Description of problem: Win Fixer continues to pop up and end internet sessions.
Logfile of HijackThis v1.99.1
Scan saved at 12:34:29 PM, on 11/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Welcome to the Dell HJT Forum... :) Sorry for the delay...we (HJT Volunteers) are just quite busy...lots of logs and too few helpers...
Lets' get to it...
_________________________________________________________________________________
Please print out or copy these instructions\tutorials to Notepad as the internet will not be (while in Safe Mode) availble to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes. ________________________________________________________________________________
Step 1. ========== Please download and install
CCleaner from
here
(Note: DO NOT run this program yet)
Step 2. ========== Please download
VundoFix.exe from
here to your desktop.
- Double-click
VundoFix.exe to extract the files...This will create a
VundoFix folder on your desktop.
- After the files are extracted, please reboot your computer into Safe Mode.
Step 3. ========== - Reboot computer into "
Safe Mode" Using the
F8 method:
- As soon as the
BIOS is loaded begin
tapping the F8 key until the
Boot Menu appears
- Use the arrow keys to select the
Safe Mode menu item
(Note: For additional help in booting into Safe Mode, see the following site - here)
Step 4. ========== We need to make sure all Hidden Files are showing so please:
* Open "
My Computer" then click on "
Tools" and from the drop down menu select "
Folder Options".
* Select the "
View" tab.
* Under the "
Hidden files and folders" heading SELECT "
Show hidden files and folders".
* UNCHECK the "
Hide file extensions for known types option".
* UNCHECK the "
Hide protected operating system files (recommended) option".
* Click "
Yes" to confirm.
* Click "
OK"
Step 5. ========== - Open the
VundoFix folder on your Desktop
- Double-click on
KillVundo.bat to run it
- You will first be presented with a warning. It should look like this:
VundoFix V2.15 by Atri By using VundoFix you agree that you are doing so at your own risk Press enter to continue....
- At this point press
enter one time.
- Next you will see:
Please Type in the filepath as instructed by the forum staff and then press enter:
-At this point please type the following file path
(Note: make sure to enter it exactly as below!):
C:\WINDOWS\system32\jkkll.dll - Press
Enter to continue with the fix.
- Next you will see:
Please type in the second filepath as instructed by the forum staff then press enter:
- At this point please type the following file path
(Note: make sure to enter it exactly as below!):
C:\WINDOWS\system32\llkkj.* - Press
Enter to continue with the fix.
- The fix will run then
HijackThis will open...
-
Select\check the following entries below,
Double-check to make sure that only these entries are checked...
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file) O2 - BHO: MSEvents Object - {6DD0BC06-4719-4BA3-BEBC-FBAE6A448152} - C:\WINDOWS\system32\jkkll.dll O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O20 - Winlogon Notify: jkkll - C:\WINDOWS\system32\jkkll.dll
- Click the "
Fix checked" button...
- After you have fixed these items, close
HijackThis - Press
Enter to exit the VundoFix program then
manually reboot your computer.
- Once your machine reboots, reboot into "
Normal Mode" and continue with the instructions below.
Step 6. ========== We now need to cleanup all the
Temp, Temorary Internet Files, Recycle Bin, etc... - Start the
CCleaner program
- Get into "
Options" => Select "
Advanced" => Deselect\uncheck "
Only delete files in Windows Temp folders older than 48 hours"
- We are only going to work with the "Cleaner" section.
(Note: Do not use the "Issues" section)
- click on the
Run Cleaner button in the lower right-hand corner
- After complete close program
- Empty Recycle Bin
Step 7. ========== Run Panda's online virus scan from
here and perform a full system scan.
- Once you are on the Panda site click the "
Scan your PC" button
- A new window will open...click the big "
Check Now" button
- Enter your
Country - Enter your
State/Province - Enter your
Valid E-mail - Select either
Home User or Company - Click the big
Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan (Note: It will take a couple minutes)
- Click on "
Local Disks" to start the scan
- When the scan completes, if anything malicious is detected, click the
See Report button, then
Save Report and save it to a convenient location.
- Post Panda scan results in your next reply
Step 8. ========== - Post a fresh new HijackTHis log
- Post the Vundofix.txt log
- Post the Panda ActiveScan results
Thanks! I know you are all busy and I appreciate your help! Here is the follow up on the information.
Chris
Fresh New Hijack Log Post:
Logfile of HijackThis v1.99.1
Scan saved at 1:31:11 PM, on 11/16/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Spyware:Spyware/Virtumonde No disinfected C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP484\A0038946.dll
Adware:Adware/StartPage.AIW No disinfected C:\WINDOWS\SYSTEM32\pmnlj.dll
Congrats... :) Your log seems to be clean. Nice Job... :) I do need you to cleanup one file and I have a recommendation...
I see that your running
Sun Java...but i cannot tell what verion you are running. The latest is
1.5.0 (build 1.5.0_05-b05). I recommend you uninstall the old version using "
Add or Remove Programs" if your version is not up to the latest. Use the following
link and either use the
Windows (Online Installation) or
Windows (Offline Installation) method. The reason why you have to uninstall the old version is that the new verion does not update the old version it just installs into a new location so if you go into your "
Add or Remove Programs" you would see both versions listed.
I can find nothing bad listed so I'm also posting my standard
{All Clean} speech below. It has good information and some recommended tools (Recommended by all who deal with Spyware Nasties). Tools like SpywareBlaster =>
SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. Definitley recommended!!
____________________________________
Delete the following
File(s) in BOLD only.
(Don't be concern if they do not exist but advise what files could not be found or deleted)
File(s) C:\WINDOWS\System32\
pmnlj.dll = Delete This File
____________________________________
The last thing I need you to do is to reset your "Hidden files and folders". System files are hidden for a reason and we don't want to have them openly available and susceptible to accidental deletion.
Open "My Computer".
Click on "Tools" and from the drop down menu select "Folder Options".
Select the "View" tab.
Under the Hidden files and folders heading UNSELECT "Show Hidden files and folders".
CHECK the Hide protected operating system files (recommended) option".
Click "Yes" to confirm.
Click "OK".
_____________________________________
Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
Disable and Enable System Restore. - If you are using Windows ME or XP then you should disable and reenable system restore to make sure there are no infected files found in a restore point. You can find instructions on how to enable and reenable system restore here:
Make your Internet Explorer more secure - This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on theSecurity tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.
Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. See this link for a listing of some online & their stand-alone antivirus programs: Virus, Spyware, and Malware Protection and Removal Resources
Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.
Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly. For a tutorial on Firewalls and a listing of some available ones see the link below: Understanding and Using Firewalls
Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software. A tutorial on installing & using this product can be found here: Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers
Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot. A tutorial on installing & using this product can be found here: Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer
Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. A tutorial on installing & using this product can be found here: Using SpywareBlaster to protect your computer from Spyware and Malware
Install IE-SPYAD - IE-SPYAD adds a list of sites and domains associated with advertisers, marketers, and crapware pushers to the Restricted sites zone of Internet Explorer. A tutorial on installing & using IE-SPYAD can be found here: Using IE-Spyad to enhance your privacy and security
Blocking Unwanted Parasites with a Hosts File - The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer. Download and Install instructions
Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.
This thread is now considered closed and I have stopped monitoring it for replies. If you still require assistance please start a new thread and post a fresh new HijackThis log. One of our volunteers will be glad to help you. :)
dobhar
2 Intern
•
1132 Posts
143
0
Posted November 12th, 2005 05:00
Welcome to the Dell HJT Forum... :) Sorry for the delay...we (HJT Volunteers) are just quite busy...lots of logs and too few helpers...
Lets' get to it...
_________________________________________________________________________________
Please print out or copy these instructions\tutorials to Notepad as the internet will not be (while in Safe Mode) availble to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.
________________________________________________________________________________
Step 1.
==========
Please download and install CCleaner from here
(Note: DO NOT run this program yet)
Step 2.
==========
Please download VundoFix.exe from here to your desktop.
- Double-click VundoFix.exe to extract the files...This will create a VundoFix folder on your desktop.
- After the files are extracted, please reboot your computer into Safe Mode.
Step 3.
==========
- Reboot computer into " Safe Mode" Using the F8 method:
- As soon as the BIOS is loaded begin tapping the F8 key until the Boot Menu appears
- Use the arrow keys to select the Safe Mode menu item
(Note: For additional help in booting into Safe Mode, see the following site - here)
Step 4.
==========
We need to make sure all Hidden Files are showing so please:
* Open " My Computer" then click on " Tools" and from the drop down menu select " Folder Options".
* Select the " View" tab.
* Under the " Hidden files and folders" heading SELECT " Show hidden files and folders".
* UNCHECK the " Hide file extensions for known types option".
* UNCHECK the " Hide protected operating system files (recommended) option".
* Click " Yes" to confirm.
* Click " OK"
Step 5.
==========
- Open the VundoFix folder on your Desktop
- Double-click on KillVundo.bat to run it
- You will first be presented with a warning. It should look like this:
VundoFix V2.15 by Atri
By using VundoFix you agree that you are doing so at your own risk
Press enter to continue....
- At this point press enter one time.
- Next you will see:
Please Type in the filepath as instructed by the forum staff
and then press enter:
-At this point please type the following file path (Note: make sure to enter it exactly as below!):
C:\WINDOWS\system32\jkkll.dll
- Press Enter to continue with the fix.
- Next you will see:
Please type in the second filepath as instructed by the forum
staff then press enter:
- At this point please type the following file path (Note: make sure to enter it exactly as below!):
C:\WINDOWS\system32\llkkj.*
- Press Enter to continue with the fix.
- The fix will run then HijackThis will open...
- Select\check the following entries below, Double-check to make sure that only these entries are checked...
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: MSEvents Object - {6DD0BC06-4719-4BA3-BEBC-FBAE6A448152} - C:\WINDOWS\system32\jkkll.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O20 - Winlogon Notify: jkkll - C:\WINDOWS\system32\jkkll.dll
- Click the " Fix checked" button...
- After you have fixed these items, close HijackThis
- Press Enter to exit the VundoFix program then manually reboot your computer.
- Once your machine reboots, reboot into " Normal Mode" and continue with the instructions below.
Step 6.
==========
We now need to cleanup all the Temp, Temorary Internet Files, Recycle Bin, etc...
- Start the CCleaner program
- Get into " Options" => Select " Advanced" => Deselect\uncheck " Only delete files in Windows Temp folders older than 48 hours"
- We are only going to work with the "Cleaner" section. (Note: Do not use the "Issues" section)
- click on the Run Cleaner button in the lower right-hand corner
- After complete close program
- Empty Recycle Bin
Step 7.
==========
Run Panda's online virus scan from here and perform a full system scan.
- Once you are on the Panda site click the " Scan your PC" button
- A new window will open...click the big " Check Now" button
- Enter your Country
- Enter your State/Province
- Enter your Valid E-mail
- Select either Home User or Company
- Click the big Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan (Note: It will take a couple minutes)
- Click on " Local Disks" to start the scan
- When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
- Post Panda scan results in your next reply
Step 8.
==========
- Post a fresh new HijackTHis log
- Post the Vundofix.txt log
- Post the Panda ActiveScan results