Problems..need help

Discussion in 'Malware Help (A Specialist Will Reply)' started by gingerveli, Jun 3, 2006.

  1. gingerveli

    gingerveli Private E-2

    Hey guys, been having some problems.
    Main problem is that my internet shuts off after around 5-10minutes, if I try to open another page I get “Page cannot be displayed”, in the title bar “cannot find server”.
    But I know it aint true, cus I cud still chat on msn messenger.
    I have attached a recent HiJack this log.
    Also getting some pop ups when i first start the net, "playeurolotto" and "adultfreindfinder".
    Any help is greatly appreciated!
     

    Attached Files:

  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    HI, please follow our standard cleaning procedure guide below as HJT can find some errant malware files it doesnt find all of them so the other scans are needed to remove as much as possible before running HJT.


    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis


    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
    • Bitdefender
    • Panda Scan
    • HijackThis
    .
     
  3. gingerveli

    gingerveli Private E-2

    I've already done the scans and been through all the instructions, will run through them again. Also i'm able to get a bitdefender log but with the panda scan, because it opens in a new window and due to my internet connection shutting down i cant get the log saved.
     
  4. gingerveli

    gingerveli Private E-2

    Ok, have run the steps through again.
    Attached are the bitdefender scan and hijack this log. No pandascan due to problem said before.
     

    Attached Files:

  5. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You appear to be running a complete unpatched, original version of Windows XP; this represents a serious security risk. It is imperative that you install SP2 and bring your OS completely up2date. If you do not bring teh OS up2date you will get infected again.

    DO NOT install SP2 unitil after we have finished disinfecting your computer.

    The version of Java installed on your computer is out-of-date. Install version 1.5.0_07 available from http://www.java.com/en/download/manual.jsp. Make sure you uninstall all older versiuons of Java.

    Windows Messenger is running in the background and represents a security risk. Disable Windows Messenger by running Shoot the Messenger.

    Download
    - Pocket Killbox

    Scan with HijackTHis and fix teh following lines:
    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open Windows Explorer navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Post a fresh HijackThis log.
     
  6. gingerveli

    gingerveli Private E-2

    Ok, have gone through the instructions as advised. So far so good.
    Attached is the new HJ log.
     

    Attached Files:

  7. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Scan with HijackThis and fix the following line:
    Reboot

    Post a fresh HijackThis log.
     
  8. gingerveli

    gingerveli Private E-2

    Think i was one step ahead and did it already.
    Heres a new HJ log.
     

    Attached Files:

  9. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Your HijackThis log is clean.

    You may want to consider uninstalling backweb-lite, though it's not malware, there are privacy concerns when left running on your system.

    Remember to install SP2 and run Windows Update to bring your system up2date.

    Lets flush all your restore points and create a new clean one for your system.

    Disable And Enable System Restore
    How to Protect yourself from malware!

    Safe surfing.
     
  10. gingerveli

    gingerveli Private E-2

    OK, my comp seems to be running ok now, no more of those pop ups, but my internet connection is still being cut off after 5-10mins. :eek:
     
  11. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

  12. gingerveli

    gingerveli Private E-2

    OK, heres the results of both scans.
     

    Attached Files:

  13. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Boot to Safe Mode.

    Start -> Run
    type regedit
    'OK'

    Navigate to the following:

    HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\mfnkstfk
    {a44fc23b-4f7d-4160-8482-e72f65131ec4} = C:\WINDOWS\System32\kfekq.dll <<=== Delete the Key

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run
    wininet.dll regperf.exe HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\mfnkstfk
    {a44fc23b-4f7d-4160-8482-e72f65131ec4} = C:\WINDOWS\System32\kfekq.dll

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run
    wininet.dll regperf.exe <<=== Loacte and Delete the Key

    Close Regedit.

    Open Windows Explorer, navigatet to and delete
    C:\WINDOWS\System32\kfekq.dll. Close Windows Explorer.

    Using the Search feature in the Start Menu; search for and delete
    regperf.exe
    .

    Reboot to Normal Mode.

    How is your computer running?
     
  14. gingerveli

    gingerveli Private E-2

    Eveything is running fine now, got help in the software section, was due to ZA. Thanks anyway.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds