Trojan horse in winkku32.dll and cool.exe problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by wedowee, Aug 9, 2006.

  1. wedowee

    wedowee Private E-2

    I have followed the lengthy instructions and have now attached my hijackthis log. It's taken me a day and a half to finish the steps due to the number of files. Thanks for all your hard work.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You need to complete ALL of the READ & RUN ME and attach the other requested logs!

    • newfiles.txt - the log from ShowNew.bat
    • Bitdefender - from step 6
     
  3. wedowee

    wedowee Private E-2

    I wasn't sure how to do that as it gave me a 3 file maximum for uploading. Here are the others, thanks for the reply.
     

    Attached Files:

  4. wedowee

    wedowee Private E-2

    I researched further in the forum and found a suggestion to remove Norton AV and install AVG Free Edition. I ran two scans on it, and it said it removed two of the big problems/virii. I'm still open to suggestions and cleaning up my PC further though. I will update again tomorrow (Wednesday).
     
    Last edited by a moderator: Aug 9, 2006
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is mentioned in the HOW TO: Attach Items To Your Post link that is provided several times in the READ & RUN ME. At any rate, you now know to use a second message. ;)

    According to the ShowNew log you do not have Spybot installed; however, your HJT log showed a Spybot DLL. Please explain. Did you uninstall Spybot only after running ShowNew? You should have installed Spybot in step 4 before ShowNew was run.

    You also did not update your Sun Java version as mentioned in step 6. You are still using Java 2 Runtime Environment, SE v1.4.2_03 which is way out of date and has security issues.

    Did you skip any other steps in the READ ME.

    After running Spybot and updating Sun Java, continue with below.

    First login as Christian and run the below:


    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Then boot into safe mode and login as Administrator and then repeat the above reset of web settings.

    You should goto Add/Remove programs and uninstall the below:
    eDonkey2000
    WaReZLinkCollector v1.5.3
    Yazzle by OIN

    Now to continue with your fixes complete the below.

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of winkku32.dll once and then click the kill button. After you have killed all of the winkku32.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below two DLLs:
    mllmj.dll

    Next double click on explorer.exe and again click once on each instance of winkku32.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below two DLLs:
    mllmj.dll

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {A4F94C0C-54A7-4DB1-9AF3-B22E63D00311} - C:\WINDOWS\g3152265.dll
    O4 - HKLM\..\Run: [eDonkey2000] "C:\Program Files\eDonkey2000\eDonkey2000.exe" -t
    O20 - Winlogon Notify: mllmj - C:\WINDOWS\system32\mllmj.dll (file missing)
    O20 - Winlogon Notify: winkku32 - C:\WINDOWS\SYSTEM32\winkku32.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now click Start, Run, and enter cmd and click OK! This will open a command prompt window. In the command prompt window enter the below commands each followed by the Enter key.
    del %windir%\temp\win*.*
    exit


    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    Now back on Killbox's main window, Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.
    C:\d8ed9e96-7086-4690-8763-dea9097b16ea.cab
    C:\sccfg.sys
    C:\WINDOWS\g3152265.dll
    C:\WINDOWS\system32\mllmj.dll
    C:\WINDOWS\SYSTEM32\winkku32.dll

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.
    After reboot locat the below folder and delete it if found:
    C:\Program Files\eDonkey2000

    Also delete all files in the below folder except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Documents and Settings\HP_Administrator\Local Settings\Temp\


    Now attach a new HJT log and tell me how the steps went.
    Also attach a new log from ShowNew.
    Make sure you tell me how things are working now!
     
    Last edited: Aug 9, 2006
  6. wedowee

    wedowee Private E-2

    I'm not sure why it reads I don't have Spybot installed. I ran it several times yesterday and again today.

    I have now updated Sun Java, as I received an error yesterday stating it would not install. But it's in there okay now.

    When logging in as Christian (non-admin acct), it gave an error while trying to reset default web settings, stating it was not allowed.

    I uninstalled WarezLinkCollector
    Yazzle was no longer there to uninstall
    (I did not uninstall eDonkey2000 as I am in the middle of several downloads. If it is a necessary step, I can uninstall it as soon as those downloads are done, but it's software I use often.)

    Process Explorer did not find any instances of mllmj or winkku32. I think the AVG antivirus software cleaned them out last nite.

    I ran HJT and clicked Fix on all options except eDonkey2000.

    I ran the fixme.reg and rec'd a msg that the reg entries successfully merged into the registry.

    I ran the delete command (del %windir%\temp\win*.*) and rec'd a msg that it could not find C:\WINDOWS\temp\win*.*, which I think means there were no files to be deleted.

    I ran Pocket Killbox and entered the 5 paths you provided, and rebooted on the final entry.

    I then deleted all files in my local settings/temp folder. The only one that would not delete was the IadHide5.dll file (modified date of 11/5/04).

    Everything appears to be running much better now. The help is greatly appreciated. Please advise if there is anything else I need to do.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    eDonkey contains malware and downloading from P2P sites like this is a major cause of PCs getting infected. See the below links for additional info:

    http://www.bleepingcomputer.com/startups/eDonkey2000.exe-7149.html

    http://www.castlecops.com/s12410-eDonkey2000.html

    http://www.fbmsoftware.com/spyware-net/Process/edonkey2000_exe/705/


    Why did you install AVG7??? You now have multiple antivirus applications installed which is what step 3 of the READ ME specifically tells you not to do. You must uninstall one.

    Then have HijackThis fix the below two lines;

    O20 - Winlogon Notify: mllmj - C:\WINDOWS\system32\mllmj.dll (file missing)
    O20 - Winlogon Notify: winkku32 - winkku32.dll (file missing)

    Now attach a new HJT log.

    Since you could not Reset Web Settings for Christian, you must either change the account to an admin account so you can do this. Or you need to look at ALL the EXE files listed in the PandaActiveScan log that appear in on of the sub-folders of:

    C:\Documents and Settings\Christian\Local Settings\Temporary Internet Files\Content.IE5

    and delete them manually. Here are just a few examples but you have loads of them (many probably came from eDonkey downloading).

    C:\Documents and Settings\Christian\Local Settings\Temporary Internet Files\Content.IE5\0TAB812N\srvame[1].exe
    C:\Documents and Settings\Christian\Local Settings\Temporary Internet Files\Content.IE5\0TAB812N\srvbox[1].exe
    C:\Documents and Settings\Christian\Local Settings\Temporary Internet Files\Content.IE5\0TAB812N\srvcvd[1].exe
    C:\Documents and Settings\Christian\Local Settings\Temporary Internet Files\Content.IE5\0TAB812N\srvhoj[1].exe
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds