b111.exe working

Discussion in 'Malware Help (A Specialist Will Reply)' started by platphoto, Oct 24, 2006.

  1. platphoto

    platphoto Private E-2

    here's my stuff. I'm not getting all of the earlier problems, but machine is still a bit wacky. Apparently .log file's no good, but I can't change the file submissiion.
    I'll try a second post.
     

    Attached Files:

  2. platphoto

    platphoto Private E-2

    Here's Hijackthis log in .txt format
     
  3. matt.chugg

    matt.chugg MajorGeek

    What earlier problems ?

    What about the BDScan and Active scan logs ?
     
  4. platphoto

    platphoto Private E-2

    Earlier problems were the b111.exe warnings. That's gone but system's running problematic. IE7 locks up all the time. I was following the b111.exe routine for the log files submitted.
    From this post: http://forums.majorgeeks.com/showthread.php?t=35407

    Where do I go for the BD and Active Scan Logs?
     
  5. matt.chugg

    matt.chugg MajorGeek

    The link you posted contains the read and run me, those scans are part of this procedure.
     
  6. platphoto

    platphoto Private E-2

    Here are logs:
     

    Attached Files:

  7. matt.chugg

    matt.chugg MajorGeek

  8. platphoto

    platphoto Private E-2

    Paragraph 6a logs, BD etc.

    Logs from 6A attached. "shownew" to come
     

    Attached Files:

  9. platphoto

    platphoto Private E-2

    Re: b111.exe working Here's "ShowNew"

    Here's Newfiles.txt..forgot about this post
     

    Attached Files:

  10. matt.chugg

    matt.chugg MajorGeek

    Sorry for the delay,

    please follow the step here: Virtumonde aka Trojan Vundo Removal


    post a new HJT, Activescan and shownew logs once its complete. (along with the vundo fix log)

    Again, sorry for the delay.
     
  11. platphoto

    platphoto Private E-2

    Here are updated logs. Fourth to come in next email.
     

    Attached Files:

  12. platphoto

    platphoto Private E-2

    ActiveScan log
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 5
    MarketResearch
    MediaTickets by OIN

    Continue by downloading a tools we will need - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,euxwvhp.exe
    O2 - BHO: (no name) - {073D18D0-25CE-A963-D9D8-02EA73AD287F} - C:\WINDOWS\system32\glfxvlc.dll (file missing)
    O2 - BHO: (no name) - {35FB2B87-8524-4D3D-A6C9-A8C488D2BC1E} - C:\WINDOWS\system32\jkkjk.dll (file missing)
    O2 - BHO: (no name) - {6C9E96DA-9F99-547D-601E-0771645DE79B} - C:\WINDOWS\system32\klxdzpc.dll (file missing)
    O2 - BHO: PrintViewBHO Class - {D4E0C464-30CE-4075-9A10-71FD106C2847} - C:\PROGRA~1\PRINTV~1\PRINTH~1.DLL (file missing)
    O4 - HKLM\..\Run: [ciaqnof.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\ciaqnof.dll,bgocigf
    O4 - HKLM\..\Run: [chegka] C:\WINDOWS\system32\dpaolc.exe reg_run
    O4 - HKLM\..\Run: [IpWins] C:\Program Files\ipwins\ipwins.exe
    O4 - HKLM\..\Run: [PVModule] C:\PROGRA~1\PRINTV~1\pvmodule.exe
    O4 - HKLM\..\Run: [epyxjlb.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\epyxjlb.dll,jlxzcpe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [yekim] C:\WINDOWS\system32\dpaolc.exe reg_run
    O15 - Trusted Zone: http://*.trymedia.com (HKLM)
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
    O20 - Winlogon Notify: jkkjk - C:\WINDOWS\system32\jkkjk.dll (file missing)
    O20 - Winlogon Notify: winsdc32 - winsdc32.dll (file missing)
    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Program Files\Common Files\{48036713-06A1-1033-1028-050513200001}\Update.exe
    C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
    C:\WINDOWS\ckgvc.dll
    C:\WINDOWS\system32\ciaqnof.dll
    C:\WINDOWS\system32\epyxjlb.dll
    C:\WINDOWS\system32\euxwvhp.exe
    C:\WINDOWS\system32\dpaolc.exe
    C:\WINDOWS\system32\glfxvlc.dll
    C:\WINDOWS\system32\klxdzpc.dll
    C:\WINDOWS\system32\kjkkj.ini
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folders and delete if found:
    C:\Program Files\PrintView
    C:\Program Files\ipwins
    C:\Program Files\Common Files\{38036713-06A1-1033-1028-050513200001}
    C:\Program Files\Common Files\{48036713-06A1-1033-1028-050513200001}

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\HP_Administrator\Local Settings\Temp

    Now download and unzip the current versions of ShowNew and GetRunKey to use to get the new logs below.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  14. platphoto

    platphoto Private E-2

    Finished all of the routines.
    LogFiles attached:
    Haven't run long enough to tell about success but all has been good to this point so far.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now attach new logs from GetRunKey and HJT! Don't wait so long this time before completing instructions. The longer you wait, the more damage that malware can cause and the less effective any steps will be in fixing problems. Normally if some one has not completed instructions in a thread and more than a week has passed, we require that the READ ME be run from beginning to end again.
     
  16. platphoto

    platphoto Private E-2

    One more time...:D
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your clean! How are things working?

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  18. platphoto

    platphoto Private E-2

    All is well except when I install "AVAST" it locks me off network (this machine is connected through wireless router)
    I can't find settings to open network so I have to uninstall AVAST to get online.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Installing Avast should not be affecting your network. It is not a firewall that could block various processes or applications from getting to the internet. BUT WHY are you installing Avast? You already had CA antivirus installed. You must only use one antivirus. You don't need to install an antivirus in step 2 if you already have one.
     
  20. platphoto

    platphoto Private E-2

    OK...I had thought Avast might be preferred since CA didn't keep me from getting into this mess in the first place.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But you would have to uninstall CA first, before installing Avast. Installing multiple antivirus applications can mess up the Windows Security Center. In addition CA is also providing you a firewall. This came from Yahoo. If you uninstall CA (that is the Yahoo stuff) you will have to install a firewall as mentioned in step 3 of the How to protect thread.
     
  22. platphoto

    platphoto Private E-2

    Dell notebook issues

    After shutting down my Dell notebook last night, I woke up to:
    "\systemroot\system32\config\SAM corrupt/absent or not writable" I frequently just close notebook and let it go into standyby/hibernate. So I'm not sure how long this p[roblem may have existed.
    I reloaded WindowsXP Home from dos prompt and all seems to be OK except my wireless connection is no longer detecting ANY nearby networks (including my own).
    What's up with that?
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Dell notebook issues

    Sorry but these are not malware issues! Try the networking forum for your wireless connection problems.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds