rlvknlg.exe

Discussion in 'Malware Help (A Specialist Will Reply)' started by Maggot_Riot, Jan 25, 2007.

  1. Maggot_Riot

    Maggot_Riot Private E-2

    Lots of problem with this one, I have no idea when or where this came from, but I havent noticed it until recently. According to other websites it goes under a crapton of other names under processes and I seem to have a lot of these! I need help removing them.

    I tried a couple ways through other sites as well as trying to remove it through regedit, but, no luck.

    So please help me, thank you!
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. Maggot_Riot

    Maggot_Riot Private E-2

    Sorry about that! I just got done with the steps.
     

    Attached Files:

  4. Maggot_Riot

    Maggot_Riot Private E-2

    And the rest.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Most of your problems are coming in through these programs or add ons:

    Uninstall thru Add/Remove in the control Panel:
    Look2Me
    NewDotNet Browser Plug-in
    PowerReg Scheduler (Spyware)
    WhenU.SaveNow (Adware)
    WildTangent
    Weatherbug
    WhenUSearch



    Please run CCleaner.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.



    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us8.hpwis.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us8.hpwis.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us8.hpwis.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.atgames.jp/atgames/html/game/mo_mmo/fanta_tennis/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us8.hpwis.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 129.242.19.197:3127
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\RunOnce: [NoIE4StubProcessing] C:\WINDOWS\system32\reg.exe DELETE "HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components" /v "NoIE4StubProcessing" /f
    O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
    O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls(2).dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls(2).dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls(2).dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls(2).dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls(2).dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls(2).dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.savewealth.com

    After clicking Fix, exit HJT.

    Now attach new logs for:

    * GetRunKey - please download the current version first!
    * ShowNew
    * HJT

    Be sure to tell us how things are running.
     
  6. Maggot_Riot

    Maggot_Riot Private E-2

    Thanks tim, but I'm having a problem with even the first step. None of those programs show up on my control panel, which.. makes them hard to remove from there. So I skipped that step, theres not much I can do from there right?


    • O4 - HKLM\..\RunOnce: [NoIE4StubProcessing] C:\WINDOWS\system32\reg.exe DELETE "HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components" /v "NoIE4StubProcessing" /f

    Didn't show up when I ran HJT

    And this error came up when trying to remove one of the files:


    • Hijack this cannot repair O10 Winslock LSP entries.
      You should use LSPFix for that, which is available from http://www.cexx.org/lspfix.htm

      If the O10 belongs to WebHancer.new.net or commonname, spybod S&D can remove it automatically.
      Spybot S&D is available from http://www.spybot.info


    As far as things are going, my internet seems to have slowed down remarkably since going through the cleaning processes. My messangers (aim/msn) are all delayed when sending a response. (After hitting enter, it would take about 10 or so seconds for the message to actually go through). And when starting up Firefox, it takes at least a minute or so to connect, and occasionally the connection will slow down.

    This isnt a problem with my connection dropping since everything seems to be in working order, this only started when I started doing the cleaning.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have not already begun to fix this! DO NOT fix the O10 lines!!!!

    [edit] Okay! That's good that you go that message! If you actually had fixed them, you would have lost your internet connection [edit]

    Hold on a minute and I'll give you the fix you need.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Here is the way to fix the Relevant Knowledge DLL in the O10 line.

    Now download LSP - Fix

    Run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the rlls(2).dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move rlls(2).dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.
    If it is already in the Remove section, just click Finish.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see something that should have been uninstall first before fixing the O10 line. Let's try uninstalling anyway. Uninstall this: RelevantKnowledge


    What is the below that I see installed?
    ddw200342.exe

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders left behind by the uninstall:
    C:\Documents and Settings\Owner\Local Settings\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 5
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Mozilla Firefox (1.5.0.9)

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    Now attach new logs from ShowNew & HJT
     
  10. Maggot_Riot

    Maggot_Riot Private E-2

    I only did what TimW said in his response, nothing was fixed since I wasnt able to fix anything.

    Also, I dont think I'll be installing the current version of firefox, seeing as.. well, I absolutely hate it.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's your decision to make. The new one is more secure.

    Also you need to delete the below files:

    C:\WINDOWS\system32\rlls(2).dll
    C:\WINDOWS\system32\rlls.dll
    C:\WINDOWS\system32\rlxf.dll
    C:\WINDOWS\system32\silc_dll.dll
    C:\WINDOWS\system32\wininet(2).dll <--- only delete this file, DO NOT delet wininet.dll
     
  12. Maggot_Riot

    Maggot_Riot Private E-2

    Theres a few of my extensions that work best with the older version, and that extension is very important to keep around. It's not just that I dislike the updated version.

    But I will get to what you suggested, right now im uninstalling the java files and I will do the other steps as well.

    also, where can I find the .dll files to delete? Run HJT and select them?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Right click Start and Select Explore to bring up Windows Explorer. Navigate to the system32 folder. Locate the files and right click on them and select Delete.

    You may have to reboot after running LSP fix inorder to delete that DLL.
     
  14. Maggot_Riot

    Maggot_Riot Private E-2

    okay just did all those steps, and here are the files.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I just noticed another file related to your Marketscore infection! Delete the below file too:

    C:\WINDOWS\system32\LDPackage.dll


    How is everything running now?

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  16. Maggot_Riot

    Maggot_Riot Private E-2

    Everything running alot more smoothly!
    Thank you for your help!
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds