Please help remove this ad/spyware

Discussion in 'Malware Help (A Specialist Will Reply)' started by chantililace, Jan 7, 2006.

  1. chantililace

    chantililace Private E-2

    Good Afternoon,

    I believe this is the notorius Winfixer..I have done pretty much everything in this thread: http://forums.majorgeeks.com/showthread.php?t=35407

    I have also downloaded the fixvundo from Symantec as well as MSAntipsyware from microsoft. They now say I am clean...but I still get the winfixer pop up when I browse along with other pop ups.

    I have aslo done a CCcleaner on my computer as well.

    Seeing that I have done the above, attached is my Hijackthis log.

    I consider myself computer literate so please let me know what I need to do to get the residual leftover on my computer off and back on track.

    Thanks in advance !
     

    Attached Files:

  2. chantililace

    chantililace Private E-2

    I am in the process of doing a bitedefende online scan and then a panda scan all in safe mode. I will post them when I am done.
     
  3. chantililace

    chantililace Private E-2

    Hello Again,

    Bitdefender did not find anything, however pandascan/activescan did under the spyware heading.

    Attached are the log files as well as another Hijackthis scan done after bitdefender and pandascan/active scan.

    PLEASE HELP !!

    Thanks in advance!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run the steps in the below thread. Start at step 3 since you already complete the other steps.

    Virtumonde aka Trojan Vundo Fix w/ Tool

    The lines from your log you will need to use to complete this procedure are:

    O2 - BHO: MSEvents Object - {CE70731D-F28D-4D81-9D61-C8EE60378401} - C:\WINDOWS\system32\vtutr.dll
    O20 - Winlogon Notify: vtutr - C:\WINDOWS\system32\vtutr.dll

    We will do some additional cleanup after you complete the procedure and attach a new HJT log.
    Some of which includes deleting the below files (and any similar ones with extension like .ini, ini2, .tmp, .tmp2, .dat and so on):
    C:\WINDOWS\system32\ddayx.dll
    C:\WINDOWS\system32\geedd.dll
    C:\WINDOWS\system32\jkhhi.dll
    C:\WINDOWS\system32\sstqq.dll
    C:\WINDOWS\system32\vturq.dll
     
  5. chantililace

    chantililace Private E-2

    Okay!...I've followed the Trojan Vundo Fix w/Tool procedure from above and attached is my Hijackthis log.

    Please give me direction now. You mentioned above we still have some cleaning to do.

    Thanks for the help so far..standing by!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: MSEvents Object - {CE70731D-F28D-4D81-9D61-C8EE60378401} - C:\WINDOWS\system32\vtutr.dll (file missing)
    O20 - Winlogon Notify: jkkjk - C:\WINDOWS\system32\jkkjk.dll (file missing)
    O20 - Winlogon Notify: vtutr - C:\WINDOWS\system32\vtutr.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:

    C:\WINDOWS\system32\ddayx.dll and xyadd.ini or xyadd with any other extension like .ini, .ini2, .bak, .bak1, ,bak2, .tmp
    C:\WINDOWS\system32\geedd.dll and ddeeg.ini or ddeeg with any other extension like .ini, .ini2, .bak, .bak1, ,bak2, .tmp
    C:\WINDOWS\system32\jkhhi.dll and ihhkj.ini or ihhkj with any other extension like .ini, .ini2, .bak, .bak1, ,bak2, .tmp
    C:\WINDOWS\system32\sstqq.dll and qqtss.ini or qqtss with any other extension like .ini, .ini2, .bak, .bak1, ,bak2, .tmp
    C:\WINDOWS\system32\vturq.dll and qrutv.ini or qrutv with any other extension like .ini, .ini2, .bak, .bak1, ,bak2, .tmp

    Notice that the non DLL file names are the reverse of the DLL file names.
    That is, ddayx backwards is xyadd
     
  7. chantililace

    chantililace Private E-2

    Good Evening Chaslang,

    I did as directed, however did not find the files you mentioned above in backwards, forwards or with those extensions under C:\Windows\System32

    I have attached the lates HJT log for your information.
    Am I clean?

    What's next - A system enable / restore as outlined in your readme first thread?

    Thanks in advance.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  9. chantililace

    chantililace Private E-2

    Hmm, my system restore was disabled throughout this removal process, my bad. What I did is left it disabled, rebooted the computer and enabled again. Any problems with this?
     
  10. chantililace

    chantililace Private E-2

    Ran out of my edit time (5mins) here is more clarification on the above:
    my system restore was disabled throughout this removal process from a few months ago when I tried removing this spyware with symantec fixvundo tool, my bad as it should not have been. What I did now is left it disabled, rebooted the computer and enabled again. Doesn't Windows prompt anyway when restoring? Am I being paranoid here? My hijackthislog is posted again.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't need to repost HJT logs now. Enabling system restore is not going to reinfected you since you have no restore points after system restore has been disabled. No, Windows will not prompt you to enable it. There is no reason why they should. Your the one that disable it and Windows is just doing what you asked.
     
  12. chantililace

    chantililace Private E-2

    Okay, I just wanted to make sure as this is the only thing I did not follow to the tee, having the system restore disabled throughout the removal process with you.

    What do you recommend of the Read me for the Java, the removal tool or manual removal, which does a better job in your opinion.

    Thanks for your help, I have been on my browser now for a half hour or so and no pop ups !!!!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't need to run the Java removal steps, you already have Sun Java installed. You may want to update to the lastest version.
     
  14. chantililace

    chantililace Private E-2

    too late I used the Java removal tool..and I guess got the latest version of sun java!
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have this? Java Runtime Environment Version 5.0 Update 6
     
  16. chantililace

    chantililace Private E-2

    Sorry for not being clear. I used the removal tool for Java under the read me link, then I installed the Java software stated from java.com, all unkowing that I didn't need to do all this in the first place.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well at least you are using the current version now. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds