tim s
Hi LISH,
Thanks for posting logs. Your doing a fine job. This is next.
To enable the viewing of Hidden files follow these steps:
Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present):
O2 - BHO: (no name) - {092428B9-FC13-48FA-895C-E183BFE53CFC} - C:\WINDOWS\system32\mljji.dll (file missing)
O2 - BHO: (no name) - {0D655062-1646-432E-BA69-73E1296BE4B0} - (no file)
O2 - BHO: (no name) - {6F2BDD91-5B5C-439A-BC19-A4E2F1301249} - C:\WINDOWS\system32\awvtt.dll (file missing)
O2 - BHO: msdn_lib.msdn_hlp - {7C2F2C76-1489-450D-B8FB-0B9692D788F9} - C:\WINDOWS\system32\msdn_lib.dll
O2 - BHO: (no name) - {93BC1AA7-8169-4029-8D1B-313203816343} - C:\Program Files\Common Files\hoket.dll (file missing)
O2 - BHO: (no name) - {AF3A3664-20CD-4D82-BB17-CC12BF6E19D0} - C:\WINDOWS\system32\sstqr.dll (file missing)
O2 - BHO: (no name) - {F8949656-53DB-48F3-AA61-3C3DD3177334} - C:\WINDOWS\system32\jkkjh.dll (file missing)
O20 - Winlogon Notify: gebcy - C:\WINDOWS\system32\gebcy.dll (file missing)
WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked and exit HijackThis.
——————————————————–
Reboot your computer in Safe Mode.
Need to check to make sure this process is not running in safemode.
End malicious processes: (if they are present)
Use Explorer to navigate to and delete the following file (if it is present) just what is in red:
Files:
Instuction on how to find files listed above:
——————————————————-
Now this is next:
Please do the following:
Here we are going to clean out cookies and temp files from your computer.
*NOTE* CCleaner deletes EVERYTHING out of temp/temporary folders. If you have anything in a temp folder, back it up or move it to a permanent folder prior to running CCleaner!
Download CCleaner from here It will start to download automatically. If ask if you want to download let it. Save to your Desktop.
Note: If you get and Error page from this link.
Try again you will see this message Your download of CCleaner will automatically start in 5 seconds. Click here if it does not do not wait go ahead and click on it.
[*]Click on the "Options" icon at the left side of the window, then click on "Advanced."
deselect "Only delete files in Windows Temp folders older than 48 hours."
[*]Click on the "Cleaner" icon on the left side of the window, then click Run Cleaner to run the program.
[*]Caution: It is not recommended that you use the "Issues" feature unless you are very familiar with the registry as it has been known to find legitimate items.
[*]After CCleaner has completed its process, click Exit.
[*]You will need to reboot here if not ask to do so.
_______________________________
Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.
Here we are going to just make sure this tool is setup correctly Do not run scan yet.
Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.
______________________________
Reboot your computer in Safe Mode.
Double-click on SmitfraudFix.exe
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.
The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.
A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.
The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
______________________________
Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
Note: If AVG Anti-Spyware screen does not fit your monitor screen Hold down the Alt button on keyboard then tap spacebar, menu should pop up then choose maximize. AVG Anti-Spyware screen should fix screen a little better.
IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
______________________________
Please post:
Thanks for posting logs. Your doing a fine job. This is next.
To enable the viewing of Hidden files follow these steps:
- Close all programs so that you are at your desktop.
- Click Start, then select My Computer)
- Select the Tools (at top of opened screen in menu and click Folder Options.
- After the new window appears select the View tab.
- Put a checkmark in the checkbox labeled Display the contents of system folders.
- Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
- Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
- Remove the checkmark from the checkbox labeled Hide protected operating system files.
- Press the Apply button and then the OK button and shutdown My Computer.
Now your computer is configured to show all hidden files.
Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present):
O2 - BHO: (no name) - {092428B9-FC13-48FA-895C-E183BFE53CFC} - C:\WINDOWS\system32\mljji.dll (file missing)
O2 - BHO: (no name) - {0D655062-1646-432E-BA69-73E1296BE4B0} - (no file)
O2 - BHO: (no name) - {6F2BDD91-5B5C-439A-BC19-A4E2F1301249} - C:\WINDOWS\system32\awvtt.dll (file missing)
O2 - BHO: msdn_lib.msdn_hlp - {7C2F2C76-1489-450D-B8FB-0B9692D788F9} - C:\WINDOWS\system32\msdn_lib.dll
O2 - BHO: (no name) - {93BC1AA7-8169-4029-8D1B-313203816343} - C:\Program Files\Common Files\hoket.dll (file missing)
O2 - BHO: (no name) - {AF3A3664-20CD-4D82-BB17-CC12BF6E19D0} - C:\WINDOWS\system32\sstqr.dll (file missing)
O2 - BHO: (no name) - {F8949656-53DB-48F3-AA61-3C3DD3177334} - C:\WINDOWS\system32\jkkjh.dll (file missing)
O20 - Winlogon Notify: gebcy - C:\WINDOWS\system32\gebcy.dll (file missing)
WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked and exit HijackThis.
——————————————————–
Reboot your computer in Safe Mode.
- If the computer is running, shut down Windows, and then turn off the power.
- Wait 30 seconds, and then turn the computer on.
- Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
- Ensure that the Safe Mode option is selected.
- Press Enter. The computer then begins to start in Safe mode.
- Login on your usual account.
Need to check to make sure this process is not running in safemode.
End malicious processes: (if they are present)
- Press the CTRL+ALT+DEL keys simultaneously to open Task Manager
- Click on the Processes tab to show running processes
- Find tmrsrv32.exe and click on it. (if present)
- Click End Process
- Close Task Manager
Use Explorer to navigate to and delete the following file (if it is present) just what is in red:
Files:
- C:\WINDOWS\system32\tmrsrv32.exe
- C:\WINDOWS\system32\msdn_lib.dll
Instuction on how to find files listed above:
- Click Start
- Click on MyComputer
- Double-Click C drive
- Now look for WINDOWS folder when found double click on it to open.
- Now look for system32 folder when found double click on it to open.
- Now look for tmrsrv32.exe file when you find this file right-click on it and choose delete.
- Look for msdn_lib.dll and delete ,too.
- done close all open windows.
——————————————————-
Now this is next:
Please do the following:
Here we are going to clean out cookies and temp files from your computer.
*NOTE* CCleaner deletes EVERYTHING out of temp/temporary folders. If you have anything in a temp folder, back it up or move it to a permanent folder prior to running CCleaner!
Download CCleaner from here It will start to download automatically. If ask if you want to download let it. Save to your Desktop.
Note: If you get and Error page from this link.
Try again you will see this message Your download of CCleaner will automatically start in 5 seconds. Click here if it does not do not wait go ahead and click on it.
- Double click on the file to start the installation of the program.
- Select your language and click OK, then next.
- Follow prompts to install finish to complete installation.
- Double click the CCleaner shortcut on the desktop to start the program.
- On the Windows tab, under Internet Explorer,
- All Boxes should have a check mark. (You will need to reenter your passwords at all sites where a cookie is used to recognize you when you visit).
- On the Windows tab, under Windows Explorer,
- All Boxes should have a check mark.
- On the Windows tab, under System,
- All Boxes should have a check mark.
- On the Windows tab, under Advanced,
- NO check marks
[*]Click on the "Options" icon at the left side of the window, then click on "Advanced."
deselect "Only delete files in Windows Temp folders older than 48 hours."
[*]Click on the "Cleaner" icon on the left side of the window, then click Run Cleaner to run the program.
[*]Caution: It is not recommended that you use the "Issues" feature unless you are very familiar with the registry as it has been known to find legitimate items.
[*]After CCleaner has completed its process, click Exit.
[*]You will need to reboot here if not ask to do so.
_______________________________
Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.
Here we are going to just make sure this tool is setup correctly Do not run scan yet.
Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
- Install AVG Anti-Spyware by double clicking the installer.
- Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
- On the main screen under Your Computer's security.
- Click on Change state next to Resident shield. It should now change to inactive.
- Click on Change state next to Automatic updates. It should now change to inactive.
- Next to the words Last Update, click on Update now. (You will need an active internet connection to perform this)
- Wait until you see the Update succesfull message.
- Click on Scanner on the toolbar at top of this screen.
- Click on the Settings tab.
- Under How to act?
- Click on Recommended Action and choose Quarantine from the popup menu.
- Under How to scan?
- All checkboxes should be ticked.
- Under Possibly unwanted software:
- All checkboxes should be ticked.
- Under Reports:
- Select Automatically generate report after every scan and uncheck Only if threats were found.
- Under What to scan?
- Select Scan every file.
- Close AVG Anti-Spyware without running yet.
- Right-click the AVG Anti-Spyware Tray Icon (Bottom right corner of computer screen near clock) and uncheck Start with Windows.
- Right-click the AVG Anti-Spyware Tray Icon again and select Exit. Confirm by clicking Yes.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.
______________________________
Reboot your computer in Safe Mode.
- If the computer is running, shut down Windows, and then turn off the power.
- Wait 30 seconds, and then turn the computer on.
- Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
- Ensure that the Safe Mode option is selected.
- Press Enter. The computer then begins to start in Safe mode.
- Login on your usual account.
Double-click on SmitfraudFix.exe
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.
The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.
A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.
The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
______________________________
Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
Note: If AVG Anti-Spyware screen does not fit your monitor screen Hold down the Alt button on keyboard then tap spacebar, menu should pop up then choose maximize. AVG Anti-Spyware screen should fix screen a little better.
- Click on the Scan tab.
- Click on Complete System Scan to start the scan process.
- Let the program scan the machine.
- When the scan has finished, follow the instructions below.
IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
- Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
- At the bottom of the window click on the Apply all Actions button.(3)
- When done, click the Save Scan Report button. (4)
- Click the Save Report as button.
- Save the report to your Desktop. I will need you to post this in your next reply.
- Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
______________________________
Please post:
- c:\rapport.txt
- AVG Anti-Spyware log
- A new HijackThis log