got ambushed last night. now wallpaper can't be changed

Discussion in 'Malware Help (A Specialist Will Reply)' started by howardturkster, Aug 25, 2008.

  1. howardturkster

    howardturkster Private E-2

    My computer got raided last night by a gang of trogans and other malware. I went through the removal procedures, and I was wondering if someone could tell me (a) if I got it all, and (b) how do i fix the desktop background problem.

    I'll attach all the necessary reports in this post and the next post.

    Thanks.
     

    Attached Files:

  2. howardturkster

    howardturkster Private E-2

    The second superantispyware report is a complete re-scan after everything else was done. also attached is a hijack this log and the mgtools log. Thanks.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You don't need to attach HijackThis logs.

    Your logs are basically clean but I would like to get some more info on the C:\Windows\kx43998.dll file I see in your logs. Locate it using Windows Explorer and then right click on it and select Properties. Now see if there is a Version tab in the window. If so, select the Version tab and on the next window select each of the listed Item names (one at a time) to get more info about the file. The most important Item is the company name. If there is no Version tab, tell me that too.


    If you are having problems setting your background, make sure that you are not blocking any changes with WinPatrol, ZoneAlarm, or any other program.
     
  4. howardturkster

    howardturkster Private E-2

    Hi Chaslang,
    Thanks for your time.

    When right-clicking and clicking properties, I see no version tab, only 'general', 'security' and 'details'. Under details it says it was created on Sunday, August 24th, and 10:01 PM, which I believe was just around the time of the attack on my computer. Under copyright on the details tab it says Microsoft Coproration (but due to your suspicion I guess that is most likely not true).

    Thanks.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I suggest that you rename the kx43998.dll file to kx43998.ddd

    And then just use your PC normally over the next week or so to see if everything works okay and that nothing mentions this missing file. If everything is alright after a week, you can just delete this file.


    Now we need to cleanup some items from running ComboFix.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  6. howardturkster

    howardturkster Private E-2

    Done (I did get a success message) and done.

    Last thing - I'm wanting to remove Zonealarm because I'm unhappy with it and install one of the other programs listed on the link you provided. Can you lend any advice on how to do this? I've googled the matter extensively, tried everything, and still can't get it done. Uninstalling from the add/remove menu doesn't work, nor does running the uninstall from the start menu programs list. Each time it says other programs are using the True Vector Monitor and that it has to be shut down first. Unchecking "startup with windows" on Zonealarm doesn't stop this. I've tried a few other ways mentioned on the net for disabling True Vector and every time I get "access is denied". I even tried rebooting into safe mode, and then manually deleting the program per instructions from the zonealarm forums (including deleting registry settings) - this really messed things up as I could no longer connect to the internet and was not even generating an IP number when looked up in ipconfig. So I restored saved registry settings and tried system restore for the rest of the stuff I deleted (hopefully that was successful... I had to leave for work after I ran it, so not positive).

    Anyway, sorry for that whole spiel, just thought I'd see if you could assist. Thanks.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You had ZoneAlarm Internet Security Suite installed. When you uninstalled it did you uninstall everything? Did you shutdown other all other applications including browsers first? You should make sure that WinPatrol is not running!!! You may want to try reinstalling ZoneAlarm. Then reboot. After the reboot shutdown ALL unnecessary programs (SUPERAntiSpyware, WinPatrol and any other programs) and also browsers. Exit all components of ZoneAlarm that it allows you to shutdown (firewall, antivirus....etc). Then in ZoneAlarm has there own uninstall program appearing in the Start Menu, use it to uninstall. If not, just try Add/Remove programs again and make sure you reboot immediately after the uninstall. Let me know what happens.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds