Go Back   Computer Juice > Computer Software > Virus, Spyware & Security
Register Points Site Spy New Posts Donate Unanswered Posts Search Forum Rules


Reply
 
LinkBack Thread Tools
  #16  
Old 31st Jul 2007, 02:11 AM
No Avatar
Member Group
 
virusinfected is offline
 
Join Date: 30th Jul 2007
Last Online: 31st Jul 2007 11:49 PM
Posts: 24
iTrader: (0)
virusinfected is on a distinguished road
Default viruses???

its a specific file called... C:\WINDOWS\system32\gebyxyv.dll
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #17  
Old 31st Jul 2007, 02:16 AM
evilfantasy's Avatar
Moderator Group
Intel ATi
evilfantasy is online now
Send a message via Yahoo to evilfantasy
 
Join Date: 15th Jul 2007
Last Online: Today 06:46 PM
Posts: 5,338
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default viruses???

OK, if you haven't noticed this thread has been moved to the Anti-Virus and Spyware forum.
Thanks Dave :)

That is what I meant by some require special removal. Virtumonde is one of them.

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the
Scan for Vundo button." when VundoFix appears at reboot.
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #18  
Old 31st Jul 2007, 02:16 AM
Dave Hybrid's Avatar
Administrator Group
Intel ATi
Dave Hybrid is offline
 
Join Date: 17th Apr 2006
Last Online: Today 04:22 PM
Age: 26
Posts: 8,105
iTrader: (0)
Dave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond repute
Default viruses???

Download and run this:

http://www.atribune.org/content/view/24/2/

Post a Hijack this log after running that and doing a reboot.
__________________

Computer Juice raffle
- Win PC hardware of your choice worth £500 / €680 / $1000 - Enter HERE!
__________________

My System: The Hybrid Lappy

CPU(s):
AMD Turion 64 x2 TL-64 2.2GHz
Motherboard:
HP nForce 560
RAM:
2GB DDR2 PC2-5300
Graphics Card(s):
Nvidia 7150M Onboard Integrated
Sound Card:
5.1 Onboard Integrated
Hard Drive(s):
250GB 5400RPM SATA300
Optical Drive(s):
18x CD/DVDRW-DL ATA
Case / PSU:
Stock HP
Cooling:
Stock HP
Network / Internet:
10/100 Nic / 10MB Virgin Cable
Monitor(s):
17" WXGA+ HD BrightView Widescreen
Operating System(s):
Windows Vista Home Premium 32 SP1

Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #19  
Old 31st Jul 2007, 02:48 AM
No Avatar
Member Group
 
virusinfected is offline
 
Join Date: 30th Jul 2007
Last Online: 31st Jul 2007 11:49 PM
Posts: 24
iTrader: (0)
virusinfected is on a distinguished road
Default viruses???

that it
Attached Files
File Type: txt hijackthis2.txt (4.8 KB, 12 views)
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #20  
Old 31st Jul 2007, 02:59 AM
Dave Hybrid's Avatar
Administrator Group
Intel ATi
Dave Hybrid is offline
 
Join Date: 17th Apr 2006
Last Online: Today 04:22 PM
Age: 26
Posts: 8,105
iTrader: (0)
Dave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond repute
Default viruses???

Tick the boxes next to these entrees and remove them.

O2 - BHO: (no name) - {004D3F2F-3B16-44BE-9BC5-52E856D7D50B} - C:\WINDOWS\System32\ddccd.dll (file missing)
O2 - BHO: (no name) - {07571FF3-F676-4DC9-8262-D26FB7FEFEE4} - C:\WINDOWS\System32\jkkjk.dll (file missing)
O2 - BHO: (no name) - {1CA0EC94-43C5-4FA0-9D1D-2B0836E9DD42} - C:\WINDOWS\System32\pmkhg.dll (file missing)
O2 - BHO: (no name) - {C6039E6C-BDE9-4de5-BB40-768CAA584FDC} - C:\WINDOWS\System32\gnjiigtu.dll
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\System32\ccciotrh.dll",forkonce
O4 - HKCU\..\Run: [Spyware Cleaner] "C:\Program Files\Spyware Cleaner\SpywareCleaner.Exe" /boot
O20 - Winlogon Notify: ddccd - C:\WINDOWS\System32\ddccd.dll (file missing)
O20 - Winlogon Notify: jkkjk - C:\WINDOWS\System32\jkkjk.dll (file missing)

Do another spybot scan and post the log.
__________________

Computer Juice raffle
- Win PC hardware of your choice worth £500 / €680 / $1000 - Enter HERE!
__________________

My System: The Hybrid Lappy

CPU(s):
AMD Turion 64 x2 TL-64 2.2GHz
Motherboard:
HP nForce 560
RAM:
2GB DDR2 PC2-5300
Graphics Card(s):
Nvidia 7150M Onboard Integrated
Sound Card:
5.1 Onboard Integrated
Hard Drive(s):
250GB 5400RPM SATA300
Optical Drive(s):
18x CD/DVDRW-DL ATA
Case / PSU:
Stock HP
Cooling:
Stock HP
Network / Internet:
10/100 Nic / 10MB Virgin Cable
Monitor(s):
17" WXGA+ HD BrightView Widescreen
Operating System(s):
Windows Vista Home Premium 32 SP1

Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #21  
Old 31st Jul 2007, 02:59 AM
evilfantasy's Avatar
Moderator Group
Intel ATi
evilfantasy is online now
Send a message via Yahoo to evilfantasy
 
Join Date: 15th Jul 2007
Last Online: Today 06:46 PM
Posts: 5,338
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default viruses???

Open HijackThis and choose Do a system scan only.

Check these boxes
O2 - BHO: (no name) - {004D3F2F-3B16-44BE-9BC5-52E856D7D50B} - C:\WINDOWS\System32\ddccd.dll (file missing)

O2 - BHO: (no name) - {07571FF3-F676-4DC9-8262-D26FB7FEFEE4} - C:\WINDOWS\System32\jkkjk.dll (file missing)

O2 - BHO: (no name) - {1CA0EC94-43C5-4FA0-9D1D-2B0836E9DD42} - C:\WINDOWS\System32\pmkhg.dll (file missing)

O2 - BHO: (no name) - {C6039E6C-BDE9-4de5-BB40-768CAA584FDC} - C:\WINDOWS\System32\gnjiigtu.dll

O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\System32\ccciotrh.dll",forkonce

O4 - HKCU\..\Run: [Spyware Cleaner] "C:\Program Files\Spyware Cleaner\SpywareCleaner.Exe" /boot

O20 - Winlogon Notify: ddccd - C:\WINDOWS\System32\ddccd.dll (file missing)

O20 - Winlogon Notify: jkkjk - C:\WINDOWS\System32\jkkjk.dll (file missing)

**IMPORTANT close all browser windows including this one.
Then click Fix Checked
Then run CCleaner
Post a new HijackThis log when done.

Last edited by evilfantasy : 31st Jul 2007 at 03:00 AM.
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #22  
Old 31st Jul 2007, 03:04 AM
evilfantasy's Avatar
Moderator Group
Intel ATi
evilfantasy is online now
Send a message via Yahoo to evilfantasy
 
Join Date: 15th Jul 2007
Last Online: Today 06:46 PM
Posts: 5,338
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default viruses???

You still need to go to windows update and get SP2 and any other critical updates. You may have to check twice. There will be more updates for SP2.
http://v4.windowsupdate.microsoft.com/en/default.asp

Last edited by evilfantasy : 31st Jul 2007 at 03:05 AM.
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #23  
Old 31st Jul 2007, 03:06 AM
Dave Hybrid's Avatar
Administrator Group
Intel ATi
Dave Hybrid is offline
 
Join Date: 17th Apr 2006
Last Online: Today 04:22 PM
Age: 26
Posts: 8,105
iTrader: (0)
Dave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond repute
Default viruses???

I'll step aside mate, looks like I'm getting in the way here... :D
__________________

Computer Juice raffle
- Win PC hardware of your choice worth £500 / €680 / $1000 - Enter HERE!
__________________

My System: The Hybrid Lappy

CPU(s):
AMD Turion 64 x2 TL-64 2.2GHz
Motherboard:
HP nForce 560
RAM:
2GB DDR2 PC2-5300
Graphics Card(s):
Nvidia 7150M Onboard Integrated
Sound Card:
5.1 Onboard Integrated
Hard Drive(s):
250GB 5400RPM SATA300
Optical Drive(s):
18x CD/DVDRW-DL ATA
Case / PSU:
Stock HP
Cooling:
Stock HP
Network / Internet:
10/100 Nic / 10MB Virgin Cable
Monitor(s):
17" WXGA+ HD BrightView Widescreen
Operating System(s):
Windows Vista Home Premium 32 SP1

Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #24  
Old 31st Jul 2007, 03:10 AM
evilfantasy's Avatar
Moderator Group
Intel ATi
evilfantasy is online now
Send a message via Yahoo to evilfantasy
 
Join Date: 15th Jul 2007
Last Online: Today 06:46 PM
Posts: 5,338
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default viruses???

No problem, you never know when I may need back up!
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #25  
Old 31st Jul 2007, 03:15 AM
No Avatar
Member Group
 
virusinfected is offline
 
Join Date: 30th Jul 2007
Last Online: 31st Jul 2007 11:49 PM
Posts: 24
iTrader: (0)
virusinfected is on a distinguished road
Default viruses???

yea....on that note i would need to check legality of my xp version. i have no idea.i just bought the pc and it was on here.

thats the new search i think
Attached Files
File Type: txt hijackthis.txt (4.9 KB, 10 views)
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #26  
Old 31st Jul 2007, 03:21 AM
evilfantasy's Avatar
Moderator Group
Intel ATi
evilfantasy is online now
Send a message via Yahoo to evilfantasy
 
Join Date: 15th Jul 2007
Last Online: Today 06:46 PM
Posts: 5,338
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default viruses???

Everything is still there. Did you close all windows before hitting fix checked?
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #27  
Old 31st Jul 2007, 03:27 AM
No Avatar
Member Group
 
virusinfected is offline
 
Join Date: 30th Jul 2007
Last Online: 31st Jul 2007 11:49 PM
Posts: 24
iTrader: (0)
virusinfected is on a distinguished road
Default viruses???

sure did
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #28  
Old 31st Jul 2007, 03:35 AM
No Avatar
Member Group
 
virusinfected is offline
 
Join Date: 30th Jul 2007
Last Online: 31st Jul 2007 11:49 PM
Posts: 24
iTrader: (0)
virusinfected is on a distinguished road
Default viruses???

gimme 5 mins and ill put up another log
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #29  
Old 31st Jul 2007, 03:36 AM
No Avatar
Member Group
 
virusinfected is offline
 
Join Date: 30th Jul 2007
Last Online: 31st Jul 2007 11:49 PM
Posts: 24
iTrader: (0)
virusinfected is on a distinguished road
Default viruses???

Originally Posted by evilfantasy View Post
Open HijackThis and choose Do a system scan only.

Check these boxes
O2 - BHO: (no name) - {004D3F2F-3B16-44BE-9BC5-52E856D7D50B} - C:\WINDOWS\System32\ddccd.dll (file missing)

O2 - BHO: (no name) - {07571FF3-F676-4DC9-8262-D26FB7FEFEE4} - C:\WINDOWS\System32\jkkjk.dll (file missing)

O2 - BHO: (no name) - {1CA0EC94-43C5-4FA0-9D1D-2B0836E9DD42} - C:\WINDOWS\System32\pmkhg.dll (file missing)

O2 - BHO: (no name) - {C6039E6C-BDE9-4de5-BB40-768CAA584FDC} - C:\WINDOWS\System32\gnjiigtu.dll

O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\System32\ccciotrh.dll",forkonce

O4 - HKCU\..\Run: [Spyware Cleaner] "C:\Program Files\Spyware Cleaner\SpywareCleaner.Exe" /boot

O20 - Winlogon Notify: ddccd - C:\WINDOWS\System32\ddccd.dll (file missing)

O20 - Winlogon Notify: jkkjk - C:\WINDOWS\System32\jkkjk.dll (file missing)

**IMPORTANT close all browser windows including this one.
Then click Fix Checked
Then run CCleaner
Post a new HijackThis log when done.
and after ive cheked these wat do i do
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #30  
Old 31st Jul 2007, 03:39 AM
evilfantasy's Avatar
Moderator Group
Intel ATi
evilfantasy is online now
Send a message via Yahoo to evilfantasy
 
Join Date: 15th Jul 2007
Last Online: Today 06:46 PM
Posts: 5,338
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default viruses???

Originally Posted by virusinfected View Post
and after ive cheked these wat do i do
Click Fix Checked towards the bottom left of HijackThis.
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote

Please support this forum, donate towards our running costs.
Reply

Thread Tools
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Tonnes of viruses, i think!! concept Virus, Spyware & Security 6 15th May 2008 12:12 PM
Viruses rsteenoven Virus, Spyware & Security 23 22nd Mar 2008 07:05 PM
How do i get rid of any viruses & spyware? Ian M Virus, Spyware & Security 16 31st Jul 2007 03:23 PM
How do i remove viruses from my computer? dastine_marie Virus, Spyware & Security 4 1st Apr 2007 08:21 AM
How do I take spyware or viruses off of a... freakofnature General Software Chat 3 17th Mar 2007 07:35 PM


Copyright ©2006 - 2008 Computer Juice.

Powered by vBulletin® Copyright ©2000 - 2008 Jelsoft Enterprises Ltd. SEO by vBSEO ©2008, Crawlability, Inc.