Hi,
this thread is just a repost of my post that a mod asked me to post in here (I was posting it the Win98/Me forum). I guess it's only appropriate since it's security related. Sorry if someone had posted about the "cniaezi.exe" bug already.

[repost]
==================

I did have this file called "cniaezi.exe" (in c:\windows\system32 directory) that keeps loading itself in my registry key HKLM/softwares/microsoft/windows/current/run. This cniaezi.exe file also has the properties like what the original poster mentioned, namely "caller.exe" and from ""!!! Furthermore, when I tried to delete its entry in my registry key, it would load itself up again at the next reboot. And yes, I did notice I was getting random popups even though I had a popup blocker running (from Avant Browser). That was when I got suspicious of a possible malware and checked my registry and did a google search on "homecalling biz" and so here I am at this site.

Anyway, I did what Crunchi said and not only did I get rid of that malware, I also got rid of a LOAD of other malware and data miners that I didn't know were in my system. I really should stop going to those russian crack sites.

Here is my log generated by HijackThis, per Crunchie. I think I'm clean now, but if any has anything to say about my log, please speak up!

=========================================

Logfile of HijackThis v1.97.7
Scan saved at 12:32:36 AM, on 6/2/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe
E:\temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe"
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: + Offline &Explorer: Download the link - file://C:\Program Files\Offline Explorer Enterprise\Add_UrlO.htm
O8 - Extra context menu item: + Offline E&xplorer: Download the current page - file://C:\Program Files\Offline Explorer Enterprise\Add_AllO.htm
O8 - Extra context menu item: Add to AD Black List - C:\Program Files\Avant Browser\AddToADBlackList.htm
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Block All Images from the Same Server - C:\Program Files\Avant Browser\AddAllToADBlackList.htm
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Download All Files by HiDownload - C:\Program Files\HiDownload\HDGetAll.htm
O8 - Extra context menu item: Download by HiDownload - C:\Program Files\HiDownload\HDGet.htm
O8 - Extra context menu item: Download using LeechGet - file://C:\Program Files\LeechGet 2003\\AddUrl.html
O8 - Extra context menu item: Download using LeechGet Wizard - file://C:\Program Files\LeechGet 2003\\Wizard.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Highlight - C:\Program Files\Avant Browser\Highlight.htm
O8 - Extra context menu item: Open All Links in This Page... - C:\Program Files\Avant Browser\OpenAllLinks.htm
O8 - Extra context menu item: Parse with LeechGet - file://C:\Program Files\LeechGet 2003\\Parser.html
O8 - Extra context menu item: Search - C:\Program Files\Avant Browser\Search.htm
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Research (HKLM)
O9 - Extra button: HiDownload (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{9466BF91-F874-434F-A6FD-0F6290318E1F}: NameServer =

Dani AI

Generated

Good summary from and sensible first step from — unzip HijackThis into its own folder and let it make backups before fixing anything. The symptoms (an executable in System32 that recreates a startup entry and causes popups) are classic of a downloader/adware that uses multiple persistence tricks, so a staged cleanup is safer than one-shot removals. See a compact removal workflow and rationale at the BleepingComputer removal guide and use a comprehensive autorun scanner such as Autoruns for discovery. (bleepingcomputer.com)

Recommended workflow (order matters): boot to Safe Mode so active protection from the malware is reduced; use a process-killer helper (RKill) and run an up‑to‑date on‑demand scanner (Malwarebytes or Microsoft Safety Scanner) to remove obvious components; then run Autoruns to locate and delete all autostart entries that point to the malicious file; finally stop the process (Process Explorer can show which process holds a file handle) and delete the executable from disk. Always keep registry/file backups and do removals from Safe Mode or offline media where possible. (bleepingcomputer.com)

If a Run key (or equivalent) comes back after reboot, persistence is likely implemented elsewhere (service/driver, scheduled task, hidden copy, or rootkit). At that point run an offline/rootkit-capable scan (Microsoft Safety Scanner / Defender Offline or a vetted rootkit scanner) and verify startup locations again with Autoruns before rebooting. After cleanup, restore clean proxy/hosts settings and rotate any passwords that were used on the machine. If multiple persistence mechanisms remain or signs of credential theft exist, full image/OS reinstall is the most reliable recovery. (learn.microsoft.com)

Cautions: do not use “Fix checked” blindly — remove only items that are identified as malicious or that match the exact file paths found on disk. Keep copies of logs (HijackThis, Autoruns, Process Explorer) for specialist review and avoid revisiting risky sites that likely caused the original infection.

Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. (Not a temporary folder or directly on the desktop & not directly on your hard drive). Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' :

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.