Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] serious issues

[Fixed] Hijackthis! Logs - [Fixed] serious issues posted in the Security & Safety forums; let's get rid of the malware first. Boot into safe mode, and navigate to and delete the following folders/files: C:\WINDOWS\TEMP\ abxwakhi.exe <-- this file while still in safe mode, close ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #29  
Old 07-09-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,629
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

let's get rid of the malware first.

Boot into safe mode, and navigate to and delete the following folders/files:

C:\WINDOWS\TEMP\abxwakhi.exe <-- this file

while still in safe mode, close all windows, open hjt, click 'perform system scan only', place a tick next to the following and click 'fix checked':

O2 - BHO: CIEPl Object - {F3727275-224F-4AB0-8642-7D461EFB82D8} - C:\WINDOWS\system32\mkagq.dll (file missing)
O20 - Winlogon Notify: mkagq - mkagq.dll (file missing
O20 - Winlogon Notify: ws_3s32 - C:\WINDOWS\SYSTEM32\ws_3s32.dll


SAS picked up a lot of stuff, but now some other stuff is raising it's head.

As for the jpg issue, right click it, choose 'open with' and then choose the program you want to open it with. If you don't see the program listed, choose browse and navigate to the one you want. If that is the app that you ALWAYS want to have open, tick the box that says 'always use this program' at the bottom.

reboot, and post a new log.

thanks,

v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall
  #30  
Old 07-09-2007
Silver Member
 
Join Date: Feb 2007
Posts: 102
Swizzleskin - See this Members User comments on their Profile page
Default bad news....I think

Ok, so the file "abxwakhi.exe did not exist, the only file that was showing in c:\windows\temp was "perflib_perfdata"

in hjt the file 02 BHO...mkagq and 020....mkagq did not exist, and 020....ws_3s2 showed up but appears to have stuck around (according to my latest hjt log).

The funny thing about the jpg is that windows picture and fax viewer is my default, however even if I right click and choose it, there is still no response, I changed my picture viewer default to IE and it opens them when I click them, I just have to close each one, and open a new one, as it doesn't understand the concept of a folder.

let me know what is next...

Swizz
Attached Files
File Type: log hijackthis.log (5.7 KB, 2 views)


  #31  
Old 07-09-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,629
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

okay, let's deal with the infections first.

Please download VundoFix.exe
to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please attach C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above
instructions starting from "Click the Scan for Vundo button." when
VundoFix appears at reboot.

Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above
instructions starting from "Click the Scan for Vundo button." when
VundoFix appears at reboot.

thanks,

v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall
  #32  
Old 07-09-2007
Silver Member
 
Join Date: Feb 2007
Posts: 102
Swizzleskin - See this Members User comments on their Profile page
Default new logs

hope we are getting closer.

Swizz
Attached Files
File Type: txt VundoFix.txt (1.7 KB, 1 views)
File Type: log hijackthis.log (5.9 KB, 1 views)


  #33  
Old 07-09-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,629
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

getting there.....

run hjt, click 'perform system scan only', place a tick next to the following, click 'fix checked':

O2 - BHO: (no name) - {335DB538-08BF-4CB6-9E85-002757D58844} - C:\WINDOWS\System32\kfvexfgw.dll
O2 - BHO: CIEPl Object - {F3727275-224F-4AB0-8642-7D461EFB82D8} - C:\WINDOWS\System32\blklf.dll
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\System32\qmbmehij.dll",setvm
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://drivecleaner.com/.freeware/in...eanerstart.cab
O20 - AppInit_DLLs: cmdl32.dll
O20 - Winlogon Notify: blklf - C:\WINDOWS\SYSTEM32\blklf.dll


It's a pesky vundo, so this may take a few whacks with a hammer. Regardless, reboot, and post a new log.

Thanks,

v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall
  #34  
Old 07-09-2007
Silver Member
 
Join Date: Feb 2007
Posts: 102
Swizzleskin - See this Members User comments on their Profile page
Default and then....

Hi Valis, so I have attached my hjt log, however when fixing the checked items the following error happened....."an unexpected error occured at procedure "modbackup_makebackup sitem=020- appinit_dllscmdl32.dll" error =5 invalid procedure call or argument.
Attached Files
File Type: log hijackthis.log (5.8 KB, 2 views)


  #35  
Old 07-10-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,629
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

take two:

Please download VundoFix.exe
to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please attach C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above
instructions starting from "Click the Scan for Vundo button." when
VundoFix appears at reboot.

Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above
instructions starting from "Click the Scan for Vundo button." when
VundoFix appears at reboot.

next, hjt:

run hjt, click 'perform system scan only', place a tick next to the following, click 'fix checked':

O2 - BHO: (no name) - {335DB538-08BF-4CB6-9E85-002757D58844} - C:\WINDOWS\System32\bxlsrqro.dll
O2 - BHO: CIEPl Object - {F3727275-224F-4AB0-8642-7D461EFB82D8} - C:\WINDOWS\system32\blklf.dll
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\System32\xtxcserj.dll",setvm
O20 - Winlogon Notify: blklf - C:\WINDOWS\SYSTEM32\blklf.dll


post back with both the vundo text and a new hjt log, please.....going to have to break out some bigger hammers, methinks.

v




__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall

Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 02:29 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top