i ran aluria spyware protection and it detected it, it was able to delete it i just wanted to know what it was. and what it did to your system
tayspen 28 <Insert title here> Team Colleague
Dani AI
Generated
Brief expert summary and practical next steps.
This detection name (trojan.evker) is not a well-documented, standalone malware family in public vendor databases — the only clear online traces are forum reports such as this DaniWeb thread. Treat the detection as a browser‑hijacker/adware style infection (the behaviour described by others in the thread matches classic CoolWebSearch‑type hijackers: changed homepage/search, HOSTS edits, added BHOs/toolbars). (daniweb.com)
Why internet access can stay broken after “removal”
Hijackers often leave behind network hooks or incomplete components. If an LSP/Winsock entry remains but the DLL is missing or corrupted, the system can lose Internet connectivity — exactly the symptom flagged in the HijackThis log noted in the thread. Microsoft documents how Winsock/LSP corruption breaks connectivity and how Windows can rebuild those keys or be repaired safely; follow vendor guidance rather than ad‑hoc fixes. ()
Actionable cleanup checklist (do these in order)
- Boot Safe Mode (or Safe Mode with Networking) and run an up‑to‑date second‑opinion scanner (Malwarebytes/AdwCleaner are good for adware/hijackers — check compatibility for older OSes). (malwarebytes.com)
- Inspect and clean the HOSTS file and IE security/trusted zones; remove unknown BHOs/toolbars and suspicious startup/scheduled tasks.
- Repair the Winsock/LSP stack using the documented Windows recovery option or a reputable LSP repair tool (follow Microsoft guidance and reinstall any apps whose network hooks are removed). ()
- If ERUNT (C:\ERDNT) fails to save registry backups, run it with elevated rights, create the ERDNT folder manually and check that UAC/antivirus aren’t blocking writes (this is a known ERUNT/permissions issue). (wilderssecurity.com)
Notes and final checks
Because “trojan.evker” as a label is obscure, preserve any original antivirus logs and, if possible, submit suspicious files to a multi‑engine scanner or vendor for analysis. If problems persist after the above, capture fresh logs (updated HijackThis or equivalent), note which items remain, and post them for targeted cleanup. (daniweb.com)
Recommended Answers
Jump to Post— dlh6213 27I believe this is a part of, or related to, CoolWebSearch (CWS), which can add addresses to the HOSTS file, redirect search and start page settings, and may put the hijacker's web site in your browsers Trusted zone.
Please follow the recommendations and instructions in the links below to …
Jump to Post— DMR 152There's only one problem indicated in your HJT log:
O10 - Broken Internet access because of LSP provider 'xfire_lsp_9028.dll' missing
You can fix your broken LSP stack with the free utility. The program is very easy to use; a tutorial …
All 7 Replies
dlh6213 27 Posting Maven Team Colleague
I believe this is a part of, or related to, CoolWebSearch (CWS), which can add addresses to the HOSTS file, redirect search and start page settings, and may put the hijacker's web site in your browsers Trusted zone.
Please follow the recommendations and instructions in the links below to help protect and cleanup your system. When you get to the third thread, go to post #6 to (hopefully) remove CWS/evker.
When you've finished, please post a HijackThis log for review.
tayspen 28 <Insert title here> Team Colleague
ok so i clicked scan waited for log to come up then exirted out...
heres is the log.
Logfile of HijackThis v1.99.1
Scan saved at 2:17:21 PM, on 8/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\PROGRA~1\ALURIA~1\asKernel.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'xfire_lsp_9028.dll' missing
O14 - IERESET.INF: START_PAGE_URL=
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
O16 - DPF: {E302F157-A890-4B6F-A421-839D25055D6D} (NLSysInfo Control) - http://novalogic.com/pub/NLSysInfo.ocx
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Aluria Security Center Spyware Eliminator Service (ASCService) - Unknown owner - C:\PROGRA~1\ALURIA~1\ascserv.exe
O23 - Service: asKernel - Aluria - C:\PROGRA~1\ALURIA~1\asKernel.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
DMR 152 Wombat At Large Team Colleague
There's only one problem indicated in your HJT log:
O10 - Broken Internet access because of LSP provider 'xfire_lsp_9028.dll' missing
You can fix your broken LSP stack with the free utility. The program is very easy to use; a tutorial can be found .
tayspen 28 <Insert title here> Team Colleague
error saving file
C:\erdnt\security1
CONTINUE WITH NEXTFILE?
it does this with every file.
when i try to back up registry
swatkat 14 Practically a Master Poster
Hi,
Try this, since you have XP SP2, there's a built-in command to repair LSP. Go to Start > All Programs > Accessories > Command Prompt. In the Command Prompt, type netsh winsock reset and press ENTER key. Next, type exit and press ENTER key. Restart the PC, and post a fresh log of HijackThis.
Also, perform a scan using Aluria, and post back whether it finds anything or not.
tayspen 28 <Insert title here> Team Colleague
Hi,
Try this, since you have XP SP2, there's a built-in command to repair LSP. Go to Start > All Programs > Accessories > Command Prompt. In the Command Prompt, type netsh winsock reset and press ENTER key. Next, type exit and press ENTER key. Restart the PC, and post a fresh log of HijackThis.Also, perform a scan using Aluria, and post back whether it finds anything or not.
k will do tommrow i am not on my comp right now ;)
DMR 152 Wombat At Large Team Colleague
Try this, since you have XP SP2, there's a built-in command to repair LSP...
Thanks for the pick-up, swatkat. :)
Be a part of the DaniWeb community
We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.