Advise on removing trojan virus

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by roadracer03, Dec 17, 2004.

  1. roadracer03

    roadracer03 Private E-2

    Hi all, I'm having a bit of a challenge getting rid of a trojan virus. Path is C:\windows\system\i2tcpu87fsilk.dll

    I have windows ME but had 98 to start with, changed to ME about 4 yrs ago.

    I did all of the things in the "read me first" thread except a couple of things.

    1. I can't boot up in "safe mode with networking support" only safe mode.
    2. I can't run the online scans but ran everything but about:buster or HSRemove.

    I'm a average computer challanged person so what ever you have me do I'll have to print out (like I did the read me first thread for trojan....) and then try

    Any idea on what I can do to get rid of this?

    Thanks for all your help with this.

    I appreciate it,

    Brian
     
  2. jarcher

    jarcher I can't handle a title

    Re: Advice on removing trojan virus

    what caught the virus
    how do you know it was there
    what anti virus,rather?

    why not?
    go ahead and run them
    or are they not 98 compat.

    you can do the online scans in normal mode

    go back to the read me(to see if you missed anything else)

    if proven unsucessful run through this before attaching a log
    NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting:
    Note that your HijackThis should be up-to-date (v1.98.2) and MUST be extracted to its own safe folder - C:\Program Files\HijackThis! Please do this!!!

    If you need a Fresh Download of HJT, get it HERE: HijackThis 1.98.2
     
  3. roadracer03

    roadracer03 Private E-2

    Ok ran the online scans. It found 2 virus'. troj lookme.d and troj dloader.j I ran everything again and nothing was caught. I put all my restore and hidden files back to norm. (the opposite of step one) and it came back. It's changing my home page. I have norton AV and I make sure my definitions are up to date. I'll try the link you gave me and see what happens.

    Thanks,

    Brian
     
  4. roadracer03

    roadracer03 Private E-2

    I've got my log if anyone cares to see it.

    Thanks

    Brian
     
  5. jarcher

    jarcher I can't handle a title

    Re: Advice on removing trojan virus

    I myself am fair at analyzing logs, I admit I am not great
    but I will look at it
     
  6. roadracer03

    roadracer03 Private E-2

    Ok, before I did this I ran my Ad-aware and then spybot with both of them having updates.

    Well I tried uploading my .log file but it says uploading error invalid file type.

    Any ideas?

    Thanks again,

    Brian
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure the file is a .log or a .txt file. You probably have the wrong file extension on it.
    I log that is directly saved from HijackThis should be a .log file.
     
  8. roadracer03

    roadracer03 Private E-2

    it says it's a log file but still says it's a invalid file type and I saved it directly from hijack this. I'm some what computer challanged but I usually have not problems uploading files. I'm not sure what to do now.

    Thanks again for all the help,

    Brian
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just cut and paste the text from notepad into a message and I'll change it into an attachment for you.
     
  10. roadracer03

    roadracer03 Private E-2

    Ok here is my lastest HJT scan. I did everything again in the tutorial except the about:Blank and HSRemove.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't appear to need about:Blank or HSremove. You do not have those hijacks.

    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).
    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Look for the below process(es) and if found, End them:
    zvrknc
    hkiveao

    I'm leaving things in below to fix from Weatherbug just incase the uninstall does not work.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://win-eto.com/hp.htm?id=31403
    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [zvrknc] C:\WINDOWS\SYSTEM\zvrknc.exe
    O4 - HKLM\..\Run: [hkiveao] C:\WINDOWS\SYSTEM\hkiveao.exe
    O4 - HKCU\..\Run: [Yahoo! Pager] 1
    O4 - HKCU\..\Run: [Weather] C:\PROGRAM FILES\AWS\WEATHERBUG\WEATHER.EXE 1
    O4 - HKCU\..\Run: [romahere3] C:\WINDOWS\SYSTEM\SML6MGUKV2O.EXE
    O4 - HKCU\..\RunServices: [Yahoo! Pager] 1
    O4 - HKCU\..\RunServices: [Weather] C:\PROGRAM FILES\AWS\WEATHERBUG\WEATHER.EXE 1
    O4 - HKCU\..\RunServices: [romahere3] C:\WINDOWS\SYSTEM\SML6MGUKV2O.EXE
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\SYSTEM\zvrknc.exe
    C:\WINDOWS\SYSTEM\hkiveao.exe
    C:\PROGRAM FILES\AWS\WEATHERBUG <--- the whole directory
    C:\WINDOWS\SYSTEM\SML6MGUKV2O.EXE

    Reset Web Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  12. roadracer03

    roadracer03 Private E-2

    Great I'll give it a try when I get home from work today since I don't have time this morning to do it.

    Thanks again I really appreciate it.

    Brian
     
  13. roadracer03

    roadracer03 Private E-2

    Well here's the new log. Looks like it's still here. :(
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not fix the location of HJT yet. You still have it here:
    C:\WINDOWS\DESKTOP\MY BRIEFCASE\NEW FOLDER\HIJACKTHIS.EXE

    And I would not say "it is still there"! We have fixed a load of problems.

    Download Pocket KillBox from here: http://www.downloads.subratam.org/KillBox.zip
    Unzip it to a folder where you can find it. Do not run it yet.

    You may want to print these instructions for reference, since you will need to close all windows to perform some of the actions below. Make sure your read thru this and ask questions before starting because when you start working on these instructions, you must do them all without stopping. Otherwise you will have to start all over again. If you encounter a problem with a step, move on to the next.

    Make sure viewing of Hidden Files and Folders is enabled per the tutorial!

    Now exit all browser sessions and stay offline.

    Run Pocket Killbox now by double clicking on Killbox.exe. Select the option: Delete on Reboot.

    In the Full Path of File to Delete box, copy and paste this entry:
    C:\WINDOWS\SYSTEM\3FEM2R~1.DLL
    Press the button with a red circle and a white X.
    When asked if you would like to Reboot, select No.

    Once again, in Full Path of File to Delete, copy and paste the following:
    C:\WINDOWS\SYSTEM\KUJUXEL97RGSKTHD.EXE
    Press the button with a red circle and a white X.
    When asked to Reboot, select Yes. But do not go back online. Stay disconnected.

    Next, launch Notepad (Start>Programs>Accessories>NotePad), and copy and paste all the two bold print lines below into it
    Go to File, in the upper menu bar, and select: Save As
    In the Save in column, look for: Desktop (You can save it anywhere you like as long as you can find it later).
    In File Name, type in: fixme.reg
    In Save as Type, use: All files (*.*)
    Click: Save

    REGEDIT4

    [-HKEY_CLASSES_ROOT\CLSID\{467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E}]

    Now, back on the Desktop, double-click on the fixme.reg file you just saved and click on Yes when asked to merge the information.

    Now, reboot into Safe Mode!

    Fix with HJT
    Now, reboot into Safe Mode! And run only HijackThis and have it Fix the following lines:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://win-eto.com/hp.htm?id=9
    O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - C:\WINDOWS\SYSTEM\3FEM2R~1.DLL
    O4 - HKLM\..\Run: [Control handler] C:\WINDOWS\SYSTEM\KUJUXEL97RGSKTHD.EXE
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    Empty Temp Folder
    Next, still in Safe Mode, go to Start>Run, and type in: %temp%
    Click OK
    When the contents are displayed, press the following two keys simultaneously: Ctrl+A to select all
    Hit Delete on the keyboard

    Look for any other bad files:
    While still in SafeMode, goto C:\Windows\system, and Sort by Date Created. Tell me if you see any other files recently created (within the last day or two) with suspiciously or randomly named .dll's, .tlb's, or .exe's (including KUJUXEL97RGSKTHD.EXE)


    Reset Web Settings
    Now click Start, Settings, and select Control Panel, and double click:Internet Options.
    On the General tab under: Temporary Internet Files, click: Delete Files
    [Place a check by: Delete Offline Content when the prompt appears, and click OK]
    Once again, under: Temporary Internet Files, click: Delete Cookies
    Next, select the Programs tab, then click: Reset Web Settings
    Now go back to the General tab and set your home page back to what you use.
    Click Apply, then OK.

    Empty your Recycle Bin.

    Reboot to Normal mode.

    Now run CWShredder and make sure you click Fix.

    Now run AdAware SE and:
    -Use the: Check for Updates Now option and download the latest reference files
    -Use the Start button, and on the next window, select: Perform Full System Scan
    -Press Next, and let Ad-aware scan the hard drive
    -When finished, right-click the window with the entries, choose: Select All from the menu, and click Next
    -Once AdAware has removed the entries, close the program

    Restart the computer.

    Now post a new HJT log and tell me how things are working.
     
  15. roadracer03

    roadracer03 Private E-2

    Well here it is. I think it all gone. Thanks chaslang for all your help!!!

    Brian
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds