I've been getting pop-ups like crazy, please help me T_T:
Logfile of HijackThis v1.99.1
Scan saved at 10:14:15 PM, on 10/4/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
My name is dobhar and I will be looking over your log. Looks like you have some "Nasties" so please give me some time to go look it over and I will post back as soon as possible. If you have any questions please post back as a reply to this Thread\Topic and I will be advised by email so I can return and help you. Do not start another Thread\Topic.
I have a question to ask...I noticed that you have
Messenger Plus! 3 installed. Did you install this yourself? If you did, during setup, did you also install it with the
Sponser Program? The Sponser Program includes adware (like LOP). If you use Messenger Plus 3, you can uninstall it and then reinstall it, without installing the Sponser Program. I am going to add a "FIX" to uninstall
Messenger Plus! 3 but if you
DID installed it
without the
Sponser Program then ignore any "FIX" to remove anything dealing with Messenger Plus! 3.
Lets' get to it...
_________________________________________________________________________________
Please print out or copy these instructions\tutorials to Notepad as the internet will not be (while in Safe Mode) availble to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes. ________________________________________________________________________________
Step 1. ========== Skip this step if you installed this program without the Sponser Program We need to uninstall some programs
(if found in list) using "
Add or Remove Programs" in the Control Panel:
- Get into
Control Panel.
- Double-click "
Add or Remove Programs".
- Look in the
Currently installed programs box for each program listed below and if it is there:
- Click on it to select it.
- Click "
Change/Remove" (or "
Change") button.
- If you are prompted to confirm the removal of the program, click "
Yes"
Messenger Plus! 3
During the uninstall of Messenger Plus 3 you will get a little window as in the example here: http://www.msgplus.net/images/sponsor_uninstall.jpg. If you can't find that window, look in your taskbar. Type the code you'll see in that window and click uninstall.
Step 3. ========== Please download
VundoFix.exe from
http://www.atribune.org/downloads/VundoFix.exe to your desktop.
- Double-click
VundoFix.exe to extract the files...This will create a
VundoFix folder on your desktop.
- After the files are extracted, please reboot your computer into Safe Mode.
Step 4. ========== - Reboot computer into "
Safe Mode" Using the
F8 method:
- As soon as the
BIOS is loaded begin
tapping the F8 key until the
Boot Menu appears
- Use the arrow keys to select the
Safe Mode menu item
(Note: For additional help in booting into Safe Mode, see the following site - http://www.pchell.com/support/safemode.shtml)
Step 5. ========== We need to make sure all Hidden Files are showing so please:
* Open "
My Computer" then click on "
Tools" and from the drop down menu select "
Folder Options".
* Select the "
View" tab.
* Under the "
Hidden files and folders" heading SELECT "
Show hidden files and folders".
* UNCHECK the "
Hide file extensions for known types option".
* UNCHECK the "
Hide protected operating system files (recommended) option".
* Click "
Yes" to confirm.
* Click "
OK"
Step 6. ========== - Open the
VundoFix folder on your Desktop
- Double-click on
KillVundo.bat to run it
- You will first be presented with a warning. It should look like this:
VundoFix V2.13 by Atri By using VundoFix you agree that you are doing so at your own risk Press enter to continue....
- At this point press
enter one time.
- Next you will see:
Type in the filepath as instructed by the forum staff Then Press Enter, Then F6, Then Enter Again to continue with the fix.
-At this point please type the following file path
(Note: make sure to enter it exactly as below!):
C:\WINDOWS\system32\ddabx.dll - Press
Enter, then press the
F6 key, then press
Enter one more time to continue with the fix.
- Next you will see:
Please type in the second filepath as instructed by the forum staff Then Press Enter, Then F6, Then Enter again to continue with the fix.
- At this point please type the following file path
(Note: make sure to enter it exactly as below!):
C:\WINDOWS\system32\xbadd.* - Press
Enter, then press the
F6 key, then press
Enter one more time to continue with the fix.
- The fix will run then
HijackThis will open...
-
Select\check the following entries below,
Double-check to make sure that only these entries are checked...
O2 - BHO: MSEvents Object - {6DD0BC06-4719-4BA3-BEBC-FBAE6A448152} - C:\WINDOWS\system32\ddabx.dll O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
<<<= Do NOT "Fix" if you installed this program without the Sponser Program
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
<<<= Do NOT "Fix" if you installed this program without the Sponser Program
O20 - Winlogon Notify: ddabx - C:\WINDOWS\system32\ddabx.dll O20 - Winlogon Notify: pmnll - C:\WINDOWS\SYSTEM32\pmnll.dll
- Click the "
Fix checked" button...
- After you have fixed these items, close
HijackThis and Press any key to Force a reboot of your computer.
- Pressing any key will cause a "
Blue Screen of Death". This is normal, do not worry! At this point if your PC does not reboot then manually reboot your PC.
- Once your machine reboots, reboot into "
Normal Mode" and continue with the instructions below.
Step 7. ========== Delete the following
file(s) and
folder(s) in
BOLD only.
(Note: Don't be concern if can't find but advise if not found)
Folder(s)... C:\Program Files\
MessengerPlus! 3 <<<= Delete This Folder =>
Skip deleting this folder if you installed this program without the Sponser Program
File(s)... C:\WINDOWS\System32\
pmnll.dll <<<= Delete This File
C:\WINDOWS\System32\
llnmp.dll <<<= Delete This File
C:\WINDOWS\System32\
llnmp.bak <<<= Delete This File
C:\WINDOWS\System32\
llnmp.bak1 <<<= Delete This File
C:\WINDOWS\System32\
llnmp.bak2 <<<= Delete This File
C:\WINDOWS\System32\
llnmp.ini <<<= Delete This File
C:\WINDOWS\System32\
llnmp.ini1 <<<= Delete This File
C:\WINDOWS\System32\
llnmp.ini2 <<<= Delete This File
C:\WINDOWS\System32\
llnmp.tmp <<<= Delete This File
C:\WINDOWS\System32\
llnmp.tmp1 <<<= Delete This File
C:\WINDOWS\System32\
llnmp.tmp2 <<<= Delete This File
Step 8. ========== We now need to cleanup all the
Temp, Temorary Internet Files, Recycle Bin, etc... - Start the
CCleaner program
- Get into "
Options" => Select "
Advanced" => Deselect\uncheck "
Only delete files in Windows Temp folders older than 48 hours"
- We are only going to work with the "Cleaner" section.
(Note: Do not use the "Issues" section)
- click on the
Run Cleaner button in the lower right-hand corner
- After complete close program
- Empty Recycle Bin
Step 9. ========== Run Panda's online virus scan from
http://www.pandasoftware.com/products/activescan.htm and perform a full system scan.
- Once you are on the Panda site click the "
Scan your PC" button
- A new window will open...click the big "
Check Now" button
- Enter your
Country - Enter your
State/Province - Enter your
e-mail address and click
send - Select either
Home User or Company - Click the big
Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan (Note: It will take a couple minutes)
- Click on "
Local Disks" to start the scan
- Post Panda scan results in your next reply
Step 10. ========== - Post a fresh new HijackTHis log
- Post the Vundofix.txt log
- Post the Panda ActiveScan results
First off I just want to thank you SO much for helping me with this. I appreciate it a lot~
I couldn't delete the pmnll.dll file because it said it was in use & I couldn't find the other files...
HIJACK THIS:
Logfile of HijackThis v1.99.1
Scan saved at 12:08:31 PM, on 10/6/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003
Craig.Peacock@beyondlogic.org Suspending PID 180 'smss.exe'
Threads [184][188][192]
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003
Craig.Peacock@beyondlogic.org Killing PID 824 'explorer.exe'
Killing PID 824 'explorer.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003
Craig.Peacock@beyondlogic.org Error, Cannot find a process with an image name of rundll32.exe
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003
Craig.Peacock@beyondlogic.org Killing PID 252 'winlogon.exe'
Killing PID 252 'winlogon.exe'
File Deleted sucessfully.
Files Deleted sucessfully.
You did not answer my question on Messenger Plus! 3. I see that you have it still installed so I'm guessing (???) that you installed it without the Sponser Program...Is this correct??? If not we need to uninstall!
Please print out or copy these instructions\tutorials to Notepad as the internet will not be (while in Safe Mode) availble to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes. ____________________________________________________
Step 1. ==========
(Note: Only run this step if you decide to uninstall Viewpopint Manager)
We need to uninstall some programs
(if found in list) using "
Add or Remove Programs" in the Control Panel:
- Get into
Control Panel.
- Double-click "
Add or Remove Programs".
- Look in the
Currently installed programs box for each program listed below and if it is there:
- Click on it to select it.
- Click "
Change/Remove" (or "
Change") button.
- If you are prompted to confirm the removal of the program, click "
Yes"
Viewpoint Manager
Step 2. ========== - Reboot computer into "
Safe Mode" Using the
F8 method as per my prevoius post
Step 3. ========== Please make sure all Hidden Files are still showing
Step 4. ========== - Open the
VundoFix folder on your Desktop
- Double-click on
KillVundo.bat to run it
- You will first be presented with a warning. It should look like this:
VundoFix V2.13 by Atri By using VundoFix you agree that you are doing so at your own risk Press enter to continue....
- At this point press
enter one time.
- Next you will see:
Type in the filepath as instructed by the forum staff Then Press Enter, Then F6, Then Enter Again to continue with the fix.
-At this point please type the following file path
(Note: make sure to enter it exactly as below!):
C:\WINDOWS\SYSTEM32\pmnll.dll - Press
Enter, then press the
F6 key, then press
Enter one more time to continue with the fix.
- Next you will see:
Please type in the second filepath as instructed by the forum staff Then Press Enter, Then F6, Then Enter again to continue with the fix.
- At this point please type the following file path
(Note: make sure to enter it exactly as below!):
C:\WINDOWS\SYSTEM32\llnmp.* - Press
Enter, then press the
F6 key, then press
Enter one more time to continue with the fix.
- The fix will run then
HijackThis will open...
-
Select\check the following entries below,
Double-check to make sure that only these entries are checked...
O2 - BHO: (no name) - {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - C:\WINDOWS\system32\pmnll.dll O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
<<<= Do NOT "Fix" if you did not ininstall ViewPoint
- Click the "
Fix checked" button...
- After you have fixed these items, close
HijackThis and Press any key to Force a reboot of your computer.
- Pressing any key will cause a "
Blue Screen of Death". This is normal, do not worry! At this point if your PC does not reboot then manually reboot your PC.
- Once your machine reboots, reboot into "
Normal Mode" and continue with the instructions below.
Step 5. ========== Delete the following
file(s) and
folder(s) in
BOLD only.
(Note: Don't be concern if can't find but advise if not found)
Folder(s)... C:\Program Files\
Viewpoint Manager <<<= Delete This Folder
<<<= Do NOT delete folder if you did not uninstall ViewPoint Manager
Step 6. ========== We now need to cleanup all the
Temp, Temorary Internet Files, Recycle Bin, etc... - Start the
CCleaner program
- Get into "
Options" => Select "
Advanced" => Deselect\uncheck "
Only delete files in Windows Temp folders older than 48 hours"
- We are only going to work with the "Cleaner" section.
(Note: Do not use the "Issues" section)
- click on the
Run Cleaner button in the lower right-hand corner
- After complete close program
- Empty Recycle Bin
Step 7. ========== - Post a fresh new HijackTHis log
- Post the Vundofix.txt log
I'm sorry, yes I uninstalled it without the sponsor program.
VUNDO:
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03 Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org Suspending PID 180 'smss.exe' Threads [184][188][192]
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03 Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org Killing PID 816 'explorer.exe' Killing PID 816 'explorer.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03 Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org Error, Cannot find a process with an image name of rundll32.exe
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03 Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org Killing PID 252 'winlogon.exe' File Deleted sucessfully. Files Deleted sucessfully.
HijackThis:
Logfile of HijackThis v1.99.1 Scan saved at 12:32:55 AM, on 10/7/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Congrats...your Hijackthis log seems to be clean...:)
I'm also posting my
{All Clean} speech below. It has good information and some recommended tools (Recommended by all who deal with Spyware Nasties). Tools like SpywareBlaster =>
SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. Definitley recommended!!
____________________________________
The last thing I need you to do is to reset your "Hidden files and folders". System files are hidden for a reason and we don't want to have them openly available and susceptible to accidental deletion.
Open "My Computer".
Click on "Tools" and from the drop down menu select "Folder Options".
Select the "View" tab.
Under the Hidden files and folders heading UNSELECT "Show Hidden files and folders".
CHECK the Hide protected operating system files (recommended) option".
Click "Yes" to confirm.
Click "OK".
_____________________________________
Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
Disable and Enable System Restore. - If you are using Windows ME or XP then you should disable and reenable system restore to make sure there are no infected files found in a restore point. You can find instructions on how to enable and reenable system restore here:
Renable system restore with instructions from tutorial above
Make your Internet Explorer more secure - This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on theSecurity tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.
Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. See this link for a listing of some online & their stand-alone antivirus programs: Virus, Spyware, and Malware Protection and Removal Resources
Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.
Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly. For a tutorial on Firewalls and a listing of some available ones see the link below: Understanding and Using Firewalls
Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software. A tutorial on installing & using this product can be found here: Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers
Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot. A tutorial on installing & using this product can be found here: Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer
Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. A tutorial on installing & using this product can be found here: Using SpywareBlaster to protect your computer from Spyware and Malware
Install IE-SPYAD - IE-SPYAD adds a list of sites and domains associated with advertisers, marketers, and crapware pushers to the Restricted sites zone of Internet Explorer. A tutorial on installing & using IE-SPYAD can be found here: Using IE-Spyad to enhance your privacy and security
Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.
Logfile of HijackThis v1.99.1
Scan saved at 1:29:48 AM, on 10/7/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003
Craig.Peacock@beyondlogic.org Suspending PID 180 'smss.exe'
Threads [184][188][192]
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003
Craig.Peacock@beyondlogic.org Killing PID 816 'explorer.exe'
Killing PID 816 'explorer.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003
Craig.Peacock@beyondlogic.org Error, Cannot find a process with an image name of rundll32.exe
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003
Craig.Peacock@beyondlogic.org Killing PID 252 'winlogon.exe'
File Deleted sucessfully.
Files Deleted sucessfully.
Please print out or copy these instructions\tutorials to Notepad as the internet will not be (while in Safe Mode) availble to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes. ____________________________________________________
Step 1. ========== Reboot your computer into "Safe Mode"e" Using the
F8 method as per my prevoius post
Step 3. ========== Please make sure all Hidden Files are still showing
Step 4. ========== - Open the
VundoFix folder on your Desktop
- Double-click on
KillVundo.bat to run it
- You will first be presented with a warning. It should look like this:
VundoFix V2.13 by Atri By using VundoFix you agree that you are doing so at your own risk Press enter to continue....
- At this point press
enter one time.
- Next you will see:
Type in the filepath as instructed by the forum staff Then Press Enter, Then F6, Then Enter Again to continue with the fix.
-At this point please type the following file path
(Note: make sure to enter it exactly as below!):
C:\WINDOWS\system32\ssqpo.dll - Press
Enter, then press the
F6 key, then press
Enter one more time to continue with the fix.
- Next you will see:
Please type in the second filepath as instructed by the forum staff Then Press Enter, Then F6, Then Enter again to continue with the fix.
- At this point please type the following file path
(Note: make sure to enter it exactly as below!):
C:\WINDOWS\system32\opqss.* - Press
Enter, then press the
F6 key, then press
Enter one more time to continue with the fix.
- The fix will run then
HijackThis will open...
-
Select\check the following entries below,
Double-check to make sure that only these entries are checked...
- Click the "
Fix checked" button...
- After you have fixed these items, close
HijackThis and Press any key to Force a reboot of your computer.
- Pressing any key will cause a "
Blue Screen of Death". This is normal, do not worry! At this point if your PC does not reboot then manually reboot your PC.
- Once your machine reboots, reboot into "
Normal Mode" and continue with the instructions below.
Step 5. ========== We now need to cleanup all the
Temp, Temorary Internet Files, Recycle Bin, etc... - Start the
CCleaner program
- Get into "
Options" => Select "
Advanced" => Deselect\uncheck "
Only delete files in Windows Temp folders older than 48 hours"
- We are only going to work with the "Cleaner" section.
(Note: Do not use the "Issues" section)
- click on the
Run Cleaner button in the lower right-hand corner
- After complete close program
- Empty Recycle Bin
Step 6. ========== - Post a fresh new HijackTHis log
- Post the Vundofix.txt log
This thread is now considered complete therefore I have stopped monitoring it for replies. If you require more help please start a new thread and a volunteer like myself will help you.
dobhar
2 Intern
•
1132 Posts
323
0
Posted October 5th, 2005 16:00
My name is dobhar and I will be looking over your log. Looks like you have some "Nasties" so please give me some time to go look it over and I will post back as soon as possible. If you have any questions please post back as a reply to this Thread\Topic and I will be advised by email so I can return and help you. Do not start another Thread\Topic.
Thank You and Surf Safe... :)