Kollah Problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by Darknight30Plus, Mar 10, 2009.

  1. Darknight30Plus

    Darknight30Plus Private E-2

    Hi all,

    I ran the READ ME RUN ME FIRST processes and still didn't get rid of Kollah. Can anyone help?

    Attached are the logs from the scans.

    Thanks, Darknight
     

    Attached Files:

  2. Darknight30Plus

    Darknight30Plus Private E-2

    Final Log
     

    Attached Files:

  3. Darknight30Plus

    Darknight30Plus Private E-2

    My wife said that she turned the computer on this morning, went to get coffee and it started booting itself down. She turned it on again, it started rolling then shut itself down again. Not sure what's going on now. :confused

    Also, after running the mb.exe scanner my Firefox stopped working. It now only give me an error about Proxy Server.

    Dark
     
    Last edited: Mar 11, 2009
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you boot into safe mode? The scans did not cause this.
    Your HJT log shows you are using a proxy server:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171

    You will need to remove these if you get it booted:
    c:\windows\t55ft3518f44.dat
    c:\windows\9gdfgjf23

    Let me know if you can do any of that.
     
  5. Darknight30Plus

    Darknight30Plus Private E-2

    TimW,

    I was able to get into safe mode and deleted the 2 files you said.

    I noticed another problem before I deleted the files... I cannot log into some forums or into private forums I'm a member of. I type my name and password and it takes me back to the login screen.

    I know it's not a problem with the forums because I can login on other computers.

    Is that a symptom of this kollah malware?

    Thanks for the help TimW,

    Dark
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It may be, or it could be the affect of having a broken proxy setting. Is this when using IE or FF?

    Please run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  7. Darknight30Plus

    Darknight30Plus Private E-2

    TimW,

    Here is the new zip file you requested. Thanks for the help!:)

    Dark
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You didnt answer my question. And I am not seeing anything in your logs. Are you typing in the web address or using your history?
     
  9. Darknight30Plus

    Darknight30Plus Private E-2

    Sorry about that. It happens both with IE and Firefox.

    I'm using 'favorites' to get to the sites.

    Dark
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try typing in the actual url.
     
  11. Darknight30Plus

    Darknight30Plus Private E-2

    Still didn't work :confused... I can log onto this forum, but it logs me out every time I leave it, whether I close my browser or leave it open and I have it marked to remember me on each visit.

    Just letting you know because I'm not sure if it's all part of the same problem...

    Thanks again for the help.

    Dark
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds