Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > General Computer Security
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


General Computer Security Get Help With System Security - This forum is not for malware removal assistance. For malware removal assistance, read the sticky topic at the top of the Virus/Trojan/Spyware Help forum, or the "First Steps" link at the top right of each page.

Reply
 
LinkBack Thread Tools
Old 07-28-2006, 11:06 PM   #1 (permalink)
Registered User
 
Join Date: Jul 2005
Posts: 2
OS: WinXP Pro


Adware.Virtumonde - Winfixer 2006 - jkkji.dll

This is not a request for help. Ive just removed Adware.Virtumonde / Winfixer 06 from my system. Ive been browsing through help forums for hours trying to get the right information. Since there are so many forms of this malware I thought I would post the steps I took to remove this infection.

***I am not part of the Tech Support Team *** All the steps listed here were only tried after lengthy investigation and checking *** Do the following at your own risk ***

1st of all I discovered the infection by using Ewido Antispyware. It found the infected file jkkji.dll, but could not remove it.

Using Ewido, Prevx1 and Windows Defender Beta 2, the weeded out most of the infection. However the jkkji.dll file proved hard to remove, because it was loaded very early in the boot process.

HijackThis did not display the jkkji.dll entries until it was RENAMED to something other than "hijackthis.exe". "Anaylse.exe" worked for me. It would only remove the entries but they were put back again on restart.

Finally I got KillBox onto the problem. I used it to delete the file, closing processes neccessary to do so. This in itself did not fix the problem - however when explorer.exe restarted (starting your start bar etc) it allowed Prevx1 to catch the dll as it was loading and stop it. One restart later and I *finally* have no infections.

I post this up in the hope that other frustrated users find some answers, lots of removal instructions for this were out of date. Hopefully this is of benefit to someone. Also I would recommend following all of the instructions in the thread "Before Posting you HijackThis Log". This fix may not work for ALL instances of this infection, especially if jkkji.dll is not the ONLY problem file. In my case I was able to stop it from downloading other trojan antispy programs.

-Smoky
Smoky_McPot is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 07-29-2006, 12:14 AM   #2 (permalink)
Analyst, Security Team
 
dorts's Avatar
 
Join Date: Mar 2006
Location: Singapore
Posts: 1,599
OS: Windows XP SP2

My System

Hi,

Great work removing them. Actually, there is an tutorial on it here.
__________________




If you think TSF have helped you, please kindly donate to TSF and help keep this site free to all.
dorts is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 07-29-2006, 03:00 AM   #3 (permalink)
Registered User
 
Join Date: Jul 2005
Posts: 2
OS: WinXP Pro


I did see that one, before i had renamed the HijackThis exe file. I was not sure about using the Vundo fix just because I had seen many older links to it. Im just glad its gone LOL. I am glad I found KillBox tho, It is going to stay in the software toolbox for a long time I imagine.
Smoky_McPot is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 02:58 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85