![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
This is my first post & I've been working on this for the past few days (these scans take forever!) Coincidentally I got the Vundo/WinAntiVirus2006 Trojan last week when I downloaded and installed PokerStars.
Attached are the logs... I need to see if someone in here will check out these logs real quick and confirm there are no more issues! Thanks!! ...the other 3 are on their way (ShowNew, HJT, & VundoFix logs) |
| Sponsored links |
|
|
|
#2
|
|||
|
|||
|
...here are the remaining logs. Hope I have everything. Also seems like there's no problem anymore, but just wanted to submit these to make sure!
Thanks again & just wanted to say this forum is a lifesaver. |
|
#3
|
|||
|
|||
|
I know we aren't supposed to bump our threads-- but I've noticed quite a few other threads getting support, feedback and help. When I look at how many views my logs have... only the vundofix and HJT logs have 1 view. Is there something I am missing or not doing correctly or is everything fine with my machine. I appreciate the support, just didn't know if I might have left something out???
|
|
#4
|
||||
|
||||
|
Welcome to Major Geeks!
Let's begin by removing a left over service from the now uninstalled Symantec Antivirus.
Also uninstall the below LiveUpdate 2.6 (Symantec Corporation) Norton WMI Update Continue by downloading two tools we will need - Process Explorer Extract it to its own folder somewhere that you will be able to locate it later. Make sure you have rebooted in Normal Mode (do not open any other processes) Make sure that one and only one Internet Explorer browser is opened up - Run Process Explorer In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top. Once you see this screen click on each instance of any of the below DLL files (if found) and then click the kill button. jnjytcaw.dll After you have killed all instances of any of the above DLLs under winlogon click ok. (If you do not find these DLLS, just continue on.) Next double click on explorer.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button. jnjytcaw.dll After you have killed all instances of any of the above DLLs under Explorer click ok. (If you do not find these DLLS, just continue on.) Next double click on iexplore.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button. jnjytcaw.dll After you have killed all instances of any of the above DLLs under iexplore click ok. (If you do not find these DLLS, just continue on.) Now just exit Process Explorer. Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now: O2 - BHO: (no name) - {10850997-1AD5-4AFC-9419-C6565300AE18} - C:\WINDOWS\System32\ddayv.dll (file missing) O2 - BHO: (no name) - {2432F099-F8E2-43C9-B765-3AF002FFC6A7} - (no file) O2 - BHO: PsapiAnalyzer Object - {6D7D5679-4E81-430C-9C18-75FE169F1D07} - c:\windows\msagent\sap.dll (file missing) O2 - BHO: (no name) - {9B8DB546-47DF-441A-BBFA-B532DB00F66D} - C:\WINDOWS\System32\ddayv.dll (file missing) O2 - BHO: 0 - {9CDDFD79-BCA3-4F72-AFB1-C8F56A085D04} - (no file) O2 - BHO: (no name) - {CD3447D4-CA39-4377-8084-30E86331D74C} - C:\WINDOWS\System32\jnjytcaw.dll O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O4 - HKLM\..\Run: [vs2T3tR] gpkskrnl.exe O4 - Startup: Download Plus.lnk = C:\Documents and Settings\Owner\Application Data\DownloadPlus.exe O4 - Startup: TA_Start.lnk = C:\Documents and Settings\Clayton\Local Settings\Temp\TICHD003.exe O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/27f2a2fb...p/RdxIE601.cab O20 - Winlogon Notify: ddayv - C:\WINDOWS\System32\ddayv.dll (file missing) O20 - Winlogon Notify: yayxxww - yayxxww.dll (file missing) After clicking Fix, exit HJT. Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry. Quote:
Quote:
Now attach the below new logs and tell me how the above steps went.
Make sure you tell me how things are working now! Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#5
|
|||
|
|||
|
It won't let me delete: The service you entered is system-critical! It cannot be deleted!
All I can do is click ok then it takes me back to the config window... Quote:
|
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
That is not true and I did say to ignore error messages and continue. Please complete the steps.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#7
|
|||
|
|||
|
The 2 following posts have the new logs attached... I'm pretty sure everything is ok... haven't had any pop-ups and system is moving a lot smoother and quicker. Thanks-- please let me know if you see anything in the logs!
Quote:
|
|
#8
|
|||
|
|||
|
Here is the HJT log... Also, what programs can I delete now that everything is under control?? Do you reccommend me keeping EZTrust Firewall/Anti-Virus or upgrading to something else?? Thanks for your time.
|
|
#9
|
||||
|
||||
|
You have one left over to fix with HJT. Fix the below line:
O2 - BHO: (no name) - {CD3447D4-CA39-4377-8084-30E86331D74C} - C:\WINDOWS\System32\jnjytcaw.dll (file missing) Quote:
Quote:
If you are not having any other malware problems, it is time to do our final steps:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#10
|
|||
|
|||
|
Appreciate all your help!!!
|
| Sponsored links |
|
|
|
#11
|
||||
|
||||
|
You're welcome. Surf safely!
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Malware removal..... Check my logs please.... | Water_Boy | Malware Removal | 5 | 03-10-07 16:37 |
| Unable to complete steps in removal guide, HELP | captain_justin | Malware Removal | 7 | 11-16-06 02:33 |
| First Post - Add. Help Needed -Steps 0-9 Complete | Stumped06 | Malware Removal | 11 | 08-07-06 23:54 |
| help with the logs,all steps have been done | cab0824 | Malware Removal | 11 | 02-09-06 20:17 |
| Hijackthis log need analysis: all steps complete | zapp | Malware Removal | 3 | 02-04-05 19:04 |