khhhe.dll ??

Discussion in 'Malware Help (A Specialist Will Reply)' started by buffaLo, Oct 6, 2005.

  1. buffaLo

    buffaLo Private E-2

    it must be new, cuz i can't get rid of it...
    it's giving me a random pop up every 5-6 pages and running in the system 32 file

    hi jack this can't delete it
    kill box can't get it
    it's running thru a program in safe mode, so no help there
    ive tried ad-aware & spybot SD
    tried to manually remove it...

    im stuck
    i just DL a-squared, so maybe that'll help

    any suggestions?
    i hate this stuff

    - buffaLo
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like Virtumundo B.

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis


    After doing the above, we will be in a position to resolve your Virtumundo problem.
     
  3. buffaLo

    buffaLo Private E-2

    whoa whoa i think its that winfixer stuff...
    im gettin a pop up with winfixer.com but the page isn't loading
    im gonna kill this thing i swear
     
  4. buffaLo

    buffaLo Private E-2

    Edit by chaslang: Very old version, inline log removed. READ ME FIRST not run.
     
    Last edited by a moderator: Oct 6, 2005
  5. buffaLo

    buffaLo Private E-2

    sorry im attaching it :(
     
    Last edited by a moderator: Oct 6, 2005
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the directions in my first message to you!
     
  7. buffaLo

    buffaLo Private E-2

    ok ok i have most of this stuff downloaded but the bitdefenders gonna take a while and i gotta head to work...

    ill hit you up when u i return

    -buffaLo
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! As soon as you complete all scans. Make sure you follow my directions for downloading,installing, and running HijackThis and attach a new log with the correct version of HijackThis.
     
  9. buffaLo

    buffaLo Private E-2

    im back from work!
    and that bastard is still on here...

    hit me up! and let me know...im going to the bar over this :eek:

    buffaLO
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're still not following directions.

    Read my editing remarks in message # 4 and 5.
     
  11. buffaLo

    buffaLo Private E-2

    ok sorry i am anxious and ADD
    i took my time this time
    PLEASE tell me im clear to move on
    i read EVERYTHING
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you follow these steps exactly! Don't rush! Do them right and it will fix your problem.

    Please make sure System Restore is OFF and the Viewing of Hidden Files & Folders is Enabled as per the tutorial.

    Please print these instructions out for use in Safe Mode with no networking and DO NOT RUN any browsers while doing these steps.

    Please download VundoFix.exe to your desktop.

    • Double-click VundoFix.exe to extract the files
    • This will create a VundoFix folder on your desktop.
    • After the files are extracted, please reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.
    • Once in safe mode open the VundoFix folder and doubleclick on KillVundo.bat
    • You will first be presented with a warning and a list of forums to seek help at. Iit should look like this
    • At this point press enter one time.
    • Next you will see:
    • At this point please type the following file path (make sure to enter it exactly as below!):

    C:\WINDOWS\System32\khhhe.dll

    • Press Enter, then press the F6 key, then press Enter one more time to continue with the fix.
    • Next you will see:
    • At this point please type the following file path (make sure to enter it exactly as below!):

    C:\WINDOWS\System32\ehhhk.*



    • Press Enter, then press the F6 key, then press Enter one more time to continue with the fix.
    • The fix will run then HijackThis will open.
    • In HiJackThis, please place a check next to the following items and click FIX CHECKED:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: MSEvents Object - {6DD0BC06-4719-4BA3-BEBC-FBAE6A448152} - C:\WINDOWS\System32\khhhe.dll
    O15 - Trusted Zone:
    http://awbeta.net-nucleus.com (HKLM)
    O20 - Winlogon Notify: khhhe - C:\WINDOWS\System32\khhhe.dll



    • After you have fixed these items, close Hijackthis and Press any key to Force a reboot of your computer.
    • Pressing any key will cause a "Blue Screen of Death" this is normal, do not worry!
    • Now please attach a new HJT log from normal mode. And tell me how things are working.
     
  13. buffaLo

    buffaLo Private E-2

    chaslang!

    it seems that i am unable to run my computer in safe mode
    i get passed the password screen fine
    but when the window prompt pops up (the one that says "click yes if you are sure you want windows to run in safe mode. . ." ), the computer seems to "glitch" and i can't click yes OR no

    then the screen is black and i get no explorer bar or desktop items, just safe mode background

    so i basically i cant perform the vundo fix until i can get my comp to run in safe mood

    this is bad, help!
    thanks
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you get into safe mode with the empty Desktop, try the below.

    Press CTRL-SHIFT-ESC at the same time to bring up Task Manager. If that works, do the below.
    Click File, New Task (Run...) and enter explorer.exe in the box and click okay. See if either your Desktop appears or a Windows Explorer window opens up. If either of these occur, you should now be able to navigate your way to the KillVundo.bat file to run it.

    Let me know what happens.
     
  15. buffaLo

    buffaLo Private E-2

    it still wont let me run explorer.exe
    i cant get passed it
    what can i do?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's use my older manual approach. Start by downloading two tools we will need:

    - Process Explorer 9.2

    - Pocket KillBox

    Extract them to there own folder somewhere that you will be able to locate them later. You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of khhhe.dll once and then click the kill button. After you have killed all of the khhhe.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of khhhe.dll and kill it.

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: MSEvents Object - {6DD0BC06-4719-4BA3-BEBC-FBAE6A448152} - C:\WINDOWS\System32\khhhe.dll
    O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
    O20 - Winlogon Notify: khhhe - C:\WINDOWS\System32\khhhe.dll

    Copy the bold text below to notepad. Save it as fixVundo.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.




    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.


    C:\WINDOWS\SYSTEM32\ehhh.ini
    C:\WINDOWS\SYSTEM32\ehhh.ini2
    C:\WINDOWS\SYSTEM32\ehhh.bak
    C:\WINDOWS\SYSTEM32\ehhh.bak1
    C:\WINDOWS\SYSTEM32\ehhh.bak2
    C:\WINDOWS\SYSTEM32\ehhh.tmp
    C:\WINDOWS\System32\khhhe.dll

    If you find any other files in this folder that begin with ehhh and end with any other extension ( the .ini is an an extension) delete them to.

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    After reboot post a new HJT log and tell me how the steps went. Doing this in normal boot mode does not always work. That is why we try to use safe mode.
     
  17. buffaLo

    buffaLo Private E-2

    i think it could be gone... ?
    im knocking on wood

    heres the log
    thank you so far!
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Yes! It's gone. But why do you now have HJT running improperly.

    C:\Documents and Settings\user name\Desktop\Installed Programs\Spyware Removal\HiJackThis\HijackThis.exe

    You had it correct before. It does not matter at this point but you should get rid of all copies of HJT except for this one: C:\Program Files\HJT\HijackThis.exe
     
    Last edited by a moderator: Jun 29, 2011
  19. buffaLo

    buffaLo Private E-2

    questions

    1.) i have had HJT in a folder thru my desktop ever since I DL about a year ago... i guess i am just used to using it there
    is there any way i can use a shortcut of HJT to keep it in my spyware removal folder?

    2.) can i turn my hidden files off again?

    3.) what do i do with this vundo fix on my desktop and can i delete the fixvundo reg key from it?

    4.) should i turn on my system restore again?

    5.) is there anything i can run just in case?

    6.) is bitdefender and that RANVirusscan okay to be in my HJT log?

    7.) should i keep all the spyware stuff i DL for this always?

    thats it! thanks so much for putting up with me and my laptop
    seeing that you are so willing to help, i might have some questions later :p

    thanks again
    buffaLo
     
  20. buffaLo

    buffaLo Private E-2

    heres the log
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is not the correct place to run it from. You need to run it like you did in message # 11. Your Spyware Removal folder is not located in a good place. No other user accounts can access it there and this is a folder area quite often attacked by malware. Also HJT and other items are Programs. They are not Documents or Settings. Put your Spyware Removal folder in a place like below and then use a shortcut if desired.

    C:\Program Files\Spyware Removal then you would have HJT in: C:\Program Files\Spyware Removal\HJT

    or even C:\Spyware Removal would be acceptable

    Not necessary and it only makes it easier for malware to hide again.

    Delete the VundoFix file and registry patch from your Desktop.

    Yes, enable system restore now that you are clean.

    There are many other tools you could run. But you do not need to unless you are still having malware problems. You should however, follow all the steps in:
    How to Protect yourself from malware!

    They are not problems. They are just components used whenever the online scanners would be run. If you delete them, they would have to be redownloaded before the scans could be run again.

    Terminnology: spyware is bad. I had you download spyware scanners/detection/removal tools not spyware. Yes keep it. There is no reason to remove it. You may need them again. Keep them updated.
     
  22. buffaLo

    buffaLo Private E-2

    ok i put the spyware removal folder in my program files
    ill continue to update my spyware scanners/detection/removal tools

    one final question:
    i see two hidden files in my program files:
    WindowsUpdate
    Winupdates

    are those ok?

    can i delete my HJT zip file btw?
    i can still run HJT, now that I have extracted everything right?

    ok ok
    im done
    THANK YOU
    buffaLo
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those are folders not files. WindowsUpdate is valid! Winupdates is from malware, delete it.

    Yes you can delete the HjijackThis.zip file if desired.
     
  24. buffaLo

    buffaLo Private E-2

    what's a !submit FOLDER?
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's from PocketKillbox. It stores copies of things it removes there so they can be submitted (if desired) for inspection. You can safely remove this folder.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds