CBAAX.DLL Problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by buzzby, Feb 3, 2008.

  1. buzzby

    buzzby Private E-2

    Hi

    I have managed to get this on my new laptop.

    Any help please

    Here is my hijackthis log

    Edit by chaslang: Inline HJT log removed. READ & RUN ME sticky not followed.


    I also have these on start up

    ssnbkeso.dll

    psllxadt.dll

    Thanks Buzz
     
    Last edited by a moderator: Feb 4, 2008
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Have you been doing things on your own with HijackThis???? Your log was much smaller than it should be. If you have been fixing things with HijackThis, restore them from the backups that HijackThis made. If you are filtering things with HijackThis than you should not be filtering them. If you are using MSconfig to control startups, you need to stop using MSconfig.

    You also need to disable Spybot's Teatimer. All of the above is explain in the READ & RUN ME given below.

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. buzzby

    buzzby Private E-2

    Hi

    Thanks for the reply.
    Followed the instructions you gave me and here is the file I have uploaded.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the requested logs from ComboFix and AVG Antispyware (if AVG gave you a log - Sometimes it does not create a log).


    Run this Norton Removal Tool (SymNRT)

    Uninstall Advanced MP3 Catalog Pro 3.36 since it was installed using a crack and could be infected. The delete the below files and folders from it if the remain.
    C:\Users\Chris Lawrence\Desktop\Advanced MP3 Catalog Pro.lnk
    C:\Users\Chris Lawrence\Desktop\Advanced.MP3.Catalog.Pro.v3.25 + Crack

    Also delete the below folder of Cracks
    C:\Users\Chris Lawrence\Desktop\Crack


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
    O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all

    After clicking Fix, exit HJT.

    Now reboot your PC.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds