help please!

Discussion in 'Malware Help (A Specialist Will Reply)' started by nanouk77, Feb 16, 2005.

  1. nanouk77

    nanouk77 Private E-2

    Hello again.

    I followed your instructions on the basic thread to remove spyware, and then on the hijack this thread.
    My logfile awaits! please help before the wife leaves me!
    Thanks :)
     
  2. Kodo

    Kodo SNATCHSQUATCH

    nanouk, a new version of HJT is out 1.99.1.
    It is not yet available on MajorGeeks.
    Please download it here and generate a new logfile to post.
     
  3. nanouk77

    nanouk77 Private E-2

    hiya Kodo
    Ive just generated the log file.
    Thanks.
    :)
     
  4. nanouk77

    nanouk77 Private E-2

    Hiya. Please find attached my log file. Thanks for all your help.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Geez! Do you really need to play all those online games!

    Make sure you now have the new version of HijackThis that Kodo mentioned.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).


    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\System32\yetodnfx.exe

    After killing all the above processes, click "Back".

    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {9287E855-A010-0278-5E1C-6C88CDB4863F} - C:\WINDOWS\System32\xhfgphdf.dll
    O2 - BHO: (no name) - {A058E069-1E27-A016-6A11-2809D8B1322D} - C:\WINDOWS\System32\jgeimrdi.dll
    O2 - BHO: (no name) - {D63FAE9B-506E-07A3-9DF7-A6E318A4F392} - C:\WINDOWS\System32\gbravwqz.dll
    O4 - HKLM\..\Run: [MOJNPluginSrIvcs] neomonap23.exe
    O4 - HKLM\..\RunServices: [MOJNPluginSrIvcs] neomonap23.exe
    O4 - HKCU\..\Run: [MOJNPluginSrIvcs] neomonap23.exe
    O20 - Winlogon Notify: Explorer - C:\WINDOWS\system32\gpp8l37u1.dll
    O23 - Service: ccpqwqcmuybn (MsUpdate5) - Unknown owner - C:\WINDOWS\System32\msupd5.exe

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\gpp8l37u1.dll
    C:\WINDOWS\System32\xhfgphdf.dll
    C:\WINDOWS\System32\jgeimrdi.dll
    C:\WINDOWS\System32\gbravwqz.dll
    C:\WINDOWS\System32\gbqxmhia.sys
    C:\WINDOWS\System32\upzvlbvv.sys
    C:\WINDOWS\System32\jsbmefvk.sys
    C:\WINDOWS\System32\yetodnfx.exe
    C:\WINDOWS\System32\msupd4.exe
    C:\WINDOWS\System32\msupd5.exe <-- look for other similarly named
    C:\WINDOWS\System32\Reloadmedude.exe
    C:\WINDOWS\System32\neomonap23.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again.

    Now:
    Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin
    And Click OK.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    You also have another problem we have been referring to as a VX2 problem or the new Look2Me problem. This is seen in those O1 lines in your log. Other steps need be perform to fix this problem.

    First Step:
    Please download the following tools and save them where you will be able to find them. I save stuff like this to a C:\downloads\Spyware-Stuff folder and I put each in their own subfolder. It makes it easy to find. Do not run anything but what I request. Make sure you download them from the links below:

    L2MeFix Tool

    Generic Detection Tool - NT/2000/XP

    VX2.BetterInternet Finder XP/2k - Version Msg126

    Pocket KillBox


    Please print out these instructions now or save locally so that you can operate with All Browser Windows CLOSED.

    Exit Browsers now before continuing

    Second Step:

    Extract all the files from the Generic Detection Tool into its own folder.
    Then run find.bat. Post the log it creates back here as an attachment (do it later when we reconnect).

    Third Step:
    Please move the L2MeFix Tool to your Desktop and DoubleClick l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix Folder on your Desktop. DoubleClick l2mfix.bat and Type 1 and ENTER to select Option #1 for Run Find Log . Allow it as much time as it needs to run until NotePad opens with a log.

    NOTE: Please do not run any other options or files in the l2mfix Folder!

    Fourth Step:

    Get a new HJT log.

    Now reconnect and come back here and post as attachments the l2mfix log the find.bat log (normally already named output.txt) and the new HJT log (this will require two posts as only two attachments can be made in a message). Based on those logs, we will determine the next steps. Please DO NOT REBOOT after scanning for these logs!! Otherwise problems may mutate and spread. Wait for me to get back to you with the next steps.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds