Pmkji.dll will not go away

Discussion in 'Malware Help (A Specialist Will Reply)' started by fade2blacks, Aug 2, 2006.

  1. fade2blacks

    fade2blacks Private E-2

    After getting some random pop up windows such as you have a virus and buy our software to get rid of it, I did some cleaning of the system I got most of everything but still was getting this pop up. So I downloaded Security Task manager and it showed that pmkji.dll was running in secret, I selected remove, it had an error but said it would remove it upon restart, It did not. I found this site and read some threads about this dll. but neither fixvundo.exe or vundofix.exe could find it. I also cannot find the file in the folder it is supposed to be in the windows/system32 but the security task manager says thats its location(I do have see hidden and system files enabled also). So please if anybody can tell me how to get rid of it the help would be most welcomed. Also does anyone know if this .dll is really dangerous and if I should change my account passwords?
     
    Last edited: Aug 2, 2006
  2. fade2blacks

    fade2blacks Private E-2

    Security task manager also gives me the text in the .dll, see if this helps.

    Edit by bjgarrick: Inline log attached!
     

    Attached Files:

    Last edited by a moderator: Aug 2, 2006
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please don't post any logs inline like that! I realize you were just trying to help but we don't need a log of text strings from the DLL file anyway.

    Yes you have a Virtumonde infection and may even have a conhook/winlogonhook infection to go along with it.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.



    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:

      • [*]runkeys.txt - the log from GetRunKey.bat
        [*]newfiles.txt - the log from ShowNew.bat
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  4. fade2blacks

    fade2blacks Private E-2

    Ok sorry about that, Also When I enabled the to see hidden system files as I checked over it I could see the file pmkji.dll but could not delete it. The .dll is still running hidden in the background according to security task manager. Also my bdscan.txt (bitdefender) is 463 kb, and no I did not change the options to show all files scanned. I have used trend micro for over 3 years and alot of stuff they have found hasnt been deleted so that could be the cause of it being so large, how can I post this file?
     

    Attached Files:

  5. fade2blacks

    fade2blacks Private E-2

    ...........
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you first empty all quarantine folders as requested in step 0 of the READ ME?

    Compress your Bitdefender log into a ZIP file and attach the ZIP file.

    Did you forget to uninstall Viewpoint Manager and Viewpoint Toolbar per step 0 of the READ ME! Uninstall them both now before continuing!


    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of pmkji.dllonce and then click the kill button. After you have killed all of the pmkji.dllunder winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below two DLLs:
    winhdn32.dll

    Next double click on explorer.exe and again click once on each instance of pmkji.dlland kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below two DLLs:
    winhdn32.dll

    Now just exit Process Explorer.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\WINDOWS\system32\b8aae146.exe
    C:\WINDOWS\system32\f3d4c18.exe
    C:\DOCUME~1\Owner\APPLIC~1\SKS~1\javaw.exe
    C:\WINDOWS\??mantec\winlogon.exe
    C:\WINDOWS\TEMP\win32.tmp.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {FCF949B8-4545-4A89-9E6A-8A313961E52E} - C:\WINDOWS\system32\pmkji.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O20 - Winlogon Notify: pmkji - C:\WINDOWS\system32\pmkji.dll
    O20 - Winlogon Notify: winhdn32 - winhdn32.dll (file missing)

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now click Start, Run, and enter cmd and click OK! This will open a command prompt window. In the command prompt window enter the below commands each followed by the Enter key.
    del %windir%\temp\win*.*
    exit

    If the above gives and error saying not found, just ignore and continue.


    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    c:\windows\warnhp.html
    C:\Program Files\Common Files\{60C1037B-09E4-1033-0415-040203200001}
    C:\Documents and Settings\Rena\Local Settings\Temporary Internet Files\Content.IE5\6PR01WFQ\Midnight_s_Inst-53[1].exe
    C:\Documents and Settings\Rena\Local Settings\Temporary Internet Files\Content.IE5\OLAZSTIB\MagicWaterfall_s_Inst-39[1].exe
    C:\Documents and Settings\Rena\Local Settings\Temporary Internet Files\Content.IE5\OLAZSTIB\MagicWaterfall_s_Inst-39[2].exe
    C:\WINDOWS\system32\ishost.exe
    C:\WINDOWS\system32\ismmon.exe
    C:\WINDOWS\system32\isnotify.exe
    C:\WINDOWS\system32\issearch.exe
    C:\WINDOWS\system32\pmkji.dll
    C:\WINDOWS\system32\yaywwuu.dll
    C:\WINDOWS\system32\ijkmp.ini
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    After reboot run Windows Explorer and delete all files in the below folder! Work around the few that Windows will not let you delete. Sort the folder by date. And do not try to delete any from the current date.

    C:\Documents and Settings\Don.YOUR-C8BH3JAGLT\Local Settings\TEMP

    Now attach a new HJT log and tell me how the steps went.

    Now also attach a new GetRunKey and new ShowNew log!

    Make sure you tell me how things are working now!
     
    Last edited: Aug 3, 2006
  7. fade2blacks

    fade2blacks Private E-2

    Ok I did that and redit it, sorry for the added post. thanks for the information.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What about the rest of the steps in message # 6?
     
  9. fade2blacks

    fade2blacks Private E-2

    Ok well just finished, had to find the time

    I could not find winhdn32.dll in both steps.

    None of these processes were on the hijack this process manager.

    It only said after I did it that 4 files from 1 folder were on the list.

    I did it anyway, The Pmkji.dll is no longer running windows security task manager and I think is completely gone, Im posting the logs, Do I still need to do a special reboot? Also there was an error on the batch when it ran to make runkeys.txt, but I dont know if that matters
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download and install Registrar Lite

    Run Registrar Lite navigate to the following keys and take ownership of them (explained further down):

    HKEY_LOCAL_MACHINE\software\microsoft\mssmgr

    To take ownership of the key do the following:
    • Copy & Paste one registry key from above into the address bar of Registrar Lite and hit the enter key. This will bring you to the regitry key.
    • Click-on Security in the Menu
    • Select Take Ownership
    • Now right click on the mssmgr key and select Delete (let me know if you receive any error messages )
    • Exit RegistrarLite
    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML

    Now Exit HijackThis!

    Now attach a new log from GetRunKey!

    How are things working?
     
  11. fade2blacks

    fade2blacks Private E-2

    Everything worked except I could not find c/programfiles viewpoint in the misc tools process manager. Also I dont know if this is the right section but recently, around the same time I noticed the pmkji.dll ( 5 or 6 days ago) my computer which is a compaq has a hibernate mode, now when it goes into hibernate mode when you move the mouse or click they keyboard nothing happens it just stays hibernated so I have to turn the computer off at the switch and restart it. Thanks so much for the help so far.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That was an incorrect cut & paste by me. It should have been the below which you should still do:


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\Viewpoint<--- the whole folder

    We still have some items to get cleaned up! Something I asked you to fix in message # 6 is still present!

    Does the below file and folder exist? If so, delete it.
    C:\Program Files\Common Files\{60C1037B-09E4-1033-0415-040203200001}\Update.exe

    Run the fixme.reg registry patch again from message # 6. Does it successfully add into the registry?

    Attach a new runkeys.txt log.

    Try the Hardware or Software Forum.
     
    Last edited: Aug 6, 2006
  13. fade2blacks

    fade2blacks Private E-2

    Didnt find update.exe, attached runkeys, everything seems to be okay thank you.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below registry key is still there and we have been trying to remove it. Are you sure the file does not exist? (The update..exe file?)


    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run]
    "{60C1037B-09E4-1033-0415-040203200001}"="\"C:\\Program Files\\Common Files\\{60C1037B-09E4-1033-0415-040203200001}\\Update.exe\" mc-110-12-0000272"


    Run Registrar Lite navigate to the following keys and take ownership of them (explained further down):

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

    To take ownership of the key do the following:
    • Copy & Paste the above registry key into the address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    • Click-on Security in the Menu
    • Select Take Ownership
    • Now right click on the {60C1037B-09E4-1033-0415-040203200001} key in the right window pane and select Delete (let me know if you receive any error messages )
    • Exit RegistrarLite
    Attach a new runkeys.txt log.
     
  15. fade2blacks

    fade2blacks Private E-2

    .......................................
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds