Trogan horse Flooder.AKA

Discussion in 'Malware Help (A Specialist Will Reply)' started by Wlfwo, Dec 7, 2006.

  1. Wlfwo

    Wlfwo Private E-2

    This was found on my morning anti-vir scan. So I did all the read and run me to clean the computer and that found other things that I need to be rid of, some spidy something and something in my D drive, nothing gets downloaded to D. Any help would be appreciated. Thanks in advance, posting the logs now.

    OK, it says my bscan is too large to post. I will run it again tomorrow if needed.

    Nancy
     

    Attached Files:

  2. Wlfwo

    Wlfwo Private E-2

    I have no idea what I did wrong with yesterdays bscan, but it worked fine this morning. So here is the bscan and the active scan.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must always check to make sure you are using the proper version of utilities specified in the READ & RUN ME and you must always work from the current online copy of the READ & RUN ME. You are not doing this. Please download and use the correct versions of GetRunKey and ShowNew and attach new logs. Also you did not run CounterSpy (or AVG Antispyware as a substitute for CounterSpy) as required in the READ ME. You must also attach the log from CounterSpy or AVG Antispyware (which every you run).
     
  4. Wlfwo

    Wlfwo Private E-2

    Sorry about that, I used the ones I downloaded last fall and used the notepad I saved with it. Here are the new scans and the avg antispy. The scan 2 is the antispy.
    Thanks,
    Nancy
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Now you know that you must always use the online READ ME to be following current procedures.


    Make sure viewing of hidden files is enabled (per the tutorial).

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 7
    J2SE Runtime Environment 5.0 Update 8
    Mozilla Firefox (1.5.0.8)

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\filesubmit <--- the whole folder

    Now run Ccleaner.

    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. Wlfwo

    Wlfwo Private E-2

    OK, here are the new scans. Everything seemed to go well. Either bitdefender or panda scan said I have a hacker virus. Nothing else seemed to pick up on that unless that is the flooder.aka thing.

    Computer runs well, I didn't notice a problem until avg said I had the flooder and I started running the "old" read and run me first, that is when I found all the other goodies.

    Thanks again,
    Nancy
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not seem like you ran the fixme.reg patch. At least not successfully. Did you run it? Did it give you a success message?

    Uninstall CounterSpy, reboot, and try the fixme.reg patch again. Then run the below to remove Windows Messenger:

    Disable/Remove Windows Messenger

    Now attach a new log from only GetRunKey.
     
  8. Wlfwo

    Wlfwo Private E-2


    Darn, yes I did. I remember it asked me if I wanted to do that. I don't remember if it said success. I will do it again. Sorry
    Nancy
     
  9. Wlfwo

    Wlfwo Private E-2

    Ok, I did the fix me again, I didn't download counterspy, I used AVG Anti-spy.

    Removed windows messenger, I don't think we use that one anyway and if my daughter does, well she can get over it.

    Here is the message that the fixme gave me, I think it's the same one I got before, but I can't swear to that since my memory sucks.:(

    Information in C:/Documents and Settings/HP_Administrator/Desktop/fixMe.reg reg has been successfully entered into the registry.

    So here is the newest runkey, and thanks ever so much.
    Nancy
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay perhaps it is Windows Defender blocking the change. Let's try something.

    Run HijackThis and select and fix the below line:
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    Then quickly do a new scan and check to see if the above line is gone. If not, uninstall Windows Defender and then fix the same line. If it is fixed, just tell me.

    Is everything running OK?
     
  11. Wlfwo

    Wlfwo Private E-2

    Yes, it says it's fixed, but it will come back, we have fixed that one each and every time (3) that you have helped me and it always comes back.

    And yes, everything is running just fine.

    Thanks,
    Nancy
     
  12. Wlfwo

    Wlfwo Private E-2

    OK, I just checked the TkBellExe is back. It always comes back. :confused:

    Nancy
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Was Windows Defender installed or uninstalled when you fixed it. Normally this line goes away easily except when a program like Windows Defender or similar is blocking it. This line is not malware. It is just unnecessary and wastes System Resources.
     
  14. Wlfwo

    Wlfwo Private E-2

    Installed, each time I think. Should I uninstall Windows Defender? And if I do should I just leave it uninstalled or reinstall it after we are done?
    Thanks again,
    Nancy
     
  15. Wlfwo

    Wlfwo Private E-2

    Ok, I uninstalled Windows Defender, ran the HJT and fixed the [TkBellExe] again, we'll see if it stays fixed this time. Re-did the fixme.reg patch, so am attaching the new runkeys log. I hope it took this time. Thanks,
    Nancy
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nope! I'm wondering if it could be a problem that ownership of the registry key has been changed. (Unless you are running Real Player and reinstating this setting each time we fix it).

    Please download and install Registrar Lite Make sure you select a Majorgeeks download link and not the Authors!

    Run Registrar Lite navigate to the following key and take ownership of it (I explained how to do that further down).

    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run


    To take ownership of the key do the following:
    • Copy & Paste the registry key from above into the Address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    • Click-on Security in the top Menu
    • Select Take Ownership
    • Now locate the TkBellExe variable in the right window pane and right click on it and select Delete
    • Now in RegistrarLite click View and then Refresh
    • Is the TkBellExe variable still gone.
    • Let me know if you get any error messages while doing this
    If the TkBellExe variable seems to have gone away, attach a new HJT log. If it did not go away, just tell me.
     
  17. Wlfwo

    Wlfwo Private E-2

    Ok, that seems to have worked, here is the new HJT file. My daughter uses real player occasionally, would just using the darn thing make it come back?

    Thanks again,
    Nancy
     

    Attached Files:

  18. Wlfwo

    Wlfwo Private E-2

    I forgot, no error messages.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's gone! ;)

    I don't believe so. I think it is an option that can probably be configured within the program but I don't allow this program on my PCs. They configure it that way when the program is installed.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  20. Wlfwo

    Wlfwo Private E-2

    As far as I know this is still on here, killit.exe, the active scan found that. Not sure about the newdotnet thing. We did get rid of the spidey whatever it was. And I am assuming my AVG got the flooder since it hasn't said anything about it since it found and quarantined it. The only thing it does say is that 2 files were changed, C:\system32\kernel32.dll and C:\system32\shell32.dll, I am assuming that AVG changed those itself? For uninfected ones? Why those would change since the infected files were in the D drive I don't know.
    Thanks,
    Nancy
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not malware. It is part of your HP software.

    That was part of Spidey which we removed. And other parts will be removed after you complete my instructions in message # 19.


    I cannot comment since I saw no information or log on this anywhere. Your system is clean based on your logs. If you run a full scan with AVG now (AFTER completing what I gave you in message # 19 first), do you have any detections?
     
  22. Wlfwo

    Wlfwo Private E-2

    Killit.exe is a rootkit then? Shows up on the Active scan as either hacker or rootkit.

    Will run message #19 and then check AVG again, it hasn't flagged anything and the flooder is in the virus vault.
    Will let you know, thanks, Nancy
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! I repeat it is just part of your HP software.

    No it doesn't. It shows up as:
    Notice the Potentially unwanted tool

    They do not say it is bad. They are just flagging it to bring it to your attention to make sure you know what it is.
     
  24. Wlfwo

    Wlfwo Private E-2

    OK, I did all of message #19, so far so good.

    What I don't understand is the hacker/rootkit that active scan said I had. This was during the actual scan. They give you a list while you are scanning and under hacker or rootkit it said I had one. It didn't specify which and the only thing I found on the report/log was the killit, so I figured that that was it.

    So I guess my question is: Would the killit show up as a hacker/rootkit during the actual scan? Not in the report, on the list during the actual scan? If not then what hacker/rootkit did I have?

    Thanks again and Thanks for being so patient with a total idiot. : )
    Nancy
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You would have to show it to me for me to know exactly what they told you, but it could be a similar thing where they list something there that may have been a potential problem. Again like a warning for you to check it out. However you have no other malware. Run a new scan with Panda if you like, and see what it tells you this time. If it still shows up, attach a copy and paste of what you see on the screen. Yes, it is possible that they are categorizing the HP killit.exe file in this aread but again that is a false detection.
     
  26. Wlfwo

    Wlfwo Private E-2

    Ok, that is what I wanted to know, seeing as it didn't show up in the log/report. It was listed while the scan was scanning, but naturally they didn't say WHAT exactly it was. I will run it again and see if only the killit shows up and then I will know that they are lumping that under hackers/rootkits. I will let you know what I find.
    Thanks bunches and have a Merry Christmas,
    Nancy
     
  27. Wlfwo

    Wlfwo Private E-2

    Rotten snots wouldn't let me copy and paste the screen. :rolleyes: While it's scanning it says I do have 1 hacker/rootkit so they must be saying the killit is one of those. I did attach the new report/log though. Nothing new on it, says I have tons of spyware even after running CCleaner before starting. I guess they have a liberal view of spyware?
    Thanks,
    Nancy
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ignore the message! It is a false positive.

    Read step 11 of How to Protect yourself from malware! to see the real story on cookies.

    Did you configure CCleaner to include Firefox/Mozilla and Cookies (which really is not needed but it is your decision)? Also is the stuff in Panda for the same user account that you ran CCleaner on. Ccleaner will only clean the account that you are currently logged into. You can also choose which cookies not to clean to avoid loosing various settings and auto login stuff (like for majorgeeks.com).
     
  29. Wlfwo

    Wlfwo Private E-2

    CCleaner already includes those two. Other than AD. we only have one account. I will check that one and make sure though. Thanks ever so much.
    Nancy
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    The cookies that Panda is flagging are for the user account named HP_Administrator
     
  31. Wlfwo

    Wlfwo Private E-2

    OK, one more quick question then, we never sign onto the HP_Administrator account, so HOW did cookies get in there? That is the account the computer came with, right?
    Nancy
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    At some point in time someone logged into that account. Yes it is probably the Administrator account that came with the PC. Maybe you even used it while booting in safe mode at some point. You can look at the dates of the files in the C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\nb64qmkq.default\ folder to get an idea of when they were created. But my point still stands, CCleaner will not clean them unless you are logged into that account. Thus the reason for the READ & RUN ME saying log into all accounts. Cookies are not problems to worry about anyway. The only reason we have you clean them during the READ ME is to make the log files more manageble in size and to make it easier for us to read thru them.
     
  33. Wlfwo

    Wlfwo Private E-2

    OK, I will make sure and do so. Thanks loads! : ) Nancy
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds