Win32:kolweb-e

Discussion in 'Malware Help (A Specialist Will Reply)' started by icefixer, Jan 31, 2008.

  1. icefixer

    icefixer Private E-2

    I ran a virus scan and it told me that I had a few win32 trojans. kolweb-e and the dialer-871 and the trojan-gen. I have ran the scans but can't remove. I also can't get into the 'set program access and defaults' also if I click on windows security alerts, it tells me that "this operation has been cancelled due to restrictions in effect on this computer. Please contact your system administrator" This also pops up if I try to add or remove programs when I go to my computer. Help. I do not have a system administator.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. icefixer

    icefixer Private E-2

    I found that it is the bolenjx virus. Now I can't get to the internet with this computer. I had to use my laptop. Can I download the read run me first and save to my laptop and write to a disk and download to my other computer.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes...save to either cd or memory stick and then move to the infected machine ...run the programs and copy to logs back to either cd or memory stick and attach them to your next reply.
     
  5. icefixer

    icefixer Private E-2

    I downloaded combo fix, mg tools, spy bot and avg but the virus will not let me install or run any of them.
     
  6. icefixer

    icefixer Private E-2

    mg tools gives me an error window. "failed to ensure dir exists:\MGtools"
    spy bot gives me an error window "error sending request. the server name or address could not be resolved"
    AVG finally let me install. and i had to reboot system.
    combo fix does nothing when i double click on the desk top icon.
     
  7. icefixer

    icefixer Private E-2

    I was able to run a hjt log/scan
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re-run HJT and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now see if you can run any of the other tools ...you should have been able to attach the MGLogs.zip.
     
  9. icefixer

    icefixer Private E-2

    The items no longer show up in the log, but i cannot run any of the tools. TO BE ABLE TO GET INTO THE CONTROL PANEL AND ADD or remove programs, I have to get into regedit and go HKEY_CURRENT-USER\CONTROLPANEL\REG_DWORD AND CHANGE VALUE TO "0" same with HKEY_LOCAL_MACHINE ALL THE WAY TO POLCIES\EXPLORER, ChaNGE NOCONTROLPANEL TO "0"
     
  10. icefixer

    icefixer Private E-2

    this is after i restart my computer.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    These items do show up in the log:
    Try going to start / run / and type "combofix.exe" without qoutes...do the same for "MGTools.exe"

    If either run ...attach the logs.
     
  12. icefixer

    icefixer Private E-2

    Thanks for your effort. I ran out of time and patients, and had to take it in to a tech service. They charged a lot. But I have to get my books done for my business.
    I was able to repair my laptop seven months ago using Majorgeeks. I tell everyone about you guys. I have learned a lot. And will keep learning. Thanks again.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry we were not able to help you this time ...let us know if it is truly fixed. :)
     
  14. icefixer

    icefixer Private E-2

    The reason I was not able to run the combofix was due to a command prompt missing according to the techy. Everything appears to be working normal now. Thanks again.
     
  15. icefixer

    icefixer Private E-2

    here is the results of the scans I was able to run. How do they look? Thanks in advance.
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Look pretty good .....and the cmd prompt missing makes sense.

    Did you at one time have McAfee and Avast installed before installing Norton? We just need to remove those items in your registry.

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 3"
    Java 2 Runtime Environment Standard Edition v1.3.1_02"
    Java 2 Runtime Environment, SE v1.4.0_01

    Reboot and install:
    Java Runtime 6

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    See if this still exists and delete it if found
    C:\Program Files\McAfee

    Then run CCleaner and after running the cleaner ...click on tools and remove:
    MarketResearch

    Otherwise:
    Your logs look clean.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
    *How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds