Popup & System Problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by jackh, Jul 23, 2005.

  1. jackh

    jackh Private E-2

    For a couple of years my computer has had very few popups and no viruses. Now I have a huge popup problem (the only thing that stops popups is to pull the plug on the Internet) and some system problems. I have been using Ad-Aware and Spybot at least once a week and am running Norton Antivirus with automatic updates and using the Goggle Popup stopper.

    I also have these System problems:

    At each boot I get two windows labeled RUNDLL one of which says “Error loading C:\WINDOWS\cfgmgr52.dll” and the other says “Error loading E6F1873B.DLL”.

    Often files will not open except from within their applications. Sometimes they won’t open without a restart.

    I have followed your procedures carefully down to running Hijack This but problems persist. I have not posted the logfile per your instructions.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You said nothing about running the READ ME FIRST sticky so I'm assuming it was not run.

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below exactly as written:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. jackh

    jackh Private E-2

    For a couple of years my computer has had very few popups and no viruses. Now I have a huge popup problem (the only thing that stops popups is to pull the plug on the Internet) and some system problems. I have been using Ad-Aware and Spybot at least once a week and am running Norton Antivirus with automatic updates and using the Goggle Popup stopper.

    I also have these System problems:

    At each boot I get two windows labeled RUNDLL one of which says “Error loading C:\WINDOWS\cfgmgr52.dll” and the other says “Error loading E6F1873B.DLL”.

    Often files will not open except from within their applications. Sometimes they won’t open without a restart.

    I have followed your procedures carefully down to running Hijack This but problems persist. I have not posted the logfile per your instructions.


    Sorry if I didn’t make it clear, but I did follow the ‘READ ME FIRST STICKY” very carefully and everything went well. Here is what I did:

    Step 1) Disabled System Restore with no problems.

    Step 2) Did not do this step.

    Step 3) Did this step successfully (I have XP Home).

    Step 4) Downloaded everything listed and saved as required.

    Scanning and Cleaning Steps:

    After booting to “Safe Mode with networking support”:

    1b. Ran Bitdefender successfully. I have a Scan Report and a Real Time Virus Report if you want to see them.
    Ran RavAntivirus as required. I don’t have a report from that.
    Ran McAfee AVERT Stinger. Report says nothing found.

    Disconnected from the Internet by pulling the plug from the router.

    2. Ran CCleaner with the options as already selected…including the “Delete Index.dat”. (The only report I have is simply a version description)

    3. Ran Ad-Aware SE (with VX2) and Spybot (with Immunize). There were the usual number of objects found and fixed

    4. Ran CWShredder, Kill2me about:Buster and HSRemover. I don’t have notes on results.

    I then ran Hijack This from folder on my desktop.

    Now I know that I should have downloaded it into a HJT folder in Program Files. Therefore I used Add or Remove Programs to delete Hijack This. Then I downloaded it again; this time into the HJT folder.

    I closed everything as required and also pulled the plug on my Internet connection so as not to be interrupted by popups. I then ran Hijack This. The Log File is attached.



    If there is any doubt about what I have done, I would be willing to repeat the whole thing again.

    Thanks for your help.

    Jack Hotz
    San Diego
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you know what the below is?
    C:\Program Files\amta\wasl.exe
    O4 - HKCU\..\Run: [Urni] C:\Program Files\amta\wasl.exe

    Is it some kind of WinAmp plugin? If not, you should added it to the list of processes below to kill and you should add the O4 line to the list of lines to fix with HJT. And then add the C:\Program Files\amta folder to the list of items to delete in safe mode.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Look in Add/Remove programs for SurfSideKick 3 and uninstall if found.

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\System32\t?skmgr.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
    O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
    O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe
    O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
    O4 - HKLM\..\Run: [mscin] C:\WINDOWS\System32\m190309.EXE
    O4 - HKLM\..\Run: [vidctrl] C:\WINDOWS\System32\vidctrl\vidctrl.exe
    O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
    O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
    O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
    O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
    O4 - HKCU\..\Run: [Ors] C:\WINDOWS\System32\t?skmgr.exe
    O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} - http://install.wildtangent.com/ActiveLauncher/ActiveLauncher.cab
    O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} - http://install.wildtangent.com/bgn/partners/wtgeneric/tradewinds/install.cab
    O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toontown.com/sv1.0.14.47/ttinst.cab
    O20 - Winlogon Notify: SideBySide - C:\WINDOWS\system32\wdapi.dll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\SurfSideKick 3 <--- the whole folder
    C:\WINDOWS\System32\vidctrl <--- the whole folder
    C:\WINDOWS\System32\E6F1873B.DLL or C:\WINDOWS\E6F1873B.DLL
    C:\WINDOWS\System32\exp.exe
    C:\WINDOWS\System32\wintask.exe
    C:\WINDOWS\System32\m190309.EXE
    C:\WINDOWS\System32\AUNPS2.DLL or C:\WINDOWS\AUNPS2.DLL
    C:\WINDOWS\cfgmgr52.dll
    C:\WINDOWS\System32\t?skmgr.exe <--- do not delete taskmgr.exe. Look for another similarly named file (probably a few 200k to 400k bytes in size.) The ? may or may not show exactly this way. If you are not sure, don't delete it.

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. jackh

    jackh Private E-2

    Before I start your process, I want to be sure I understand.

    "Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder."

    I have Ccleaner already installed. Did you mean reinstall? Where is the READ ME FIRST?

    I am running XP. Prefech has many files. Do you really mean delete them all?
     
  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Since Chas isnt here at the moment, to keep you moving along.

    If you already have it installed just run the program. The READ ME FIRST is the sticky thread.
    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Yes, delete them all!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    BJ is correct!

    No I did not say re-install. I was just reminding you what Ccleaner is. It is a program downloaded while running the READ ME FIRST. Many people forget and ask "what is Ccleaner"?

    And yes all files in the Prefetch folder can always be deleted. Good ones will come back as necessary.
     
  8. jackh

    jackh Private E-2

    I got down to running HiJack This and used Kill Process on the one item.

    But when I clicked "Back" and clicked Scan, nothing happened. I closed and opened HJT, then clicked Scan again nothing happened.

    What's next?

    Thanks for you patience.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are clicking the wrong Back button. Click the one on the lower right of the screen so you get back to the true Scan window. Now you can click Scan. Start the procedure at the beginning to make sure nothing as started up again.
     
  10. jackh

    jackh Private E-2

    I started the procedure from the top with these results:

    Since the C:\Program Files\amta folder was unknown to me, it was added to the list of Safe Mode deletes.

    Add/Remove Programs did not show SurfSideKick 3 but did have SurfSideKick (even after being removed the first thru). So I removed it.

    I did kill process C:\WINDOWS\System32\t?skmgr.exe again.

    Everything on your list of HJT items were “Fixed” except the following which were not on my HJT list:

    R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
    O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
    O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
    O20 - Winlogon Notify: SideBySide - C:\WINDOWS\system32\wdapi.dll

    I deleted the only items on your Safe Mode list that I could find:

    C:\Program Files\amta folder
    C:\WINDOWS\System32\vidctrl <--- the whole folder
    (Athough I couldn’t find C:\WINDOWS\cfgmgr52.dll I did find an empty C:\WINDOWS\cfgmgr52 which I left)

    I ran Ccleaner and deleted all c:\windows\Prefetch files.

    The computer is running like a top! No Popups. No “Error Loading” messages at startup. Files are opening normally.

    MANY, MANY THANKS FOR YOUR HELP. IT’S VERY GENEROUS OF YOU TO DONATE TIME TO HELP OTHERS.

    Now is a good time to finally install SP-2 to my XP Home system. I have had a CD but was afraid of causing problems by installing it. Do you have any advice on that subject?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Delete the cfgmgr52 file too.

    You forgot to do the last step of my instructions:
    Do not install Win XP SP2 until we have verified you are clean by looking at the log.
     
  12. jackh

    jackh Private E-2

    Yeah, I just remembered.

    I spoke too fast about no popups. I just got two...but that's nothing compared to what it was.

    I'll relax and wait to do SP-2. Therer is another popup interfering with my typing....and another!
     
  13. jackh

    jackh Private E-2

    I wasn't sure the attachment worked so I'm trying again.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In message # 4 I asked the below but you did not answer the question. Please answer because this seems supicious.
    You still have some problems that I asked you to fix in message # 4. We will cover them again.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
    C:\WINDOWS\System32\vidctrl\vidctrl.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [mscin] C:\WINDOWS\System32\m190309.EXE
    O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
    O4 - HKLM\..\Run: [vidctrl] C:\WINDOWS\System32\vidctrl\vidctrl.exe

    Also fix the below wasl.exe line if you did not know what it was.
    O4 - HKCU\..\Run: [Urni] C:\Program Files\amta\wasl.exe

    O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\nsvsvc <--- the whole folder
    C:\WINDOWS\System32\vidctrl <--- the whole folder
    C:\Program Files\amta <--- delete the folde if you decided it was an unknown
    C:\WINDOWS\System32\m190309.EXE

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Make sure you tell me if you cannot find any of these files or folder. Also tell me if you find them but cannot delete them.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and continue with the steps below. You have a Look2Me VX2 infection we need to fix.

    Download this: L2MeFix Tool

    Please print out these instructions now or save locally so that you can operate with All Browser Windows CLOSED.

    Exit Browsers now before continuing


    Please move the L2MeFix Tool (I had you download above) to your Desktop and DoubleClick l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix Folder on your Desktop. DoubleClick l2mfix.bat and type 2 and ENTER to select option #2 for Run Fix. Then, press any key to Reboot your machine.

    Your computer will go crazy for a bit, but just let it run. It should eventually spit out a log in Notepad.

    Do not run any other files in the L2MFix folder.


    When it finishes, get a new HJT log and then reconnect to the internet.

    Post the log from L2MeFix and the new HJT log as attachments.


    Let me know how things look now.
     
  15. jackh

    jackh Private E-2

    As to: C:\Program Files\amta\wasl.exe, I don’t know what that is.

    I disabled System Restore and enabled viewing of hidden files.

    The two processes were killed in HJT and the six items were fixed.

    In Safe Mode the first two folders were deleted but I could not find these items:
    C:\Program Files\amta <--- delete the folde if you decided it was an unknown
    C:\WINDOWS\System32\m190309.EXE

    Ran Ccleaner.

    Deleted all files in c:\windows\Prefetch.

    Downloaded and ran L2MeFix.

    Logs for L2MeFix and HJT are attached.

    The computer seems to be running fine. I have had two popups in the 30 min. since the procedure was completed.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not post the logs as Word Documents. They are in text format to begin with. Keep them that way. Word Docs are annoying and too big. You will find that sometimes they are even too big to post.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still show many of the same problems in your HJT log. Are you sure you are clicking fix? Are you getting any error messages?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download Pocket KillBox but do not run it yet.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfgmgr52.dll
    O4 - HKLM\..\Run: [mscin] C:\WINDOWS\System32\m190309.EXE
    O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
    O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe

    After clicking Fix, exit HJT.

    Now please extract the files from the Pocket KillBox download into its own folder and run killbox.exe

    Next, you will be entering items into Pocket KillBox. Please select the “Delete on Reboot” Option. Copy&Paste each of the file names listed below into the box one by one, making sure Delete on Reboot is Checked for each entry. Click the Red X for each entry, but DO NOT Allow your machine to be rebooted until the last item has been entered:

    ** Note: For any of the .dll files, check the Unregister .dll Before Deleting box as well. If this option is not enabled, don't worry about it.
    C:\Windows\System32\Program\BackWeb-8876480.exe <--- I'm not sure what the full path to this file is??? If you know, then use what you know.
    C:\WINDOWS\cfgmgr52.dll
    C:\WINDOWS\System32\m190309.EXE

    After entering the last file, say YES and allow your PC to reboot. If you get a Pending Files operation error or for any other reason it fails to reboot, just reboot it yourself.

    After reboot post a new HJT log and tell me how the above steps went.
     
  19. jackh

    jackh Private E-2

    I may be generating the wrong HJT log file. When I run HJT I click on “Do a System Scan and Save a Logfile”. This takes me to the next screen where a logfile pops up.

    I then check the appropriate files and I click “Fix Checked”. So the logfile I send may be created before the items are fixed.

    Should I have been checking Scan at some point?
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The logs files need to be obtained after you fix what I give you to fix. Notice the end of message #4. A new HJT log is supposed to be obtained and post after all the above steps had been followed. The same goes for message # 18. You run HJT to fix everything then you exit HJT and run Killbox to delete files. After that you are rebooting and getting a NEW HJT log to post.
     
  21. jackh

    jackh Private E-2

    I followed the procedure in post #18.

    Downloaded Pocket Killbox.

    Turned off Restore; unchecked Hide Files and Folders; unchecked Hide Extensions for Known File Types. No browsers running.

    Ran HJT; selected the four items and clicked Fix.

    Ran Pocket Killbox; selected “Delete on Reboot”; copied-and-pasted the three items one at a time; one .dll item required a check in “Unregister…” box.

    One problem. Couldn’t find the “BackWeb-8876480.exe” file using XP’s Search. But I found this using Google’s Desktop Search: ” C:\Program Files\Logitech\DesktopMessenger\8876480\Program\BackWeb-8876480.exe”

    But the file wasn’t there. Did find “BWCHelpr-8876480.dll” ; “BWfiles-8876480.dll” ; “bwscriptext-8876480.dll’

    So I used the path you provided.

    Had to reboot myself. Then ran HJT and am attaching the text file.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay your log is now clean of malware. How are things working?
     
  23. jackh

    jackh Private E-2

    Popups are gone and computer is working normally.

    The only thing I've noticed so far is that Norton AntiVirus is turned off after booting. So it has to be turned back on. It's been that way for a couple of weeks.

    Now I need to be sure I never have another attack. The first thing is to install SP-2. Any advice on how to proceed?
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may want to uninstall Norton, reboot, and then reinstall to see if it fixes the problem.

    To help keep your PC clean, run the steps in the below thread. The first step in that thread you will see is to goto Windows Update:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds