RunTime error in Explorer and IExplorer

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by awake, Jul 22, 2005.

  1. awake

    awake Private E-2

    Hi there - hope you can help - I'm tearing whats left of my hair out here...

    Problem: When booted into XP(pro), launching Win Explorer gets me a C++ Runtime error box with "The application has requested the runtime to terminate it in an unusual way etc etc"
    Similar for iexplorer but simpler "Abnormal program termination" error box
    I havent experienced this type of runtime error with any other apps e.g. outlook, office etc.

    When I run in Safe mode (with Networking), I dont get the problem

    I've run through all the instructions in thread 35407 very carefully
    A few malware, spyware things removed but no error messages, or cant remove type messages... Although Ive noticed that each time i run spybot, It finds something called Haxdoor-H, says its removed (this is in safe mode or normal), but keeps coming back.

    Have run Hijack this ensuring msconfig normal (all) boot mode, and no (other than memory resident etc) progs running incl explorer as per t=38752. Ready to send to you if you require.

    Any help would be VERY MUCH appreciated!!!

    Many Thanks
     
  2. awake

    awake Private E-2

    Sorry ... forgot to add that this problem first occured last tues 19th July after, following a reboot, I noticed that Norton Systemworks (2004) password manager came up as disabled, with request for me to insert install disk etc... At this time the explorer.exe bug became evident. Systemworks generally seemed corrupted, wouldnt start etc , so I de-installed completely and successfully re-installed.

    Just to stress, this came out of the blue... i.e not following the installation of any new software or any other configuration changes....

    Thanks again for any advice
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How did you run the READ ME FIRST it iexplore always terminates? Or did you use a different browser?

    Make sure the below guidelines for installing and running HijackThis are followed and post your log as an attachment:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  4. awake

    awake Private E-2

    Thanks for the quick reply Chas,

    I'm still able to use explorer and iexplorer in the foreground as long as I leave the error windows open i.e as soon as i close them, they close explorer/iexplorer

    I've attached my log - hope it sheds some light?

    Thanks again for your help.... This problem has really got me... disappointing as earlier in the week I had great success in removing a load of stubborn malware from a friends PC but only by virtue of following 35407 - They were very impressed as was I !!!

    Regards...Awake
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You really need to evaluate where you are spending your time surfing. You are badly infested. This is going to take some time. And we will have to do this in stages. I'm trying to look at your log now.

    In the meantime, look in Add/Remove programs for any of the below and uninstall if found. Tell me if you find any of them:
    Windows
    kalvsys
    Internet Optimizer
    AutoLoaderAproposClient

    The below items have long been on a rogue tools list at: http://www.spywarewarrior.com/rogue_anti-spyware.htm They should be removed too.
    SPYWATCH
    POPUPWATCH
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Local Security Authority Service or lsass

    Then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Now repeat the above for the below two services:
    NTLOAD
    NTSVCMGR

    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Local Security Authority Service

    If that does not work, use the short name: lsass

    Now repeat the above steps with HJT to delete the below two services:
    NTLOAD
    NTSVCMGR

    You may be told to reboot at this point. Do not reboot just exit HijackThis when finished and post the results of doing this. Any problems? Then move on too the next message.


     
  7. awake

    awake Private E-2

    Thanks Chas... I hope that with all the spyware blockers etc and what Ive learnt from READ ME FIRST + installed things like spyware blaster etc that I wont get as badly infested again... I'd never heard of majorgeeks.com until last week... best site i've seen in ages for these sorts of problems... and have learnt lots from you guys so far..

    Have had a look at the list you suggested in add/remove. None of the 4 are in there..
    "Windows" variants as follows:
    Windows Installer 3.1 (KB893803)
    Windows media connect
    WinXP Serv Pack 2 (no surprises there!)
    Windows Mobile Zip

    Thanks for your efforts...Regards
    Awake
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you see my message before the one you just post?
     
  9. awake

    awake Private E-2

    Hi again Chas,
    replying now to your 2nd set of instructions.
    AOK - although when stopping LSASS in services.msc, I initially got the following erro:

    "Could not stop the LSASS on local computer

    Error 123: The filename, dir name or volume label syntax is incorrect"

    However, the status did change to stopped, was able to change to disabled + no probs with the other two services and AOK in HJT - Have not rebooted or anything as you suggested...

    Thanks
    Awake
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hopefully my previous message took care of the three bad services but I'm leaving them in the steps below just incase.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\system32\mui\721w\cache\srunner.exe
    C:\WINDOWS\system32\mui\721w\cache\srunner.exe

    After killing all the above processes, click "Back".

    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)

    You should consider changing user names and passwords. The below RFA.dll is PWSteal.Bankash.F It is a Trojan horse program that attempts to steal user names and passwords. Make sure you fix this.
    O2 - BHO: ReadFile Class - {811ABD55-9D94-4892-AB46-11D7DA29B8AE} - C:\WINDOWS\system32\RFA.dll

    O4 - HKLM\..\Run: [Windows AdStatus] C:\Program Files\Windows AdStatus\WinStat.exe
    O4 - HKLM\..\Run: [yncnqrov] C:\WINDOWS\yncnqrov.exe
    O4 - HKLM\..\Run: [u35X3sX] nvrci.exe
    O4 - HKLM\..\Run: [SvcH0st] C:\WINDOWS\msexploren.exe /i
    O4 - HKLM\..\Run: [salm] c:\temp\salm.exe
    O4 - HKLM\..\Run: [nvsvca32] C:\WINDOWS\nvsvca32.exe
    O4 - HKLM\..\Run: [kalvsys] C:\windows\system32\kalvewz32.exe
    O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
    O4 - HKLM\..\Run: [AutoLoaderAproposClient] "C:\temp\CXTPLS~1.EXE" /PC=CP.CDT3 /ShowLegalNote=nonbranded /ForSupportedBrowsers
    O4 - HKLM\..\Run: [ap9h4qmo] C:\WINDOWS\system32\ap9h4qmo.exe
    O4 - HKCU\..\Run: [SPYWATCH] C:\Program Files\Spyware Remover\SpyWatch.exe /STARTUP
    O4 - HKCU\..\Run: [POPUPWATCH] C:\Program Files\Spyware Remover\PupupWatch\PopUpWatch.exe /STARTUP
    O4 - HKCU\..\Run: [f0u7Rib8V] nvmelper.exe
    O4 - Startup: PowerReg Scheduler.exe
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O23 - Service: Local Security Authority Service (lsass) - Unknown owner - C:\WINDOWS\system32\mui\721w\cache\srunner.exe
    O23 - Service: NTLOAD - Unknown owner - c:\windows\system32\dllcache\win32\winlogon.exe
    O23 - Service: NTSVCMGR - Unknown owner - c:\windows\system32\dllcache\win32\winlogon.exe


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\Windows AdStatus <--- the whole folder
    C:\Program Files\Internet Optimizer <--- the whole folder
    C:\Program Files\Spyware Remover <--- the whole folder
    C:\temp <--- delete all files in this folder unless you know you saved something here you need but anything you need should not be in a temp folder.
    C:\WINDOWS\system32\mui\721w\cache\srunner.exe
    C:\WINDOWS\yncnqrov.exe
    C:\WINDOWS\msexploren.exe
    C:\WINDOWS\nvsvca32.exe
    C:\WINDOWS\system32\RFA.dll
    C:\windows\system32\nvrci.exe
    C:\windows\system32\kalvewz32.exe
    C:\WINDOWS\system32\ap9h4qmo.exe
    C:\WINDOWS\system32\nvmelper.exe


    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.


    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  11. awake

    awake Private E-2

    Chas - You are the Man !!! - Ran through the previous post (took a while, but I got there) and the problem seems to have gone away..

    Stopped all the processes listed using HJT, then rebooted into safe mode to do the deletes - although only the following existed:

    Folder C:\Prog files\spyware remover
    Folder C:\Prog files\Internet optimizer
    Folder C:\Temp
    C: Windows\system32\mui\721w\cache\srunner.exe

    Ive attached a new HJT log - would be grateful if you could have a final look and see if you think the infestation has gone

    But all in all the original problem has gone so I am delighted..

    Thank you so much for your time and the quick responses... You are a real star!!!

    Regards..Awake
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. One of the items we were trying to fix still remains.

    O23 - Service: Microsoft Printer Spooler Service (ssv) - Unknown owner - C:\WINDOWS\system32\mui\721w\cache\srunner.exe (file missing)

    First just try to simple fix this entry using HijackThis. If that does not work, use the steps from message # 6 again (using services.msc and HJT to delete the NT service).
     
  13. awake

    awake Private E-2

    Yep.. got it... fixed in HJT - then disabled in services.msc.... Rebooted... its gone

    Thanks again for all your help - Im very grateful

    Regards
    Awake
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  15. awake

    awake Private E-2

    Hello again,

    PC has been running fine since your help last Friday - thanks again..

    Did a spybot tonight (trying to get into a better habit of pro-actively checking now - have A2 installed and running + spyware blaster + spybot) and notice that Haxdoor-H is still lurking around (One reg entry)

    Do you know much about Haxdoor (I believe it disables AV software and funnily enough my problems last week all started after I booted up and found Norton AV corrupted..) and how to remove it properly?

    spybot log and HJT logs attached (HJT looks pretty clean to me - am i right?)

    Thanks for any advice
    Regards
    Awake
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  17. awake

    awake Private E-2

    Hi again Chas,
    no I dont have radmin installed - but happy to if it would help get to the bottom of this...
    PLease let me know...
    Thanks
    Awake
     
  18. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    awake,

    Chaslang is on vacation for a few days so I will be assisting you from here. Are you currently still having the problem with the error?
     
  19. awake

    awake Private E-2

    Hi there,
    Yes - problem still exists - although apart from existing in spybot log, I'm not experiencing any other obvious problems - wander if its something left over from before?

    Rgds... Awake
     
  20. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Let's start with a fresh HJT log from normal mode.
     
  21. awake

    awake Private E-2

    hi,
    Thanks for response... HJT log attached
     

    Attached Files:

  22. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your HJT log shows no problems, however I want to dig a little deeper to see if anything is hiding.

    Generate a StartupList log using HijackThis.
    Run HJT and on the first screen, click the button that says "Open the Misc Tools section". In the next window first select "List also minor sections (full)" and then click the button that says "Generate StartupList log". CLick Yes to the Do you want to continue prompt. Now a notepad window will come up with the Startuplist.txt file. It is already saved in the the directory HJT is running from. So just come back here and upload the file as an attachment to your next message.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm back!

    I still do not believe there are any problems. The last thing mentioned was a Haxdoor-H problem found using Spybot. The below registry was given:

    HKEY_LOCAL_MACHINE\System\RAdmin\v2.0\Server\Parameters\DisableTrayIcon!=B=0


    I think this is a valid registry key for RAdmin. The program must either be installed on the system or it previously had been installed. It is not malware. If we delete that registry key and you have this program installed, we will break the program. You must be sure that the program is not actually install and never has been installed on this PC by any user.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds