I ran all the Microsoft updates and rebooted… guess what? lkkakk.exe is back. I will follow the last few steps and see if I can get rid of it again.
Thanks!
Glen
It did not kill it. After I updated McAfee, it keeps giving me an alert that it is still there and calls it a Downloader-YH.dr virus. Yes, I do know how to use regedit. It is also giving me a slightly different location for the file, but as I stated above, the file is not actually there. The supposed infected file name used to be as follows:
C:\Windows\system32\lkkakk.exe
McAfee now shows it as follows:
C:\Windows\system32\lkkakk.exe\lkkakk.exe
Hijack This shows it the same as before:
c:\windows\system32\lkkakk.exe
I can't find it in any location. I have done a search, searching hidden files and system directories, but there no occurance of this file.
Thanks!
Glen
Did you set a new Restore Point? If not, do that first just in case.
click Start>Run and type regedit tap enter key.
Regedit will open. At the top of the window click edit> Find> then copy and paste the following into the window.
lkkakk
Then click find now.
When you find the entry right click on it and select delete, answer ok at the prompt.
Next, press "F3" to continue searching, if another instance is found, repeat the above steps, until you see the "completed searching" message.
Do the same for. KavSvc
Don't delete any other entries. Exit regedit, rescan with HJT and post a new log.
I found one instance of each lkkakk and kavsvc. They were both values and not keys. It looks like to took lkkakk out of the hijack log. Here is the log and I will reboot to see if anything comes back.
Logfile of HijackThis v1.99.1
Scan saved at 11:09:53 AM, on 4/30/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Logfile of HijackThis v1.99.1
Scan saved at 11:16:42 AM, on 4/30/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
I think those two are tied together. Go look at some of the previous logs. When lkkakk.exe is gone, the cuii issue is there. lkkakk came back, but cuii is gone. What do you think?
Solo removed 8 Qoologic trojans, including the ciiu.exe. I have rebooted and ran a hijack log. lkkakk.exe is still there.
Logfile of HijackThis v1.99.1
Scan saved at 12:19:56 PM, on 4/30/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Download FindRK-files.zip from here. http://skads.org/special/rkfiles.zip
Extract the FindRK-files.zip folder from zip to your desktop. (it cannot be run from the zip)
Reboot into safe mode. Open the FindRK-files folder.
Double click on "rkfiles.bat" . It can take a while to run.
When the cmd.exe window closes reboot your computer to normal mode.
A log file was created. It is found at C:\Log.txt.
OK… Here is the RKFiles log. Looks like we found the ciiu.exe file.
C:\Documents and Settings\Jodi Bailey\Desktop
PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
Files Found in system Folder…………
————————
C:\WINDOWS\SYSTEM32\lkkakk.exe: UPX!
C:\WINDOWS\SYSTEM32\quuou.dll: UPX!
C:\WINDOWS\SYSTEM32\winup2date.dll: UPX!
C:\WINDOWS\SYSTEM32\winup2date.dll.tcf: UPX!
C:\WINDOWS\SYSTEM32\winup2date.dll4911.tcf: UPX!
C:\WINDOWS\SYSTEM32\wmconfig.cpl: UPX!
C:\WINDOWS\SYSTEM32\ykkgk.dat: UPX!
C:\WINDOWS\SYSTEM32\elitewdz32.exe: FSG!
C:\WINDOWS\SYSTEM32\eliteztg32.exe: FSG!
C:\WINDOWS\SYSTEM32\DFRG.MSC: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAAAAAwGpEc213
C:\WINDOWS\protector_update.exe: PEC2
Files Found in all users startup Folder…………
————————
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ciiu.exe: UPX!
Files Found in all users windows Folder…………
————————
C:\WINDOWS\svcproc.exe: UPX!
C:\WINDOWS\tsc.exe: UPX!
C:\WINDOWS\vsapi32.dll: UPX!t4
Finished
bye
Back in Killbox go > file > paste from clipboard,
Click the red highlighted X button and say yes to the prompt, then click OK.
Exit Killbox and restart your PC.
Reboot into safe mode. Open the FindRK-files folder.
Double click on "rkfiles.bat" . It can take a while to run.
When the cmd.exe window closes reboot your computer to normal mode.
A log file was created. It is found at C:\Log.txt.
OK… We're getting there, I think…
C:\Documents and Settings\Jodi Bailey\Desktop
PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
Files Found in system Folder…………
————————
C:\WINDOWS\SYSTEM32\DFRG.MSC: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAAAAAwGpEc213
C:\WINDOWS\protector_update.exe: PEC2
Files Found in all users startup Folder…………
————————
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ciiu.exe: UPX!
Files Found in all users windows Folder…………
————————
C:\WINDOWS\vsapi32.dll: UPX!t4
Finished
bye
Start Killbox place a tick next to [x]delete on reboot.
Copy this whole list into the windows clipboard, all the Bolded below.
C:\WINDOWS\protector_update.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ciiu.exe
Back in Killbox go > file > paste from clipboard,
Click the red highlighted X button and say yes to the prompt, then click OK.
Exit Killbox and restart your PC.
Reboot into safe mode. Open the FindRK-files folder.
Double click on "rkfiles.bat" . It can take a while to run.
When the cmd.exe window closes reboot your computer to normal mode.
A log file was created. It is found at C:\Log.txt.
Locate the log and add it to your next post.
If they are still there, Do the same thing again with killbox only run it in Safe Mode
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI