WinFixer for me also

Discussion in 'Malware Help (A Specialist Will Reply)' started by rickster327, Oct 6, 2005.

  1. rickster327

    rickster327 Private E-2

    I've spent the entire day working on this and following the directions in the "Read Me first before asking for support".

    Now I'm at the dreaded HiJackThis log file.
    It is attached.
    thanks.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run ALL steps in the READ ME FIRST. I see no signs of the online scanners being run. This is the very first Step and it tells you not to skip it.
    Did you skip anything else?

    You also will need to disable Spybot's Teatimer before we can fix your Virtumundo (Winfixer) problem.

    To disable TeaTimer, run Spybot and click Mode and select Advanced Mode. Then click Tools and select Resident. Now in the right window pane, uncheck TeaTimer.
    Also while this is open, in the left column now select IE Tweaks and then in the right pane make sure all the Miscellaneous locks are unchecked.
    Now quit Spybot!

    Post a new HJT log attachment after completing all the above and we will then be able to give you a fix for your Virtumundo (Winfixer) problem.
     
  3. rickster327

    rickster327 Private E-2

    I was not connected to the internet as it slows the computer to a crawl. I aplogize, I will do the online scans and will post the log from the subject machine..
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you Disable Teatimer! I'm going to post a fix for your Virtumundo problem and perhaps it will speed up your connection so you can run the scans afterwards.

    Please make sure System Restore is OFF and the Viewing of Hidden Files & Folders is Enabled as per the tutorial.

    Please print these instructions out for use in Safe Mode with no networking and DO NOT RUN any browsers while doing these steps.

    Please download VundoFix.exe to your desktop.

    • Double-click VundoFix.exe to extract the files
    • This will create a VundoFix folder on your desktop.
    • After the files are extracted, please reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.
    • Once in safe mode open the VundoFix folder and doubleclick on KillVundo.bat
    • You will first be presented with a warning and a list of forums to seek help at. Iit should look like this
    • At this point press enter one time.
    • Next you will see:
    • At this point please type the following file path (make sure to enter it exactly as below!):

    C:\WINDOWS\java\classes\unplay.dll

    • Press Enter, then press the F6 key, then press Enter one more time to continue with the fix.
    • Next you will see:
    • At this point please type the following file path (make sure to enter it exactly as below!):

    C:\WINDOWS\java\classes\yalpnu.*

    • Press Enter, then press the F6 key, then press Enter one more time to continue with the fix.
    • The fix will run then HijackThis will open.
    • In HiJackThis, please place a check next to the following items and click FIX CHECKED:
    O2 - BHO: (no name) - {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - C:\WINDOWS\system32\jkkjj.dll (file missing)
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\java\classes\unplay.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O20 - Winlogon Notify: jkkjj - jkkjj.dll (file missing)
    O20 - Winlogon Notify: unplay - C:\WINDOWS\java\classes\unplay.dll



    • After you have fixed these items, close Hijackthis and Press any key to Force a reboot of your computer.
    • Pressing any key will cause a "Blue Screen of Death" this is normal, do not worry!
    • After reboot look for the below files and delete if found:
    c:\windows\system32\jkkjj.dll
    c:\windows\system32\jjkkj.ini <--- read the filename carefully! It is the inverse of above.
    c:\windows\system32\jjkkj.ini2
    c:\windows\system32\jjkkj.bak
    c:\windows\system32\jjkkj.bak2
    c:\windows\system32\jjkkj.tmp

    • Now run the online scanners in safe mode (or normal boot mode).
    • Now please attach a new HJT log from normal mode. And tell me how things are working.
     
  5. rickster327

    rickster327 Private E-2

    I ran into a snag-
    When I was in KillVundo.bat and I typed "C:\WINDOWS\java\classes\unplay.dll" and hit enter,F6, enter it says "Please be sure you typed the correct filepath, the filepath you entered does not seem to exist" ; "Press enter to exit htis program and check the filepath"

    Any suggestions?
     
  6. rickster327

    rickster327 Private E-2

    I am hooked in to Safe Mode and running the online virus scanners. I will post an new HJT log when the Bit Defender, RAV, and Stinger are done again.
     
  7. rickster327

    rickster327 Private E-2

    Here is a new log after doing the online scans, and stinger.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - C:\WINDOWS\system32\jkkjj.dll (file missing)
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\java\classes\unplay.dll (file missing)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O20 - Winlogon Notify: jkkjj - jkkjj.dll (file missing)
    O20 - Winlogon Notify: unplay - C:\WINDOWS\java\classes\unplay.dll (file missing)

    After clicking Fix, exit HJT.
    Now reboot your PC (in normal mode) and post a new HJT log. And tell us how things are working.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds