pmkhf.exe and wwmdyjfh.dll

Discussion in 'Malware Help (A Specialist Will Reply)' started by mercylessme, Jul 24, 2008.

  1. mercylessme

    mercylessme Private E-2

    Everytime I start up my system it always reports that this two files are missing.
    Anyone knows how to restore them or have any idea of its uses?
    Any help is greatly appreciated.

    Note: If this is in the wrong section, please tell me which forums i should be posting in. I'm still a newbie
     
  2. Adrynalyne

    Adrynalyne Guest

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide


    Note: If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    Starting your computer in Safe mode
     
  3. mercylessme

    mercylessme Private E-2

    Hmm, I ran CCleaner but the problem still remains, while waiting for spybot to run I'll just ask another question. Windows Update is always off, is there any other way to turn it on? I tried through control panels but it returns the same error that it is unable to start. Also, a few websites recommended me to try running it through services.msc, yet also returns that it is disabled. Is there any way to solve this problem? Or is it also due to the fact that my computer might be infected?

    Off-Topic: Tks for the welcome ^^
     
  4. Adrynalyne

    Adrynalyne Guest

    Well, lets start with getting you cleaned up first. Please follow the read & run me first verbatim. This will expediate getting you cleaned up and on your way to happier computing.
     
  5. mercylessme

    mercylessme Private E-2

    Hmm, so far the errors have been cleared. Yet the window update problem still exists. I'm worried that it might become a problem. Tks for your help in solving me the previous problem ^^
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you want our help, you need to complete the instructions already given. There is no sense in posting anymore messages until you do so.
     
  7. mercylessme

    mercylessme Private E-2

    Here is the two log files for SAS and Malware Bytes, hope it helps
     

    Attached Files:

  8. mercylessme

    mercylessme Private E-2

    The other two log files~ Hopefully i got it correct
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now that's better. Did you notice all the malware that the READ & RUN ME found and removed?

    Do you have any idea what the below driver is for?
    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 3
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) 6 Update 3

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\QTTask.exe" -atboottime

    After clicking Fix, exit HJT.

    Now reboot your PC.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now delete the below file if found:
    D:\WINDOWS\000001_.tmp

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. mercylessme

    mercylessme Private E-2

    Sorry about the earlier mistake >< I'm still new... Gimme awhile to run the steps~ Tks for your patience =X
    Edit: I don't think i've heard of such a program or such a driver...
     
  11. mercylessme

    mercylessme Private E-2

    Everything seems to be working fine now~ Tks for you help~ ^^
    Should I do anything about the unknown driver?
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    No! Especially if things are running okay. That drivere seems to be something related to gaming or gaming sites.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the combo-fix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combo-fix folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  13. mercylessme

    mercylessme Private E-2

    Everything seems to be working fine, but something seems to be wrong somewhere. i'll go scan again and see if it comes up with anything... btw, any idea what this is?
    IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is quite contradictory. :) You will have to explain in more detail what you mean.


    Microsoft Input Method Editor which is used to ease the input of Asian characters in MS Office. I believe this one is for Japanese. See this: http://www.microsoft.com/windows/ie/ie6/downloads/recommended/ime/default.mspx
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds