vx2.look2me problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by Peeksnit, Sep 4, 2005.

  1. Peeksnit

    Peeksnit Private E-2

    I have a similar problem as jazzy on 9-1-05. I ran CW Shredder after many attempts to identify and clean current virus. Have used spybot and adaware and Norton AntiVirus. I copied HijackThis to a serperate folder under C:\program files. I opened and ran HijackThis and saved the log, but was cautioned that loading file in temp. I wasn't sure how to "unzip the highjackthis.exe file to folder" in chaslang's reply to jazzy. I've attached the log but not sure if valid or worse. I have spend several hours and not getting very far....any help is GREATLY appreciated.
     

    Attached Files:

    • log.txt
      File size:
      8.5 KB
      Views:
      4
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read the announcement and sticky threads. HJT logs should only be posted when requested and then they must be attachments to your message. And you need to get HijackThis.exe extracted from the ZIP file you downloaded. You are currently running it directly from the ZIP file.

    To get hijackthis.exe extracted from the ZIP File into the location we requested do the following.

    The below will work for WinXP based system since it can deal with ZIP files.

    You need to create the C:\Program Files\HJT folder. Do the following:

    - Click START and select Explore.
    - Select the drive where Windows is installed (normally C:)
    - Navigate to the C:\Program Files folder and select it.
    - Now click the on the top menu where it says File and then select New.
    - Then select Folder
    - A new folder is created and highlighted.
    - Just type HJT to overwrite the default name (New Folder)


    To extract hijackthis.exe:
    - locate the HijackThis.zip file you downloaded and right click on it
    - Select Extract All and click Next
    - Browse your way to the C:\Program Files\HJT folder created above
    - Select the folder and click Next

    Using Winzip:
    - locate the HijackThis.zip file you downloaded and right click on it and select Extract to. This will open Winzip.
    - Use the Folders/drives navigation pane to locate and select the C:\Program Files\HJT folder you previously created. After selecting it, make sure it shows in th Extract to: box.
    - Click the Extract button


    Please run the steps below.

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem, boot into normal mode and make sure you follow these directions:


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You also need to run the other tool given to Jazzy.

    Download the following tool and save it where you will be able to find it.

    L2MeFix Tool

    Please print out these instructions now or save locally so that you can operate with All Browser Windows CLOSED.

    Exit Browsers now before continuing

    Please move the L2MeFix Tool to your Desktop and DoubleClick l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix Folder on your Desktop. DoubleClick l2mfix.bat and Type 1 and ENTER to select Option #1 for Run Find Log . Allow it as much time as it needs to run until NotePad opens with a log.

    NOTE: Please do not run any other options or files in the l2mfix Folder!

    Now reconnect and come back here and post as an attachment the l2mfix log.
     
  4. Peeksnit

    Peeksnit Private E-2

    Looks like I am still infected. I re-ran Bitdefender and said I have one file infected with Adware.wheaterbug.A.

    I ran the L2mefix tool AFTER going thru the 4 steps to clean up the computer. I apologize, I saw the list and wanted to "get after it". I have attached the log and additionally attached the log for Hijack This after going through the four steps to clean the machine.

    Recap:
    Original running of Bitdefender indicated still infected.
    RavAntivirus did not find any virus. Avert Stinger did not identify anything. Ad-Aware SE with VX2 cleaner found 5 negligible risks that I deleted. CWShredder did not find anything nor did Kill2me. HSRevove removed 8 items. Spybot found 1 which was removed and ran immunize. CCleaner deleted 42.4MB and 1175 temp files and have log if you need to see.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Post your BitDefender log. Quite often it just reports th Wheaterbug.A porblem in AOL or AIM files. I'm not sure that it is really a problem.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.

    On the page that opens, scroll down to CWShredder Service ... right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    CWShredder Service

    Now exit HJT and do not reboot if it asks you to do so. We will be rebooting in safe mode in a few lines.



    Okay let's start by downloading two tools we will need:

    - Process Explorer 9.2

    - Pocket KillBox

    Extract them to there own folder somewhere that you will be able to locate them later.

    Reboot in Safe Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of pmkkk.dll once and then click the kill button. After you have killed all of the pmkkk.dll's under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of pmkkk.dll and kill it.

    Now just look for the below process in Process Explorer and right click on it and Kill it.C:\WINDOWS\etb\pokapoka65.exe

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R3 - URLSearchHook: (no name) - _{4FC95EDD-4796-4966-9049-29649C80111D} - (no file)
    O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\system32\pmkkk.dll
    O4 - HKLM\..\Run: [System service65] C:\WINDOWS\etb\pokapoka65.exe
    O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
    O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O20 - Winlogon Notify: pmkkk - C:\WINDOWS\system32\pmkkk.dll
    O23 - Service: CWShredder Service - Unknown owner - D:\cwshredder.exe (file missing) <--- this line should already be gone


    Copy the bold text below to notepad. Save it as fixVundo.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.


    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.

    C:\WINDOWS\system32\vtsqp.dll
    C:\WINDOWS\SYSTEM32\kkkmp.ini
    C:\WINDOWS\SYSTEM32\
    kkkmp.ini2
    C:\WINDOWS\SYSTEM32\
    kkkmp.bak
    C:\WINDOWS\SYSTEM32\
    kkkmp.bak2
    C:\WINDOWS\SYSTEM32\
    kkkmp.tmp
    C:\WINDOWS\system32\pmkkk.dll

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    After reboot post a new HJT log.
     
  6. Peeksnit

    Peeksnit Private E-2

    I've attached the Hijack This log. When I ran Process Explorer, was not able to find C:\WINDOWS\etb\pokapoka65.exe to kill.

    Also, just want to note that there are icons on Explorer that are odd looking and include: People Search, Find Any Email, HOT Ringtones, Online Dating, Online Casinos and Virus Scan. I have family that goes on the pc and may have added but don't really think so. Just wanted to give you this info in case it means anything???

    As Always, THANKS.

    Tom aka peeksnit
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! We fix your Virtumundo problem but you still have the Elite Toolbar problem ( C:\WINDOWS\etb\pokapoka66.exe )

    Run Process Explorer now in normal boot mode and select kill process tree.

    Then look for the folder C:\WINDOWS\etb and delete it.

    Then run HijackThis and have it fix:
    O4 - HKLM\..\Run: [System service65] C:\WINDOWS\etb\pokapoka65.exe

    Then reboot and look at a new HJT log and see if this stuff remains fixed. If not, download and run the following:

    EliteToolbar Remover

    Then see how things look. Post a new HJT log.
     
    Last edited: Sep 9, 2005
  8. Peeksnit

    Peeksnit Private E-2

    Quick update. I just completed running norton antivirus and it indicated that it identified C:\WINDOWS\etb\pokapoka65.exe and deleted it. It also deleted proxy inst[1].exe 3 times and xud 63.dll. Should I continue with your last list or anything I should do differently?

    Tom
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Check a new HJT log yourself. Do you still see the process running? Do you see the O4 line ? If so, you need to fix it?

    It's rather strange that it did not detect it before. Did you just update Norton or something?
     
  10. Peeksnit

    Peeksnit Private E-2

    I DID just update Norton (was current when originally ran) you are correct. I went into Hijack This and found the 04 and tried to fix but doesn't appear to clean/fix. Should I do the following as indicated in prior message??




    Run Process Explorer now in normal boot mode and select kill process tree.

    Then look for the folder C:\WINDOWS\etb and delete it.

    Then run HijackThis and have it fix:
    O4 - HKLM\..\Run: [System service65] C:\WINDOWS\etb\pokapoka65.exe

    Then reboot and look at a new HJT log and see if this stuff remains fixed. If not, download and run the following:

    EliteToolbar Remover as indicated in
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes follow the steps in the previous message.
     
  12. Peeksnit

    Peeksnit Private E-2

    I am a little confused, not sure about how to: Run Process Explorer now in normal boot mode and select kill process tree.
    THEN look for the folder C:\WINDOWS\etb and delete it. When I press process, kill tree it asks if I want to kill. Are these instructions in reverse, after highlighting explorer.exe and identifying c:\windows\etb??? If so, I do not see C:\windows\etb. Perhaps I am looking in the wrong place??

    I DO see pokapoka66.exe after expanding explorer tree in processes and dying to blast it! Too much caffeine I guess. Thanks....Tom
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No the steps are in the right order. You cannot delete the etb folder if the process which is running from it (pokapoka66.exe) is still running. So you need to find the pokapoka66.exe process in Process Explorer and right click on it and select Kill process tree. Then immediately attempt to delete the C:\WINDOWS\etb folder by running Windows Explorer and navigating to the C:\Windows folder and locate the etb folder. Right click on it and select Delete (Note: You are not doing the delete of the folder from Process Explorer. You are using Windows Explorer).

    Do you know what Windows Explorer is? Right click the Start button and select Explore. That's Windows Explorer.

    Have you run EliteToolbar Remover yet. If not, please run it now!
     
  14. Peeksnit

    Peeksnit Private E-2

    In prior message I was not certain I should delete the pokapoka66.exe process but did so. Went to Hijack This and file was still there after repeated "fixes" so went to Elite Toolbar Remover and voila!!!!! I am cured for now. Thank you many times over. My son has used this pc (alot) and wants to know if he can use again. I have no reason to keep him off it, but told him he could "open" any files that are required, before proceeding. Any additional advice?

    Also, should I leave all of downloaded applications on the pc and re-enable system restore?



    Tom
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is no reason to remove any of them. Yes re-enable system restore. You should also work thru the steps in the below (some you may already have done so ignore the ones you have). Make sure you do check Windows Update (step 1):

    How to Protect yourself from malware!
     
  16. Peeksnit

    Peeksnit Private E-2

    Thx again.....REALLY appreciate all your help. It is very easy to feel like the lone ranger and calling up for support can be expensive AND takes extensive time with no real guarantees that person on other end will be able to help, especially in a reasonable timeframe.

    Tom
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome Tom!

    I'll let you in on a little secret. Many times people have come here to get problems fixed because a Tech Support person (who could not fix their problems) sent them here. Even Microsoft and Dell have sent people here.
     
  18. Peeksnit

    Peeksnit Private E-2

    That is quite a compliment. I am going to refer a friend from Indiana who is about to toss his machine.

    thanks again.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    Send all your friends here!
     
  20. Peeksnit

    Peeksnit Private E-2

    I have had continual problems with Outlook ('02 in XP) going up and down all day long. Actually hasn't happened for about a week for no apparent reason except I was spending more time trying to clean other computer. I tried to look up similar problems in software archives and also current topics for software. Is there any way to "search" on the archives without going thru each one?

    btw, I DID copy the virus thread to two friends with problems.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try Search which is one of the upper title bars and select Advanced Search. The select All Open Forums (which should be the default. It sounds like a Software Forum topic to me.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds