trjoan horse downloader.small.33.f

Discussion in 'Malware Help (A Specialist Will Reply)' started by aNg3LbAbi3, May 7, 2005.

  1. aNg3LbAbi3

    aNg3LbAbi3 Private E-2

    hi, i am new here. so sry if this is the wrong place. i tried reading to find anything bout this, but i couldnt. i am stupid when it comes to computers. anyways, here's my sad story. i have had virus problems for the last 3 months. they are the same viruses reoccurring over and over. its annoying and tiresome. i figure out with the help of my brother who is a computer genius and who also refered me to this site. he said this site is awesome and always helps him. anyways, he asked me questions bout the viruses and i told him. i have several back up disks i saved information on. he thinks they somehow hid in there. thing is i scanned these backup disks. they have all my information i really need. i notice each time i put them in, couple hours or sometimes a day the same virus keeps popping up. i would like to delete these viruses off my disks somehow. i made backup disks cuz i keep reformatting. i have been reformatting at least 10 times now in the past three months. i recently reformatted my laptop the other day and now it has a virus again. i dont know how to fix it, somebody please help me. i am rlly sorry if this has been covered before or if its in the wrong place. i will try to be as accurate as possible.

    here are some pics i took of AVG finding the virus (screenshots). this was just friday night too.

    The virus keeps popping up in my Local Settings/Temporary Internet Files/Content.IE5/blahh (its always a different folder)
    *i have two or three different ones*
    http://img53.echo.cx/img53/6442/stupidvirus1fl.png

    the other one infects windows media player.
    the file is always a inst[2].exe or OLD12AC.TMP
    http://tinypic.com/4v5zjk
    http://tinypic.com/4v5zzk

    thanks in advance.

    edit//
    i forgot to mention that i sometimes can locate them and delete them or heal them. then sometimes i cant. also when it effects windows media player its windows media player itself. i delete windows media player and it just keeps coming back (the file; wmplayer.exe).
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First I have to ask why are you formatting so often? Is it because of virus problems or for some other reason? It should not be necessary to do this so often and chances are that if you are doing that so often, you probably are not getting all the proper patches and updates applied to your system.

    Second, what do you mean by backup disks? Spare harddisk, CD, floppies? How much are you backing up?

    Please follow ALL of the steps below completely. Do not skip anything.

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus RemovalMake sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENTto your next message. (Do NOT copy/paste the log into your post).
     
  3. aNg3LbAbi3

    aNg3LbAbi3 Private E-2

    I thought i might answer this first before running all the tests and what not. My answer might help you to figure out whats goin on. I am reformatting because this virus shuts down the computer and after 3 times, you can barely turn it on. these are all laptops by the way.

    backup disks are just all my information i wanted to save. they're Memorex CD-R Recordable, 52x ,700 MB. 8o min. thats all what it says. i dont know what else to use, if you have something better, please let me know.

    also, i had just reformatted both laptops. now one i can barely turn on again. i also need information out of there. this one is almost gone also. today i found two viruses, the same ones. i might not even have a laptop by tommorrow. i probbably wont even be able to reply by tonight. anyways, thanks for responding. you'll have to excuse my slowness because im not that great with any kind of electronics except cell phones. thanks in advance.

    feel free to im me, with any help of any sort or advice, thanks.
    aim: xswtang3lbabyx --if im away leave a msg and i will get it. thanks
     
  4. aNg3LbAbi3

    aNg3LbAbi3 Private E-2

    sry for double posting, but i have a problem again...i did this...

    For Windows XP:

    1: Right click on the My Computer icon on your desktop and select properties.
    2: Click on the system restore tab.
    3: Check the box that says "Turn off system restore on all drives". Click OK.
    4: Click Yes when you are prompted to restart the computer
    5: To re-enable System Restore, follow steps 1-3, but in step 3, click to clear the Disable System Restore check box.

    but the computer didn't restart. i am sure i click yes, i watched myself click it. so what do i do now?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't worry about it! Just continue to complete the procedures.
     
  6. aNg3LbAbi3

    aNg3LbAbi3 Private E-2

    before i do Scanning And Cleaning Steps, do i run all these programs first? it doesnt say so. it just says this :Your system is now ready to be properly scanned for spyware, trojans and viruses. im slow, and im follow direct instructions. i think you guys want me to run them but you never said so. at least not literally or directly however you say it. i want to skip that and go the scanning and cleaning steps but im afraid i might mess up something so im goin to wait till someone responds cuz im confused now. thanks in advance

    Ad-Aware SE.......Install, click Check for Updates now and get any updates, then exit.
    Ad-Aware VX2 Cleaner Plug-In.....Install only
    CCleaner.............Install only, then exit
    Spybot................Install, do the search for updates now and get any updates, then exit.
    SpywareBlaster...Install, click Download Latest Protection Updates, Check for Updates, and then Enable All Protection, then exit. It does a great job of blocking known vulnerabilities as well as known malicious websites.
    McAfee AVERT Stinger.....No installation required! Ready to run as is.
    CWShredder......No installation required! Just unzip it to a folder.
    Kill2me..............No installation required! Just unzip it to a folder.
    about:Buster......No installation required! Just unzip it to a folder. Click Update and download any before scanning.
    HSRemove........No installation required! Ready to run as is. (Only for WinNT, 2K, XP)
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It tells you when to run them in the section titled:

    Scanning And Cleaning Steps: (These 4 steps are NOT optional and must be run!!)

    Just follow the steps.
     
  8. aNg3LbAbi3

    aNg3LbAbi3 Private E-2

    it took me forever to get into safe mode, at least 7 tries. anyways, i ran the two online scans in safe mode. only Symantec Security Check found 1 virus or threat. but i could not find where to get rid of the virus or how to find the name of the virus. its hard to do anything with the window size so small. before i ran these scans i found the same viruses again infecting the same areas. i was able to delete one but the other i couldn't. the one i couldnt delete was windows media player. it just keeps coming back after i delete it. why is this? also i ran the CCleaner but i was confused whether to check everything in the Windows tab or just the Internet Explorer part. So i just checked internet explorer since that's all you mentioned. Where do i download Spybot DSO Exploit patch? i downloaded everything you listed but i didnt see Spybot DSO Exploit patch. so now i am stuck in this area. what do i do now? thanks in advance
     
  9. aNg3LbAbi3

    aNg3LbAbi3 Private E-2

    how do i edit? i dont want to keep double posting. okay so i finished running all the scans although no one answered. i just searched for the Spybot DSO Exploit patch and in one of the forums it said as of 4/15/2005 you didnt need it cuz Spybot came out with a new version. i hope that is correct. I scanned with Spybot and it found 1 entry, it said "Alexa Related". I then ran CWShredder which didn't find anything. Kill2Me said something similar to no files found as suspicious, but i ran it anyways. it said it removed it if present. I ran the Buster report and it said no ads found on sys, attempted clean of Temp folder, pages rest..done!. i ran Buster x2. i then ran HS remove and it found 10 items and that was removed. i restarted the computer to try and switch back over to normal mode and it wont let me. it says i have delted this file "<windowsroot>\system32\ntoskrnl.exe", could this be windows media player? because windows media player was infected. before i could access the internet, IE took me straight to this page http://hsremove.com/done.htm. also before i got onto the internet. i decided to run avg and see if the scans got rid of the virus. unfortunately, it didnt. so here is a link to what avg found. i was able to head it. http://img84.echo.cx/img84/8458/o512o57mc.png
    so now i cant go back into normal mode. help please. thanks in advance.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ccleaner should be run with the default options set. You should clean all the items by default. Just do not use the other tabs (like the Issues tab).

    The Spybot DSO patch is no longer needed since the new release came out (forgot to remove that line from the procedure - now it is removed. Thanks!)

    You were not suppose to run about:buster or HSremove. They are only for problems with about:blank or HSA hijackers which you do not have.

    I'm not sure what happen to your ntoskrnl.exe file but try the below:

    Open a command prompt window by clicking Start, Run, and enter cmd and click OK.
    In the command prompt window type the below commands each follow by the enter key. Make sure you type them exactly as written.

    cd c:\windows\system32

    copy "..\driver cache\i386\ntoskrnl.exe"


    If prompted to overwite the existing file, type y and enter.

    If you receive a file not found error, make sure that the path in the copy command is correct. If it is correct and you still receive the error, then try the following commands:

    cd "c:\windows\driver cache\i386"

    expand sp1.cab -F:ntoskrnl.exe c:\windows\system32



    Again, if you are prompted to overwrite the file, type y and then enter.

    Now reboot and see if this problem is fixed. Now post the HijackThis log I requested.
     
    Last edited: May 13, 2005
  11. aNg3LbAbi3

    aNg3LbAbi3 Private E-2

    oh my godddd!!!!!!!!! my computer is gonig psycho!! i have only rebooted it into normal mode for like 15 minutes and avg has pulled up four viruses and norton 1. ahhhhh!! not only that, there are pop ups like crazy!! i have pop up blockers too. and i cant attach the log file. im bout to call it quits and reformatt. but i rlly need my information on this computer. its telling me this "Upload Errors
    hijackthislog.txt:
    Attachment in Progress. Can be deleted here." i first tried uploading it as .log but it wouldnt work, so i thought i would try .txt. this laptop is a mess. i hate computers.
    i know you strongly advised not to paste it here...but what should i do? email it to you?
    here is what is says when i first open windows and everything loads.
    http://img225.echo.cx/img225/702/openincpu5ou.png
    viruses popping up:
    http://img64.echo.cx/img64/2364/o513o5avg1hk.png
    http://img55.echo.cx/img55/1650/o513o5avg26ym.png
    http://img55.echo.cx/img55/8217/o513o5norton9kh.png
    this junk pops up in the middle of all the viruses
    http://img64.echo.cx/img64/9673/o513o58ee.png
    then these two popup:
    http://img64.echo.cx/img64/1760/o513o5avg34mk.png
    http://img55.echo.cx/img55/3330/o513o5avg44cj.png
    btw i wasnt able to delete the bloodhound. whenever i reformatt i always see that cmd window you told me to enter into the run window. its the first thing i see after i reformatt. the first bold instructions to copy the ntoskrnl.exe (sp?) didnt work until i tried the second bold instructions. just thought you should know that. i will try clicking on your name and emailing the log. thanks in advance
    edit//DO NOT CLICK ON THE LINKS BESIDES THE PICS, I DIDNT INSERT THEM,THANX!!!
    edit//nevermind they went away. odd...like i said this thing is goin nuts. before i edited there were links in every 5 words that i typed. oh well.
    edit//i cant email you, heh forgot you guys dont want emails. i will just wait till you respond.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Disconnect (physically unplug your cable) from the internet and exit all browsers. Then safe a new HijackThis log. Now reconnect to the internet and try to post your log even if you have to post it inline.
     
  13. aNg3LbAbi3

    aNg3LbAbi3 Private E-2

    finally i can attach the log. since it took you awhile to reply, i kept getting popups. so i disconnected from the internet by pulling the cable line out. then i ran avg and found SIXTEEN more viruses. its still running too. bleh, computers are a waste of money. what do you mean by inline? in the actual post?
    this poped up while i was offline:
    http://img47.echo.cx/img47/9421/o513o5bman25fn.png
    http://img47.echo.cx/img47/5797/o513o5norton26te.png
    image shack wont let me upload the screenshot i got of the 16 viruses. oh well.
    avg just finished and found 21 viruses, 20 were successfully healed. i cant use print screen to show anymore pics because it says "paint: mspaint.exe-bad image (blue bar of window), The application or DLL C:\WINDOWS\System32\WINMM.dll is not a valid image. Please check this against your installation diskette. (gray area). the other popup of ms paint says Paint (blue bar), Make sure you are using the correct version of the OLE libraries (gray area). thanks in advance
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are you running two instances of HijackThis and why didn't you install it as requested? You have the below in your log:

    C:\Documents and Settings\Slide Queen\Local Settings\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe
    C:\Documents and Settings\Slide Queen\Local Settings\Temp\Temporary Directory 3 for hijackthis.zip\HijackThis.exe

    This means yo are running it twice and that you are running it directly from the ZIP file which I requested that you not do. You must fix this or you will not get any backups.
    Why are you trying to view winmm.dll. It is not an image file.

    You need to open Control Panel and run Add/Remove programs and uninstall WeatherBug.

    I do not use AIM so explain to me why there are two types of AIM running. aim.exe and aim+.exe
    Why are both required?

    You have both AVG and Symantec antivirus scanners installed. You must use only one. Pick one and uninstall the other.

    Download and run this: EliteToolbar Remover

    I'm looking at the rest of your log now.



     
    Last edited: May 14, 2005
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also run follow the below steps:

    To fix your problem with nail:

    - Click Start > Run and type: cmd and then click OK! This brings up a command prompt window.
    - At the command prompt opens, type the below command and then hit the enter key:

    nail.exe /FullRemove

    Now the Aurora problem:

    Download and run the uninstaller: Aurora Uninstaller

    After you run this tool, reboot and then continue with the steps below!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you know what the below is?

    C:\Program Files\ATS\ats.exe

    There are some trojans that go by this filename.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Look in Add/Remove programs for Internet Optimizer and uninstall if found.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).


    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\System32\kkpian.exe
    C:\Documents and Settings\All Users\Application Data\msw\BMan1.exe
    c:\windows\system32\rzlvfkj.exe
    C:\Program Files\ATS\ats.exe


    After killing all the above processes, click "Back".

    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchmiracle.com/sp.php
    O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll
    O2 - BHO: &EliteSideBar - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} - C:\WINDOWS\EliteSideBar\EliteSideBar 08.dll
    O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll
    O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
    O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
    O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitepaa32.exe
    O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\kkpian.exe
    O4 - HKLM\..\Run: [BMan] C:\Documents and Settings\All Users\Application Data\msw\BMan1.exe
    O4 - HKLM\..\Run: [cfgmgr51] RunDLL32.EXE C:\WINDOWS\cfgmgr51.dll,DllRun
    O4 - HKLM\..\Run: [epatxa] c:\windows\system32\rzlvfkj.exe

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:

    C:\Documents and Settings\All Users\Application Data\msw <--- the whole folder
    C:\WINDOWS\EliteToolBar <--- the whole folder
    C:\Program Files\Internet Optimizer <--- the whole folder
    C:\WINDOWS\System32\kkpian.exe
    c:\windows\system32\rzlvfkj.exe
    c:\windows\system32\AUNPS2.DLL
    C:\WINDOWS\cfgmgr51.dll
    C:\windows\system32\elitepaa32.exe <-- also delete all other filenames beginning with elite and ending with exe in the system32 folder.


    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.


    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.


    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  18. aNg3LbAbi3

    aNg3LbAbi3 Private E-2

    I did not run two of them while trying to run the Hijackthis, it mentioned something about it trying to run from the Temporary Internet Files. I couldnt use print screen to paste into paint to show you what popped up so you would know exactly what was said because paint would not let me access it forawhile. I am not trying to view this winmm.dll; i don't know what that is. avg was pulling up that file as a virus. i was trying to delete it, not view it. aim+ is a clone of aim that allows you to be on more than one screen name. i run two because i share the laptop; we both like to be on at the same time. is AVG better or Symantec Antivirus? I don't even know how i got the Elite toolbar, it just popped up and wont let me access the yahoo or aim toolbar. My brother is the one who recommended me to this forum, I couldn't find the link. So, I tried to google your forum, I had no luck and found a similar one. This program "
    C:\Program Files\ATS\ats.exe" I had downloaded the Program "Anti-Trojan Shield" from that similar forum, thinking it would help; now I know it doesn't. My brother finally got online later and told me your forum so I never went back to the other. So, I don't remember the name. I went ahead and removed the Anti-Trojan Shield Program and deleted the folder. I forgot to mention i have alot of transparent icons, folders, and etc since I removed the system restore. why is this? I will try to do as much as I can because my printer is broken so I can't print your posts. here are some more error windows that popped up while i was waiting for your response.
    http://img37.echo.cx/img37/2523/o513o5error9vm.png
    and here is the only screen shot i got of the 21 viruses; i took the screenshot at 16 and afterwords couldn't anymore cuz i couldnt access paint.
    http://img37.echo.cx/img37/1584/o513o5avglotsvirus5rm.png
    i deleted all the files with avg, hopefully i didnt delete files i needed.
    i will have to do the procedures later tonight, i have to go to work. i will post tonight if not tommorrow. thanks for all the help.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If two hijackthis.exe files show in your process list. You had two of them running.

    I do not need to see a screen image. You are getting that message because HijackThis is running from Temp Internet folder (TIF) because you are not extracting it from the ZIP file as requested in my directions.

    I also do not need you to keep posting any info about popups each time you come back. Until we are done fixing the problems, you will still have problems. Complete all my steps first and then let's see where things stand. But FIRST install HijackThis properly by extracting it from the ZIP file into the folder requested.


    Please complete running the steps in messages # 14 to 17.
     
  20. aNg3LbAbi3

    aNg3LbAbi3 Private E-2

    I remember you saying in each session I need to do something, I can't seem to find where. Do I always have to disable system restore and go into safe mode? Or was it repeating the cleaning steps? Thanks in advance.
     
  21. aNg3LbAbi3

    aNg3LbAbi3 Private E-2

    Nevermind, I found where you mentioned it. I found it after I posted, that crap always happens to me. Anyways, I booted into safe mode and disabled restore.
    this did not work:
    Also run follow the below steps:

    i typed it exactly as instructed and it says 'nail.exe' is not recognized as an internal or external command, operable progam or batch file. i forgot to turn system restore off while removing aurora uninstaller and elite toolbar remover, so should i run it again or no? they both were removed succesfully, and i restarted as instructed after using the Aurora. I uninstalled Symantec. I fixed the Hijackthis.exe and put it in the folder C:\Program Files\HJT. When I extracted everything it made another folder called "hijackthis" inside the HJT, so i copy and pasted the hijackthis.exe into the C:\Program Files\HJT and deleted the "hijackthis". I hope I did not mess up anything. It seems you want me to run it directly from C:\Program Files\HJT. Sorry, I did not read thouroughly and unzip the file. I have finished steps 14-16. I will continue now with 17. I thought I should let you now the nail removal did not work. Thanks for all your help. Once again sorry for double posting.

    By the way your link you gave me for the Elite Tool Bar Remover was a broken link. When I clicked on it, it send me here http://download4465.html/ but I figured it out.
     
  22. aNg3LbAbi3

    aNg3LbAbi3 Private E-2

     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This sounds a little contradicting! First you say you are not getting anymore popups and then you say you are still getting popups. I would say you are still getting them because you still do not have all your problems fixed and some new problems have showed up.

    I do not use a popup blocker as I have not really found one necessary. And if you use Firefox as a browser, a popup blocker is built in.

    You need to open Control Panel and run Add/Remove programs and uninstall Weatherbug!

    Your new problems require some special tools to helps us fix them. First we need to find a bunch of hidden bad files. The steps below will help us do that:

    Follow the steps below:

    1 - Please EXTRACT all files from Qoologic Tool to its own folder - C:\Program Files\QoologicFinder . Then, DoubleClick Find-Qoologic.bat to run the tool. It should produce a log - Please attach that with your next post!

    2 - Please EXTRACT all the files form RKFiles Tool to its own folder - C:\Program Files\RKTOOL. Then, Please boot to SAFE MODE and DoubleClick rkfiles.bat to run the tool. Let it run and then, when it finishes, look for a log at C:\Log.txt and please attach that log after rebooting back to normal mode.

    After posting the above two logs, we will work up fix for your remaining problems.

     
  24. aNg3LbAbi3

    aNg3LbAbi3 Private E-2

    lolz. sorryy i edited to say there were popups and didnt reread what i had posted. i was rushing to leave the house. i also didnt wait long enough to see about the popups and viruses. i am still getting viruses but not as much. i already uninstalled weatherbug since the last time i posted. everyone says Firefox is better than Internet Explorer, which would you recommend? here are the two logs you requested. thanks for all your help.
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you still have system restore disabled. It should remain disable until we have fixed all problems.

    Download Pocket Killbox and save it to its own folder where you can find it.

    Read thru the below steps and make sure you understand them before starting. Ask questions if you have any before starting.

    Run Killbox by double clicking on the killbox.exe file.

    Check the following boxes:

    Standard File Kill
    End Explorer Shell While Killing file

    Copy & paste (you must use copy & paste - typing will give an error) the full path of each of the files below (one at a time - see directions after the list) into the Full Path of File to Delete box.

    C:\WINDOWS\ZZOMR.DLL
    C:\WINDOWS\system32\kkawg.dat
    C:\WINDOWS\system32\kkpian.exe
    C:\WINDOWS\system32\qojuexx.exe
    C:\WINDOWS\system32\rrisegb.dll
    C:\WINDOWS\system32\uukdo.dll
    C:\WINDOWS\system32\ikw1.sys
    C:\WINDOWS\system32\mirindaspe.exe
    C:\WINDOWS\system32\v3zdm.exe
    C:\WINDOWS\ikw1.sys
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\iikr.exe



    With the full path to the file name in the Full Path of File to Delete textbox. The filename will appear under the box in a blue color to indicate it was found. Now Click the Red X and for the confirmation message that will appear, you will need to click Yes. If the file is successfully delete you will get a message of confirmation. Just click OK!
    Do this for each of the files listed. Some will not be deleted. Make sure you keep a list of them.

    Now for any files not deleted properly above (the ones you wrote down), do the below (if all of them deleted, skip these steps):
    - in Killbox select the option to Delete on Reboot
    - uncheck the option to End Explorer Shell While Killing file

    Copy & paste the full path of each of the files you could not delete above into the box and then click the Red X and for the confirmation message that will appear, you will need to click Yes. A second message will ask to Reboot now? You will need to click No (since you are not finished adding all related files in yet).

    When you do enter the last file name that needs to be deleted, click Yes on the last file.
    Note: Killbox will let you know if the file does not exist.

    Okay so now your PC should be reboot. If you get an error message about Pending Operations, just reboot your PC yourself.

    After reboot download and install Microsoft® Windows AntiSpyware and make sure you get the updates but do not run a scan yet.

    Now reboot into safe mode with no network support, make sure you have no browsers opened and then run a full scan with MS Antispyware and let it fix what it finds.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  26. aNg3LbAbi3

    aNg3LbAbi3 Private E-2

    thanks again for helping, i really appreciate it. here is the log you requested.
    i have a question...everytime i run HiJackThis it already has the old log, once its ran again does the new log replace the old one automatically. i saved the new log as hijackthis2.log.the cpu seems fine so far, it really hasn't been that long to know. thanks again for all the help. :)
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have not uninstall Weather Bug. It is in your log.
    O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE 1

    Please open Control Panel and run Add/Remove Programs. Look for Weather Bug or Weather and uninstall it.

    Each time you run HijackThis to create a log, it defaults to creating a file named hijackthis.log which will overwrite the previous log saved with the same name. For uploading here, it is sometime necessary to change the name of the file each time. As you already did, it is useful to just add a number to the log file each time.

    You MUST remember to exit your browsers before running HijackThis. You had two of them running:

    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe

    Were you able to complete the steps in message # 25 properly? It does not look like it. I still see the same problems.

    Download this: ABIremover

    Unzip it into its own folder. Now boot into safe mode with no network support and do not open any browsers. Now run the the ABIremover.exe file.

    When done reboot into normal mode and post a new HJT log.
     
  28. aNg3LbAbi3

    aNg3LbAbi3 Private E-2

    i have uninstalled it. its not in the add/remove programs anymore. i also saw it say, weatherbug succesfully removed. i know for a fact i removed it.
    http://img275.echo.cx/img275/4796/filesprog7ui.png you can look at the screen shot. im most postively sure i did exit all browsers. everything went fine with message 25, C:\WINDOWS\system32\rrisegb.dll; was the only file that would not delete. i checked so it would delete when i restart. since then i have only had one virus pop up in the same location, Local Setting/Temporary Internet Files/blahh folder/filewhaever.exe. could you please let me know if i need to boot into safe mode to do certain things or not, like each time. im always confused whether to go ahead and boot into safe mode, or wait until you say so. also, once i finish the session or tutorial, should i turn system restore on again? or leave it. i will proceed with the tutorial tommorrow. its 11:20 pm here and i have to get up early. thanks for your time and helping.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    My directions always tell you what mode to be in.

    Did you run ABIremover? If so, I need to see a new HJT log.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Since you did not post the new HJT log, I'm going to assume things are the same as in the last log you posted.

    System restore should still be disabled until we are finished fixing all problems.
    Make sure viewing of hidden files is enabled.

    If you are sure you are closing your browsers then they could be running due to a malware problem. So my below process is going to have you kill any that may be running.

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    c:\windows\system32\ugczktn.exe
    C:\Program Files\Internet Explorer\iexplore.exe <--- kill all instances of iexplore.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\kkpian.exe
    O4 - HKLM\..\Run: [vfhbvdy] c:\windows\system32\ugczktn.exe
    O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE 1
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (file missing) (HKCU)
    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\kkpian.exe
    c:\windows\system32\ugczktn.exe
    C:\Program Files\AWS <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  31. aNg3LbAbi3

    aNg3LbAbi3 Private E-2



    i also downloaded and ran this. it supposedly removed things. thanks for all your help. here is the new log. thanks again.
     

    Attached Files:

  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must not reboot or power down you PC after posting logs. Your problems are changing names when you do and that it the reason you are not finding some of the items I listed to be fixed.

    I did not say run CCleaner with read me. I said run Ccleaner and added an note explaining that it was one of the items your downloaded while running the READ ME FIRST sticky thread.

    Task Manager is brought up by hitting CTRL-ALT-DEL simultaneously. You could also use the Process Manager of HJT to kill the processes if necessary.

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\windows\system32\notepad.exe
    c:\windows\system32\ilkpaq.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [ksarvg] c:\windows\system32\ilkpaq.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    c:\windows\system32\ilkpaq.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner. Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    DO NOT REBOOT after posting your log.
     
  33. aNg3LbAbi3

    aNg3LbAbi3 Private E-2

    hi, sorry it took so long to respond. i have been busy with work and i also went on vacation. i just got back from vacation yesterday. it took me forever to find my thread. the computer has been restarted since the last time i posted. my family members were using it and it froze. do i follow the last steps you told me still? thanks in advance.
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! If those same items still exist and nothing new has popped up. In 3 weeks, alot can change.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds