I think we're clean (winfixer) - would you check?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by elhoo, Oct 6, 2005.

  1. elhoo

    elhoo Private E-2

    Hi
    Followed all the steps for scanning and cleaning (had no idea those on-line scans would take hours!). I would like to know if everything is ok now. We were having problems with winfixer -- but it seems to be gone now. Thanks for any help you can give me.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you were having Winfixer (really a Virtumundo B problem) you are probably still infected.

    If you have run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal then continue with the below steps. Otherwise complete ALL the sticky thread steps first.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis

     
  3. elhoo

    elhoo Private E-2

    Yes, it took me all day to follow all 4 steps. I will now run the hijack this. Adaware found the reg of winfixer, that's why I thought we were clean. (can you tell I'm not so good at this!) Thanks in advance for your help.
     
  4. elhoo

    elhoo Private E-2

    I have attached the hijack this log. Thanks
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are still infected. I will work up a fix for you. But answer a question. The below O10 line indicates a problem with your Pure Networks Home Network Software. Do you use this sotware and are you seeing any problems with it.

    O10 - Broken Internet access because of LSP provider 'connwsp.dll' missing

    See if the following file exists: c:\windows\system32\connwsp.dll.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please make sure System Restore is OFF and the Viewing of Hidden Files & Folders is Enabled as per the tutorial.

    Please print these instructions out for use in Safe Mode with no networking and DO NOT RUN any browsers while doing these steps.

    Please download VundoFix.exe to your desktop.


    • Double-click VundoFix.exe to extract the files
    • This will create a VundoFix folder on your desktop.
    • After the files are extracted, please reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.
    • Once in safe mode open the VundoFix folder and doubleclick on KillVundo.bat
    • You will first be presented with a warning and a list of forums to seek help at. Iit should look like this
    • At this point press enter one time.
    • Next you will see:
    • At this point please type the following file path (make sure to enter it exactly as below!):

    C:\WINDOWS\System32\pmkhh.dll

    • Press Enter, then press the F6 key, then press Enter one more time to continue with the fix.
    • Next you will see:
    • At this point please type the following file path (make sure to enter it exactly as below!):

    C:\WINDOWS\System32\hhkmp.*

    • Press Enter, then press the F6 key, then press Enter one more time to continue with the fix.
    • The fix will run then HijackThis will open.
    • In HiJackThis, please place a check next to the following items and click FIX CHECKED:


    O2 - BHO: MSEvents Object - {6DD0BC06-4719-4BA3-BEBC-FBAE6A448152} - C:\WINDOWS\system32\pmkhh.dll
    O4 - HKLM\..\Run: [NI.UWFX5RS_0001_0808] "C:\WINDOWS\Downloaded Program Files\UWFX5RS_0001_0808NetInstaller.exe"
    O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O20 - Winlogon Notify: pmkhh - C:\WINDOWS\system32\pmkhh.dll




    • After you have fixed these items, close Hijackthis and Press any key to Force a reboot of your computer.
    • Pressing any key will cause a "Blue Screen of Death" this is normal, do not worry!
    • Now please attach a new HJT log from normal mode.
     
  7. elhoo

    elhoo Private E-2

    Funny you should ask about the network -- we couldn't access the internet today through the network. I used the search function to look for that file (is that the correct way to do it?) and it couldn't find anything. I will be working on your next set of instructions for awhile. I never enabled system restore when I was done doing the 4 step cleaning process so it is still disabled. Here I go...
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! The below will be necessary too.

    Download LSP - Fix

    Run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the connwsp.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move connwsp.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.
    If it is already in the Remove section, just click Finish.

    However if this does not give you internet access, you may need to reinstall the software you are using for your home network.
     
  9. elhoo

    elhoo Private E-2

    I've done the Vundo fix and attached the hijack this log. About the network -- we don't have any software, we just plugged in a wireless network and windows xp runs it. Does that make any difference for your fix? (sorry about the lapses of time between posts -- I'm slow and unsure of myself plus I'm running around the house getting dinner etc. done!)
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just run LSP-fix and let's see what happens.

    What's for dinner? ;)
     
  11. elhoo

    elhoo Private E-2

    Hmmm, let's see -- a rosemary and garlic encrusted beef tenderloin with twice baked potatoes and sauteed fresh green beans...RIGHT! I wish. Cheese burgers and tatertots. Yum Yum.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Cheeseburgers are okay! But tatertots! Not!!! ;)

    Did you try LSP-fix?
     
  13. elhoo

    elhoo Private E-2

    Did the fix -- but now my husband is doing something with the other (networked) computer. He says he still can't get on. Anyway, how did the hjt log look?
    And hey, what's wrong with tater tots?????
     
  14. elhoo

    elhoo Private E-2

    I think I was supposed to do another HJT log after doing the LSP fix so I ran one and attached it. I also have a couple of questions -- lately when I try to search the internet when I'm on AOL, a weird screen comes up that is all light blue and shows only what AOL wants me to see. I usually just type in google and go through that. Also, when I search the internet when I'm on comcast it always goes through yahoo. (these are probably really stupid questions). OK and here's the best one yet. When I go back and enable the restore, will it give me the right restore points? By the way, thank you so much for all the help you've given me today/tonight!
    Ellie
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But is that we have been working on running okay! Your HJT log is clean!

    French Fries are much better. IMO!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what your issue with AOL is. I don't use it! If you use AOL you are stuck with all the stupid stuff they do!

    When you say you search the internet, what do you mean? Whose browser are you running? Are you connected to AOL at this time? What are you typing in the the address bar? Or are you clicking on some search icon?

    All system restore points are gone. They could not be trusted to be clean. That is what step 1 of the READ ME FIRST has you disable system restore. Otherwise bad stuff could get revived out of system restore. When you re-enable system restore, new restore points will start being created again.
     
  17. elhoo

    elhoo Private E-2

    Jeez, I thought you'd gone to bed already! Yeah! my computer is clean. THANK YOU! Do I go back and enable system restore and hidden folders now?

    Aol is a pain, I don't know why I bothered asking about it. The other time I get on the web is through comcast. I'll type in 'whatever' in the search bar at the top of their page and it always comes up as a yahoo search. When we first got dsl it wasn't using yahoo. Maybe that's their defaut search engine? I really am incredibly dense about this stuff, which is kinda stupid since I'm on the computer all the time.
    Anyway, french fries are ok, but even better handcut, fried and doused in vinegar, salt and old bay. (imho) Thank you so much for helping and putting all the directions down in ways I could follow and understand. Take care,
    Ellie
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I never sleep! ;)

    Enable system restore but there is no need to change the hidden files and folders settings. That would only make it easier for baddies to hide from you again.

    Your still not being specific. What browser do you use when you connect thru Comcast? Do they have their own browser? What searchbar? Do you mean the Address Bar in Internet Explorer?

    French Fries (handcut is great) with Ketchup and salt!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds