Help!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by ArPa, Oct 9, 2007.

  1. ArPa

    ArPa Private E-2

    A couple of days I got internet in my house. Since that day my computer started acting kinda weird and then all these pop-up windows started coming up saying that I needed to run a scan cause someone gained unauthorized access to my computer.

    I called my ISP and told them the problem I had so they directed me to this web page. I already read and followed step-by-step the READ AND RUN ME FIRST guide and now I have the log files.

    Please help me fast and I would really, really appreciate it very much. Thanks!!

    PS. Part 1 of 2
     

    Attached Files:

    Last edited: Oct 9, 2007
  2. ArPa

    ArPa Private E-2

    Here's the rest of the log files.

    PS. Part 2 of 2
     

    Attached Files:

  3. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, we need to rename HijackThis to "analyzethis.exe".

    Before attaching the new log, run the scan below.

    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    After completing the below, attach fresh logs from the below...

    • GetRunKey
    • ShowNew
    • HijackThis
    • ComboFix
     
  4. ArPa

    ArPa Private E-2

    Ok, here are the new log files. I will send them in 2 separate messages cause I could only upload 3 at a time.

    PS. Part 1 of 2
     

    Attached Files:

  5. ArPa

    ArPa Private E-2

    Here is the second part.

    PS. Part 2 of 2
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, please disable any antivirus and/or antispy programs you have installed so they will not block this fix.

    Step 1:
    First, we need to disable and remove a service.
    • Now Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to SupportSoft Sprocket Service
    • Then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste ddoctorv2 into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Step 2:
    Now scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )

    Again, make sure ALL browser windows are closed when you click FIX.

    Step 3:
    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    Step 4:
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt

    Step 5: Begin here after rebooting from Step 4!
    Next Reset Web Settings & Default Security Settings

    Note for IE 6 users:
    To Reset Web Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK

    To Default Security Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Security Tab and click Default Level for Internet, Local Intranet, Trusted Sites, and Restricted Sites. For IE 7 users, simply click the "Reset all zones to default level" button.

    Note for IE 7 users:
    Select Internet Options, then the Advanced Tab and then the Reset button under Reset Internet Explorer Settings.


    Step 6:
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.


    Step 7:
    After you have completed ALL of the above in the correct order, please attach the following logs.
    • HijackThis Log
    • ShowNew Log
    • GetRunKey Log
    • Avenger Log
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  7. ArPa

    ArPa Private E-2

    Ok, here are the new log files. When I ran HijackThis I wasn't able to find: 02-BHO: (no name) {411F7CBB-EFA2-4275-8BB4-6A57-2415-986E} C:\WINDOWS\system 32\jkhhh.dll. I dont know what you want me to do about it. Also, my computer isn't letting me download stuff off the internet so I had to look for someone else and download it for me. What can I do to fix this.

    PS. Part 1 of 2
     

    Attached Files:

  8. ArPa

    ArPa Private E-2

    Its not letting me upload the avenger.txt. I opened it and its a blank document. What do I do next?
     
    Last edited: Oct 10, 2007
  9. ArPa

    ArPa Private E-2

    Ignore message posted today at 10:39.

    I re-did the avenger.exe scan and was able to obtain a log file so here it is.

    PS. Part 2 of 2
     

    Attached Files:

    Last edited: Oct 10, 2007
  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, have HJT fix the below entry.

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme1.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme1.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    Finally, we need to run Avenger once more, just like you did before.

    Once completed, attach fresh logs from the below.

    • GetRunKey
    • ShowNew
    • HijackThis
    • Avenger
     
    Last edited: Oct 19, 2007
  11. ArPa

    ArPa Private E-2

    I wasn't able to find... O2 - BHO: (no name) - {6BDBFC07-B779-4929-9D2F-8A6EE3BDF1ED} - C:\WINDOWS\system32\jkhhh.dll... but I found this one... 02 - BHO: (no name) - {CAD0343B-536D-481C-93CE-E800E0B7D6A} - C:\WINDOWS\system32\jkhhh.dll... I'm not sure if this is the right one. Let me know so I can continue. Thanks!!
     
  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    You are going to have to stop rebooting, once you attach your logs, you must NOT reboot or else this mutates causing it to change names making the fixes useless.

    Follow the previous fix, attach new logs and do not reboot until you hear back from me.
     
  13. ArPa

    ArPa Private E-2

    Here are the new log files.

    PS. Part 1 of 2
     

    Attached Files:

  14. ArPa

    ArPa Private E-2

    Here are the rest.

    PS. Part 2 of 2
     

    Attached Files:

  15. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, uninstall Windows Defender and AVG Anti-Spyware, also disable anything else as in antivirus or antispy applications.

    Once you have completed the above, do NOT reboot yet.

    Have HJT fix the below entries...

    Next, run Avenger again just like you did before....

    Once you complete the above, attach fresh logs from the following:

    • GetRunKey
    • ShowNew
    • HijackThis
    • Avenger
     
    Last edited: Oct 14, 2007
  16. ArPa

    ArPa Private E-2

    Here are the new log file.
     

    Attached Files:

  17. ArPa

    ArPa Private E-2

    Here are the new log file.
     
  18. ArPa

    ArPa Private E-2

    Here are the new log file.
     
  19. ArPa

    ArPa Private E-2

    I tried uploading hijackthis log file and it says its already there. How can I upload it again?
     
  20. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Copy and paste it inline and I will attach it for you.

    I also need the new Avenger log, I left that out in my last post.
     
  21. ArPa

    ArPa Private E-2

    Im not sure if this is what Im supposed to do but here it is...

    Originally Posted by ArPa
    I tried uploading hijackthis log file and it says its already there. How can I upload it again?

    Im attaching the avenger log file but it said there was an error saving the .zip file. Dont know if I did something wrong.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Avenger did not run properly. Try shutting down your antivirus and any other protection software and running the Avenger fix again. Then attach the logs BJ requested again.

    You have to get a NEW HJT log or it will not attach. The same goes for all logs!
     
  23. ArPa

    ArPa Private E-2

    It's still not letting me run the Avenger. I follow the steps and still gives me the same error.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you shut down both AVG Antispyware and AVG 7 antivirus?

    Please attach a new HijackThis log either way.
     
  25. ArPa

    ArPa Private E-2

    Yes, I shut both of them down since BJ told me to and he also said not to reboot my computer till he told me and I havent since.

    Its still not leting me attach the log file of hijackthis. What do you want me to do? It keeps telling me that, that log file is already in the thread. Can I e-mail it to you? Ive attached the other two log files. Thanks!!
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This means you are trying to attach the same log as did last time. As stated in my previous message, you must get a new HijackThis log. That means you must run HijackThis and save a new log to attach.
     
  27. ArPa

    ArPa Private E-2

    I did what you said in the last message and this is what I got.
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is the below for?
    C:\Documents and Settings\Owner\Desktop\TrueTransparency\TrueTransparency\TrueTransparency.exe

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {CAA67599-E724-43E8-A2CE-F3B35ABDE000} - C:\WINDOWS\system32\jkhhh.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [^ORM`SQT] C:\puiwhclf.bat
    O4 - HKLM\..\Run: [smddypbw] C:\irofwyeo.bat
    O4 - HKLM\..\Run: [obyexpoi] C:\jcvcagfb.bat
    O4 - HKLM\..\Run: [ladqltje] C:\epauckvw.bat

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Did you install the below keyloggers & dialer?
    Code:
    "C:\WINDOWS\"
    absolu~1.lnk  Oct  4 2007       29952  "absolute key logger.lnk"
    aconti.ini    Oct  4 2007       24064  "aconti.ini"
    aconti.sdb    Oct  4 2007       26880  "aconti.sdb"
    aconti~1.txt  Oct  4 2007       11776  "acontidialer.txt"
     
    "C:\WINDOWS\system32\"
    ACESPY        Oct  4 2007              "acespy"
     
    "C:\WINDOWS\system32\"
    ace16win.dll  Oct  4 2007       12288  "ace16win.dll"

    Right click Start and select Explore to open Windows Explorer. Use it to find and delete the below files if found:
    C:\Documents and Settings\yaqlctas.txt
    C:\Program Files\cobwriyp.txt
    C:\Program Files\analyse.exe.exe
    C:\puiwhclf.bat
    C:\irofwyeo.bat
    C:\jcvcagfb.bat
    C:\epauckvw.bat
    C:\WINDOWS\system32\drvmekr.dll
    C:\WINDOWS\system32\jkhhh.dll
    C:\WINDOWS\system32\ktasr.dll
    C:\WINDOWS\system32\systeminfo3.dll
    C:\WINDOWS\system32\hhhkj.bak1
    C:\WINDOWS\system32\hhhkj.bak2
    C:\WINDOWS\system32\hhhkj.tmp
    C:\WINDOWS\system32\hhhkj.ini
    C:\WINDOWS\system32\conf.dat
    C:\WINDOWS\system32\cookie1.dat
    C:\WINDOWS\system32\ps1.dat
    C:\WINDOWS\system32\rc.dat
    C:\WINDOWS\system32\drivers\arrow.gif
    C:\WINDOWS\system32\drivers\gb^ibmsp.sys
    C:\WINDOWS\system32\drivers\jkmcutic.sys

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.


    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  29. ArPa

    ArPa Private E-2

    This right here... C:\Documents and Settings\Owner\Desktop\TrueTransparency\TrueTransparency\TrueTransparency.exe... is a program that makes Windows XP windows become invisible but I don't need it anymore so it will be removed.

    I also ran the HijackThis and deleted the requested items. I also saved the fixme.reg to my desktop and added it to the registry.

    Concerning the keyloggers & dialers... from what I saw, I haven't installed any of those items.

    Also, I right-clicked the start menu and the computer did not let me delete... C:\WINDOWS\system32\jkhhh.dll and, I wasn't able to find...
    C:\WINDOWS\system32\hhhkj.bak1
    C:\WINDOWS\system32\hhhkj.bak2
    C:\WINDOWS\system32\hhhkj.tmp
    C:\WINDOWS\system32\hhhkj.ini

    I also ran the ATF-Cleaner and was able to delete lots of unnecessary stuff.

    Concerning the Avenger log. I tried running the previous message but it gives me an error message saying that it couldn't save the zip file. What can I do to attach it?

    Now, my computer is actually working a little faster than what it was but Im having problems downloading. In order for me to get the programs that the READ & RUN ME FIRST guide told me to, I had to look for someone else to download them for me and then I could install them. Also, everytime I change to a new window, pop-ups open. Some of them are inappropriate and its something that I don't want in my computer. Another thing is that, at first when I tried to open the task manager, it told me that it had been disabled by the administrator (which is me) and it wouldn't let me open it until now, so, I'm guessing that's a good sign, right? Well, let me know what I can do about the log file. I attached the GetRunKey, ShowNew and HJT.

    Thanks!!

    PS. When will I be able to activate the anti-virus and anti-spyware protection?
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because you never did step 2 of the READ ME properly and also the fixME.reg patch did not get added successfully to the registry. Do step 2 of the READ ME properly and then continue on with the below steps where we will use a different method to delete some stubborn files.

    First try the fixME.reg patch again and tell me if you receive a message saying it was successfully added to the registry.


    Continue by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    Make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of any of the below DLL files (if found) and then click the kill button.
    jkhhh.dll

    After you have killed all instances of any of the above DLLs under winlogon click ok.
    (If you do not find these DLLS, just continue on.)

    Next double click on explorer.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button.
    jkhhh.dll

    After you have killed all instances of any of the above DLLs under Explorer click ok.
    (If you do not find these DLLS, just continue on.)

    Next double click on iexplore.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button.
    jkhhh.dll

    After you have killed all instances of any of the above DLLs under iexplore click ok.
    (If you do not find these DLLS, just continue on.)


    Now just exit Process Explorer.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {CAA67599-E724-43E8-A2CE-F3B35ABDE000} - C:\WINDOWS\system32\jkhhh.dll
    O4 - HKLM\..\Run: [ubqcffrm] C:\hhagbrer.bat
    O4 - HKLM\..\Run: [gykixhnd] C:\cyhyevdu.bat
    O4 - HKLM\..\Run: [ahqnbmoc] C:\pqjkstsr.bat

    After clicking Fix, exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files
    it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and
    • choose copy):
    C:\hhagbrer.bat
    C:\cyhyevdu.bat
    C:\pqjkstsr.bat
    C:\WINDOWS\absolute key logger.lnk
    C:\WINDOWS\aconti.ini
    C:\WINDOWS\aconti.sdb
    C:\WINDOWS\acontidialer.txt
    C:\WINDOWS\btmgrbwy.txt
    C:\WINDOWS\ccibyawc.txt
    C:\WINDOWS\dsdxirmv.exe
    C:\WINDOWS\system32\ace16win.dll
    C:\WINDOWS\system32\jkhhh.dll
    C:\WINDOWS\system32\hhhkj.bak1
    C:\WINDOWS\system32\hhhkj.bak2
    C:\WINDOWS\system32\hhhkj.ini
    C:\WINDOWS\system32\drivers\anvmunvb.sys
    C:\WINDOWS\system32\drivers\nkrslhrp.sys
    C:\WINDOWS\system32\drivers\qduyryav.sys
    C:\WINDOWS\system32\drivers\tmabgcms.sys
    C:\WINDOWS\system32\drivers\uvhjvklc.sys
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now run ATF-Cleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  31. ArPa

    ArPa Private E-2

    First of all, the fixme.reg file, was added to the registry so there's no problem with that.

    I downloaded (well, had to ask someone else to do it for me) Explorer and Killbox and follow the instructions and everything went well. With the Explorer, I wasn't able to locate... jkhhh.dll... so I don't know if it was something I needed to find.

    I did not get any prompts concerning... PendingFileRenameOperations.

    I ran the ATF-Cleaner and here are the new logs.

    Thanks!!

    PS. Can I re-activate the virus and spyware protection?
     

    Attached Files:

    Last edited: Oct 16, 2007
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your antivirus is already running. You can reinstall AVG Antispyware after doing the below but if you are using the free version of AVG Antispyware it does not provide you any active protection after the 15 day trial period.


    Use Hijackthis to fix the below line:

    O2 - BHO: (no name) - {CAA67599-E724-43E8-A2CE-F3B35ABDE000} - (no file)

    Then Exit HijackThis.

    Now locate and delete the below files ( boot into safe mode and delete them if they will not delete in normal boot mode ):

    C:\Documents and Settings\llvyuhub.txt
    C:\windows\aconti.ini
    C:\windows\aconti.sdb
    C:\windows\acontidialer.txt
    C:\windows\dsdxirmv.exe
    C:\WINDOWS\system32\ace16win.dll
    C:\WINDOWS\system32\drivers\anvmunvb.sys
    C:\WINDOWS\system32\drivers\nkrslhrp.sys
    C:\WINDOWS\system32\drivers\oetyoesy.sys
    C:\WINDOWS\system32\drivers\tmabgcms.sys
    C:\WINDOWS\system32\drivers\uvhjvklc.sys


    Now delete the below folder:
    C:\WINDOWS\system32\acespy

    Now if in safe mode, get into normal boot mode and then attach new logs from ShowNew and HijackThis.

    How is everything working right now?
     
  33. ArPa

    ArPa Private E-2

    Ok, I deleted the files you requested in Safe Mode and this file... O2 - BHO: (no name) - {CAA67599-E724-43E8-A2CE-F3B35ABDE000} - (no file)... was not on the HJT. I'm guessing it was deleted somehow.

    Here are the new log files.

    The computer is actually working pretty good except that I still can't download stuff. And, I've been trying to check my e-mail (Yahoo!) and it gives me a page that says that it's not connected to the internet. Also, I'm having problems uninstalling programs. I want to uninstall programs I hardly use but it doesn't give me the option to do so. The only one's it does give me an option to uninstall, are the one's I installed after my computer got that virus but I can't uninstall the rest. Let me know what I can do about this.

    Thanks!!
     

    Attached Files:

    Last edited: Oct 16, 2007
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This may not be a malware issue. Make sure you have your network configured properly. Are you using a router? Make sure you have your PC setup for using DHCP and that it is getting an IP address asigned to it from either your router (if you have one) or your cable or DSL modem (which ever you use).

    This is not a malware problem. At some point in time (before you came here) you removed the uninstall information for all of your programs. When you first came here your first newfiles.txt log indicated that only the below programs still had uninstall information in your registry:
    And now you have since added the below to the list of installed programs

    The only possible solution for this would be to try and use system restore to go back to a point in time before you removed all of this information. And you would have to figure out when this was. Another slow solution is to reinstall all of your software and updates to get them back into the registry.

    NOTE: Doing a System Restore to a point where malware was still on you system, will result in restoring the malware too which means you will need to start at the begining of the READ ME process again to remove all malware.


    Please delete the below folder now:
    C:\!KillBox

    Your logs show no more signs of malware. I you are sure you have your network setup properly, you could try using the below to see if it will repair you internet connection.

    XP TCP/IP Repair
     
  35. ArPa

    ArPa Private E-2

    Currently, I'm not using a router but I plan to do that very soon.

    About the uninstalling part... I can re-install all the programs... that's no problem. I wouldn't want to do a System restore and have to re-do all this process and waste your time so I'll just re-instal everything.

    I have my my computer hooked up correctly so I'll run the link you sent me.

    Right now, the only thing I'm still having problems with is... downloading. I tried downloading the link that you sent and it gives me a HTTP 403 Forbidden window so I don't know what to do. That's just about it.

    Thank you so much for all your help. I think you just helped me saved well over $200 by guiding me throughout the whole process. You guys keep up the good work. I give you guys a thumds up!! Good luck!! :cool

    PS. Could I delete the programs I installed or do I need to keep them? And, do I need to keep the log files for every program I ran? Let me know, thanks!!
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So then are you saying you are getting and IP address and the you can surf the internet but you just cannot download anything?

    What browser are you using? If Internet Explorer, try using this: Mozilla FireFox


    You can uninstall anything that you don't want to keep around. Some of the items we gave you are not really installed. Thus you would just delete them. I will post our normal, final steps so you can see what we suggest removing. Anything not mentioned, is upto you whether you want to keep or not but many tools (like Process Explorer and Pocket Killbox) are worth keeping around and take up very little disk space.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  37. ArPa

    ArPa Private E-2

    Alrighty then... I deleted the files mentioned right there and I'll keep KillBox and Process. I'll also stop using IE and will download Firefox.

    Once again, thanks for all your help. I appreciate. Keep it up!!
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not answer my question! And I don't know that FireFox will definitely work for you. It all depends on what your connection problem is but it does not appear to be malware.
     
  39. ArPa

    ArPa Private E-2

    Well, I'll answer the questions from the previous message.

    Yes, I can surf the internet but I cannot download anything.

    I am using IE.

    PS. Do I need to keep... ComboFix-quarantined-files.txt?
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then check to make sure you are not blocking downloading in your settings. Also try FireFox and tell me if you can download with it.

    No you can delete it too.
     
  41. ArPa

    ArPa Private E-2

    How do I check if I'm blocking them? It started doing that after I got infected but before that, everything was perfect.

    I am currently using Firefox right now. I still haven't tried to download stuff but I will do that soon and I will let you know how it went in the next message.

    Thanks!!
     
  42. ArPa

    ArPa Private E-2

    I tried downloading off of Firefox and it blocks the download. I don't know what to do. It does not even let me go the the Microsoft Windows Update page. It just says there was an error. Firefox works faster that IE but, what's the use if I can't download. What can I do to fix that?
     
  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure you are not blocking downloads in ZoneAlarm? As a quick test, you could just shutdown/exit ZoneAlarm and see if you can download. Do not remain running for any extended period of time with ZoneAlarm shutdown.

    What version of Windows XP are you using (home, media, pro)?
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In fact I see a potential porblem with a file that may have been deleted that was required for ZoneAlarm. You will need to reinstall ZoneAlarm. But try shutting it down first just to see what happens.
     
  45. ArPa

    ArPa Private E-2

    I shut down ZoneAlarm like you asked to, and everything is working great. Now, I'm able to download and install programs. Do you know what was the setting I had that blocked the downloads? Currently, I'm using Windows XP Home Edition. Let me know what I can do and thank you very much!!
     
  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would like you to reinstall ZoneAlarm first since I believe a file from it was deleted. Then let's see what happens.
     
  47. ArPa

    ArPa Private E-2

    Its telling me to use service manager to shut down the TrueVector service and then restart the setup.
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try doing just this first part and see if you can then reinstall.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to TrueVector Internet Monitor
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.

    If you still have a problem, then also do the below.


    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pastevsmon into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot when it tells you it needs to.

    Then reinstall.
     
  49. ArPa

    ArPa Private E-2

    I went to Control Panel > Add/Remove Programs, and this time it was different cause I was able to uninstall. I'm about to reboot my compurter and will re-install it again.
     
  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let us know the results after reinstalling.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds