![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
i've followed all the initial steps and have had 0 success in ridding my PC of annoying popups which include: WinSpyware 2007, broadcaster.com, cpufeed.com...
i've attached my hijackthis, please help? |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
Welcome to Majorgeeks!
Running the READ ME means that you have to follow ALL of the instructions. This includes running all of the requested tools and attaching the 6 requested logs from the READ ME. HijackThis logs are the last thing we ask for. Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
Downloading, Installing, and Running HijackThis Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#3
|
|||
|
|||
|
okay - I have followed every preliminary step as requested and I am still suffering from major popups...
i've attached my hijackthis and bdscan to this thread and will attach my activecan, runkeys and newfiles to another thanks |
|
#4
|
|||
|
|||
|
attached are the other txt. files
thanks! |
|
#5
|
||||
|
||||
|
Where is the log from CounterSpy? Please attach it.
Also uninstall the below two programs as requested in step 0 of the READ ME: Viewpoint Manager (Remove Only) Viewpoint Media Player Also you have not properly completed the instructions in step 2 of the READ ME. Please do them now before continuing. Also uninstall the below old Sun Java version as requested in step 6 of the READ ME: Java 2 Runtime Environment, SE v1.4.2 Also please install HijackThis where requested in step 7 of the READ ME. You installed it exactly where we specify not to install it. Also it would be best if you renamed the executable as we requested so it is easier to recognize when it is running. What you named it looks like malware and could result in it being deleted as such. You have this: C:\Documents and Settings\Jason\Desktop\hey.exe It should be this: C:\Program Files\HJT\analyse.exe Do ALL of the above before continuing. Now let's start by working on you multiple layered Vundo infection. Please run the below tool multiple time until it comes up not finding anything. Virtumonde aka Trojan Vundo Removal Then attach the log from VundoFix and also new logs from ShowNew and HJT so we can continue with more manual removal steps which will more than likely be necessary. QUESTION: Why are you running this PC without protection? You have no antivirus, no antispyware, and no firewall applications!
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter Last edited by chaslang; 05-16-07 at 22:45.. |
| Sponsored links |
|
|
|
#6
|
|||
|
|||
|
i've completed the missed tasks that you'd listed and have attached my hijackthis, shownew, and counterspy logs - i will attach my vundo log in another.
thanks very much! |
|
#7
|
|||
|
|||
|
attached is my vundofix log --
|
|
#8
|
||||
|
||||
|
You chose to Ignore the stuff CounterSpy found related to Morpheus. This needs to be uninstalled. Morpheus is a bundler of malware!!! If you want to save any MP3 files then move them someplace else. Then goto Add/Remove programs and uninstall anything related to Morpheus. You need to get everything out of the below folder that you need. Then delete the below folder (preferably delete the Streamcast folder).
C:\PROGRAM FILES\STREAMCAST\Morpheus Then run CounterSpy again and fix anything it finds. Save a new log and attach it. You did not answer my question. Quote:
Now uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall: C:\Documents and Settings\All Users\Application Data\Sunbelt Software C:\Program Files\Sunbelt Software Continue by downloading two tools we will need - Process Explorer - Pocket KillBox Extract them to their own folder somewhere that you will be able to locate them later. Make sure you have rebooted in Normal Mode (do not open any other processes) Make sure that one and only one Internet Explorer browser is opened up - Run Process Explorer In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top. Once you see this screen click on each instance of any of the below DLL files (if found) and then click the kill button. ekmsawek.dll gebcyxu.dll kgalkhbr.dll lmiyetfk.dll gebcyxu.dll vtssr.dll vtutr.dll wipkcwsd.dll After you have killed all instances of any of the above DLLs under winlogon click ok. (If you do not find these DLLS, just continue on.) Next double click on explorer.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button. ekmsawek.dll gebcyxu.dll kgalkhbr.dll lmiyetfk.dll gebcyxu.dll vtssr.dll vtutr.dll wipkcwsd.dll After you have killed all instances of any of the above DLLs under Explorer click ok. (If you do not find these DLLS, just continue on.) Next double click on iexplore.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button. ekmsawek.dll gebcyxu.dll kgalkhbr.dll lmiyetfk.dll gebcyxu.dll vtssr.dll vtutr.dll wipkcwsd.dll After you have killed all instances of any of the above DLLs under iexplore click ok. (If you do not find these DLLS, just continue on.) Now just exit Process Explorer. Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now: O2 - BHO: (no name) - {2A5AC230-563B-4227-B943-3AF191C8DA6F} - C:\WINDOWS\system32\efedd.dll (file missing) O2 - BHO: (no name) - {3E8EC2D9-806B-4C7F-AE7F-F44AD4ABE8B5} - C:\WINDOWS\system32\gebcyxu.dll O2 - BHO: (no name) - {55DB983C-BDBF-426f-86F0-187B02DDA39B} - C:\WINDOWS\system32\kgalkhbr.dll O2 - BHO: (no name) - {B6FA9160-48CD-4CA4-91C3-AF85D364C0ED} - (no file) O2 - BHO: (no name) - {C0DFBC9B-0A1D-40E3-AEE0-53333E875F54} - C:\Program Files\Messenger\holemu.dll O2 - BHO: (no name) - {C779E147-3118-4C40-BC4C-BEC036B7A23C} - C:\WINDOWS\system32\vtssr.dll (file missing) O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [WindowsUpdate] rundll32.exe "C:\WINDOWS\system32\lmiyetfk.dll",realset O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing) O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing) O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing) O20 - Winlogon Notify: gebcyxu - C:\WINDOWS\SYSTEM32\gebcyxu.dll O20 - Winlogon Notify: vtutr - C:\WINDOWS\system32\vtutr.dll (file missing) After clicking Fix, exit HJT. Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry. Quote:
it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue. Select:
C:\Program Files\Messenger\holemu.dll C:\WINDOWS\SYSTEM32\cmd.ftp C:\WINDOWS\SYSTEM32\ekmsawek.dll C:\WINDOWS\SYSTEM32\gebcyxu.dll C:\WINDOWS\SYSTEM32\kgalkhbr.dll C:\WINDOWS\system32\lmiyetfk.dll C:\WINDOWS\system32\gebcyxu.dll C:\WINDOWS\system32\vtssr.dll C:\WINDOWS\system32\vtutr.dll C:\WINDOWS\SYSTEM32\wipkcwsd.dll C:\WINDOWS\SYSTEM32\rsstv.bak1 C:\WINDOWS\SYSTEM32\rsstv.bak2 C:\WINDOWS\SYSTEM32\rtutv.bak1 C:\WINDOWS\SYSTEM32\rtutv.tmp C:\WINDOWS\SYSTEM32\dswckpiw.ini C:\WINDOWS\SYSTEM32\haidtbwp.ini C:\WINDOWS\SYSTEM32\kewasmke.ini C:\WINDOWS\SYSTEM32\kfteyiml.ini C:\WINDOWS\SYSTEM32\rsstv.ini C:\WINDOWS\SYSTEM32\rtutv.ini C:\WINDOWS\SYSTEM32\smpi1\lb66.exe C:\WINDOWS\SYSTEM32\smpi1\lib06.exe
If Killbox does not reboot just reboot your PC yourself. After reboot locate the below folder and delete if found: C:\WINDOWS\SYSTEM32\smpi1 Also run Windows Explorer and double check to make sure all the files we tried to delete with Killbox were deleted. If not, delete them. Now run Ccleaner! Now attach the below new logs and tell me how the above steps went.
Make sure you tell me how things are working now! Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter Last edited by chaslang; 05-19-07 at 14:38.. |
|
#9
|
|||
|
|||
|
ok - I followed every step you'd listed -
still getting popups i've attached my HJT, Shownew, and Runkey - will attach my last CounterSpy log to another. as far as the lack of firewall + virus protection on my PC, it was a mystery to me as to why it wasn't working - i've alway had it running and updated - it seems to be operating one minute, and then turning itself off the next - when i've attempted to turn the firewall on i'm denied. however, i download AVAST and it seems to be working well. |
|
#10
|
|||
|
|||
|
Counter Spy log attached
|
| Sponsored links |
|
|
|
#11
|
||||
|
||||
|
Quote:
If you are referring to the Windows firewall (and I assume you have to be since no real firewall is installed) then it will not matter much anyway since the Windows firewall is totally inadequate. Better than nothing? Yes! But still inadequate especially since there are so many free alternatives that are better. Could you please install GetRunKey and ShowNew properly into the folder that was requested in the READ ME. You have way too much stuff that is not categorized into subfolders in your My Documents folder and it is making your logs unnecessarily long and harder to look at. Also GetRunKey and ShowNew are not documents. They are programs. Just install both GetRunKey & ShowNew into the same recommeded folder which is C:\MGtools Pocket Killbox appears to have not been able to properly delete many of the problem files. We will try another tool this time named Avenger. Make sure that one and only one Internet Explorer browser is opened up - Run Process Explorer In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top. Once you see this screen click on each instance of any of the below DLL files (if found) and then click the kill button. ecqdwqee.dll mllli.dll gebcyxu.dll gjcgyudf.dll kgalkhbr.dll ljhhh.dll After you have killed all instances of any of the above DLLs under winlogon click ok. (If you do not find these DLLS, just continue on.) Next double click on explorer.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button. ecqdwqee.dll mllli.dll gebcyxu.dll gjcgyudf.dll kgalkhbr.dll ljhhh.dll After you have killed all instances of any of the above DLLs under Explorer click ok. (If you do not find these DLLS, just continue on.) Next double click on iexplore.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button. ecqdwqee.dll mllli.dll gebcyxu.dll gjcgyudf.dll kgalkhbr.dll ljhhh.dll After you have killed all instances of any of the above DLLs under iexplore click ok. (If you do not find these DLLS, just continue on.) Now just exit Process Explorer. Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now: O2 - BHO: (no name) - {55DB983C-BDBF-426f-86F0-187B02DDA39B} - C:\WINDOWS\system32\ecqdwqee.dll O2 - BHO: (no name) - {5D13499A-F927-43BF-85E8-A1BF29FEE049} - (no file) O2 - BHO: (no name) - {9081EC48-5F3A-4E0E-8BD1-8EBB0E3FC356} - C:\WINDOWS\system32\mllli.dll O20 - Winlogon Notify: mllli - C:\WINDOWS\system32\mllli.dll After clicking Fix, exit HJT. Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry. Quote:
Quote:
Now attach the below new logs and tell me how the above steps went.
Make sure you tell me how things are working now! Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter Last edited by chaslang; 05-20-07 at 01:30.. |
|
#12
|
|||
|
|||
|
followed the steps - so far no popups! - nice
![]() attached: shownew, runkey, avenger I will attach my hjt to another thread - can you suggest free firewall/anti-virus program? i see several listed here on major geeks, but i'd like to know which you feel are the better ones - thanks! |
|
#13
|
|||
|
|||
|
hjt attached!
|
|
#14
|
||||
|
||||
|
Avast is fine! My final instructions after you are all clean will give a bunch of tips and useful tools with links.
Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now: O4 - HKLM\..\Run: [setup] rundll32.exe "C:\WINDOWS\system32\rojehplu.dll",realset After clicking Fix, exit HJT. Boot into safe mode and use Windows Explorer to delete: C:\WINDOWS\SYSTEM32\rojehplu.dll C:\WINDOWS\SYSTEM32\ulphejor.ini Now run Ccleaner Now reboot in normal mode Now attach the below new logs and tell me how the above steps went.
Make sure you tell me how things are working now!
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#15
|
|||
|
|||
|
followed steps - everything went smooth
-attached: getrunkey, shownew, hjt web browsing is perfect - no popups and working fast! thanks! |
| Sponsored links |
|
|
|
#16
|
||||
|
||||
|
Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| winantivirus removal, malware removal | dookie22 | Malware Removal | 1 | 09-12-06 15:15 |
| Baffling Audio Problems, Can you solve them-or is it futile? | mands1833 | Hardware | 9 | 06-10-06 18:55 |
| my efforts are futile! | beaumango | Malware Removal | 1 | 03-22-05 20:34 |
| RAID 0....worth the effort? | Texasbobby | Hardware | 5 | 12-05-04 15:05 |
| still can't view .pdf files in browser (despite much effort and research) | navyandcream | Software | 7 | 11-06-04 17:21 |