Help! No idea whats wrong

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Quinndrew5, Dec 1, 2004.

  1. Quinndrew5

    Quinndrew5 Corporal

    I have all these annoying popups and in my hijack this file there are a bunch of things listen under 01 and 10, but i cannot git rid of them. Ive tried Hijach this, ad-aware, CCleaner, CWShreder (removes the same two things over and over), and about buster. Can someone help me out
     
  2. Quinndrew5

    Quinndrew5 Corporal

    i just realized that whatever i have, causes the my documents window to pop up every few minutes.
     
  3. Quinndrew5

    Quinndrew5 Corporal

    Anybody have any idea, its really messing my computer up, the popups are getting unbareable and it keeps downloading more stuff all the time.
     
  4. lifeafterny

    lifeafterny Private E-2

    Hey,

    I am not a mod here, but i will guarantee once trhey see your post they will tell you to please follow their spyware and malware removal tutorial before posting anything.

    it's located at the top of the forum.
     
  5. lifeafterny

    lifeafterny Private E-2

  6. PhilliePhan

    PhilliePhan Guest

    And here is the cut & paste canned speech.....

    Quinndrew5 has been here enough to know this ;)

    Generally, it is a good idea to start with the Cleanup Tutorial HERE:
    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan and Virus Removal

    This will remove a lot of stuff that would otherwise clog a HJT log.

    Please note the steps that you are able to complete and the ones that give you problems. Note that you need to be in Safe Mode with System Restore OFF (if you have it - you didn't give OS) and have the Viewing of Hidden Files ENABLED as per the instructions in the link. Make sure to do the Online Scans.

    Post back and let us know how you fared. Also, send us a HijackThis Log. Make sure to follow the instructions below:

    Note that your HijackThis should be up-to-date (v1.98.2) and MUST be extracted to its own safe folder - C:\Program Files\HijackThis!

    If you need a Fresh Download of HJT, get it HERE: HijackThis 1.98.2

    Also note that, before you scan, you MUST close all running programs including your web browser, e-mail and items in the system tray.

    Please save your HJT Log as a .txt File and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    Somebody will take a look when they get a chance.

    Best luck :)
    PP
     
  7. Quinndrew5

    Quinndrew5 Corporal

    thanks for the help...... i ran the programs, but once i was in safe mode i wasnt able to access the internet but luckily i already had updates versions of most of the listed programs. So i did as much as i could, i have a hijack this log for when i was in safe mode and one for right now ( i dont no if they are different).... also when i ran CWShreder it said something about it coming from Windows media player, so i unistalled that as it said to do, and in my ccleaner i had been fixing isues that had to do with the windows media player. Permission to post log(s)?
     
  8. lifeafterny

    lifeafterny Private E-2

    again i am not in charge here...

    but chance are the people who are in charge will turn you in this direction before hijackthis log is posted:

    http://forums.majorgeeks.com/showthread.php?t=38752

    also, if you have xp and you go to run - msconfig - boot, you can choose safemode/and click network to have internet access.
     
  9. Quinndrew5

    Quinndrew5 Corporal

    o believe me, im well aware of the rules
     
  10. Quinndrew5

    Quinndrew5 Corporal

    not trying to be a pain, but im crammed for time, can i post my log?
     
  11. PhilliePhan

    PhilliePhan Guest

    Go ahead and post a fresh one from Normal Windows. We, too, are crammed for time, but somebody will take a look when they get a chance.

    Please make sure to follow the instructions below:

    Note that your HijackThis should be up-to-date (v1.98.2) and MUST be extracted to its own safe folder - C:\Program Files\HijackThis!

    If you need a Fresh Download of HJT, get it HERE: HijackThis 1.98.2

    Also note that, before you scan, you MUST close all running programs including your web browser, e-mail and items in the system tray.

    Please save your HJT Log as a .txt File and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    PP :)
     
  12. Quinndrew5

    Quinndrew5 Corporal

    ok here it is, let me no if its not a .txt or isnt right
     

    Attached Files:

  13. PhilliePhan

    PhilliePhan Guest

    Please put HijackThis into its own, safe Folder - C:\Program Files\HijackThis!

    ALSO: Please download this tool - http://www.cexx.org/lspfix.zip

    THEN:
    Please run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the calsp.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move calsp.dll into the Remove section.

    Do the same for aklsp.dll.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.

    Now, Reboot and then scan with HijackThis and attach that log and we’ll deal with the other malware items. I'll try to check back when I get a chance.

    PP
     
  14. Quinndrew5

    Quinndrew5 Corporal

    Ok, did all that and was successful, but i still have the 01 files. also, just out of curiousity, what does going into safe mode do to help fix things?
     
  15. Quinndrew5

    Quinndrew5 Corporal

    Forgot about my new hijack this!....
     

    Attached Files:

  16. Quinndrew5

    Quinndrew5 Corporal

    Im calling it quits for the night, ill be back probabley around 3 tomorrow to try to see what else i can do, if you can figure anything out let me no and ill work on it, thanks for you help so far!
     
  17. Quinndrew5

    Quinndrew5 Corporal

    Ok, im back for a while
     
  18. Quinndrew5

    Quinndrew5 Corporal

    Any body have any idea how to get rid of this stuff, my log is a few posts below and i have completed the apropriate steps.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You never ran the online scanners from the READ ME FIRST. I do not believe they will fix this problem but they are supposed to be run. They could have found other issues.

    Also, no browsers should be running anytime you use HijackThis. You had: C:\Program Files\Internet Explorer\iexplore.exe

    Make absolutely sure no browsers are running during these steps!! Print the below steps so you can follow along after disconnecting. So exit all of your browsers now and stay disconnected until I say to run one.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O1 - Hosts: 69.20.16.183 auto.search.msn.com
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O15 - Trusted Zone: http://*.frame.crazywinnings.com

    Now open a command prompt window by clicking Start, Run, and enter cmd in the box and click OK.
    Now enter the following command and then hit the enter key.
    attrib +r +h +s c:\windows\system32\drivers\etc\hosts

    Let me know if any error message occurs upon running this command.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  20. Quinndrew5

    Quinndrew5 Corporal

    thanks for the help, but when you say disconnect, do u mean from the interent because im a little confused, u later say something bout boot back into normal mode. so can u just clarify what disconection or safe mode steps to take and when to please
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry I left out a few works. This quoted text:

    Should be replaced by:

    Make absolutely sure no browsers are running during these steps!! And I am going to have you physically disconnect (unplug your cable) from the internet too. So print the below steps so you can follow along after disconnecting. So exit all of your browsers now and physically stay disconnected until I say to get a new HJT log.
     
  22. Quinndrew5

    Quinndrew5 Corporal

    I did as you said with no result, while in disconnected i seemed to have fixed the problem, but now that im back it came back and for hte thing with CMD, it just says that it cannot be found. i posted both logs (while disconnected and as of right now)
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are still forgetting to shut down you browser when using HJT.
    C:\Program Files\Internet Explorer\iexplore.exe

    It will interfere with proper operation of HJT when fixing and we do not want to see it running while scanning (unless specifically requested).

    The fix I gave you needs that command line "attrib" command to work. But I screwed up and forgot you had c:\winnt not c:\windows change the command to be

    attrib +r +h +s c:\winnt\system32\drivers\etc\hosts
    and try the whole fix all over again
     
  24. Quinndrew5

    Quinndrew5 Corporal

    when i ran hijack this! i only had word (which had the directions) and hijack this running, was there something else i should have done?
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    According to your HJT log: C:\Program Files\Internet Explorer\iexplore.exe was running. If you are 100% sure you closed down all Internet Explorer browsers (exit them not minimize them) then this could be part of your problem. That would mean some piece of malware is keeping a hidden IE session open. Check it again yourself and let me know what you find out.

    Did you run that procedure again with the proper c:\winnt command?
     
  26. Quinndrew5

    Quinndrew5 Corporal

    Yea im sure, i did the stuff in safe mode (and i cant even access the inernet while in safe mode anyways), also i will try to run it again like you said, and no i havent done the cmd with the new comand yet, i was waiting for you to respond about IE, but im gonna do it right now.
     
  27. Quinndrew5

    Quinndrew5 Corporal

    Ok, i did the cmd correctly and nothing happened, and i had the same thing happen for hijack this, while the internet was off, it seemed to go away, but now that i am back online, it came back. I have the two new logs attached again
     

    Attached Files:

  28. Quinndrew5

    Quinndrew5 Corporal

    Ok, now every hour or so a new virus downloads, like bulls eye network etc..... its easy to remove but its just annoying, i got all the crap out of my hijack this log (the new stuff, not the stuff we have been working on) except i cant get this one thing out

    O4 - HKLM\..\Run: [kalvsys] C:\winnt\system32\kalvbfi32.exe
     

    Attached Files:

  29. Quinndrew5

    Quinndrew5 Corporal

    Popups just keep coming, now it is at the point where whenever i type in a new url, another browser opens to a website (different everytime)
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download CWShredder 2.0 from: http://www.majorgeeks.com/download3019.html
    Install CWShredder 2.0. Do not run it yet.

    Download Giant Antispyware from: http://www.giantcompany.com/p_antispyware.aspx
    Click the link for the free trial. Install this and run it.


    Download Pocket Killbox from here: http://www.downloads.subratam.org/KillBox.zip

    Unzip the files to the folder of your choice.

    Double-click on Killbox.exe to run it. In the "Paste Full Path of File to Delete" box, copy and paste the following:

    C:\WINDOWS\httpfilter.dll

    Now put a tick by Delete on reboot. Also put a check in the box by Unregister .dll before deleting.

    Click on the button with the red circle with the X. It will ask for confimation. Click Yes and then No when it asks if you want to reboot now.

    After you come back up from reboot do not run anything except what I give you below.
    Run CWShredder 2.0 and make sure you select FIX.

    Next run Hijack This again and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now and do not open any browsers until I say to do so:
    O1 - Hosts: 69.20.16.183 auto.search.msn.com
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O1 - Hosts: 69.20.16.183 ieautosearch
    O4 - HKLM\..\Run: [kalvsys] C:\winnt\system32\kalvbfi32.exe
    O15 - Trusted Zone: http://*.frame.crazywinnings.com
    O18 - Filter: text/html - {EE7A946E-61FA-4979-87B8-A6C462E6FA62} - C:\WINNT\httpfilter.dll

    Now restart your computer safe mode. Run HijackThis again and recheck to see if the above lines are still fixed. If not, fix them again. While in safe mode, use Windows Explorer to delete:
    C:\winnt\system32\kalvbfi32.exe
    C:\WINNT\httpfilter.dll <--- hopefully this one is already gone
    C:\WINNT\httpfilter2.dll <--- look for this one two and delete if found.

    Reboot normal mode. Again Run HijackThis again and recheck to see if the above lines are still fixed. If not, fix them again. Now finally open your browser and then exit your browser. Check another HijackThis log now with no browsers open and save the log. Now come back here and post this final log.
     
    Last edited: Dec 4, 2004
  31. Quinndrew5

    Quinndrew5 Corporal

    Wow, ill make sure i do that right away, but first, should i be connected to the interent while im doing all this?
     
  32. Quinndrew5

    Quinndrew5 Corporal

    Did everything as you said, but it still came back, posted my log
     

    Attached Files:

  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Damn! There are a couple new process running now:

    C:\WINNT\System32\paypay.exe <--- this looks bad
    C:\WINNT\System32\drwtsn32.exe <--- did you run Dr Watson for some reason
     
  34. Quinndrew5

    Quinndrew5 Corporal

    Never even heard of dr. watson
     
  35. Quinndrew5

    Quinndrew5 Corporal

    updated log, those two things you spoke of are gone.
     

    Attached Files:

  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! Only Dr. Watson is gone. paypay.exe is still there and now you have other problems too. Like NaviSearch and BullsEye Network. Where have you been surfing?

    You should run a full scan with Giant Antispyware. It sometimes fixes those two items.

    I would like you to goto SysInternals and download three programs. ProcessExplorer, Regmon (Registry Monitor), and Filmon (File Monitor). Just download them and unzip all of them into a directory like c:\sysinternals. They do not require any installation. You just double click on them to run them. I provide two links below for each program. One for the program itself and one that will give you a little insight into what the program is used for.

    http://www.sysinternals.com/files/procexpnt.zip ----http://www.sysinternals.com/ntw2k/freeware/procexp.shtml
    http://www.sysinternals.com/files/ntregmon.zip ----http://www.sysinternals.com/ntw2k/source/regmon.shtml
    http://www.sysinternals.com/files/NTFILMON.ZIP ----http://www.sysinternals.com/ntw2k/source/filemon.shtml

    I'm hoping that if we have all three of these running when fixing those O1 - Hosts lines using HijackThis that we can catch the process that runs, or
    modifies the registry, or modifies the hosts file itself. Then we can locate the file/process and try to remove it.
    So run those three items. And do the following to configure a few things how we want. Note: Get HijackThis running and all three of these program
    running and configured as indicated below before clicking fix with HijackThis.
    1) run ProcessExplorer -
    Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked. Now click on explorer.exe. Now also under
    the View menu choose "Select columns" and put a check mark on "Image Path".
    Use it to observe what processes are running and just before we have HJT fix the O1 entries and just after they are fixed. If you see the file that
    runs, write down the full file name and path to file and post it back here.
    2) run filemon -
    When it comes up, change the *.* in the Include box to say hosts. Then click Apply and OK. The Filemon window now comes up and will monitor for
    anything accessing hosts. After you use HJT to fix the O1 lines, also come back to the Filemon screen and click File and then uncheck the Capture
    Events selection to stop the capture process. Then use File, Save As to save the log to a file like filemon.log and post it back here as an
    attachment.

    3) run regmon -
    When it comes up, click the icon that sort of looks like a diamond with some blue color on top. This is the Regmon filter. In this filter, enter the
    following hosts; 69.20.16.183 ;httpfilter.dll Then click Apply and then OK. It will ask if you want to apply the filter to the current output.
    Say yes. After you use HJT to fix the O1 lines, also come back to the Regmon screen and click File and then uncheck the Capture Events selection to
    stop the capture process. Then use File, Save As to save the log to a file like regmon.log and post it back here as an attachment.

    Okay so after getting that all setup. Run HJT and select the below items and then click fix:
    O1 - Hosts: 69.20.16.183 auto.search.msn.com
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O15 - Trusted Zone: http://*.frame.crazywinnings.com
    O18 - Filter: text/html - {EE7A946E-61FA-4979-87B8-A6C462E6FA62} - C:\WINNT\httpfilter.dll
    Then save all the logs from the SysInternal programs (and the path of anything that you see run in ProcessExplorer) and post them back here.
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may have problems trying to run those three programs. Seems that this malware causes a problem that indicates you do not have debug level permissions.

    Do the following using Windows search and please configure Windows search as follows:
    If you use Search, you need to do the following:
    Click Search and the Select "All files and folders"
    Enter the filename in the "All or part of the file name:" box
    Now select "More advanced options"
    Make sure the following check boxes are checked:
    - Search system folders
    - Search hidden files and folders
    - Search subfolders
    Then click the Search button.


    Then do a search for these files:
    kalvsuy32.exe
    iosyko.exe
    iwrop.dll
    sywin16.dll

    Let me know if they are found and where. I would assume c:\windows\system32
     
  39. Quinndrew5

    Quinndrew5 Corporal

    I am in the middle of running those three programs you listed, i am having a few problems. first off, on the first one, you say to click on explorer.exe, i did so and im not really sure what exackly you want me to look for before and after running hijack this. Also, the second program will not open and you suggested the follwing searches in your next post. Im not sure if u realize im running Windows 2000, becuase i do not have those three things in my advanced options for searching. Also when you say search within "all files and folders" do u mean to scan through to look for those files? (providing the advanced options will not make a difference, i was not able to find any of those files that could be causing the second program to not open) Thanks for the help
     
  40. Quinndrew5

    Quinndrew5 Corporal

    my bad, i miss read your search procedure, but im still kinda confused, i think it might have something to do with windows 2000 vs. XP, because the options you speak of i dont have.
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it's my fault! I forgot you had Win2K. All you needed to do was just run the search. Win2k does not need to configure the search to include all files.
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you able to run ProcessExplorer and Filemon?

    But Regmon would not run? Right? What error message did you get?
     
  43. Quinndrew5

    Quinndrew5 Corporal

    sry for the constant questions, but i was just trying to get a feel for the two programs i could run while i was waiting for a reply from you and originally in the third one there was a a bunch of things listed in the botom portion. Now there is nothing, and when i enter the thing u said to do, it stays blank. I have redownloaded it twice now and nothing changes. Not that that will do me any good since i am becoming quite inept at figuring these things out lol.
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Filemon and Regmon will be blank after setting up the filters I gave you. They will only show info that matches what we are filtering on. Since we were looking for access to the hosts file (and the IP address too), I put them in the filter list. If you simple accessed your hosts file yourself, you would see it popup in Filemon.

    So you are able to run all 3 programs then, is that true?
    Other people having this O1 - Hosts issue cannot.
     
  45. Quinndrew5

    Quinndrew5 Corporal

    nope, couldnt run the second one, and i dont no if you saw or not but i had trouble doing the searches.
     
  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I guess you missed messages # 41 & 42
     
  47. Quinndrew5

    Quinndrew5 Corporal

    yea, u most have posted them right as i was posting 43 sry, didnt even notice them
     
  48. Quinndrew5

    Quinndrew5 Corporal

    the error for filmon was that access was denied and that the program might already be running (which it isnt)
     
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did it say anything with the word debug in it?

    Can you please post the exact message word for word?
     
  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please try renaming the filemon.exe program to: myfmon.com
    And then try to run myfmon.com. Let me know what happens.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds