pop up help

Discussion in 'Malware Help (A Specialist Will Reply)' started by Julie6915, Jun 5, 2005.

  1. Julie6915

    Julie6915 Private E-2

    I started by having Ceres trouble. I seem to have gotten rid of that but still get pop ups with nothing but "-" on the title bar. I've followed all of the steps posted by Major Attitude and ran hijackThis.
    I'm running W2k.
    One line I find in my log file is "O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe" I followed the hijackThis log help and can't seem to get rid of the problem.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Use Add/Remove programs to uninstall SurfSideKick 3

    If that does not work, make sure you have run all of the READ ME FIRST and then follow the steps below.


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. Julie6915

    Julie6915 Private E-2

    That worked with the pop ups! There is still one thing that is a minor irritation but hopefully not a predictor of future problems. When I'm scrolling through a web page it will suddenly lose focus (almost as if it wants to produce a pop up) then I have to click on the IE window to put the focus back to that page. I ran hijackThis again and still see things like "O15 - Trusted Zone: *.frame.crazywinnings.com" so I know something is going on. (just a note - I had done all the steps in the READ ME FIRST). I have attached my log. Let me know what you think. Thanks a bunch!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file move.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.)
    Double-click on the move.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to merge say yes.


    You must remember to exit browsers ( C:\Program Files\Internet Explorer\IEXPLORE.EXE ) before using HijackThis.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [ctrnzuv] C:\WINNT\system32\ctrnzuv.exe
    O15 - Trusted Zone: *.frame.crazywinnings.com <--- probably already gone due to above step
    O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM) <--- probably already gone due to above step


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINNT\system32\ctrnzuv.exe
    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner.
    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. Julie6915

    Julie6915 Private E-2

    Seems to have fixed the "focus" problem. I followed your instructions but upon running HJT, this came back: "O4 - HKLM\..\Run: [ctrnzuv] C:\WINNT\system32\ctrnzuv.exe"
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you find the C:\WINNT\system32\ctrnzuv.exe file previously and were you able to delete it?
     
  7. Julie6915

    Julie6915 Private E-2

    Yes. After making the registry edits, I booted into safe mode, deleted the file and ran Ccleaner.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Look in c:\windows\system32 for other files with similar names to ctrnzuv.exe

    There may even be ones ending with .dll

    Tell me what you find. Also sort the system32 folder by date. What other filenames do you see with the dates around the same time as ctrnzuv.exe.
     
  9. Julie6915

    Julie6915 Private E-2

    This has the same date/time: epx30104.exe as the ctrnzuv.exe
    These two share the same WinStat11.dll, WinStat11.dat, partypoker.ico.
    There is WinStat10.dll and WinStat10.dat that have the same time. I opened the dat files and it's a bunch of jibberish. I found this on a different date: ctrnzuvndw30104lib.dll in system32 folder.
    And while searching, I don't find the actual ctrnzuv.exe file but still get "O4 - HKLM\..\Run: [ctrnzuv] C:\WINNT\system32\ctrnzuv.exe" in the HJT log.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you really need Party Poker?

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    ctrnzuv.exe

    After killing that process exit out of HJT.

    Now with Windows Explorer navigate to the c:\windows\system32 folder and locate the below files and one at a time right click on them and select Rename. Change the names as given below (Note: You will get a message like "If you change a file name extension, the file may become unusable. Are you sure you want to change it?" Just say yes.)
    ctrnzuv.exe to ctrnzuv.xxx
    ctrnzuvndw30104lib.dll to ctrnzuvndw30104lib.ddd
    WinStat11.dll to WinStat11.ddd
    WinStat11.dat to WinStat11.ttt
    WinStat10.dll to WinStat10.ddd
    WinStat10.dat to WinStat10.ttt

    Then run HijackThis and have it fix the below line:
    O4 - HKLM\..\Run: [ctrnzuv] C:\WINNT\system32\ctrnzuv.exe

    Exit HJT.

    Reboot your PC. After reboot get a new HJT log and post it here. Let me know how the steps went and what your current status is.
     
  11. Julie6915

    Julie6915 Private E-2

    I didn't need party poker, it just kept reappearing. I deleted it and
    I renamed ctrnzuvndw30104lib.dll to ctrnzuvndw30104lib.ddd
    WinStat11.dll to WinStat11.ddd
    WinStat11.dat to WinStat11.ttt
    WinStat10.dll to WinStat10.ddd
    WinStat10.dat to WinStat10.ttt
    as well as epx30104.exe and uskitndw30103lib.dll b/c they looked suspicious. It seems to have gotten rid of the ctrnzuv.exe
    Check it out.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks good now. I would would now delete all those files that we renamed.

    Now that you are clean, we want to keep it that way. To help do this, you should follow the steps in the below thread:

    How to Protect yourself from malware!
     
  13. Julie6915

    Julie6915 Private E-2

    Ok, will do. Thanks SO much. You're a life saver.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome Julie! Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds