porn sites come up

Discussion in 'Malware Help (A Specialist Will Reply)' started by spyware sucks, Oct 11, 2004.

  1. spyware sucks

    spyware sucks Private First Class

    ok one of them is gone but i still can't get rid of

    O4 - HKLM\..\Run: [jbp] C:\WINDOWS\System32\jbp.exe

    is it a serious thing? if not then i'll just forget about it
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I repeat:

    Did you do this

     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do your settings match the below:

    Right Click Start.
    Select Explorer.
    Select the Tools menu and click Folder Options.
    Select the View Tab.
    Under the Hidden files and folders heading select Show hidden files and folders.
    Uncheck the Hide extensions for known file types option.
    Uncheck the Hide protected operating system files (recommended) option.
    Click Apply.
    Click OK.
     
  4. spyware sucks

    spyware sucks Private First Class

    oh. im sorry. its really late right now here. sorry

    i found it but it is neither read only or running. but i cannot delete it.
     
  5. spyware sucks

    spyware sucks Private First Class

    ok i deleted jbp.exe

    but i cannot find counter.cab my settings are how you instructed
     
  6. spyware sucks

    spyware sucks Private First Class

    i think i foudn the source for the popups.

    my firewall notifies me that C:\Windows\System32\ovejtba.exe is trying to connect to neededware.com

    should i delete this file?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then why couldn't you find jbp.exe all this time.

    FIx the O4 line in HJT now. Reboot and post a new log.

    Ignore counter.cab, HJT probably removed it.
     
  8. peterparker

    peterparker Corporal

    Wow Chaslang, just wanted to drop a note and say how patient you are. Learning a lot from this site.
     
  9. spyware sucks

    spyware sucks Private First Class

    all right
     

    Attached Files:

  10. spyware sucks

    spyware sucks Private First Class

    i was just wondering if you know what Generic Host Process for Win32 Services and NDIS Usermode I/O Driver are. i currently blocked them with my firewall. but the notification shows up pretty often.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They are valid processes but they normally do not need internet access. Just tell your firewall to always use the same setting.

    Your problem O4 line process has now renamed itself to:
    O4 - HKLM\..\Run: [ovejtba] C:\WINDOWS\system32\ovejtba.exe


    Please follow the steps below:

    1 - Please EXTRACT all files from Qoologic Tool to its own folder - C:\Program Files\QoologicFinder . Then, DoubleClick Find-Qoologic.bat to run the tool. It should produce a log - Please attach that with your next post!

    2 - Please EXTRACT all the files form RKFiles Tool to its own folder - C:\Program Files\RKTOOL. Then, Please boot to SAFE MODE and DoubleClick rkfiles.bat to run the tool. Let it run and then, when it finishes, look for a log at C:\Log.txt and please attach that log.
     
  12. spyware sucks

    spyware sucks Private First Class

    should i reboot to normal mode after the RKTOOL scan?
     
  13. spyware sucks

    spyware sucks Private First Class

    ok here are the logs of the those scans
     

    Attached Files:

    • file.txt
      File size:
      2.1 KB
      Views:
      1
    • log.txt
      File size:
      790 bytes
      Views:
      1
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you know what the below line is for (from your HJT log)?

    O4 - Global Startup: Microsoft Broadband Networking.lnk = %SystemRoot%\Installer\{06B2B442-19FE-4398-BD4B-F5C00928DD8E}\_18be6784.exe
     
  15. spyware sucks

    spyware sucks Private First Class

    Microsoft Broadband Networking is my wireless networking.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I thought so. Rather a strange entry/filename to have! Looks alot like typical malware.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download Pocket KillBox and extract it to its own folder.

    IMPORTANT: Now print these instruction or copy them locally. I want you to run all of the below steps while physically disconnected from the internet. Do not reconnect until I say to do so. And do not open a browser until I say to.

    OK! Disconnect now before continuing.

    Now run killbox.

    Now, Copy and Paste C:\WINDOWS\system32\Dwapilib.tlb into the box – If it exists, it will show up in Blue. Check the option to Replace on Reboot and also check the Use Dummy option and also check the End Explorer Shell While Killing File option too. Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click No!

    Now, Copy and Paste C:\WINDOWS\system32\ovejtba.exe into the box – If it exists, it will show up in Blue. Check the option to Replace on Reboot and also check the Use Dummy option and also check the End Explorer Shell While Killing File option too. Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click No!

    Now, Copy and Paste C:\WINDOWS\RMAGEN~1.DLL into the box – If it exists, it will show up in Blue. Check the option to Replace on Reboot and also check the Use Dummy option and also check the End Explorer Shell While Killing File option too. Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click Yes and allow Killbox to reboot your PC.

    If you get an error message about "Pending Operations" just reboot your PC yourself.

    Now get a new HJT log and post it here. Tell me how the above steps went.
     
  18. spyware sucks

    spyware sucks Private First Class

    im not too sure how to disconnect from our internet without screwing things up..because basically its connected all the time.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Cable or DSL?

    Just unplug the Ethernet cable that plugs into the back of your PC.
    Plug it back in later where I say to come back here.
     
  20. spyware sucks

    spyware sucks Private First Class

    but if im disconnected how will open this site?

    i disabled my wireless and ran killbox. here is the HJT file.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't need to be connected to this site while running the steps! That's the whole point.
    When finished (where I ask you to post a new log) obviously you would have to reconnect.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps the way I wrote them. You still have

    O4 - HKLM\..\Run: [ovejtba] C:\WINDOWS\system32\ovejtba.exe
     
  23. spyware sucks

    spyware sucks Private First Class

    ok so i have to be physically disconnected? not just disabled?
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's the best method to be sure that nothing can really get in or out.

    Did you actually run Killbox to remove those files? Did it give you any errors? Did you reboot afterwards? Did you get any error messages on reboot?
     
  25. spyware sucks

    spyware sucks Private First Class

    i ran killbox and it gave no errors. i also rebooted but when i rebooted the C:\WINDOWS\system32\ovejtba.exe opened a couple times in a cmd thing.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please explain in more detail what you mean. What is a cmd thing?
    Do you mean a some command prompt windows opened and showed that filename?
     
  27. spyware sucks

    spyware sucks Private First Class

    yes. im not sure how to go into more detail because i am no good on computers. but yes it was a sort of command prompt like the one that appears when i am doing the Qoologic and RKfile scan.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you open Windows Explorer and navigate to c:\windows\system32 can you see the ovejtba.exe file?

    If so, how large is it?
    Do you know how to put files into a ZIP file? Do you have WinZIP installed?
     
  29. spyware sucks

    spyware sucks Private First Class

    There are actually 2 files that are similar

    C:\\windows\system32\ovejtba.exe is 56 bytes
    C:\\windows\system32\ovejtbandw30104lib.dll is 48 kb

    i don't know how to zip
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the following:


    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    ovejtba.exe

    After killing that process exit out of HJT.

    Now with Windows Explorer locate the two files and one at a time right click on them and select Rename. Change the names as follows:

    ovejtbandw30104lib.dll to ovejtbandw30104lib.ddd
    ovejtba.exe to ovejtba.xxx

    Let me know if you were able to do that or if you get an error message.
     
  31. spyware sucks

    spyware sucks Private First Class

    i did not find that process
     
  32. spyware sucks

    spyware sucks Private First Class

    when i try to change it i get this message:

    If you change a file name extension, the file may become unusable. Are you sure you want to change it?
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Say yes and see if it allows the file names to be changed!
     
  34. spyware sucks

    spyware sucks Private First Class

    yes i was able to change them
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Run HJT and have it fix the below line:
    O4 - HKLM\..\Run: [ovejtba] C:\WINDOWS\system32\ovejtba.exe

    Then rescan with HJT and make sure it does not come back and that it does not come back with a new name. Let me know.
     
  36. spyware sucks

    spyware sucks Private First Class

    all right. it was removed by HJT but i am not sure if it came back with a new name. here is the HJT log.
     

    Attached Files:

  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it did not. Not yet anyway. Now this is the next step.

    I want you to reboot your PC but the method we will use must be non-graceful. I want you to pull the power chord to your PC (yes you read that correctly). I want to try to prevent it from spawning on shutdown. Before pulling the power chord, exit every application that is open (this browser window too). Even close items in your system tray.

    Then afterwards, wait about a minute and plug the power chord back in. Boot your PC back up and get a new HJT log. Then open your browser and come back here and post your log.

    Time for me to get some sleep! I'll be back tomorrow (damn, it's already tomorrow).
     
  38. spyware sucks

    spyware sucks Private First Class

    i need to sleep too..is it all right if i do this tomorrow?
     
  39. spyware sucks

    spyware sucks Private First Class

    oh btw which is the system tray?
     
  40. spyware sucks

    spyware sucks Private First Class

    nevermind ill just sleep later. here is the HJT log. i really really hope this is the end all this..k good night. see you later
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By system tray, I mean the items on the lower right of your screen. Part of the Taskbar. Normally right near the clock.

    You forgot the log. Is the O4 line gone?
     
  42. spyware sucks

    spyware sucks Private First Class

    oh wow. stupid me..i think the O4 line is gone
     

    Attached Files:

  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  44. spyware sucks

    spyware sucks Private First Class

    GREAT! I'm assuming theres no more malware? I can't thank you enough for your assistance chaslang. You are very dependable.
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds