Please help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by aeidein, Feb 16, 2007.

  1. aeidein

    aeidein Private E-2

    I am using Windows XP SP2. I (stupidly) attempted to download a keygen from seriall.com and instead got malware.
    (WARNING: MALWARE: http://www.seriall.com/download/quick_batch_keygen.exe

    Several scans with various programs seemed to have gotten rid of most of it; however, a spyware ad still popped up occasionally, and I turned to MajorGeeks for help.

    I was going through the Read & Run Me First and tried to reboot with F8 in Safe Mode (the preferred method). Upon hitting F8 and selecting "Safe Mode", it gave me the following error message:
    We apologize for the inconvenience, but Windows did not start successfully.
    along with options to start Windows normally, using the last good (known) configuration, or in safe mode (safe mode, with networking, with command prompt). I tried all of the options and none worked except "Start Windows normally."

    I followed the MSConfig method and checked the /SAFEBOOT option under the BOOT.INI tab. This proved unsuccessful as well, and it gives me the same message. Now I seem to be locked out of the OS! Please help!
     
  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Welcome to Major Geeks. What, if any, error messages do you get at boot?
     
  3. aeidein

    aeidein Private E-2

    We apologize for the inconvenience, but Windows did not start successfully. A recent hardware or software change might have caused this.

    If your computer stopped responding, restarted unexpectedly, or was automatically shut down to protect your files and folders, choose Last Known Good Configuration to revert to the most recent settings that worked.

    If a previous startup attempt was interrupted due to a power failure or because the Power or Reset button was pressed, or if you aren't sure what caused the problem, choose Start Windows Normally.

    Start Windows in Safe Mode​
    Start Windows in Safe Mode with Networking​
    Start Windows in Safe Mode with Command Prompt​
    Last Known Good Configuration (your most recent settings that worked)​

    Start Windows Normally​

    Use the up and down arrows to move the highlight to your choice.



    Any option selected eventually brings me back to the same screen.

    I don't have my Windows XP disc (I don't think my PC shipped with one). Is there any way to modify/restore the boot.ini file?

    If there is not, I am considering acquiring a Windows Vista disc and installing it overtop (which should allow me to boot and still retain all my files, right?)
     
  4. aeidein

    aeidein Private E-2

    I'm glad to say that I've resolved the problem (using Hiren's BootCD to remove the /SAFEBOOT switch from boot.ini) and can now boot into Windows! Please ignore the previous post.

    The malware problem still persists; I will complete scans and post logs soon (tomorrow, if I have time).


    Also, this error appears almost immediately upon boot. Hitting OK ends explorer.exe, which restarts and gives me the error again.
    http://img215.imageshack.us/img215/6545/buffem0.png


    Thanks in advance.
     
  5. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Your copy of explorer.exe may have been replaced with an infected copy or malware is interfering with explorer.exe.

    I'll know better once I see your logs.
     
  6. aeidein

    aeidein Private E-2

    Logs for:
    • BitDefender
    • Panda ActiveScan
    • HijackThis
     

    Attached Files:

  7. aeidein

    aeidein Private E-2

    Logs for:
    • GetRunKey
    • ShowNew
    • AVG Antispyware
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to follow the directions on the download pages for GetRunKey and ShowNew. They were not run properly. It appears that you either did not extract the files from the ZIP file to run them or that maybe you received one of the error messages listed on the download pages and failed to take the corrective actions.
     
  9. aeidein

    aeidein Private E-2

    My apologies.

    I also failed to mention that these were run in normal boot mode.

    Attached are the proper logs.
     

    Attached Files:

  10. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Once again follow directions. Neither ShowNew or GetRunKey are installed as directed in the instructions for both tools. Until you get both batch files where they belong they will not show any information that is useful.

    Download new copies of both and extract ShowNew and GetrunKey to C:\MGTOOLS.
     
  11. aeidein

    aeidein Private E-2

    Download GetRunKey.Zip and ShowNew.Zip from the below links and extract all files from both ZIP files into a folder of their own. You can extract both ZIP files into the same folder. Like C:\MGTools Do not run the scans yet!!!

    Sorry, guess I misunderstood the instructions. Didn't know it was required for them to be in C:\MGTOOLS or in the same directory.

    I downloaded new copies of both, extracted them to C:\MGTOOLS, ran ShowNew.bat and GetRunKey.bat, and attached the logs to this post.

    These were run in normal boot mode.
     

    Attached Files:

  12. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You are not following directions. UNZIP ShowNew and GetRunKey. They are not being ran properly.

    Download
    - Pocket Killbox

    Copy the contents of the below quote box to Notepad; Save As FixReg.reg to your Desktop; make sure File Type: is set to All Files (*.*).
    Close Notepad.

    Locate FixReg.reg on your Desktop. Double-click on it and answer 'Yes' when asked if you want to merge with the registry.

    Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click Delete Selected Temp Files
    Then after it deletes the files click the Exit (Save Settings) button.

    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue..

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Reboot

    Post the following logs:
    ShowNew
    GetRunKey
    HijackThis
     
  13. aeidein

    aeidein Private E-2

    I'm almost positive that I've extracted GetRunKeys and ShowNew properly. This is what I did the first couple of times (extracted with WinRAR).

    http://img266.imageshack.us/img266/8918/mgtoolsiz4.png

    This time, I used the Zipped Folder Extraction Wizard that came with Windows.

    http://img441.imageshack.us/img441/6241/mgtoolsxo2.png

    What indicates that they weren't run properly?



    HijackThis could not fix:


    I received the following error while following the instructions for Killbox.

    http://img61.imageshack.us/img61/8561/pendbc3.png
     

    Attached Files:

    Last edited: Mar 1, 2007
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may be extracting them from the ZIP but you are still running the batch files from inside the ZIP file or you are getting error messages like indicated on the download pages for the tools.

    Try this! Right click Start and select Explore which will open up a Windows Explorer session (this is how you need to run the bat files as explained on the download pages). Then navigate to C:\MGTOOLS Now once the Windows Explorer address bar shows you are in C:\MGTOOLS, doubleclick on GetRunKey.bat to run it. Then do the same for ShowNew.bat

    We can tell the programs are not being run correctly based upon the contents of the logs.
     
  15. aeidein

    aeidein Private E-2

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Start, Run and enter cmd and click OK. This will open a command prompt window. In the command prompt window enter the below commands (shown in bold. Other text is just comments and FYI.)

    cd c:\MGTOOLS
    ltime

    What do you see? (Note: You can right click on the top bar of the Command Prompt window to Edit and do Marking, Copying & Pasting).

    LOCATE *.* /D- /NR /L

    What do you see? (Note there are spaces before *.* and after *.* Also there are spaces before each / )

    dir | find "bytes free"

    What do you see?

    GetRunKey

    Do you notice any error messages now? Make sure you scroll back in the command prompt window to look for any error messages.
     
  17. aeidein

    aeidein Private E-2

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    From the command prompt, type dir

    Now what do you see?

    No, not yet! It is still incomplete.
     
  19. aeidein

    aeidein Private E-2

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And when you type in ltime, nothing happens??? How about if you enter ltime.exe

    Also use enter the below! BESURE TO ENTER it exactly as written. Capital letters are required in the arguments as shown!!!

    locate.com *.* /D- /NR /L

    Also from the command prompt type in regedit

    What happens? Does the WindowsRegistry Editor open?
     
  21. aeidein

    aeidein Private E-2

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmmm?? That's strange. It appears that something is blocking you from running .com and .exe files from a DOS type level. Try the below from the command prompt in the MGTOOLS folder.

    C:\MGTOOLS\ltime.exe

    Anything???

    No matter what happens, continue with the below.


    Now please download Blacklight Beta
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the BlackLight log at the end of this procedure.



    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java 2 Runtime Environment, SE v1.4.2_03

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Symantec Network Drivers Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteSNDSrvc into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Continue by downloading another tool we will need

    - Process Explorer


    Extract it to its own folder somewhere that you will be able to locate it later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)
    Also make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of jkklk.dll once and then click the kill button. After you have killed all of the jkklk.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of jkklk.dll and kill it. (If you do not find the dll, just continue on.)

    Next double click on iexplore.exe and again click once on each instance of jkklk.dll and kill it. (If you do not find the dll, just continue on.)

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    O2 - BHO: (no name) - {31F591A0-B799-40FC-B6AC-97CF772781F6} - C:\WINDOWS\system32\jkklk.dll
    O20 - Winlogon Notify: jkklk - C:\WINDOWS\system32\jkklk.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\jkklk.dll
    C:\WINDOWS\system32\klkkj.dat
    C:\WINDOWS\system32\klkkj.dat2
    C:\WINDOWS\system32\klkkj.ini
    C:\WINDOWS\system32\klkkj.ini2
    C:\WINDOWS\system32\klkkj.tmp
    C:\WINDOWS\system32\klkkj.tmp2
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now run Ccleaner!

    Now attach the below new logs (hopefully GetRunKey & ShowNew work now) and tell me how the above steps went.

    1. Blacklight log
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!
     
  23. aeidein

    aeidein Private E-2

    Attached Files:

  24. aeidein

    aeidein Private E-2

    Everything's working great. Thank you so much, chaslang and Shadow_Puter_Dude, for your help.

    If there's anything I could do for you - invites to private trackers, perhaps - let me know.

    How do the logs look?
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Remember my instructions said to ignore error messages??? ;) It did delete it and it was not critical.

    I'm not sure why you cannot get the processes used by GetRunKey and ShowNew (ltime, grep, and locate) to run but your HJT log is clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  26. aeidein

    aeidein Private E-2

    Thanks again! :)
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds