Page 1 of 9 123 ... LastLast
Results 1 to 10 of 87

Thread: Having Problems Again!!!

  1. #1
    Join Date
    Nov 2007
    Location
    Adelaide Australia
    Posts
    54

    Having Problems Again!!!

    Hello Judy,
    I'm having problems with a pop-up or an add-on that keeps telling me that I need to update my security suite and to protect myself against spyware..
    I have aleardy done the cleanup stages and have followed the Symantec procedure for removal. I could not see the registry entries to delete them and have used the Unhook ini cab file to no avail. I have delete suspect folders in my hard drive and it seems to have reduced the incidents of them popping up but not all. Internet Explorer seems to run slow and freeze.

    I did get this message when booting into safe mode LoadLibrary("H:\Documents and settings\all users\application data\jmfkrkpu.dll")failed. The specific module could not be found.

    Spybot search and destroy has deleted that file which is in recovery in the Zloc.uc section or folder.

    Attached is my Log file.
    Regards
    Damian
    Attached Files Attached Files

  2. #2
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    1. Please print these instructions as they will be needed later when internet access is not available.
    2. Save these instructions in word or notepad to the desktop where they can be easily found.
    3. Download VundoFix and save it to your desktop.
    4. When it has completed downloading, double-click VundoFix.exe to run it.
    5. Click the Scan for Vundo button.
    6. Once it's done scanning, click the Remove Vundo button.
    7. You will now receive a prompt asking if you want to remove the files, click the YES button. Once you click yes, your desktop will go blank as it starts removing Vundo.
    8. When completed, it will prompt that it will shutdown your computer, click the OK button.
    9. When the computer has shutdown, turn your computer back on.
    Run a new HJT scan and post that log and the VundoFix log here.
    There are more than vundo showing on the computer so there are going to be more steps to take.

  3. #3
    Join Date
    Nov 2007
    Location
    Adelaide Australia
    Posts
    54

    Vundo did not detect files.

    Hi again,
    Downloaded and ran Vundo but did not detect infected files. I ran it several times but to no avail. Have attached HJT Log.
    I Failed to mention that Spybot search and destroy has Virtumonde that Vundo was trying to find in recovery. Should I delete the files immediately?

    Regards
    Damian

  4. #4
    Join Date
    Nov 2007
    Location
    Adelaide Australia
    Posts
    54

    Talking HJT Log

    OOPS forgot to add file.
    Attached Files Attached Files

  5. #5
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Ok, well your latest log shows a Trojan that the first one didn't show...and still is showing what looked like Vundo...
    Do this please;
    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log in the next post.
    Note:
    • Do not mouseclick combofix's window while it is running. That may cause it to stall.

  6. #6
    Join Date
    Nov 2007
    Location
    Adelaide Australia
    Posts
    54

    ComboFix.exe

    Hello,

    Ok I downloaded combofix.exe and ran the program. A small window opened and displayed Abort.-07-11-08.1
    Current date 2007-11-18. This copy of combofix has expired. please dowload an updated copy. When i closed the window the program seemed to run a little more then another window opened and said that it had unistalled the program. When Internet explorer had closed it had left an IE shortcut on the desktop and then followed by an IE error message that it needed to be shut down.
    Wasnt sure whether to post another HJT Log but have done so.

    Regards
    Attached Files Attached Files

  7. #7
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Try this one combofix

  8. #8
    Join Date
    Nov 2007
    Location
    Adelaide Australia
    Posts
    54

    Combofix

    Hi There,
    Sorry but that did the same as the last one.

    Cheers

  9. #9
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Let me do some checking.

  10. #10
    Join Date
    Nov 2007
    Posts
    7
    I am having the exact same problem with ComboFix. Getting expired message and having the application delete itself.

    Thanks for letting us know what to do to get ComboFix working.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •