume in drive C has no label Volume Serial Number is 07CF-070E Directory of C:\WINDOWS\SYSTEM 1,132.93 MB free ——- Hidden Files in System Directory ——- Volume in drive C has no label Volume Serial Number is 07CF-070E Directory of C:\WINDOWS\SYSTEM HPF71T13 GID 16,826 11-11-00 9:32p HPF71t13.GID HPF71H13 GID 8,628 10-17-00 10:36p HPF71h13.GID FOLDER HTT 13,122 07-14-99 1:51a folder.htt DESKTOP INI 266 07-14-99 1:51a desktop.ini 4 file(s) 38,842 bytes 0 dir(s) 1,132.92 MB free —————- User Agent ———— REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] "{AE9CE44A-8023-E39A-C590-81600D23D52A}"="" —————— Locate.com Results —————— No matches found. ———— Strings.exe Qoologic Results ———— C:\WINDOWS\VPTNFILE.693: TROJ_QOOLOGIC.G C:\WINDOWS\VPTNFILE.693: TROJ_QOOLOGIC.C C:\WINDOWS\VPTNFILE.693: TROJ_QOOLOGIC.B C:\WINDOWS\VPTNFILE.693: TROJ_QOOLOGIC.A C:\WINDOWS\LPT$VPN.693: TROJ_QOOLOGIC.G C:\WINDOWS\LPT$VPN.693: TROJ_QOOLOGIC.C C:\WINDOWS\LPT$VPN.693: TROJ_QOOLOGIC.B C:\WINDOWS\LPT$VPN.693: TROJ_QOOLOGIC.A C:\WINDOWS\hosts.bev.txt: 127.0.0.1 www.qoologic.com C:\WINDOWS\hosts: 127.0.0.1 www.qoologic.com ————– Strings.exe Aspack Results ————- C:\WINDOWS\vsapi32.dll: ASPACK EXE C:\WINDOWS\vsapi32.dll: ASPACK2 EXE C:\WINDOWS\vsapi32.dll: ASPack 1.08.04 C:\WINDOWS\vsapi32.dll: ASPack 1.08.03 C:\WINDOWS\vsapi32.dll: ASPack 1.08.02b C:\WINDOWS\vsapi32.dll: ASPack 1.08.01 C:\WINDOWS\vsapi32.dll: ASPack 1.08 C:\WINDOWS\vsapi32.dll: ASPack 1.07b C:\WINDOWS\vsapi32.dll: ASPack 1.61 C:\WINDOWS\vsapi32.dll: ASPack 1.05b C:\WINDOWS\vsapi32.dll: ASPack 1.03 C:\WINDOWS\vsapi32.dll: ASPack 1.02 C:\WINDOWS\vsapi32.dll: ASPack 1.01 C:\WINDOWS\vsapi32.dll: ASPack 1.00 —————– HKLM Run Key —————— ————– Strings.exe Umonitor Results ————- REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ScanRegistry"="c:\\windows\\scanregw.exe /autorun" "TaskMonitor"="c:\\windows\\taskmon.exe" "SystemTray"="SysTray.Exe" "LoadPowerProfile"="Rundll32.exe powrprof.dll,LoadCurrentPwrScheme" "ccApp"="\"c:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\"" "Symantec Core LC"="C:\\Program Files\\Common Files\\Symantec Shared\\CCPD-LC\\symlcsvc.exe start" "IS CfgWiz"="c:\\Program Files\\Common Files\\Symantec Shared\\cfgwiz.exe /GUID NIS /CMDLINE \"REBOOT\"" "URLLSTCK.exe"="c:\\Program Files\\Norton Internet Security\\UrlLstCk.exe" "AVG7_CC"="C:\\PROGRA~1\\GRISOFT\\AVGFRE~1\\AVGCC.EXE /STARTUP" "AVG7_EMC"="C:\\PROGRA~1\\GRISOFT\\AVGFRE~1\\AVGEMC.EXE" "AVG7_AMSVR"="C:\\PROGRA~1\\GRISOFT\\AVGFRE~1\\AVGAMSVR.EXE" Beverly
Here 'tis.

Logfile of HijackThis v1.99.1
Scan saved at 2:22:25 PM, on 6/26/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\HJT\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.earthlink.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by America Online
N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.yahoo.com"); (C:\Program Files\Netscape\Users\edjulia2\prefs.js)
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [IS CfgWiz] c:\Program Files\Common Files\Symantec Shared\cfgwiz.exe /GUID NIS /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\RunServices: [MSNIA] C:\PROGRA~1\MSN\MSNIA\MSNIASVC.EXE
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ccEvtMgr] "c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [SndSrvc] C:\PROGRA~1\COMMON~1\SYMANT~1\SNDSRVC.EXE
O4 - HKLM\..\RunServices: [ccProxy] c:\PROGRA~1\COMMON~1\SYMANT~1\CCPROXY.EXE
O9 - Extra button: RealGuide - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab


Beverly
Great Job :thumbup:

Log looks good :D


Do the following:
In Windows, on the Windows desktop, double-click the My Computer icon.

On the Tools menu, click Folder Options.
On the View tab, check Hide file extensions for known file types.

Check Hide protected operating system files. Then, under the "Hidden files" folder, uncheck Show hidden files and folders.
If you see a warning message, click Yes.
Click Apply.
Click OK.




If you dont have these three programs I would recommend that you get them. Spywareblaster, Spywareguard and IESPY AD. They will add 1000's of sites to your resticted zone and block some hijacks from happening. I also have a FREE FIREWALL and FREE ANTI VIRUS if you need one.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Safe Surfing. :D
Will do, and thanks for the further suggestions LD. My next task will be getting Norton re-installed, back up to date, and running properly. I'll look into your recommendations, as well as giving my dad a lesson on updating and running AdAware and SpyBot himself (along with instructions NOT to call his ISP's tech support again, since they told him to disable Norton in the first place). Beverly
Great job :thumbup:

You're more then welcome.
Glad we were able to help

Peace be with you :wavey:





If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI