clipartfree.exe virus removal and other problems

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by imlostinbetween, Apr 2, 2006.

  1. imlostinbetween

    imlostinbetween Private E-2

    Hey, I am having a few problems which are causing my PC to have a slow startup, run very slowly, and have frequent crashes. I have already completed all of the steps (in the introductory thread), except CCleaner which was unable to start because of run time error "0". My anti-virus program found no problems with a full system scan, and Adaware and spybot found no problems as well. My computer is a Dell Dimension 3000, Intel Pentium 4, 2.80 GHz, 512 RAM, Win XP v. 5.1.2600.

    First, I think I might have a virus, clipartfree.exe, detected by bitdefender. This virus sent an e-mail to individuals in my address book. I removed a virus which made a roach go across my screen and after that I had a security warning message on startup to install ntsyv.exe in C:/windows/system32 by an unknown publisher. Also, when I restart my computer the programs SMax4PNP.exe and hpoenm07.exe are "unable to end" and I have to click close to restart or shut down.

    For some reason, I can't open links in IE (which is another problem, I guess.) Therefore, I cannot attach the hijackthis log and the Bitdefender log via Manage Attachments; however, I can paste the log into the text area. So, I will paste the logs at the end of my message because they may be helpful.

    Thanks for any help you can give me!
    Heather

    Edit by chaslang: Inline HJT and BD logs attached
     

    Attached Files:

    Last edited by a moderator: Apr 2, 2006
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    While I look at and attach your logs for you, please go back and follow the directions in step 7. You did not install HijackThis as requested. In fact, you are running it exactly how we request it not to be run (that is, directly from the ZIP file).

    Where is the PandaActive scan log?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also note, you skipped step 3 of the READ ME! I see both AVG and eTrust EZ Antivirus. Pick the one you prefer and uninstall the other.

    Your Sun Java version is way out of date and must be updated. Then you should uninstall the old versions. We will do this later.

    Let's get an installed programs list from HijackThis too!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
     
  4. imlostinbetween

    imlostinbetween Private E-2

    Okay, I did everything that you told me that I was able to do. I cannot do the Panda scan because I cannot open links. Sorry about that. I corrected HJT as you requested and got the list of programs. As before, I can't attach because of my problem with links. I checked the settings in IE so I don't understand why I can't open links (on the bottom of the IE window it says "Error on page.") So, I will add the list in the bottom of my message.

    Thanks for all of your time so far.

    Ad-Aware SE Personal
    Adobe Reader 7.0.7
    AOL Uninstaller (Choose which Products to Remove)
    AVG Free Edition
    Banctec Service Agreement
    Cayman 3300 Series USB Network Adapter
    CCleaner (remove only)
    Dell Driver Reset Tool
    Dell Media Experience
    Dell Picture Studio v3.0
    Dell Support 5.0.0 (630)
    GTK+ 2.8.9 runtime environment
    HijackThis 1.99.1
    hp psc 700 series
    IncrediMail Xe
    Intel(R) 537EP V9x DF PCI Modem
    Intel(R) Extreme Graphics 2 Driver
    Intel(R) PRO Network Adapters and Drivers
    Intel(R) PROSet for Wired Connections
    Internet Explorer Default Page
    iPod for Windows 2005-03-23
    iTunes
    Jasc Paint Shop Photo Album 5
    Jasc Paint Shop Pro Studio, Dell Editon
    Java 2 Runtime Environment, SE v1.4.2_03
    Learn2 Player (Uninstall Only)
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB886903)
    Microsoft Plus! Digital Media Edition Installer
    Microsoft Plus! Photo Story 2 LE
    Modem Event Monitor
    Modem Helper
    Modem On Hold
    MSN
    Musicmatch for Windows Media Player
    Musicmatch® Jukebox
    QuickTime
    RealPlayer Basic
    RelevantKnowledge
    Security Update for Step By Step Interactive Training (KB898458)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player 10 (KB911565)
    Security Update for Windows XP (KB883939)
    Security Update for Windows XP (KB890046)
    Security Update for Windows XP (KB893756)
    Security Update for Windows XP (KB896358)
    Security Update for Windows XP (KB896422)
    Security Update for Windows XP (KB896423)
    Security Update for Windows XP (KB896424)
    Security Update for Windows XP (KB896428)
    Security Update for Windows XP (KB896688)
    Security Update for Windows XP (KB899587)
    Security Update for Windows XP (KB899588)
    Security Update for Windows XP (KB899591)
    Security Update for Windows XP (KB900725)
    Security Update for Windows XP (KB901017)
    Security Update for Windows XP (KB901214)
    Security Update for Windows XP (KB902400)
    Security Update for Windows XP (KB903235)
    Security Update for Windows XP (KB904706)
    Security Update for Windows XP (KB905414)
    Security Update for Windows XP (KB905749)
    Security Update for Windows XP (KB905915)
    Security Update for Windows XP (KB908519)
    Security Update for Windows XP (KB911927)
    Security Update for Windows XP (KB912919)
    Security Update for Windows XP (KB913446)
    Sonic DLA
    Sonic RecordNow!
    Sonic Update Manager
    SoundMAX
    Spybot - Search & Destroy 1.4
    SpywareBlaster v3.4
    The GIMP 2.2.10
    The Interview With God Screen Saver
    Update for Windows XP (KB894391)
    Update for Windows XP (KB896727)
    Update for Windows XP (KB898461)
    Update for Windows XP (KB910437)
    Viewpoint Media Player
    Windows Installer 3.1 (KB893803)
    Windows Installer 3.1 (KB893803)
    Windows Media Format Runtime
    Windows Media Player 10
    Windows Media Player 10
    Windows XP Hotfix - KB834707
    Windows XP Hotfix - KB867282
    Windows XP Hotfix - KB873333
    Windows XP Hotfix - KB873339
    Windows XP Hotfix - KB885250
    Windows XP Hotfix - KB885835
    Windows XP Hotfix - KB885836
    Windows XP Hotfix - KB886185
    Windows XP Hotfix - KB887472
    Windows XP Hotfix - KB887742
    Windows XP Hotfix - KB888113
    Windows XP Hotfix - KB888302
    Windows XP Hotfix - KB890047
    Windows XP Hotfix - KB890175
    Windows XP Hotfix - KB890859
    Windows XP Hotfix - KB890923
    Windows XP Hotfix - KB891781
    Windows XP Hotfix - KB893066
    Windows XP Hotfix - KB893086
    WordPerfect Office 12
     
  5. imlostinbetween

    imlostinbetween Private E-2

    I attached the list with my laptop. Thanks.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Look in Add/Remove Programs for the below and uninstall if found.
    PartyPoker
    RelevantKnowledge
    Viewpoint Media Player

    Also a Note! The below programs are out of date. You need to get the current versions installed:
    Java 2 Runtime Environment, SE v1.4.2_03
    SpywareBlaster v3.4


    Download LSP - Fix

    Run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the rlls.dll file (in the “Keep” section) to select it.



    Then, Select the >> button to move rlls.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.
    If it is already in the Remove section, just click Finish.


    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    c:\windows\system32\rlvknlg.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [ntsyv[1]] C:\WINDOWS\system32\ntsyv[1].exe
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
    O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
    O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll <--- these should be gone already after running LSP-fix
    O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\PartyPoker
    c:\windows\system32\rlvknlg.exe
    c:\windows\system32\rlls.dll
    C:\WINDOWS\system32\ntsyv[1].exe
    C:\Documents and Settings\Deb\My Documents\clipartfree.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  7. imlostinbetween

    imlostinbetween Private E-2

    A quick question, is Party Poker malware? My dad uses it ... so I don't want to delete it. Thanks.
     
  8. imlostinbetween

    imlostinbetween Private E-2

    Another problem, in LSP, there is no " rlls.dll " - but there is mswsock.dll (description says Tcpip), winrnr.dll (description says NTDS), and rsvpsp.dll (description says Protocol handler). I fixed the updated to Java but i'm not sure if I should go to the next step yet.

    Thanks
    Heather
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It went away when you uninstalled Relevant Knowledge. Just skip LSP fix and continue. Uninstalling Party Poker is your choice. It is not necessarily malware but many of these online poker/casino sites do contain stuff that is not really trust worthy. Many people use them! We just don't recommend them ourselves in malware forums (much like P2P applications are frowned on).
     
  10. imlostinbetween

    imlostinbetween Private E-2

    Thanks for your help! All of my issues are gone, I think. The only problem I see is that ntsyv[1] is still in the Startup (from the System Configuration Utility). I am not sure if this is a bad thing or not, just wanted to check. I am going to add the log to the end of my message (can't open manage attachments).

    Thanks
    Heather

    Edit by chaslang: Inline log attached
     

    Attached Files:

    Last edited by a moderator: Apr 5, 2006
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes we need to get that O4 line fixed and make sure the file is deleted!


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [ntsyv[1]] C:\WINDOWS\system32\ntsyv[1].exe
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\system32\ntsyv[1].exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .


    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.
     
  12. imlostinbetween

    imlostinbetween Private E-2

    Okay, thanks again for your help. I was unable to find ntsyv[1] in System 32 or C:. I fixed HJT but it is still in the startup.

    Thanks
    Heather
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have something hiding that is restarting this malware. Let's get you better protected with a firewall before we go any further. Please refer to step three in the below link and install ZoneAlarmFree firewall (we will come back to the rest of the steps in this link later).

    How to Protect yourself from malware!

    After installing the firewall, it should tell you to reboot, so please do so. Then continue to the below. We are going to run HijackThis using a different method and we are going to run another tool too.

    Copy the below quoted text into a new notepad document.
    Click File> Save as... and change Save as type to all files, set the File name to runhjt.bat and save it to your Desktop.
    Now execute runhjt.bat by double clicking on it. A new HJT log will come up. The file is already save in the folder where HJT is run from. This should be C:\Program Files\HJT if you followed our directions for installing HJT. Attach this new log.


    Then run the steps in the below and attach the WinPfind log too:

    Running WinPfind by OldTimer
     
  14. imlostinbetween

    imlostinbetween Private E-2

    Hey, thanks so much for you consistent support. I have the logs from the two scans and i also downloaded and installed zone alarm free. I switched from Internet Explorer to Firefox also.

    Thanks Again
    Heather
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later to run it.

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click OK.

    Paste C:\WINDOWS\system32\ntsyv[1].exe into the box titled Full Path of File to Delete box in Pocket Killbox. Check mark the box that says "Delete on Reboot" Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click YES and it will reboot.

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    After reboot immediately run HijackThis and double check for the below line and xix it if found:
    O4 - HKLM\..\Run: [ntsyv[1]] C:\WINDOWS\system32\ntsyv[1].exe

    Then get a new HJT log and attach it here.
     
  16. imlostinbetween

    imlostinbetween Private E-2

    Thanks. HJT did not find that line and it is no longer in startup (if that matters any). Is it alright to allow Sonic Update to access the internet?

    Thanks Again
    Heather
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but it is only for updates and a feature you may not even use or want. Read the below:
    http://www.liutilities.com/products/wintaskspro/processlibrary/sgtray/

    If you do not want or need this feature, you can just have HJT fix the below line.
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  18. imlostinbetween

    imlostinbetween Private E-2

    Thanks so much for all of your help. My computer is running extremely well now. Thanks again.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds