Member Panel


Sponsors and Ads

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] Another bactera virus problem

[Fixed] Hijackthis! Logs - [Fixed] Another bactera virus problem posted in the Security & Safety forums; Hya Sir Golitech , sorry for the late reply. I haven't been feeling to well the last couple of days. Lets see if something shows up here: 1. start HijackThis ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #7  
Old 06-10-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hya Sir Golitech , sorry for the late reply. I haven't been feeling to well the last couple of days.

Lets see if something shows up here:


1. start HijackThis
2. click on 'Config'
3. click on 'Misc Tools'
4. Put a check in 'List also minor sections (full)'
5. click on 'Generate StartupList log'
6. click on 'yes' to make the log
7. Then post the resulting log please


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #8  
Old 06-11-2006
Sir Golitech's Avatar
Bronze Member
My PC
 
Join Date: May 2006
Posts: 13
Sir Golitech - See this Members User comments on their Profile page
Default

Hi Joe, thanks for the response once again. Sorry your not feeling well.
This is a strange one, it seems to mimick related sites. For example, every time I come to this site I get a WinAnti Virus popup window. I'm so close to reformating it's not even funny.
Attached Files
File Type: txt startuplist.txt (11.3 KB, 1 views)


__________________
  #9  
Old 06-11-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Ah , we have something here:

(no name) - C:\WINDOWS\system32\jkhfg.dll - {341B05E9-5B82-4E7E-BDB3-AC040A9BD6BC}

That is from a Vundo infection , lets get rid of it:

Please download VundoFix.exe from here , and save it to your desktop.
  • Double-click VundoFix.exe to run it.
  • Put a check next to Run VundoFix as a task.
  • You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
  • When VundoFix re-opens, click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will shutdown your computer, click OK.
  • Turn your computer back on.
Please post the contents of C:\vundofix.txt and a new HiJackThis log.

And it looks like you switched to Kerio for a firewall and removed the Symantec suite? If yes , then lets get rid of this task:

download KillBox by Option^Explicit from HERE.

Double click on Killbox.exe and then check the delete on reboot button.

Enter the following filepath and filename into the Full path of file to delete box:

C:\WINDOWS\Tasks\Symantec NetDetect.job

Click the red circle with the white x and allow your computer to reboot.
(if killbox doesn't reboot on its own then please reboot manually)


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Last edited by joe5; 06-11-2006 at 05:14 AM.
  #10  
Old 06-11-2006
Sir Golitech's Avatar
Bronze Member
My PC
 
Join Date: May 2006
Posts: 13
Sir Golitech - See this Members User comments on their Profile page
Default

Sorry, but I wasn't sure what HJT log you wanted, so I've posted both startup and scan logs.
Yeah I got rid of Nortons only cause it's such a resource hog and AVG does a great job. I reinstalled Nortons, in hope it would fix my problem.
Attached Files
File Type: txt startuplist2.txt (11.2 KB, 1 views)
File Type: txt hijackthis2.txt (6.1 KB, 2 views)
File Type: txt VundoFix.txt (251 Bytes, 1 views)


__________________
  #11  
Old 06-11-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Ok , the Vundofix didn't actually remove the infection , but it did remove its cloaking abilities. So now it is possible to remove it manually.


Please download Process Explorer by Systernals from HERE.

Make sure you still have KillBox by Option^Explicit from HERE.



Then boot up in SAFE MODE and stay in safe mode (hit f8 when booting up), untill the entire fix is done.


Unzip Process Explorer and double click on procexp.exe

In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.
Once you see this screen click on each instance of jkhfg.dll once and then click the kill button.
After you have killed all of the jkhfg.dll's under winlogon click OK.

Next In the top section of the Process Exlporer screen again , double click on explorer.exe and again click once on each instance of jkhfg.dll then click the kill button.
Once you have done that click OK again.


Next run HijackThis and place a check beside each of the following:

O2 - BHO: (no name) - {C49E47D3-9D15-4E9C-802F-A0808743D37F} - C:\WINDOWS\system32\jkhfg.dll
O20 - Winlogon Notify: jkhfg - C:\WINDOWS\system32\jkhfg.dll
Now click fix checked and close HijackThis.
Please copy the text in the quote below, and paste it into a blank notepad window.

Save it as vundo.reg and in the "save as" type box choose "all files".
Once you have saved it double click it and allow it to merge with the registry.

Code:
REGEDIT4 
 
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B8B55274-0F9A-41E5-9067-A3539BD9E860}] 
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44}] 
[-HKEY_CLASSES_ROOT\CLSID\{581F22DA-7202-4F21-AEF3-114787156016}] 
[-HKEY_CLASSES_ROOT\CLSID\{B8B55274-0F9A-41E5-9067-A3539BD9E860}] 
[-HKEY_CLASSES_ROOT\CLSID\{44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44}] 
[-HKEY_CLASSES_ROOT\MSEvents.MSEvents] 
[-HKEY_CLASSES_ROOT\MSEvents.MSEvents.1] 
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEvents] 
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEvents.1]

Double click on Killbox.exe and then check the delete on reboot button.

Enter the following filepath and filename into the Full path of file to delete box:

C:\WINDOWS\system32\jkhfg.dll

Click the red circle with the white x and allow your computer to reboot.
(if killbox doesn't reboot on its own then please reboot manually)

After your computer has rebooted please run Hijackthis again and post a new Hijackthis log.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #12  
Old 06-11-2006
Sir Golitech's Avatar
Bronze Member
My PC
 
Join Date: May 2006
Posts: 13
Sir Golitech - See this Members User comments on their Profile page
Default

Well that was fun...
Attached Files
File Type: log hijackthis.log (5.9 KB, 2 views)


__________________

Reply
New! Norton Internet Security 2008 – Download Now Click Here

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 11:28 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top