receiving annoying pop-ups and already did a scan, posting results

Discussion in 'Malware Help (A Specialist Will Reply)' started by cher_hc_43, Apr 6, 2006.

  1. cher_hc_43

    cher_hc_43 Private First Class

    I hav3e had this problem more than once with the annoying pop-ups,malware ect. so I did all the necessary scans and I am posting my logs to see if anything is left over from my scans. thanks

    cheryl

    p.s.
    ran bit defender and it found nothing so I am posting
    the panda that found problems.
     

    Attached Files:

  2. cher_hc_43

    cher_hc_43 Private First Class


    my norton popped up with a security risk message and it did a scan, I saved what it found if you could tell me what it is. thank you well it's not
    letting me upload it but norton found adware.Ezula whaty exactly is that?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    According to the HijackThis log you attached you still have Virtumonde and need to run the VundoFix tool again and attach a new log. Also delete the two file Panda showed:

    C:\WINDOWS\system32\pmkjh.dll
    C:\WINDOWS\system32\vtstt.dll

    If you are having these problems more than once, you need to be more careful where you are surfing and what you are clicking on. Last time I asked you about your Norton stuff having a fireall and you said it did. Are you sure it has a firewall? Which running process indicates the firewall?
     
  4. cher_hc_43

    cher_hc_43 Private First Class

     
  5. cher_hc_43

    cher_hc_43 Private First Class

    I ran a vundo scan again and it said nothing found, now after I ran the HJT and vundo I ran Symantec Adware.Ezula Removal Tool 1.0.3 do you think maybe that took care of the problem? should I run another HJT and post it?

    thank you
    cheryl
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you delete those two files I gave you?

    Ezula has nothing to do with Virtumonde.

    Please download and install the below so you will be ready for my next steps.

    ExplorerXP

    ExplorerXP is like Windows Explorer but much better/more powerful and can locate and delete files that Windows Explorer will not even show.

    Please attach a current HJT log.
     
  7. cher_hc_43

    cher_hc_43 Private First Class

    I couldnt find those 2 files that you posted I went into the HJT to try and delete them but they werent there, so I am posting my recent HJT let me know how it looks. thank you for your help

    cheryl
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't look for them in HijackThis. They are not registry keys. They are files that were shown in your Panda log. You need to delete them using Windows Explorer or the Explorer.Xp program I asked you to download and install. But we no longer need that program since your current log shows that Virtumonde has been disabled now.

    Just run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: InfoDocReader Object - {295BA105-3506-4D25-B0DD-54346320BDC5} - C:\WINDOWS\system32\ddccc.dll (file missing)

    After clicking Fix, exit HJT.

    Then tell me how things are working.
     
  9. cher_hc_43

    cher_hc_43 Private First Class

    when i went into the HJT to remove the line you posted the only thing I see is, 02-BHO{295BA105-3506-4D25-BODD-5434632OBDC5} no file, is this the one that you want me to select and delete? also when I ran the HJT in the msconfig I didnt set it as normal startup, did you want it set at that and then repost a new log?


    thanks
    cheryl
     
  10. cher_hc_43

    cher_hc_43 Private First Class

    Well i went ahead and did normal startup and made sure everything loaded in then I ran the explorerxp and found the 2 files that panda scan found and I deleted them, everything seems to be running just fine, but I still need to know if you want me to delete that other 02-BHO found in the HJT, please let me know.

    thank you for all your help
    cheryl
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! It is the same line without the filename showing!

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  12. cher_hc_43

    cher_hc_43 Private First Class

    Thank you for your help! Everything is running smoothly now. You guys are great :)

    cheryl
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Surf safely!
     
  14. cher_hc_43

    cher_hc_43 Private First Class

    sorry but I wasnt sure where to post this so I thought I would just add it to my post, on your home page you have programs there that can be downloaded, I was looking into the RemovalT Pro and the Paessler site inspector, how safe are the programs that you list to download? Are they malware free? thanks

    cheryl
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Messages like that should be sent to the owners. All software of Majorgeeks is malware free!

    Personally I do not recommend RemoveIT Pro XT SE
    I find it to have too many false positives and it's methods of identifying problems leave a lot to be desired. A full blown antivirus package is much better.
     
  16. cher_hc_43

    cher_hc_43 Private First Class

    ok thank you

    cheryl
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Just using the tools and following the guidelines in the How to protect thread should provide you with adequate protection. Just remember that you can be the ultimate weak link if you are not careful what you download, where you surf, what you click on, etc.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds