View Single Post
Old 08-12-2007, 11:06 PM   #4 (permalink)
Pancake
Security Team (ret.)
 
Pancake's Avatar
 
Join Date: Nov 2003
Location: Victoria.Australia
Posts: 7,404
OS: XP Pro SP3


Re: Still needing help with pop ups

Ok....few more things to clean out.


Have "Hijack This" fix all the following items in the list below by placing a check in the appropriate boxes.Confirm that you have only the listed ones checked, then press <Fix checked> and Close HJT.

O2 - BHO: 0 - {316C3DC2-0EE5-4712-A690-BA0BE6D69BE4} - C:\Program Files\Common Files\zyliv.dll
O2 - BHO: (no name) - {CF46BFB3-2ACC-441b-B82B-36B9562C7FF1} - C:\WINDOWS\system32\wxvhaeif.dll
O2 - BHO: (no name) - {E959E770-16F3-4212-B0A9-328F636E93C3} - C:\WINDOWS\system32\pmkhg.dll
O2 - BHO: (no name) - {E9BD0828-1FD9-410C-A50F-43EBE65D310F} - C:\WINDOWS\system32\hgghhef.dll
O4 - HKLM\..\Run: [vihorug] C:\Program Files\ComPlus Applications\vihorug22011.exe
O4 - HKCU\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\bluovwxw.dll",forkonce
O20 - Winlogon Notify: hgghhef - C:\WINDOWS\system32\hgghhef.dll
O20 - Winlogon Notify: pmkhg - C:\WINDOWS\system32\pmkhg.dll

Reboot...............
==============================

Please copy this page to *Notepad* and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.

It's IMPORTANT to carry out the instructions in the sequence listed below.


1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.


Open *notepad* and copy/paste the text in the quotebox below into it:


Quote:
File::
C:\Program Files\Common Files\zyliv944
C:\Program Files\Common Files\zyliv944.dll
C:\WINDOWS\ukqw
C:\WINDOWS\system32\tsuninst.exe
C:\Program Files\Common Files\ukqw
C:\Program Files\Common Files\zyliv782.dll
C:\Program Files\Common Files\zyliv173.dll
C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\Program Files\Common Files\W?nSxSC:\WINDOWS\system32\f10WtR
C:\WINDOWS\retadpu77.exe
C:\Program Files\svhost
C:\WINDOWS\svhost.exe
C:\Program Files\Common Files\zyliv496.dll
C:\Program Files\Common Files\zyliv.dll
C:\WINDOWS\tk58.exe
C:\Program Files\Common Files\zyliv874
C:\WINDOWS\system32\cojydbmm.dll
C:\WINDOWS\system32\xtkfqqqe.exe
C:\WINDOWS\system32\ljdsrngr.exe
C:\WINDOWS\rassb0578.exe
C:\WINDOWS\vjcwogxA.exe
C:\WINDOWS\vjcwogx.exe
C:\WINDOWS\system32\mwinkmdt.exe
C:\WINDOWS\system32\dwdsrngt.exe
C:\WINDOWS\system32\f02WtR
C:\WINDOWS\b138.exe
C:\WINDOWS\b103.exe
Folder::
C:\VundoFix Backups
Save this as *CFScript.txt*, in the same location as ComboFix.exe


Image: http://img.photobucket.com/albums/v6...s/CFScript.gif

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at *C:\ComboFix.txt*

*Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall*


===================================================
Please post back ...

C:\ComboFix.txt and a New HijackThis log
__________________
Eddy
Pancake is offline