post READ & RUN etc...help needed

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by boudewijnzen, Jul 8, 2006.

  1. boudewijnzen

    boudewijnzen Private E-2

    To start, i have followed the proceedure outlined in the READ AND RUN ME FIRST post as required. This includes the net scans. Having done this, i find my laptop is still harbouring soyware,adware whatever it is. im no expert. What i DO know is my machine has gone from being speedy and responsive to taking significantly longer to become active after being switched on (were talking minutes after reaching the 'desktop' screen). It is sluggish and often provides pop-ups and warning windows when on the internet.
    All virus, adware programs detect, say they have deleted, but fail to remove whatever it is thats on this machine. So, i am asking for any kind persons help. As required i have followed instructions and will attach the three logs neccesary. To emphasise the problem, this machine acts as if it has a significant resource hog running, such as Azureus, when it has nothing of the sort. I have concidered this could be the result of the various antivirus programs etc downloaded off the READ AND RUN, running themselves, but i doubt it.
    So...please find attached the three logs:Hijackthis, Activescan and bdscan.
    Any help you could offer me would really be greatly valued, this site hasnt let me down yet!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You skipped step 3 of the READ & RUN ME. You must uninstall either AVG7 or Symantec. Do this NOW before continuing with the below.

    Did you purchase CounterSpy? If not, uninstall it. You don't need it since you have Windows Defender.


    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of mljjjkk.dll once and then click the kill button. After you have killed all of the mljjjkk.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of mljjjkk.dll and kill it. (If you do not find the dll, just continue on.)

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    O9 - Extra button: Ãâ·Ñ¾«²ÊÊÓƵ³¬Á÷³©ÔÚÏß¹Û¿´ - {022C4009-5283-4365-97BF-144054B40E2E} - http://itv.mop.com (file missing)
    O9 - Extra 'Tools' menuitem: ²¥°ÔµçÊÓ - {022C4009-5283-4365-97BF-144054B40E2E} - http://itv.mop.com (file missing)
    O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} - http://85.255.114.166/1/rdgGB2405.exe



    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now click Start, Run, and enter cmd and click OK! This will open a command prompt window. In the command prompt window enter the below commands each followed by the Enter key.
    del %windir%\temp\win*.*
    exit


    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    Now back on Killbox's main window, Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.

    C:\Documents and Settings\Windows user\My Documents\DivXPro511Adware.exe
    C:\Program Files\DAEMON Tools\SetupDTSB.exe
    C:\WINDOWS\system32\mljjjkk.dll


    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now attach a new HJT log and tell me how the steps went.
    Make sure you tell me how things are working now!
     
  3. boudewijnzen

    boudewijnzen Private E-2

    hi, well i did what you said. In process explorer, in both winlogon.exe and explorer.exe selections you outlined, there was no mljjjjkk.dll apparent. oh, and when doing the start, run, cmd bit when typing the line provided it reported it could not find that path. Im literally typing this as ive rebooted the machine, and it seems to have started up faster, and there have been no pop-ups while online as of yet, fingers crossed. I'm attaching a new HJT log, and will check back in a while/tommorow to see what you think and report anything that happens in the meantime. thanks for the help so far, G
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to attach the new log.

    Also please run the below procedure and attach the newfiles.txt log.
     
  5. boudewijnzen

    boudewijnzen Private E-2

    sorry, i must appologise for not attaching the HJT.log, it was late! here are both files. Ive had one pop-up for 'adultfriendfinder' last night, and thats it so far.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because you still have another hidden Virtumonde infection and it was why I asked for the log from ShowNew.


    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of fccbc.dll once and then click the kill button. After you have killed all of the fccbc.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of fccbc.dll and kill it. (If you do not find the dll, just continue on.)

    Now just exit Process Explorer.


    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    Now back on Killbox's main window, Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.

    C:\WINDOWS\SYSTEM32\fccbc.dll
    C:\WINDOWS\SYSTEM32\cbccf.ini

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now attach a new HJT log and a new log from ShowNew

    Also tell me how the steps went.

    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds