W32/Trats and JKKLK.DLL Viruses

Discussion in 'Malware Help (A Specialist Will Reply)' started by LisaRose122, Jan 22, 2008.

  1. LisaRose122

    LisaRose122 Private E-2

    God I hope you all can help me!! I have been 3 days now trying to get rid of W32/Trats and jkklk.dll.They are both viruses supposedly and NOTHING I do gets rid of them.I am at my wits end and don't know where to go on this or what to do.I use McAFee as a virus scan and I have used quite a few different spyware removals and what have ya.I need to get this off my computer.I have quit using IE for the time being and have installed Firefox.I just need to know how to get this/these things off my system.Any help will be appreciated.I know alot about computers but am yet still illerate in the removal of a virus that don't seem to want to go away.
    Thank you
    LisaRose122
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. LisaRose122

    LisaRose122 Private E-2

    Thank you Chaslang...I did everything step by step where ya told me to go and I am happy to say that it got rid of them viruses for me and also cleaned my computer really good :celebrate I even ininstalled and reinstalled IE7 and I am still having a little bit of a problem with it tho....it don't want to show images right and also on one of my homepages it messes everything up...not really sure what is going on with it yet.Any suggestions?Thank you again for your help....it was highly appreciated!!
    ~~HUGGERS~~
    LisaRose122
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome, but you really should complete the instructions given and attach the logs that were requested. I really doubt that you are clean even if you are not seeing the symptoms.

    IE7 problems should be discussed in the Software Forum.
     
  5. LisaRose122

    LisaRose122 Private E-2

    Sorry about that...I was up til after 3am doing all of that stuff.The only report/log I have is the Combo Fix one...I am thinking that is the only one that gave me one.I do see on the AVG Anti Spyware where there is one but it won't let copy and paste it.Do you want me to do them all again and try to get a log of them all?I am sending the combofix one tho.Please let me know...If that is what you want me to do and I don't hear from you today/tonight tho I will have to do that in a couple of days because my Mom is getting surgery in the morning.Thanks again for all your help.( I Hope it attached right)
    Thank you
    LisaRose122
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then you did not finish the READ ME. We need the log from MGtools. It is the most important one of them all. If you ran MGtools as requested the log will be C:\MGlogs.zip as stated in the READ ME.


    Note: You are definitely still infected from what I saw in ComboFix alone. How bad remains to be seen when we get the MGlogs.zip file.
     
  7. LisaRose122

    LisaRose122 Private E-2

    Can you tell me what I am still infected with? I went where you told me to get that log at and the only zip file there will not let me attach it.Would it help if I ran it again.
    Thanks,
    A very disgusted LisaRose122
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have the most recent version of Virtumonde and only manual procedures will fix it.
    Also you have TVMedia .

    Do you have the C:\MGtools folder on you hard disk? You should if you ran MGtools.exe

    You should also have the C:\MGtools.exe file which is what we asked you to download.

    What ZIP file are you trying to attach? You should only be trying to attach the MGlogs.zip file and nothing else. You will not have the MGlogs.zip file if you did not successfully run MGtools.exe as requested.
     
  9. LisaRose122

    LisaRose122 Private E-2

    I ran that MGTools again and found what you needed this time and it is attached....thank you for all your help and I will be waiting to hear from you.
    Thank you
    LisaRose122
     

    Attached Files:

  10. LisaRose122

    LisaRose122 Private E-2

    I just got your reply on the Virtumonde ...What is that and where do I go to remove it?I hope I get it all taken care of...I HATE having ANYTHING on my computer and will go crazy til it's gone.
    LisaRose122
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are going to have to get me a new MGlogs.zip file now after your stop using MSconfig to control startups as was requested in step 1 of the READ ME. You must select Normal Startup and you must not use MSconfig like this anymore.

    You can then create the new log by doing the below.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below log.
    • C:\MGlogs.zip
     
  12. LisaRose122

    LisaRose122 Private E-2

    Here is the new MGTools results...And yes it is done right this time....thanks again for all your help.I hope I have the right one attached.
    LisaRose122
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now we need to use a new tool.
    • Download and save to RenV.exe to your Desktop (must be on the Desktop)
    • Now Copy the bold text in the below code box to notepad. Save it as Log.txt to your desktop. (It must be on your Desktop).
    Code:
    C:\hp\KBD\KBD .EXE
    C:\Program Files\Pando Networks\Pando\Pando .exe
    C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig .exe
    C:\WINDOWS\SMINST\RECGUARD .EXE
    C:\WINDOWS\system\hpsysdrv .exe
    C:\WINDOWS\system32\ctfmon .exe
    C:\WINDOWS\system32\hkcmd .exe
    C:\WINDOWS\system32\ps2 .exe
    
    • Now using your mouse, drag Log.txt onto RenV.exe
    • When finished, RenV.exe will produce a new log names Log.txt on your Desktop may or may not ask for this log later.
    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    Java(TM) 6 Update 3
    Web Savings from Ebates <-- should have been uninstalled in step 0 of the READ ME


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - SOFTWARE - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
    O20 - AppInit_DLLs: mad.dll

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below log:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Mar 5, 2008
  14. LisaRose122

    LisaRose122 Private E-2

    Chaslang...I really appreciate all the help you are giving me...As I had said earlier ..My Mom is getting surgery in the morning and we are leaving at 3:30am because the hospital is at least an hour away and her surgery is scheduled for 5:30am....Now I will be gone all day and part of the evening...when I get back I will do all of this that you told me to do.I would do it now but my 3yr old grandson loves turning the computer off when I ain't home....so I will do it when I get back.Thank you again.
    LisaRose122
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome and good luck with your mom's surgery.
     
  16. LisaRose122

    LisaRose122 Private E-2

    Hi Chaslang...I hope you are still willing to help me fix my computer.Sorry it has been so long....The day after my Mom's surgery I got the flu real bad and was laid up with it for about 3 weeks....My Mom's surgery went well by the way.

    Now I have did what you told me to do and got down to the Avenger and downloaded that and was following what you said to do but there is no magnifying glass icon in there for me to click on and so I am so lost as to what to do.I really need to get this taken care of because I can not use certain programs correctly and images don't show for me.I don't care too much for Firefox browser but yet IE don't work right.Thanks for all your help.
    LisaRose122
     
  17. LisaRose122

    LisaRose122 Private E-2

    I forgot to tell you that when I downloaded that RenV.exe...that 2 other things came up on my desktop also and they are...nircmd.exe and sed.exe.....what do I do with them?
    Thanks again
    LisaRose122
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's great, but too bad you got sick. :(

    Since I posted the fix and you trying to run it, Avenger has been updated to a new version. Go back to the procedure now and try again. I modified it for the new version of Avenger.

    Nothing until we finish your cleanup.;)
     
  19. LisaRose122

    LisaRose122 Private E-2

    Hi Chaslang...I have finally go to do all of this and I am hoping it worked.Now let me tell you tho ...when I got to this part...

    O2 - BHO: (no name) - SOFTWARE - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
    O20 - AppInit_DLLs: mad.dll

    Them 3 things were not there.So I didn't delete anything.Please tell me I am ok now.I have been messing with this for so long now that I soooo want it to be fixed.I am attaching what you requested.Please let me know when it is safe to uninstall Firefox and update IE if needed.
    Thank you for everything!!
    LisaRose122
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The above was not there because you did not follow all of my instructions in message # 13.

    One part said
    And then after running Avenger, I said:
    You did not do these steps and still need to ( but now it will say jre1.6.0_05 not jre1.6.0_04 ) and then you will have to attach another new MGlogs.zip file.
     
  21. LisaRose122

    LisaRose122 Private E-2

    I started over because I want to do this right...well I uninstalled the Java stuff and then did the MGTools again and them things are still not in there...I am attaching a copy of the HJT scan before I move on,so please get back to me as soon as ya can.Thank you.
    LisaRose122
     

    Attached Files:

  22. LisaRose122

    LisaRose122 Private E-2

    Hey Chaslang....I went ahead and just did it all over again...and that stuff is still NOT there!! And I did this step by step and double checked and everything.I am attaching the MGTools and Avenger logs again tho.Please let me know how this is now.
    Thank you again.
    LisaRose122
     

    Attached Files:

    Last edited: Mar 30, 2008
  23. LisaRose122

    LisaRose122 Private E-2

    And I still don't see the Avenger file attached...trying it again.
     
  24. LisaRose122

    LisaRose122 Private E-2

    OMG...why won't it attach???
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it is! See your HijackThis log and you will see the below which I said would be there now:

    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"

    This is not malware. It is just an automatic update program for Sun Java and we just don't believe you should have it running all the time wasting resources and slowing down startup. It is not a problem if you don't fix it.


    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix. If we had you run Avenger, you can delete all files related to Avenger now.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    3. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
     
  26. LisaRose122

    LisaRose122 Private E-2

    I have did everything Chaslang and I appreciate all of your help and patience with me.I also removed that one thing in my HJT log(the java thing).I had McAFee as my anti virus scan and switched back to my AVG after reading that it uses alot of resources and there is alot more things that are moving better now.I am still having a little bit of a problem with IE6...I have that and Firefox both...but with both of them actually..I can't see all of the images at different sites.Is there anything else you can suggest?I am so glad that my computer is now clean...oh and I did download a firewall.
    Thank you again for everything.
    LisaRose122
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It could just be a setting that you need to adjust in your browers or you could be blocking things with your firewall. I would suggest posting in the Software Forum and describing in detail what happens. And does it happen on all websites? Does it happen with your firewall shutdown? Does it happen in safe boot mode?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds