Need Help with hjt log plz

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by champagne supernova, Oct 10, 2004.

  1. champagne supernova

    champagne supernova Private E-2

    Hi.
    i followed all the steps in the 'read this first' thing and it seemed to work. but since then programs like 'exdl1.exe' and 'bargains.exe' have tried to acces the internet. i took a look at Chaslang's guide, but it's too complicated. rather than screw something up, could someone just tell me what to do? here's my HJT log:

    Thanks!

    Edit by chaslang: Inline log changed to an attachment.
     

    Attached Files:

    • hjt.txt
      File size:
      8.6 KB
      Views:
      7
    Last edited by a moderator: Oct 10, 2004
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should have read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Do not post a HijackThis log until we ask you to and when we do it must be text document attachment to your message. To do this save the log file and select manage attachments in a new thread to upload it. All running programs should be closed, including your web browser, e-mail, items in the tray, anything you can close... Close before running Hijack This!

    And my Generic Solution thread does not apply to your problems!
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First go to Add/Remove programs and look for an uninstall to WebRebates. If you find one, uninstall it and let me know that you found it and if it worked. Also do this for the SpyDeleter problem, do the below:

    Click Start, Run, and enter into the box the following without the quotes "Notepad"
    Now copy and paste the contents the next 3 lines (including the blank line) into the notepad window.
    REGEDIT4

    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB74C951-ACA1-4e33-A94C-A9261EB2CCB7}]


    Now save it as file name: "delspy.reg" (without the quotes).
    Use Save as file type: All files (*.*)
    Save it on your Desktop where it is easy to locate.

    Now on your Desktop double-click on delspy.reg.

    At the prompt "Do you wish to merge the information into the registry?"
    Answer 'Yes' and wait for a message to appear similar to "Merged Successfully".
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  5. champagne supernova

    champagne supernova Private E-2

    ok, i uninstalled webrebates alright, and merged the registry entry.
    Also, you said "All running programs should be closed" when when running HJT. Does this include zonealarm, norton, etc?
     
  6. champagne supernova

    champagne supernova Private E-2

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Leave ZoneAlarm & Norton running unless we request it to be shut down. I think I will update the tutorial to specifically say leave them alone unless asked.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find the below processes and right click on them and select End process tree:
    SyncroAd.exe
    wship6.exe
    bargains.exe


    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:
    regsvr32 /u C:\WINDOWS\2_0_1browserhelper2.dll
    then click OK. If a dialog box confirming this action appears, click OK.

    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:
    regsvr32 /u C:\WINDOWS\System32\nvms.dll
    then click OK. If a dialog box confirming this action appears, click OK.

    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:
    regsvr32 /u C:\WINDOWS\System32\mscb.dll
    then click OK. If a dialog box confirming this action appears, click OK.

    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:
    regsvr32 /u C:\WINDOWS\System32\msbe.dll
    then click OK. If a dialog box confirming this action appears, click OK.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/sidesearch.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.begin2search.com/sidesearch.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.begin2search.com/sidesearch.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.begin2search.com/sidesearch.html
    R3 - URLSearchHook: (no name) - _{20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)
    O2 - BHO: (no name) - SOFTWARE - (no file)
    O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0_1browserhelper2.dll
    O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dll
    O2 - BHO: AceGain DLInterceptor - {CA70AF0D-0D07-4b80-9ECE-B0F1BEFC5822} - C:\Program Files\Byteswarm\DLInterceptor.dll
    O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll
    O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [Windows SyncroAd] C:\Program Files\Windows SyncroAd\SyncroAd.exe
    O4 - HKCU\..\Run: [wship6] C:\WINDOWS\System32\wship6.exe
    O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_f...8953c90b23b7fc1
    O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.3dgroove.com/download/GrooveAX.cab
    O16 - DPF: {D18B7EC3-EECA-11D3-8E71-0000E82C6C0D} - http://www.slotchbar.com/ist/softwa.../ist_remove.cab
    O16 - DPF: {FDF6378C-7B5D-4ABF-BA1F-92748305FFAC} (DownloadManagerInstall Control) - http://beta.byteswarm.com/agent/1.3.0.1/DMInstall.cab


    Boot in safe mode and use Windows Explorer to delete:
    C:\WINDOWS\2_0_1browserhelper2.dll
    C:\WINDOWS\System32\nvms.dll
    C:\WINDOWS\System32\mscb.dll
    C:\WINDOWS\System32\msbe.dll
    C:\Program Files\Windows SyncroAd <-- the whole directory
    C:\WINDOWS\System32\wship6.exe
    C:\Program Files\BullsEye Network <-- the whole directory

    Now reboot in normal mode and post another log (attachment please) and tell how things are working.
     
  9. champagne supernova

    champagne supernova Private E-2

    I checked in task manager, and bargains.exe is still running. is that bad?
    here's my log...
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! You should look for it in Add/Remove programs and uninstall it. Look for BullsEye Network or Bargains. Also Webrebates is still there. I thought you uninstalled it. Also a couple of O2 BHO DLLs I ask you to fix in HJT and delete the files are still present. Did you have any problems running my previous steps? You need to provide feedback on steps we ask you to run.

    Kill the bargains.exe process with Task Manager.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll
    O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll
    O4 - HKLM\..\Run: [Mmgsvc] C:\WINDOWS\mmgsvc.exe
    O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
    O4 - HKCU\..\Run: [Mmgsvc] C:\WINDOWS\mmgsvc.exe
    O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm

    Boot in safe mode and delete:
    C:\WINDOWS\System32\mscb.dll
    C:\WINDOWS\System32\msbe.dll
    C:\Program Files\Web_Rebates <---- the whole directory
    C:\Program Files\BullsEye Network <---- the whole directory
    C:\WINDOWS\mmgsvc.exe

    Boot normal mode and provide feedback on these steps. Post a new HJT log.
     
  11. champagne supernova

    champagne supernova Private E-2

    ok... i did delete web rebates, and when i tried to find in add/remove programs it wasn't there (i'm not having any more trouble with that). i deleted the stuff you told me to and bargains.exe isn't running now, though i'll restart and check again. i should have told you that when you told me to delete

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/sidesearch.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.begin2search.com/sidesearch.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.begin2search.com/sidesearch.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.begin2search.com/sidesearch.html
    R3 - URLSearchHook: (no name) - _{20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)
    O2 - BHO: (no name) - SOFTWARE - (no file)
    O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0_1browserhelper2.dll
    O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dll
    O2 - BHO: AceGain DLInterceptor - {CA70AF0D-0D07-4b80-9ECE-B0F1BEFC5822} - C:\Program Files\Byteswarm\DLInterceptor.dll
    O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll
    O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [Windows SyncroAd] C:\Program Files\Windows SyncroAd\SyncroAd.exe
    O4 - HKCU\..\Run: [wship6] C:\WINDOWS\System32\wship6.exe
    O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_f...8953c90b23b7fc1
    O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.3dgroove.com/download/GrooveAX.cab
    O16 - DPF: {D18B7EC3-EECA-11D3-8E71-0000E82C6C0D} - http://www.slotchbar.com/ist/softwa.../ist_remove.cab
    O16 - DPF: {FDF6378C-7B5D-4ABF-BA1F-92748305FFAC} (DownloadManagerInstall Control) - http://beta.byteswarm.com/agent/1.3.0.1/DMInstall.cab
    , i couldn't find some of them.
    well all seems fine, and if i don't post, it's because your instructions worked. thanks alot! your sooo smart. :)
     
  12. champagne supernova

    champagne supernova Private E-2

    OMG!
    bargains.exe is still running. i followed all of your instructions. plz help!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please check Add/Remove programs for Bargain Buddy (or anything similar)?

    Please post another HijackThis log. Do not make any changes yourself to anything. Also please leave your PC running until you hear back from me. (You can disconnect from the Internet for safety and shut off your monitor. Just leave the PC on.)
     
    Last edited: Oct 12, 2004
  14. champagne supernova

    champagne supernova Private E-2

    sorry... i should have told you that i DID find an option to remove Bullseye network and i removed it, but after a while it came back. i just deleted it again (after ending bargains.exe), and heres my log.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But did you look for Bargain Buddy?
     
  16. champagne supernova

    champagne supernova Private E-2

    Yes, i checked for it, and somthing sililar, but couldn't find anything
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These lines are still in your log and the files are still on your PC:
    O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dll
    O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll
    O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll

    Go back and look at the steps I asked you to do in messages # 8 and #10. and do them again. This time give me some results on what happens.
     
  18. champagne supernova

    champagne supernova Private E-2

    I remember deleting those files. i'm sure of it. i just deleted them again, scanned again, and they got deleted ok. (but i'm sure i deleted them before)
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you also delete the files using Windows Explorer?

    Reboot and see if the appear in a new HJT log?

    Okay so now where do we stand with Bullseye Network/bargains.exe
     
  20. champagne supernova

    champagne supernova Private E-2

    Yes, i did everything you said, and now bargains.exe is running, i still have bullseye network folder in prog files, and these files are still in my hjt log:
    O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dll
    O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll
    O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll

    also,
    C:\WINDOWS\System32\mscb.dll
    C:\WINDOWS\System32\msbe.dll
    C:\Program Files\BullsEye Network <---- the whole directory
    are still there. i'll go back and try it one more time.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's try this again but with a slightly different procedure.

    You will need to print these instructions because after reading this sentence you MUST exit ALL browser sessions and physically disconnect from the internet (that means unplug the ethernet cable from your DSL or Cable modem from your PC. For analog modems, unplug your phone line. ) This is done to make sure nothing can get in or out of your PC even though you don't see it happening.

    Okay, exit your browsers (including this one) and unplug you cables NOW! DO NOT OPEN ANY BROWSER WINDOWS AGAIN until told to and only run what I specify and nothing else.

    Make sure you boot into safe mode!

    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:
    regsvr32 /u C:\WINDOWS\System32\nvms.dll
    then click OK. If a dialog box confirming this action appears, click OK.

    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:
    regsvr32 /u C:\WINDOWS\System32\mscb.dll
    then click OK. If a dialog box confirming this action appears, click OK.

    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:
    regsvr32 /u C:\WINDOWS\System32\msbe.dll
    then click OK. If a dialog box confirming this action appears, click OK.

    Tell me the results of each of those three regsrv32 commands.

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find the below process and End it (if found):
    bargains.exe

    Tell me if you found it and were able to end it.

    Use Windows Explorer to delete:
    C:\WINDOWS\System32\nvms.dll
    C:\WINDOWS\System32\mscb.dll
    C:\WINDOWS\System32\msbe.dll
    C:\Program Files\BullsEye Network <-- the whole directory

    Tell me the results of each of those file/directory deletions.

    While in safe mode run HijackThis and select the following lines and then click FIX
    O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dll
    O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll
    O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll


    Now reboot in normal mode, reconnect your cables and post another log (attachment please) and tell how things are working. Don't forget to give me all the results that I asked for.
     
  22. champagne supernova

    champagne supernova Private E-2

    I ran all the commands, and they succeeded just fine. next, i checked for bargains.exe and it wasn't running. all the files you told me to delete in windows explorer were all there, and i deleted them all. when i ran hijkthis, but couldn't find any of the things. bargains.exe is still running, though. here's my log:
     
  23. champagne supernova

    champagne supernova Private E-2

    HERE it is (pushed wrong button, sorry):
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you saying when you booted in safe mode bargains.exe was not running but when you got back to normal boot mode it was running?

    And now all the files and the directory are back too?
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First make sure your in a state where bargains.exe is running. Then do the following:

    Download ProcessExplorer from: http://www.sysinternals.com/files/procexpnt.zip

    Unzip it and now run ProcessExplorer and lets configure some options first:
    Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked. Now click on bargains.exe. Now also under the View menu choose "Select columns" and put a check mark on "Image Path".
    Now click on File and then Save As. And save the process list. Post it back here as an attachment. Also, from now on if I say to kill a process, use ProcessExplorer instead of Task Manager. Sometimes ProcessExplorer can kill things that Task Manager cannot.
     
  26. champagne supernova

    champagne supernova Private E-2

    here it is...
     

    Attached Files:

  27. champagne supernova

    champagne supernova Private E-2

    Yes. bargains.exe wasn't running in safe mode, but when i booted up normal it was there. also, i deleted all the files you told me to in safe mode, but now theyre back.
    (when i scanned in safe mode with hjt, it couldn't find the lines you told me to fix, but i booted to normal and it detected them)
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is why we ask for feedback. We always need to know exactly what happens. We cannot see what it happening. This is important information that I did not know.
     
  29. champagne supernova

    champagne supernova Private E-2

    Sorry :( i'll be more detailed from now on.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay this time we are going to start in normal mode! And this has to be run when you see the problem with bargains.exe is

    showing. This is going to be some repetition from before but since the problem came back, we have to do it all again but with some additional steps to try to get rid of the pest once and for all (I hope). Make sure you report the results for each step. You need to print or copy this information locally because we are going to end all Internet Explorer sessions and your Explorer shell very soon. When we end the shell your Desktop will be missing all of the icons (don't panic - this is normal behavior). Do not run any programs other then the ones requested. I also suggest you read thru all of it first to make sure you understand how to do all these steps. Ask questions before starting!

    1) Physically disconnect you ethernet cable that connects your DSL or Cable modem to your PC. If you have an analog modem (dial-up), disconnect the phone. DO NOT SKIP THIS STEP!!!
    2) Exit ALL Internet Explorer and any other browser sessions NOW!
    3) Click Start, Run, and in the Open box enter "cmd" without the quotes and then click OK or press Enter. This should open up a

    command prompt window.
    4) In the command prompt window enter the following three commands each followed by the enter key. Click OK if a dialog box

    confirming this action appears.

    regsvr32 /u C:\WINDOWS\System32\nvms.dll
    regsvr32 /u C:\WINDOWS\System32\mscb.dll
    regsvr32 /u C:\WINDOWS\System32\msbe.dll

    Leave the command prompt window open!

    5) Open Task Manager by pressing CTRL-ALT-DEL simultaneously. Click the "Processes" tab, and then find the bargains.exe process

    and end it. Watch the processes window for a minute and make sure it does not come back. If it does, kill it again and tell me

    about it. That you had to end it a second time.

    Exit Task Manager.

    6) Run HijackThis and select the following lines and then click FIX
    O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dll
    O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll
    O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll

    Now exit HijackThis.

    7) Now open Task Manager again by pressing CTRL-ALT-DEL simultaneously. Click the "Processes" tab, and then end ALL instances of

    iexplore.exe and then explorer.exe. After ending any iexplore.exe and explorer.exe processes double check for bargains.exe

    again. If found, end it again. (Let me know if you find it running here.)

    At this point you should have noticed that your desktop is gone. No icons etc. DO NOT EXIT TASK MANAGER THIS TIME.

    8) Next, click on the "Applications" tab of Task Manager, select C:\WINDOWS\System32\cmd.exe and click "Switch to".

    9) Now type in the following command lines each followed by the enter key. Make sure you keep track of what happens here we must be sure these files get deleted.

    cd C:\WINDOWS\System32
    attrib -r -h -s nvms.dll
    attrib -r -h -s mscb.dll
    attrib -r -h -s msbe.dll

    del nvms.dll
    del mscb.dll
    del msbe.dll

    cd C:\Program Files\BullsEye Network <-- Make sure you command line prompt shows you that you are in this directory.
    attrib -r -h -s *.*
    dir <-- You should see the bargains.exe file. Make note of what else you see.
    del *.* <-- click yes to confirm the delete of all files
    cd .. <-- this is a cd followed by a space followed by two periods.
    rd C:\Program Files\BullsEye Network\ <-- don't forget the ending \

    Tell me the results of each of those file/directory deletions.

    10) Close the command prompt window (by typing exit or by clicking on the X at the top right) and then switch back to Task Manager

    again by pressing CTRL+SHIFT+ESC simultaneously until you get back to Task Manager.

    11) In Task Manager click on the "File" menu and choose "New Task"

    12) In the window type explorer and then press "OK" to reopen the Windows shell

    13) Now reboot in normal mode, reconnect your cables and post another log (attachment please) and tell how things are working. Don't forget to give me all the results.
     
  31. champagne supernova

    champagne supernova Private E-2

    ok... this is weird, but i made an amazing discovery!
    1) i unhooked my network cable.
    2) exited all broser sessions.
    3) opened command prompt.
    4) entered the 3 regsvr32 commands without trouble, window popped up to confirm. (left command promt open!)
    5) opened task manager, ended bargains. i waited for a minute to see if it popped up again. it didn't.
    6) i scanned with hjt, but the 3 specified lines were NOT there, so i exited.
    7) ended explorer.exe using task manager, (iexplorer was not present). bargains.exe was NOT running.
    8) switched to command prompt.
    9) i ran the specified attrib and del commands on the 3 .dll files. next, i changed the drive to C:\Windows\bullseye network , and used the attrib command (no alert came up). i used the dir command, but couldn't see bargains.exe*. i did, however, find these:
    ad.dat
    ub.dat
    uninstall.exe
    bin <--- a folder *i just checked in windows explorer, and 'ad.dat' and
    *uninstall.exe were not there.
    * (also, bargains.exe is located in the 'bin' folder)

    i next used the del *.* command, and got no alert.
    then, i used 'cd ..', and when i tried 'rd C:\program files\bullseye network\',
    i got the following alert:
    could not find file specified
    could not find path specified
    could not find file specified

    10) closed the command prompt and switched to task manager.
    11-12) started new task entitled 'explorer'
    13) i rebooted.

    ok.. i scanned with hjt at startup, and the follow were detected (though they wern't in step 6 {also bargains.exe wasn't running}).
    then i had a hunch, and i think this will help out alot.
    i kept task manager open, and opened windows explorer. to my amazment, bargains.exe started up. i ended it and tried this again. same result.
    i tried this with a few other programs, and the only one that made bargains.exe start up was internet explorer. hope it helps.
    here's my hjt log...
     

    Attached Files:

  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I said you need to have the bargains.exe problem when you start the steps. You are not suppose to end it until I tell you to do that which is in step 5. Also the files from step 6 should have been there if bargains.exe had been running as I stated.

    Try again following the procedure as written.

    I don't understand something. You said you

    "changed the drive to C:\Windows\bullseye network , and used the attrib command (no alert came up). i used the dir command, but couldn't see bargains.exe*. i did, however, find these:
    ad.dat
    ub.dat "

    Since when is Bullseye Network in the Windows folder. We have only been seeing reports for it in C:\Program Files\Bullseye Network .
    If you see it in C:\Windows we need to remove that folder too. If there is a bin subfolder you will need to cd to it first and del all files in the bin folder. Then cd .. and rd bin. Then cd .. and rd "Bullseye Network" with the quotes
     
  33. champagne supernova

    champagne supernova Private E-2

    i'm sorry. i meant program files. also, i did leave bargains.exe running until step 6.
    also, i just thought of something you should know. everytime you asked me to run hjt, i had to get to it from windows explorer. sorry i failed to mention that before.
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay can you go back and make sure all the files in that Bullseye Network folder get deleted. Also the bin folder too. As I said in my last message:

    If there is a bin subfolder you will need to cd to it first and del all files in the bin folder. Then cd .. and rd bin. Then cd .. and rd "Bullseye Network" with the quotes

    And after step 12, empty the recycle bin and c:\windows\prefetch folder too.
     
  35. champagne supernova

    champagne supernova Private E-2

    ok... i did the commands you told me to and the whole bullseye folder is gone. i've deleted it prior to this with windows explorer (before i asked you for help), and it was gone for a while but it always came back. we'll see what happens.
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Let me know! Did you empty the recycle bin and windows prefetch?

    Did you double check to make sure the DLL file are still gone?
     
  37. champagne supernova

    champagne supernova Private E-2

    ok... i was going to reply and i wrote a message, but there was something messed up with my comp and i had to shut down. well i started it up to post and just guess what's running? bargains.exe is still friggin running and i'm starting to think there's no hope!
    also, whats windows prefetch? and i used cmd to delete them, so they never reached the recycle bin.
     
  38. champagne supernova

    champagne supernova Private E-2

    ok... i just found out something usefull. i was messing around seeing when bargains.exe would run. i found out that when i open (or switch folders in) windows explorer, bargains.exe starts up. (Windows explorer also takes longer to start it up if bargains is not running). bargains also starts up when i run internet explorer, or change websites.
    i tried an experiment. i'll walk you through it. (keep in mind that throughout this whole procedure, my netwrk cable was unhooked)

    ok... i'll tell you what i did. i ended bargains.
    1) i used command promt and deleted the whole bullseye network folder according to your directions.
    2) i searched the registry and deleted anything with {bullseye network; bargains; msbe.dll; nvms.dll; mscb.dll} for a value/folder name.
    3) i next searched all files on my computer and delteted all files/folders with the name {bargains; bullseye network}.
    4) i checkd all the files\folders, and they seemed to be gone. bargains.exe didn't even start when i ran windows explorer.
    5) i restarted my computer and ran windows explorer, to see if bargains would be running.
    6) to my dismay, it was runing again, and all the files i deleted had appeared again.
    since my network cable was unplugged through all of this, i'm guessing there's an evil program on my comp that keeps installing it. i hope this info can be of help to you!
    PS: (i even deleted the 3 lines found in hjk scan immediatly before step 1, and they're on my comp again)
     
  39. Kodo

    Kodo SNATCHSQUATCH

    Chas,
    This the crap we were talking about the other night.. exe's hooking onto the execution of Explorer and IE etc.
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It certainly appears that way Kodo. There seem to be a lot of these appearing lately. What do you think about trying a solution like you gave Kittee
     
  41. Kodo

    Kodo SNATCHSQUATCH

    I think it would be a good start anyway. I'm running out of ideas here..
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    OK!

    Champagne, please try the below possible solution Kodo has come up with. However just prior to doing that you should perform the steps we have been using to get rid of the Bullseye stuff. Just do not reboot or run any thing else afterwards. So here is what we are going to do.

    First download Kodo's RESTORE.ZIP . It has an SP1 explorer.exe file within it along with a batch file (a .bat file). Extract the batch file onto the root of C:\ such that it's path is C:\restore.bat . Then place Kodo's version of explorer.exe also in the root of C:\ such that its' path is C:\explorer.exe

    Now we need to fix the BullsEye stuff again. So what you need to do is go back to message number 30 and run all the steps up to and including 10. Then use these new steps below to finish the procedure:

    11) In Task Manager click on the "File" menu and choose "New Task" and type C:\restore.bat and hit enter.

    12) Now go to file ..new task and type Explorer.exe then press "OK" to reopen the Windows shell

    13) Now reboot in normal mode, reconnect your cables and post another log (attachment please) and tell how things are working. Don't forget to give me all the results.
     
  43. champagne supernova

    champagne supernova Private E-2

    ok... we've run into a thing here. after i used the regsvr32 commands i scanned using hjt, but couldn't find the specified lines.so i rebooted and could see them in hjt.
    i found out thatwhen i use the regsvr32 commands it deletes them.
    i then used regsvr32 command then ran hijackthis after every line:

    1) if i regsv32 nvms.dll then O2 - BHO: NLS UrlCatcher Class is gone.
    2) if i regsvr32 mscb.dll then O2 - BHO: CB UrlCatcher Class is gone.
    3) if i regsvr32 msbe.dll then O2 - BHO: ADP UrlCatcher Class is gone.

    should i just skip the hjt part of step 5?
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes if they were gone already it is basically not necessary. Also you meant regsvr32 /u filename. Right? regsvr32 filename would register the files.
     
  45. champagne supernova

    champagne supernova Private E-2

    yes. that's what i meant. regsvr32 /u. i'll try that now and let you know.
     
  46. champagne supernova

    champagne supernova Private E-2

    ok... i just did what you said. everyathing went the same way as i said in post # 31, except i got the bin folder in bullseye network deleted.
    i ran restore.bat and started the new explorer, but after reboot and access internet explorer, bargains is still running and msbe, nvms,and mscb.dll are there along with bullseye network folder.
     
  47. champagne supernova

    champagne supernova Private E-2

    hey.. i was just wondering.. my computer has been running crapping slow at startup and shutdown (like 2 or 3 times slower than usual). is this one of the effects of having bargains exe on my computer or a different issue?
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure! It could be!

    I want to try something that we may have been missing. The last HJT log you posted had this line in it:

    O4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.exe

    Please run HijackThis again and do all the fixes how we have been doing them for the BullsEye crap and include the above line to be fixed too.

    Also when you boot to safe mode to delete files locate:
    C:\Program Files\NaviSearch\bin\nls.exe
    and rename it to:
    C:\Program Files\NaviSearch\bin\nls.BADexe

    I don't want to delete it yet. Until we are sure what it is. I think it may be part of the problem.

    Then boot in normal mode and open and close Windows Explorer and Internet Explorer a coupld of times. Then post a new HJT log.
     
  49. champagne supernova

    champagne supernova Private E-2

    ok... did you want me to go back and do one of the things you said + those instructions? here's what i did.
    1) delteted the 4 lines using hjt.
    2) rebooted in safe mode and, using windows explorer, deleted bullseye network and navsearch (the 3 .dll files in WINDOWS were not there).
    bargains.exe is still running.
     
  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to post a new HJT log and did yo rename the nls.exe file.

    Do not shutdown bargains.exe if you see it running. We need to see it in your log.

    I also want you to bring up Task Manager and look for bargains.exe to be running. If it is not running, keep Task Manager open and open an Internet Explorer session or Windows Explorer session (whatever is necessary to make it appear in Task Manager). Now leave Task Manager running and open up a command prompt window as we have done before.
    Now in Task Manager watch bargains.exe as you end all explorer.exe sessions and iexplore.exe sessions. I want to see if ending any of them causes bargains.exe to stop running. Let me know if ending any of these also ends bargains.exe (also tell me which one).

    If you wound up ending your Window shell (explorer) above then get it back by switching back to Task Manager by pressing CTRL+SHIFT+ESC simultaneously until you get back to Task Manager. In Task Manager click on the "File" menu and choose "New Task". In the window type explorer and then press "OK" to reopen the Windows shell.

    Then come back and tell me the results.
     
    Last edited: Oct 16, 2004

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds