jkhhe.exe

Discussion in 'Malware Help (A Specialist Will Reply)' started by tm711, Jan 17, 2008.

  1. tm711

    tm711 Corporal

    Yesterday the laptop was working fine. On the usual sites and than bam it starts slowing down, so I restart it and I get this message that says "C:/WINDOWS/system32/jkhhe.exe. Make sure you typed the name correctly, and then try again. To search for file, click the start button, and then click search." It has a ok button which I hit and then another message pops up Desktop 'Could not load or run 'C:/WINDOWS/system32/jkhhe.exe' specified in the registry. Make sure this file exists in your computer or remove the reference to it in the registry." I click ok and nothing. I searched the registry and the closest thing I could find on in search is jkhhe.dll application extension. The kicker is I can't use the Internet it won't connect. I have done crapcleaner,ad-aware, ez antiviral and hijackthis with nothing coming up. I can't download any new removel systems because I can't connect to the internet. Thanks for any help in advance.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide


    If you cannot download the tools on the problem PC, you will need to download them using another PC and then transfer them to the problem PC using a USB drive, a CD,.....etc. The same will be true for the logs but in reverse order.
     
  3. tm711

    tm711 Corporal

    I have scanned my laptop with: Ad-Aware, CrapCleaner, Spybot, EZ antivirus, AVG antispyware, Combofix, MGtools. Logs for AVG, Combofix, and MGtools are attached. I downloaded AVG, Comgofix, and MGtools to a disc on another computer and transferred them to the lap top that way. I do have Hijack this installed and can run that from the laptop.

    After running Combofix I no longer get the messages that I got yesterday.

    But when I try to connect to the net I get a message that says that windows cannot renew my IP address. The laptop is on a wireless network that runs through the PC. The PC works fine.

    Also, I cannot restore to any points before the laptop went bad. All restore points prior to 1/18 no longer exist.

    I suspect that parts of this trojan (or whatever it is) still linger in my system or else my registry is messed up, but I have no idea what to do about it.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not follow the instructions in the READ & RUN ME properly. In the very first steps we specify that you must not have more than one antivirus program installed. You have both CA Etrust and McAfee installed. Once of these must be uninstalled immediately. If you uninstall McAfee then also run the below after uninstalling it:

    McAfee Consumer Product Removal Tool

    You also need to uninstall Viewpoint Media Player as requested in step 1.

    You do need to uninstall Java 2 Runtime Environment, SE v1.4.2_03 which is 3 or more years out of date and is a major security risk, but we will wait until you have an internet connect so you can also update to the current version.

    You don't need it. It is already embedded in MGtools.

    Installing multiple antivirus program and multiple firewalls (not sure it you had more than one firewall) can break many things.


    What is in the below folder? Do you recognize this folder?
    2008-01-16 11:46 . 2008-01-16 11:46 <DIR> d-------- C:\temp\Ryuan1


    *** IMPORTANT WARNING ****

    You have a Trojan.Bancos infection.
    You are strongly advised to do the following immediately:
    1. Disconnect infected computer from the internet and from any networked computers until the computer can be cleaned. If you have network compters, start checking them for problems too.
    2. Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
    3. From a clean computer, change *all* your online passwords -- for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
    Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passords and transaction information.



    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [SPOLSV] C:\WINDOWS\system32\tracerts.exe

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  5. tm711

    tm711 Corporal

    I have done all the steps you requested.

    Uninstalled Mcafee and ran the Product Removal Tool. There was this message after running the tool, "I Task Scheduler::Delete() failed".

    Uninstalled Viewpoint.

    I do not recognize the file C:\temp\Ryuan1.

    Removed Windows Messenger.

    Ran HJT. C:\Program Files\Messenger\msmsqs.exe was not there. The other two items were, and they have been fixed.

    Ran Avenger - log attached

    Ran CCleaner.

    Ran GetLogs -log attached

    Still no internet connection but considering my problem that is not important right now.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then delete that folder.

    Also delete the below file:
    C:\WINDOWS\mrofinu572.exe.tmp


    Other than the above your logs are clean, but you should consider whether you can really trust this PC anymore. Do you use it for any financial transactions? If so, you may really want to consider, a total reinstall after deleting your partition. Do not just reinstall, you must delete the partition to be safe.

    It's your decision on how you want to proceed.


    Not sure if you want to try fixing this or you want to reinstall. Running the below, may or may not fix your connections issues:

    XP TCP/IP Repair
     
  7. tm711

    tm711 Corporal

    Thank you very much. This is the most awesome site on the web!

    It was the lap top which was infected. I have scanned the PC with 5-6 different programs and it is comes up clean. I will check out the link you have provided. I do not know what delete the partition means.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That still is not a guarantee. We always see people reporting that all scans are clean but when we look at the logs we ask for, we always find problems.

    See this: http://support.microsoft.com/kb/313348

    There are many links on the internet that discuss things like this. disk partitioning is the creation of logical divisions upon a hard disk that allows one to apply operating system-specific logical formatting. See: http://en.wikipedia.org/wiki/Disk_partitioning
     
  9. tm711

    tm711 Corporal

    I have run all the steps in malware removal on the pc. The logs are attached. AVG would not generate a report, but it found Adware.Websearch, and said that there was one trace HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\User Data\AVI. Now that the laptop is running, I thought that I should check for any problems on the PC. Also, the lap is now connecting to the internet - I have made no changes to it since I last posted logs etc on here.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you know what the below folder is for?
    Code:
    C:\Program Files\
    118_PR~1      Jan 18 2008              "118_problems"
    Now let's remove a bad service.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to .NET Framework Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste.NET Connection Service into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Uninstall the below software:
    Java 2 Runtime Environment, SE v1.4.0_01
    LiveReg (Symantec Corporation)
    LiveUpdate 1.6 (Symantec Corporation)

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU
    O4 - HKCU\..\Run: [ PAL Evidence Eliminator] C:\Program Files\PAL Evidence Eliminator\Cleaner.exe
    O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  11. tm711

    tm711 Corporal

    Sorry for the delay chas but I got called out of town on business.

    Deleted the flder 118_problems. It was a temp folder I hade made and I forgot to delete it. It is gone now.

    Getting rid of .Net Framework Service the stop button would no operate. I set startup to Disable. When I exited it was shown as disabled.

    Ran HJT (not MGtools) and did as instructed, everything went ok.

    Removed Java 2 Runtime from the Control Panel.

    Rebooted from Stop.

    Installed new Java Runtime.

    Ran HJT; did all 5 fixes.

    Merged fixme with registry as instructed.

    Downloaded Avenger as instructed and ran it. At reboot there was a command prompt that said it could not find C:Avenger. Is this because I saved it to the desktop and not to the C drive?

    Ran CCleaner.

    Logs attached.

    I have noted that reboots faster than it did before.

    Also at last reboot, my firewall asked I would allow netstat.exe to access the internet- I denied it.
     

    Attached Files:

  12. tm711

    tm711 Corporal

    As a follow up to the netstat thing, perhaps this will save some time.

    I did a search, and I have the following:

    NETSTAT.EXE in I386, properties attribute it to microsoft.

    NETSTAT.EX_ in I386, version is unknown.

    NETSTAT.EXE-o4F18BCO.pf in Windows\Prefetch

    netstat.exe in System32.

    netstat.exe in Windows Service Pack Files\I386.

    I typed the file names just as they appear (all caps or all lower case).

    At command prompt ran netstat, the result are attached as a notepad file.

    Checked my Firewall log and I am getting repeatedly hit by 24.64.***.***, is this related to netstat?

    I hope this helps.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Netstat is run by GetRunKey.bat which is part of MGtools but it is not run at reboot. It is run when you run GetLogs.bat. Is that what you really meant, or did you really mean during boot?

    Please give the full IP address.


    Your logs are clean.
     
  14. tm711

    tm711 Corporal

    It asked if I wanted to run netstat at reboot. It has not done it again.

    The IP is 24.64.89.59.16614. But the IP varies like this: 24.64.***.***.***

    I did some research on netstat, and I was wondering if I had a bad netstat would my firewall be blocking this IP so much? In other words, have I been hacked?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would assume that IP address is your ISP?
    Code:
    [B]IP Address[/B]   : 24.64.89.59 [ S0106001636c8cdce.cn.shawcable.net ]
    [B]ISP          :[/B] Shaw Communications
    [B]Organization :[/B] Shaw Communications
    [B]Location     :[/B] [IMG]http://img.cqcounter.com/flags/ca.gif[/IMG] CA, Canada
     
     
  16. tm711

    tm711 Corporal

    No. That is the one that my firewall has to block repeatedly.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Perhaps you need to check who is actually providing your internet service. Shaw Communications is a legit ISP.

    Are you using Road Runner now?

    Did you use to use Shaw?

    Does Road Runner lease from Shaw?

    Attach a piece from your firewall log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds