Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

System tool Version 2.20 HELP


  • This topic is locked This topic is locked
5 replies to this topic

#1 winkeytoofly

winkeytoofly

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:10:59 AM

Posted 16 December 2010 - 03:46 PM

Ok so i ran Malwarebytes and it removed one infected file, after using the registration code provided by Rogue AMP on youtube.

this restored my desktop and no long sending warnings but now in my TASKBAR systemtool version 2.20 is still showing up, so i went to task manager and saw a jkjf6308.exe with the discreption of Registry System. Ran RLKILL and it ended this process, reran Malwarebytes and still nothing it still there on start up.

Im assuming this .exe is related to system tool because after i run it it goes away but obviously i still have the trojan......Any have any ideas please!!!!!

Running Windows 7.

BC AdBot (Login to Remove)

 


#2 winkeytoofly

winkeytoofly
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:10:59 AM

Posted 16 December 2010 - 04:11 PM

Downloaded SAS and running the scan now.


The true name of the exe running in taskmanager. jkjfbo6301.exe

#3 winkeytoofly

winkeytoofly
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:10:59 AM

Posted 16 December 2010 - 05:39 PM

This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Ran as Kyle on 12/16/2010 at 17:34:25.


Services Stopped:


Processes terminated by Rkill or while it was running:


C:\ProgramData\jKjFb06301\jKjFb06301.exe
C:\Users\Kyle\Desktop\rkill.exe


Rkill completed on 12/16/2010 at 17:34:57.



Just ran SAS as well and believe i deleted the host and reset it using the step provided

#4 winkeytoofly

winkeytoofly
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:10:59 AM

Posted 16 December 2010 - 05:58 PM

What can i do to remove this program, im just running Rkill everytime i boot but i dont feel like this is the safest thing to do.....

#5 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:10:59 AM

Posted 18 December 2010 - 06:10 PM

Hello winkeytoofly ,

Posted Image

Delete this folder : C:\ProgramData\jKjFb06301


This tool is not a toy. If used the wrong way you could trash your computer. Please use only under direction of a Helper. If you decide to do so anyway, please do not blame me or ComboFix.

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

1. Download this file - combofix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

2. Double click combofix.exe & follow the prompts.
3. When finished, it will produce a log for you. Post that log in your next reply please.

Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall.

If you have trouble running it the first time, then rename ComboFix.exe to winkey.exe and try again.

Thanks,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#6 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:10:59 AM

Posted 27 December 2010 - 12:01 PM

Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users