Spyware Just wont Go away.

Discussion in 'Malware Help (A Specialist Will Reply)' started by blackprophet, Apr 6, 2006.

  1. blackprophet

    blackprophet Private E-2

    OK so I ran everything that is posted to do. When I ran ad-aware and Counterspy I found virtumonde. I tired using the virtumonde fixer but when I press run as a task, it gives me an runtime error that says: File not found and then it closes. I tired just running it and it found stuff and cleaned it but I suspect its not totally gone. I had to use Hijack this to get rid of MLLML.DLL.

    I'll include my Panda scan log and my HJT Log. Ive been here a few times so Ill thank you for all the help in the past and the help I will hopefully get now.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please attach the Bitdefender and CounterSpy logs as requested in the READ & RUN ME. Also your HJT log should have been obtained after completing the READ ME not before. It shows no signs of PandaActiveScan being run but you did post a log from Panda.


    Start by downloading Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locateit later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:O2 - BHO: DosSpecFolder Object - {FDA4DFFB-2C3D-4730-8D7E-28523C7F2F67} - C:\WINDOWS\SYSTEM\MLLIG.DLL
    O4 - HKLM\..\RunOnce: [*MLLIG] rundll32.exe C:\WINDOWS\SYSTEM\MLLIG.DLL,CreateProtectProc rerun

    Now exit HijackThis!

    Copy the bold text below to notepad. Save it as fixVundo.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.

    C:\WINDOWS\SYSTEM\GILLM.DAT
    C:\WINDOWS\SYSTEM\GILLM.ini
    C:\WINDOWS\SYSTEM\GILLM.ini2
    C:\WINDOWS\SYSTEM\GILLM.tmp
    C:\WINDOWS\SYSTEM\GILLM.tmp2
    C:\WINDOWS\SYSTEM\GILLM.bak
    C:\WINDOWS\SYSTEM\GILLM.bak1
    C:\WINDOWS\SYSTEM\GILLM.bak2
    C:\WINDOWS\SYSTEM\MLLIG.DLL

    If you find any other files in this folder that begin with gillm and end with any other extension ( the .ini is an an extension) delete them to.

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    After reboot post a new HJT log and tell me how the steps went.
     
    Last edited: Apr 7, 2006
  3. blackprophet

    blackprophet Private E-2

    That HJT log is from after the Panda scan. I Dont know why its showing as bofre. Ok I followed all your instructions but doesnt seem like it did anything. Gillm and millig just keep reapearing. Im going to include the Log from counterspy that I missed before and the New HJT log that I got after following the new instructions yougave me. Bitdefender found nothing so thats why I didnt include the log but I forgot to mention it. thanks again.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you actually find the files I was asking you to delete? Did they delete when you tried to delete them? Were there any other filles named gillm.xxx (where xxx could be anything).

    There are a few other registry keys we need to fix to as CounterSpy indicates. These were not in my list. That is why we ask for the logs from the scanners. The can tell useful info even if they do not fix the problems. Let's try another tool that often can help fix Virtumonde which can be very difficult on Win 9x systems.

    Run the procedure in the below link and then attach the spysweeper.txt log.

    Running Spy Sweeper

    Then attach a new HJT log and let me know if it help or not.
     
  5. blackprophet

    blackprophet Private E-2

    Ok Did it and will include the relevant logs. I found those files. Gillim deleted then would reapear in seconds. Millig Wouldn't delete. There was only Millig.DLL, Gillim.ini, and Gillim.bat2. Im not yet sure if it has helped or not.
     

    Attached Files:

  6. blackprophet

    blackprophet Private E-2

    Ok I just checked, The Millig fill was gone. The gillim files were still there so I deleted them, and it seems that they didnt come back. So Im keeping my fingers crossed for now.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but is it still in your HJT log. Spy Sweeper had a problem running on your PC. It kept running out of memory. You probably need to exit everything possible including ALL browsers before running it. It could not quarantine the C:\WINDOWS\SYSTEM\MLLIG.DLL file.

    If this file is still present, you can boot into DOS mode (not a command prompt - I mean boot to true DOS mode) and then change to the C:\WINDOWS\SYSTEM folder and manually locate and delete the MLLIG.DLL file.
     
  8. blackprophet

    blackprophet Private E-2

    Ok So I tried to get HJT to fix it and its gone. I checked for the files but its not there. I restarted and came back on and its still gone. So I think its all done thanks!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds