Massive Mal-ware Invasion

Discussion in 'Malware Help (A Specialist Will Reply)' started by tgflag, Jul 6, 2006.

  1. tgflag

    tgflag Private E-2

    It's been a couple years since I was so stupid to click on a link knowing I shouldn't. I have been invaded big time and it seems there is no stopping it. Can't boot in safe mode, need to use the task manager to even get the computer to run, when I run spy-bot, ad-aware, AVG, they clean, then it starts just manifesting itself all over again. I can't do anything before pages just keep popping up. I have read over this site the last couple days and did the STICKY thing. I have a couplet txt files from the online scan tools. I tried to attach a report of what my computer is but it says the file is too big. I really would appreciate some help as to where to start. I will pay if you want. I have purchased about 4 different spyware programs and all have failed to even touch the situation. I have returned and got my money back. I am close to giving up and just re-load windows. The time is outwieghing the effort. Thanks.:mad:
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow the directions in step 7 of the READ ME exactly as written and attach your HijackThis log. You appear to have a lot of problems.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's also get an installed programs list from HijackThis too!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
     
  4. tgflag

    tgflag Private E-2

    Hello and can't tell you how much I appreciate your even considering helping me. I have attached the log file and hope I can wade throught this. Again thanks !!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to attach the Uninstall list that I requested.

    Did you purchase NoAdware4 ?

    Uninstall this junk: SpywareBot


    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\WINDOWS\System32\4a54ecb1.exe
    C:\WINDOWS\F?nts\n?pdb.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [cnz92e63] RUNDLL32.EXE w1d85cfc.dll,n 00192e62000000031d85cfc
    O4 - HKLM\..\Run: [w1d87f79.dll] RUNDLL32.EXE w1d87f79.dll,I2 00192e6201d87f79
    O4 - HKLM\..\Run: [4a54ecb1.exe] C:\WINDOWS\System32\4a54ecb1.exe
    O4 - HKLM\..\Run: [spywarebot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
    O4 - HKCU\..\Run: [Saas] "C:\PROGRA~1\TSKS~1\iexplore.exe" -vt yazr
    O4 - HKCU\..\Run: [4a54ecb1.exe] C:\Documents and Settings\Capt. Quag\Local Settings\Application Data\4a54ecb1.exe
    O4 - HKCU\..\Run: [Hgkt] C:\WINDOWS\FNTS~1\NPDB~1.EXE
    O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
    O20 - AppInit_DLLs: C:\WINDOWS\System32\nopdb.dll

    NOTE: You will get an error message from HJT about the AppInit_DLLs line. Just ignore it, click OK and continue.


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:

    C:\Program Files\Cowabanga <--- the whole folder
    C:\Program Files\SpywareBot <--- the whole folder
    C:\Program Files\SpyQuake2.com <--- the whole folder
    C:\Program Files\T?sks <--- the whole folder
    C:\Documents and Settings\Capt. Quag\Local Settings\Application Data\4a54ecb1.exe
    c:\windows\f?nts\n?pdb.exe
    c:\progra~1\tsks~1\iexplore.exe
    c:\windows\system32\4a54ecb1.exe
    C:\WINDOWS\System32\nopdb.dll
    C:\WINDOWS\System32\cnz92e63.dll
    C:\WINDOWS\System32\w1d85cfc.dll
    C:\WINDOWS\System32\w1d87f79.dll
    c:\windows\downloaded program files\YazzleActiveX.inf
    C:\WINDOWS\securedisk.exe
    C:\WINDOWS\ssqbn.exe
    C:\WINDOWS\sys10-2559123892006.exe
    C:\WINDOWS\UmFpZCBQZXJmb3JtYW5jZQ\oAIDtF1ktrLAvaLQsqc3tk.vbs
    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Jul 7, 2006
  6. tgflag

    tgflag Private E-2

    Hello chaslang, ...Again thanks for your time and I tried to do what you ask. When I go into HJT and follow your instructions for the Uninstall list, HJT just closes. There is no file saved. I tried it a couple times and then I even searched my computer for the file and it's not there. Also, there were a few items that I could not find to delete that you listed. (pdb.exe...w1d87f79.dll....YazzleActiveX.inf.....Securedisk.exe....ssqbn.exe....windows sys10 thing......and the last item.) It would not let me delete nopdb.dll. I tried the properties and then running task mgr. and it was not there. There didn't seem to be anything that was similar. I ran all the cleaners again, and then ran HJT again. I have attached another log from the last and latest run. Things are pretty much the same. Pop-ups keep coming up and IE keeps opening up randomly. 2 3 or 4 windows will open up at at time. Appreciate your time...Mark
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because you did not fix some of the items from my instructions last time. The below are still present in your log.
    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    C:\PROGRA~1\TSKS~1\iexplore.exe
    C:\WINDOWS\FNTS~1\NPDB~1.EXE

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - Default URLSearchHook is missing
    O4 - HKCU\..\Run: [Hgkt] C:\WINDOWS\FNTS~1\NPDB~1.EXE
    O4 - HKCU\..\Run: [Saas] "C:\PROGRA~1\TSKS~1\iexplore.exe" -vt ndrv
    O20 - AppInit_DLLs: C:\WINDOWS\System32\nopdb.dll

    NOTE: You will get an error message from HJT about the AppInit_DLLs line. Just ignore it, click OK and continue. MAKE SURE YOU TELL ME WHAT HAPPENS HERE. YOU MYST MAKE SURE YOU FIX THIS O20 AppInit_DLLs line


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete (the question marks in the below file/folder names are due to unprintable characters in the names. You need to determine the real folder and filenames.)
    C:\Program Files\T?sks\iexplore.exe
    C:\Program Files\T?sks <--- the whole folder
    c:\windows\f?nts\n?pdb.exe
    C:\WINDOWS\System32\nopdb.dll


    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  8. tgflag

    tgflag Private E-2

    Okay, did what you ask. At first, couldn't "kill the process" on the entries you listed. They just kept re-appearing. I moved along and performed the rest of what you said, and then went back, and now I could kill the first two instructions. I could FIX the c-20 line with the dll thing. The whole screen went blank but did not lock up. I just moved along. HOWEVER, I still cannot do anything about the nopdb.dll. It will not let me touch it. I do not see anything in task manager that even resembles this. Under properties, the read-only attribute is unchecked. No matter how many times I try, it keeps saying that it is a system file being used and unable to delete. I have attach another log. Thanks again, Mark
     
  9. tgflag

    tgflag Private E-2

    I am not sure I attached the log. Also, you ask me to tell you how things were. Pop-ups still very active. Thanks.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you did not attach the HJT log. Please attach it after doing the below

    We need to get rid of the AppInit_DLLs item to get rid of you problems.

    Please downloadThe Avenger by Swandog46 to your Desktop.
    • Double click on Avenger.zip to open the file and extract avenger.exe to your Desktop
    • Copy the below quoted text (which is a script for Avenger) into your clipboard by highlighting it and pressing
      CTRL+C
    • Now, run The Avenger program by double clicking its icon on your Desktop.
    • Under "Script file to execute" choose "Input Script Manually".
    • Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
    • Paste the text copied to clipboard into this window by pressing (Ctrl+V).
    • Click Done
    • Now click on the Green Light to begin execution of the script
    • Answer "Yes" twice when prompted.
    The Avenger will automatically do the following:
    • It will Restart your computer. (When the script being executed contains "Drivers to Unload",
      The Avenger will actually reboot your system two times.)
    • On reboot, it will briefly open a black command window on your desktop, this is normal.
    • After the reboot, it creates a log file that should open with the results of Avenger’s actions. This log
      file will be located at C:\avenger.txt
    • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped
      them and moved the zip archives to C:\avenger\backup.zip.
    Please attach the c:\avenger.txt file to your next message.

    Now also attach a new HJT log.
     
  11. tgflag

    tgflag Private E-2

    Okay, I think I handled the task and I uploaded the 2 txt. files you asked for. I might add that the system froze on the second reboot. I didn't know what to do so I just rebooted manually. I also might add that I have my fingers crossed upon these reboots. You see, it freezes when I reboot and I have no control of the desktop. Sometimes it reboots in "safe-recovery" desktop and sometimes not. But what I have figured out that I need to do is run the task manager, end the process of explorer. Then run explorer through task manager and I am back in business. I am afraid one of these times, she is going to stop and freeze for good. Anyways, here's the stuff you ask for and Wow, your putting alot into this and I hope you realize I am truly grateful. Mark
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is now clean! Any remaining problems you are having with booting may not be malware issues. I will look at one more quickscan but if it shows nothing we will be finished with malware removal and I will give you final steps for your security and then send you on to the Software Forum


    Run the below procedure and attach the newfiles.txt log.
     
  13. tgflag

    tgflag Private E-2

    Okay, I thank you for your effort. I am still being taken over by the pop-ups, and even while I am writing this, my cursor will go away, a pop-up will flash, and I need to click in this window to re-activate the cursor. I ran the cCleaner, the ad-awareSE, spybot, and the AVG virus programs. Then I ran the "newfile" thing, and did another HJT log. I have attached. Appreciate your effort and help. If things continue, we'll probably just deal with starting over. Thanks again for all your help. Mark
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It looks like you did not follow the directions for using ShowNew
    It appears that you did not extract all file from the ZIP file. Try again.

    I don't need anymore HJT logs right now. You log was (and still is clean). If you are still having popup problems something else is hiding. Make sure you follow directions properly and get the log from ShowNew
     
  15. tgflag

    tgflag Private E-2

    Hello and I have tried to attach another newfiles.txt file. I really don't know what I am doing wrong as when I extract the zip file, I get 2 items. A shownew.bat & locate.com.
    That's all that is there. I run the shownew.bat program, it makes the newfiles.txt file, comes up in notepad, I close it, it is on my C drive and I attach it here. Hope this is what your looking for. .... Latest developement is I have no Task Manager anymore. A window comes up and says it has been disabled by my administrator.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This time you did it correctly. Look for yourself at the too logs an you will easily see the difference.


    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of jkkli.dll once and then click the kill button. After you have killed all of the jkkli.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below two DLLs:
    viufpdud.dll

    Next double click on explorer.exe and again click once on each instance of jkkli.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below two DLLs:
    viufpdud.dll

    Now just exit Process Explorer.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    Now back on Killbox's main window, Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.

    C:\WINDOWS\SYSTEM32\jkkli.dll
    C:\WINDOWS\SYSTEM32\viufpdud.dll
    C:\WINDOWS\SYSTEM32\ilkkj.tmp
    C:\WINDOWS\SYSTEM32\ilkkj.ini
    C:\WINDOWS\SYSTEM32\ilkkj.ini2


    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    After reboot, delete all files in the below folders (Windows will have 2 or 3 in use and you will not be able to delete them - just work aroun them)
    C:\Documents and Settings\Capt. Quag\Local Settings\TEMP
    C:\Windows\Temp

    Now attach a new HJT log and a new log from ShowNew.

    Also tell me how the steps went.

    Make sure you tell me how things are working now!
     
    Last edited: Jul 11, 2006
  17. tgflag

    tgflag Private E-2

    Hello and we're back. It has been quite an ordeal to keep the machine running. Really have to be honest with you and tell you things are getting worse. Hate it when you ask me to re-boot. My AVG virus program keeps popping up and telling me about virus'. I keep healing them, but some are in system32 and nothing can be done. And everytime it reboots, task manager is dis-abled. Once I am all the way into windows, I am froze up. I have to re-boot and catch it just right to be able to run regedit, re-set the default value for task manager, then get into windows, then stop the explorer task, then run explorer and I am back into business. Once I am in, constant windows popping up, taking over, kicking me out of the internet, and the AVG thing popping up. I have attached the logs you asked after doing all the tasks. You tell me when you want to stop. I will take no offense to this. I can just reformat if you say enough is enough. Thanks, Mark
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below files are still there:

    C:\WINDOWS\SYSTEM32\jkkli.dll
    C:\WINDOWS\SYSTEM32\ilkkj.ini

    This means you are still infected with Virtumonde and it also means that something you did in the previous procedure did not work. Let's try again.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of jkkli.dll once and then click the kill button. After you have killed all of the jkkli.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of jkkli.dll and kill it. (If you do not find the dll, just continue on.)

    Tell me later what you found or did not find in the above steps.


    Now just exit Process Explorer.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    Now back on Killbox's main window, Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway (The names are correct as I wrote them below. One file name is the inverse of the other.)

    C:\WINDOWS\SYSTEM32\jkkli.dll
    C:\WINDOWS\SYSTEM32\ilkkj.ini

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    After reboot, delete the below files if still found (tell me if you find them here):
    C:\WINDOWS\SYSTEM32\jkkli.dll
    C:\WINDOWS\SYSTEM32\ilkkj.ini

    Now attach a new HJT log and a new log from ShowNew.

    Also tell me how the steps went.

    Make sure you tell me how things are working now!
     
  19. tgflag

    tgflag Private E-2

    Hello and no need for me to attach any logs. You will just tell me I am still infected. I ran and did what you ask 3 times. Still the same and no different. Under the winlogon.exe in Process Explorer, there is not or never is any signs of jkkli.dll. But under explorer.exe, there is numerous. Maybe six or seven. AND, everytime I reboot, they reappear, but I can kill them. Under normal windows operation, C;\WINDOWS\SYSTEM32\jkkli.dll, I cannot delete it. It keeps coming up with the "another program is using" thing. However, I could delete 3 instances of ilkkj.bat1, ilkkj.bat2, ilkkj.ini. The virus that keeps popping up is "dlh9jkdq7.exe". Says it's in system32 and cannot heal it because it's in system file. Maybe you already know this and maybe it's connected with what we're trying to get rid of. I will add one more thing. After I run process explorer and do the kill thing, and after I deleted the files out of system32 through windows, everything is much more stable and I can at least use my computer. Things still happen but not as much. But I don't want to reboot as I will be right back where I started and everytime I reboot, it disables the task manager.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to follow the directions and attach the logs! I know it is frustrating but sometimes malware requires multiple repetitions to remove. Your system was very badly infected from the very start and this has complicated matters. We have fixed about 50 cases of this Virtumonde in last week alone. Perhaps you have a new form or the infection that is making the procedure not work properly or the only other reason would be that directions are not being followed exactly (only you can answer the last one).

    I have created a new version of ShowNew. It is now version 0.06 beta You need to download the new version of it and get a new log! This may help us find your hidden malware problems. Then I want you to do the below:

    - run this Virtumonde aka Trojan Vundo Removal - and attach the VundoFix log

    - now attach a new HJT log.
     
    Last edited: Jul 14, 2006
  21. tgflag

    tgflag Private E-2

    I have attached a new HJT log. I did run the Virtumonde tool you ask and it came up clean. Said there were no files. So .... there was no log. You said something about downloading your latest ShowNew tool and I can't find it anywhere on your site to download.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I already gave you the link in message number 12. Just re-download it.
     
  23. tgflag

    tgflag Private E-2

    Okay, I found it. I left my computer on over-night and lost the internet all together. Needed to re-boot and it seems there is tons of stuff happening when I re-boot. All sorts of pop-ups and warnings. I only said this because I have attached another HJT log. Thanks.
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of jkkli.dll once and then click the kill button. After you have killed all of the jkkli.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below two DLLs:
    qonluhqd.dll

    Next double click on explorer.exe and again click once on each instance of jkkli.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below two DLLs:
    qonluhqd.dll

    Now just exit Process Explorer.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    C:\WINDOWS\System32\4a54ecb1.exe
    C:\Windows\xpupdate.exe


    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    O2 - BHO: - {2ed5ed83-b3a1-4a5f-a78e-75c3da55bb0b} - blank (file missing)
    O2 - BHO: Yvakt Class - {AE0ECC2F-0C33-494C-8B22-B57A7763027F} - blank (file missing)
    O2 - BHO: (no name) - {B49D0213-58D2-4AA4-9A88-3A567EA207A5} - C:\WINDOWS\System32\jkkli.dll
    O4 - HKLM\..\Run: [4a54ecb1.exe] C:\WINDOWS\System32\4a54ecb1.exe
    O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
    O4 - HKCU\..\Run: [4a54ecb1.exe] C:\Documents and Settings\Capt. Quag\Local Settings\Application Data\4a54ecb1.exe
    O4 - HKCU\..\Run: [WinMedia] C:\DOCUME~1\CAPT~1.QUA\LOCALS~1\Temp\1.tmp3072.exe
    O20 - Winlogon Notify: jkkli - C:\WINDOWS\System32\jkkli.dll
    O20 - Winlogon Notify: satau320 - satau320.dll (file missing)
    O21 - SSODL: DCOM Server 2236 - {2C1CD3D7-86AC-4068-93BC-A02304BB2236} - C:\WINDOWS\System32\2236_27.dll
    O21 - SSODL: tOZdIwboDgMGH - {F0BF163C-5A15-BC96-1E14-B538C1F58DF0} - C:\WINDOWS\System32\kq.dll (file missing)


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now click Start, Run, and enter cmd and click OK! This will open a command prompt window. In the command prompt window enter the below commands each followed by the Enter key.
    del %windir%\temp\win*.*
    exit


    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
    C:\WINDOWS\srvjcr~1.exe
    C:\WINDOWS\srvmfl~1.exe
    C:\WINDOWS\xpupdate.exe
    C:\WINDOWS\SYSTEM32\4a54ecb1.exe
    C:\WINDOWS\SYSTEM32\ipodra~1.exe
    C:\WINDOWS\SYSTEM32\kernels8.exe
    C:\WINDOWS\SYSTEM32\wtstr.exe
    C:\WINDOWS\SYSTEM32\2236_27.dll
    C:\WINDOWS\SYSTEM32\jkkli.dll
    C:\WINDOWS\SYSTEM32\mscdaux.dll
    C:\WINDOWS\SYSTEM32\qonluhqd.dll
    C:\WINDOWS\SYSTEM32\ilkkj.tmp
    C:\WINDOWS\SYSTEM32\ilkkj.ini
    C:\WINDOWS\SYSTEM32\ilkkj.ini2
    C:\WINDOWS\SYSTEM32\w0192e62.ini
    C:\Documents and Settings\Capt. Quag\Local Settings\Application Data\4a54ecb1.exe


    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    After reboot run Windows Explorer and locate the below folders and delete ALL files in them. Windows may have a few files in use and will not let you delete them. Just work around those and delete all others.

    C:\WINDOWS\TEMP\
    C:\Documents and Settings\Capt. Quag\Local Settings\TEMP


    Now attach a new HJT log and tell me how the steps went.
    Make sure you tell me how things are working now!
     
  25. tgflag

    tgflag Private E-2

    Howdy, I am back. Was hit with a massive storm and we were without power for a few days. Tried doing all you ask. Things seem better already. Machine is more stable and not the constant pop-ups. There for awhile, was getting 10 to 12 pop-ups in a row. Couldn't even do anything. Now things seem cool. Okay, ....First, nothing in Process Manager. Second, could not do the commands in the "DOS" enviroment. Did not have a C:\....I had C:\Documents and Settings\Capt.Quag\....when I entered in the command you ask, nothing happen and kept saying it was invalid. Tried changing directories back and forth and could not get just a C:\ prompt. Did not recieve the message "PendingFileRenameOperations prompt.

    Thanks, Mark
     

    Attached Files:

  26. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Chas is on Vacation.

    Your HijackThis log appears to be clean.

    How is your computer running?
     
  27. tgflag

    tgflag Private E-2

    Thanks for looking things over, I appreciate it. Things are pretty much that same. Right now I have about 8 internet sites that opened on their own. Keeps kicking me out of whatever I am in. Constant pop-ups and pop-unders. I have tried virus programs, mal-ware programs, spy-ware programs. Been fighting this over a month now. Looks like I am just going to either reformat or get a new hard drive.
    I am running a raid system stripped 0. Can you tell me a site or how to get advice on formatting my system. Having 2 hard drives, I guess I am a little confused to formatting and starting over. Appreciate it very much. Thanks Mark
     
  28. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Rename hijackthis.exe to analyse.exe.

    Post a fresh HijackThis log.
     
  29. tgflag

    tgflag Private E-2

    Renamed as you asked. Posted another log as you asked. Went out last night and bought a new "single" hard. WD 300 SATA. Really hate to do it, but have too much time invested, and can't get anything done. If you don't see anything, or don't know what to do, I won't bother you guys anymore. Just in writing this message, over 11 pop-ups and pop-unders flashed. Kicked me out of typing this message 3 times. Can't even use the computer. Very nerve racking. Want to literally put people in jail and throw away the key that do this kind of stuff. Just don't understand it.
     

    Attached Files:

  30. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    The is nothing in the log to explain your pop-ups. The only thing left is to look for a rootkit.

    Download Blacklight Beta from here:
    http://www.f-secure.com/blacklight/try.shtml
    • Hit I accept. It will take you to download page.
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please post contents of log.
     
  31. tgflag

    tgflag Private E-2

    The site must be down. That link doesn't take me anywhere. I even tried to google that, and same thing. Nothing there. Will try later.
     
  32. matt.chugg

    matt.chugg MajorGeek


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds