Winfixer 2005

Discussion in 'Malware Help (A Specialist Will Reply)' started by jhs, Oct 16, 2005.

  1. jhs

    jhs Private E-2

    I'd appreciate any assistance in removing Winfixer 2005.

    Computer specs: Windows XP Pro w/ sp2 update, 2.8 ghz Pent 4 processor, 512 KB RAM, 80 GB HD

    I've done the following:
    Disabled System restore
    Enabled viewing of hidden files
    Ran Bitdefender - no problems
    Ran RAV - no problems
    Ran Trojanscan - 2 game programs identified and removed (also removed from recycle bin)

    In Safe mode:
    Ran CCleaner
    Ran Adaware twice, first time in normal mode. Identified over 200 items to be removed including some registry items. Fixed and ran it again in safe mode - no problems. I can submit original quarantine list if needed.
    Ran Spybot - no problems
    Ran MSFT Antispyware - no problems

    Attached: Hijackthis logfile (run in normal mode)

    Thanks for your help! I really appreciate it.


    jhs
     

    Attached Files:

  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please make sure System Restore is OFF and the Viewing of Hidden Files & Folders is Enabled as per the tutorial.


    Please print these instructions out for use in Safe Mode.

    Please download VundoFix.exe to your desktop.

    • Double-click VundoFix.exe to extract the files
    • This will create a VundoFix folder on your desktop.
    • After the files are extracted, please reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.
    • Once in safe mode open the VundoFix folder and doubleclick on KillVundo.bat
    • You will first be presented with a warning and a list of forums to seek help at.
      it should look like this
    • At this point press enter one time.
    • Next you will see:
    • At this point please type the following file path (make sure to enter it exactly as below!):
    C:\WINDOWS\system32\ddayx.dll

    • Press Enter, then press the F6 key, then press Enter one more time to continue with the fix.
    • Next you will see:
    • At this point please type the following file path (make sure to enter it exactly as below!):
    C:\WINDOWS\system32\xyadd.*

    • Press Enter, then press the F6 key, then press Enter one more time to continue with the fix.
    • The fix will run then HijackThis will open.
    • In HiJackThis, please place a check next to the following items and click FIX CHECKED:
    O2 - BHO: MSEvents Object - {8DBF02DA-4360-4A7E-BEA1-347B87816327} - C:\WINDOWS\system32\ddayx.dll
    O20 - Winlogon Notify: ddayx - C:\WINDOWS\system32\ddayx.dll

    • After you have fixed these items, close Hijackthis and Press any key to Force a reboot of your computer.
    • Pressing any key will cause a "Blue Screen of Death" this is normal, do not worry!
    • Once your machine reboots please attach a fresh HJT log from normal mode.
     
  3. jhs

    jhs Private E-2

    Thank you. I followed the instructions and have attached a new HJT file.

    HJT did not start automatically - I restarted in SAFE mode, started HJT and followed the instructions from there. I hope it worked.

    Thanks!

    jhs
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, you must uninstall Microsoft AntiSpyware and then repeat the fix. Next time attach the new HJT log from normal mode.
     
  5. jhs

    jhs Private E-2

    uninstalled msft antispyware

    entered safe mode and re ran vundofix

    program said it could not find the first file

    rebooted in normal mode, ran hijack this - new log attached.

    Thanks again!

    jhs
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Okay let's start by downloading two tools we will need:

    - Process Explorer 9.2

    - Pocket KillBox

    Extract them to there own folder somewhere that you will be able to locate them later.


    Reboot in Safe Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of C:\WINDOWS\system32\mlljg.dll once and then click the kill button. After you have killed all of the C:\WINDOWS\system32\mlljg.dll's under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of C:\WINDOWS\system32\mlljg.dlland kill it.

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: MSEvents Object - {8DBF02DA-4360-4A7E-BEA1-347B87816327} - C:\WINDOWS\system32\mlljg.dll
    O20 - Winlogon Notify: mlljg - C:\WINDOWS\system32\mlljg.dll


    Copy the bold text below to notepad. Save it as fixVundo.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.


    C:\WINDOWS\system32\gjllm.ini
    C:\WINDOWS\system32\gjllm.ini2
    C:\WINDOWS\system32\gjllm.bak
    C:\WINDOWS\system32\gjllm.bak1
    C:\WINDOWS\system32\gjllm.bak2
    C:\WINDOWS\system32\gjllm.tmp
    C:\WINDOWS\system32\mlljg.dll

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    After reboot post a new HJT log.
     
  7. jhs

    jhs Private E-2

    All tasks accomplished - I hope!

    Attached is the latest HJT logfile.

    BTW, I have not had anymore winfixer 2005 popups!

    jhs
     

    Attached Files:

  8. jhs

    jhs Private E-2

    I just had a screen pop up again (it looks like a legitimate windows security warning). This time it didn't progress to the three other screens or restart my browser.

    jhs
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are still infected! Lets try this again with a couple slight changes to the procedure. One change is in the registry patch so make sure you re-download it. Also make sure you have NO BROWSERS opened while running these steps and that you do boot in safe mode. So print or save these instructions locally so you can operate offline with all browsers closed.

    Reboot in Safe Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of C:\WINDOWS\system32\mlljg.dll once and then click the kill button. After you have killed all of the C:\WINDOWS\system32\mlljg.dll's under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of C:\WINDOWS\system32\mlljg.dll and kill it.

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: MSEvents Object - {8DBF02DA-4360-4A7E-BEA1-347B87816327} - C:\WINDOWS\system32\mlljg.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundler/CAB/RealArcadeRdxIE.cab
    O20 - Winlogon Notify: mlljg - C:\WINDOWS\system32\mlljg.dll



    Copy the bold text below to notepad. Save it as fixVundo.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.

    C:\WINDOWS\system32\gjllm.ini
    C:\WINDOWS\system32\gjllm.ini2
    C:\WINDOWS\system32\gjllm.bak
    C:\WINDOWS\system32\gjllm.bak1
    C:\WINDOWS\system32\gjllm.bak2
    C:\WINDOWS\system32\gjllm.tmp
    C:\WINDOWS\system32\mlljg.dll

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    After reboot post a new HJT log.
     
  10. jhs

    jhs Private E-2

    Sorry it took so long to get back to you. I really appreciate the assistance.

    Attached is the latest HJT log.

    Thanks

    JHS
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks good now! Anymore problems?
     
  12. jhs

    jhs Private E-2

    THANKS!!!!!

    I appreciate the help.

    God Bless....

    JHS
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds