View Full Version : I Seriously Hope The Person That Invented SearchMiracle Has A Serious Accident! HELP!
Empirical Truth
01-23-2005, 10:30 AM
Hello everyone I'm new here, and have decided to post and ask for expert help as a last resort. I've been looking at these types of forums for a while now, and have not even entertained the thought of trying to fix the problem myself, as I don't wanna screw up my comp. It was just overhauled and reformatted!!!
The reccuring problem(s)....
SearchMiracle Hijacker and EliteToolBar
Now, I should mention that I keep getting these F'n popups!!! I'm running Spyware Blaster, Spybot, Norton AntiVirus, and Spyware Guard.
Oh Lord, I am getting so angry, please, someone save me so that my Internet is a pleasure once again, and not a cause of overwhelming stress.
Also, I am not a computer whiz, so please, make this step by step for me, if you would be kind enough to do so.
Thank you so much for your time, patience, and assistance! I will forever be endebtted should this problem be solved.
I will post a log file of Hijack This!
Thanks a million again.
Empirical Truth
01-23-2005, 10:31 AM
Logfile of HijackThis v1.98.2
Scan saved at 1:19:48 PM, on 1/23/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\LimeWire\LimeWire 4.2.4\LimeWire.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\SpywareGuard\sgmain.exe
C:\PROGRA~1\ICQ\ICQ.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\msnmsgq.exe
C:\WINDOWS\shch.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\unzipped\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe"
O4 - HKLM\..\Run: [Mirabilis ICQ] C:\PROGRA~1\ICQ\ICQNet.exe
O4 - HKLM\..\Run: [kalvsys] C:\windows\system32\kalvewx32.exe
O4 - HKLM\..\Run: [msnmsgq32] C:\WINDOWS\msnmsgq.exe
O4 - HKLM\..\Run: [SvcH0st] C:\WINDOWS\shch.exe /i
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /1
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: LimeWire 4.2.4.lnk = C:\Program Files\LimeWire\LimeWire 4.2.4\LimeWire.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
Empirical Truth
01-23-2005, 10:47 AM
The wishing of misfortune may be a bit sadistic yes, I'm just sooo irritated. I leave the comp for 10 minutes to find 30 popups? WTF is that?
The log file doesn't seem to be nearly as long as most of the ones I've seen. Is this a good sign?
nightowl
01-23-2005, 10:52 AM
Let me take a peek, Run ADaware and Spybot. Delete all Temporary Internet Files, Cookies, , Empty recycle bin.
Be back in a bit........Jim
http://forums.designtechnica.com/showthread.php?t=5583
Empirical Truth
01-23-2005, 10:54 AM
ok thanks after doing these things, I'll post a new log. I first have to go d/l adaware.
thanks Jim
nightowl
01-23-2005, 10:59 AM
O4 - HKLM\..\Run: [kalvsys] C:\windows\system32\kalvewx32.exe
You need to kill this first. It can be stubborn. Heres How:
1. Go to Safe Mode (F8 on startup)
You need to do a search on your computer and look for any files where the first 4 letters begin with KALV
kalvewx32.exe
may be several on your computer.
When you find these files you need to rename them. You need to remove the exe and replace it with the name old so the file looks like this
kalvewx32.old
(The Files may not have ewx They can be any 3 letters but the first 4 letters are always KALV)
If it works, you can go back to safe mode, and search "*.OLD" And delete those files. Empty Recycle Bin.
Reboot and post a new log..........Jim
Empirical Truth
01-23-2005, 11:36 AM
ok Jim, here's the scoop...
I found 31 kalv files, about half with the .exe, in the middle of the file name, so i replaced those with "old", and the end extension were left as ".pf"
The other half didn't contain .exe at all, so i still put .old at the ends.
when i searched for .old, only half of the total kalv files came up.....
I deleted ALL of the kalv files, 31 of them, I hope i didn't screw myself.
Anyways, here is my new log file post-reboot.....
Empirical Truth
01-23-2005, 11:37 AM
Logfile of HijackThis v1.98.2
Scan saved at 2:19:23 PM, on 1/23/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe
C:\WINDOWS\msnmsgq.exe
C:\WINDOWS\shch.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\LimeWire\LimeWire 4.2.4\LimeWire.exe
C:\PROGRA~1\ICQ\ICQ.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\unzipped\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe"
O4 - HKLM\..\Run: [Mirabilis ICQ] C:\PROGRA~1\ICQ\ICQNet.exe
O4 - HKLM\..\Run: [kalvsys] C:\windows\system32\kalvewx32.exe
O4 - HKLM\..\Run: [msnmsgq32] C:\WINDOWS\msnmsgq.exe
O4 - HKLM\..\Run: [SvcH0st] C:\WINDOWS\shch.exe /i
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /1
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: LimeWire 4.2.4.lnk = C:\Program Files\LimeWire\LimeWire 4.2.4\LimeWire.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
Empirical Truth
01-23-2005, 11:39 AM
our friend
O4 - HKLM\..\Run: [kalvsys] C:\windows\system32\kalvewx32.exe
remains :eww
Oops I neglected to mention that I'm also running Webroot SpySweeper.
The latest log was posted without running any Spyware programs, and deleting any subsequent findings, or deleting temp int files.
nightowl
01-23-2005, 11:47 AM
Did you empty recycle bin? I'll take another look here.........Jim
Empirical Truth
01-23-2005, 11:47 AM
I did, yeah.
Empirical Truth
01-23-2005, 11:48 AM
Not getting any popups so far either....
nightowl
01-23-2005, 11:55 AM
Reboot To Safe Mode (tap F8 on Startup)
Delete these Files
C:\WINDOWS\msnmsgq.exe
C:\WINDOWS\shch.exe
Still In Safe Mode Place a check next to each of these and click Fix Checked.
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O4 - HKLM\..\Run: [kalvsys] C:\windows\system32\kalvewx32.exe
O4 - HKLM\..\Run: [msnmsgq32] C:\WINDOWS\msnmsgq.exe
O4 - HKLM\..\Run: [SvcH0st] C:\WINDOWS\shch.exe /i
Still In Safe Mode Delete all Temporary Internet Files, Cookies, Do a Defrag on your C Drive, Empty recycle bin.
Start/All Programs/Accessories/System Tools/Disc Defragment
Then Reboot and post a new log.
I've noticed the last few weeks this same problem.Kalvsys still showing up after deleteing all the files. But killing the rest of the stuff with HijackThis (including Kalvsys) seemed to work in some cases. Hope it works here. It can be stubborn at times. Whoever came up with it should be thrown in jail.........Jim
nightowl
01-23-2005, 11:56 AM
I'll be back after lunch.......Jim
Empirical Truth
01-23-2005, 11:57 AM
LOL yes indeed.
ok I'll go thru the steps now
thanks!
nightowl
01-23-2005, 01:18 PM
Did it work? Post a new log...........Jim
Empirical Truth
01-23-2005, 03:07 PM
here it is.....
Logfile of HijackThis v1.98.2
Scan saved at 5:54:13 PM, on 1/23/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\LimeWire\LimeWire 4.2.4\LimeWire.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\SpywareGuard\sgmain.exe
C:\PROGRA~1\ICQ\ICQ.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\unzipped\hijackthis\HijackThis.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe"
O4 - HKLM\..\Run: [Mirabilis ICQ] C:\PROGRA~1\ICQ\ICQNet.exe
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /1
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: LimeWire 4.2.4.lnk = C:\Program Files\LimeWire\LimeWire 4.2.4\LimeWire.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
Empirical Truth
01-23-2005, 03:18 PM
spy sweeper still picked up elite bar with only six traces- no searchmiracle this time.
ALMOST HOME FREE
nightowl
01-23-2005, 09:11 PM
I like it when they cooperate, This log is clean.
Keep it that way. Download SpywareBlaster for prevention Here is the link.
http://www.javacoolsoftware.com/spywareblaster.html
Run and Update Adaware and Spybot at least once a week to keep it clean.
Update SpywareBlaster once a week Enable all Protection and let it run in the background.........Jim :vivi
Empirical Truth
01-24-2005, 06:15 AM
Yo Jim I just gotta say....
Thank you- a thousand thank you's- if I ever have another problem God forbid, I'll come and give you a holler most definitely.
Now I can be happy again.....
well except for the fact that the only girl I ever loved is seeing someone else.
*Chi-Lite's "Have You Seen Her" plays in head*
thanks again Jim, you're the man!
peace
nightowl
01-24-2005, 09:37 AM
Glad I could help, have a good one.........Jim :vivi
vBulletin® v3.8.1, Copyright ©2000-2009, Jelsoft Enterprises Ltd.