Jump to content


Honorary Members
  • Posts

  • Joined

  • Last visited

Posts posted by JeanInMontana

  1. If I knew where it was or how it was hiding, we would not be here. Sorry, but it's a new variant, and we are doing the best we can to get it into the MBAM definitions so it can remove it. The people behind it are brilliant and it's a shame they can't put that to good rather than evil.

    O2 - BHO: (no name) - {3787B284-825E-486C-900D-D57056AED3E5} - c:\windows\system32\uyxgnon.dll <==== I need a sample of the highlighted portion of that entry please. Zipped and attached here. Then delete it. I thought I had asked for it but I don't see it. Now run HJT in scan only put a check next to these files and click fix.

    O2 - BHO: (no name) - {3787B284-825E-486C-900D-D57056AED3E5} - c:\windows\system32\uyxgnon.dll

    O4 - HKLM\..\Run: [cw9k9s4nfpzv] C:\WINDOWS\system32\cw9k9s4nfpzv.exe

    And then use File Assassin in MBAM to delete that file C:\WINDOWS\system32\cw9k9s4nfpzv.exe You will find it under the Tools tab. Reboot.

    Update MBAM again it's at 962 now, might have the stuff we need. Run another scan and post that log and a new HJT log.

  2. I would reinstall the program, it has to be damaged in some way for it to show a file missing. It could be malware related with the boot hang, your log is looking good.

    You are running an outdated and unsafe version of Java. You need to uninstall it via Add/Remove programs and delete the program file also. Then go here http://java.sun.com/javase/downloads/index.jsp and install the correct version for your system. Choose the offline installation.

    Your running an outdated and unsafe version of Adobe latest version. Or get the alternative faster lighter on resources Foxit PDF Reader and Editor Look at the Downloads tab here or if you don't want to see the features etc.

    Keep other software known for vulnerabilities updated also. Use the Secunia Inspector free scan to identify risks in outdated versions.

    Your also behind on Windows updates, before you install SP3 I recommend you do a Disk check for errors and defrag. Go to My Computer, right click on Local Disk C and choose properties. Then the tools tab, put a check in both boxes for the error check option and say yes to reschedule the check on the next boot, then reboot. After the error check, do the defrag.

    Are you seeing any symptoms?

  3. Pretty bold statement to make there Jean. I wish I was making some money doing this...... there is such a thing as being a friend and I happen to be the goto friend. If you don't like to help then don't. I am not going to take money from a friend when they are in need. I told you that I fixed it myself so that is less you have to do ..... isn't that the point?

    Yes bold and backed with fact!! http://www.malwarebytes.org/forums/index.p...post&p=8736

    Yeh I would be.. I run a small computer service shop on the side and alot of my issues are spyware and virus problems. This would cut down my time involved to fix this. Hard to bill @ $50/hr and spend 5 hours and charge $250! May as well wipe it clean and start over for $100 to be fair to the customer.

    thanks, Rip_Chain

    Your done making money from our help.

  4. Since this topic has had no reply for over 5 days it will be closed to prevent other from posting into it. Should you decide to resume with your assistance PM any staff member and we will be happy to reopen the topic.

    Note: the fixes in this topic are for this system only. Applying them to your system can cause severe damage and result in utter system failure. If you need help start your own topic and someone will be happy to assist you.

  5. Since this topic has had no reply for over 5 days it will be closed to prevent other from posting into it. Should you decide to resume with your assistance PM any staff member and we will be happy to reopen the topic.

    Note: the fixes in this topic are for this system only. Applying them to your system can cause severe damage and result in utter system failure. If you need help start your own topic and someone will be happy to assist you.

  6. McAfee identified MBAM as Vundo. Not the best detection. :)

    File: C:\WINDOWS\system32\bcchxego.dll

    Process: C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe

    Process description: Malwarebytes' Anti-Malware

    I saw that MBAM had updated since your scan is why I asked for a new one. Your not having any symptoms? One more HJT log please.

  7. The Soundman showing in your log is not legit, and the Radmin entry had a missing file, so it was just clean up. The program isn't there or not functioning.

    OK delete this file C:\WINDOWS\system32\vtfahv.dll sorry I should have said that yesterday. I'm on day 3 of a headache and not really thinking well. Now run HJT again in scan only put a check next to the lines below and click fix.

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

    O2 - BHO: {92cc7d5f-5d50-4d6b-a654-c94cf3e1bd54} - {45db1e3f-c49c-456a-b6d4-05d5f5d7cc29} - C:\WINDOWS\system32\vtfahv.dll

    O23 - Service: Radmin Server V3 (RServer3) - Unknown owner - C:\WINDOWS\system32\rserver30\RServer3.exe (file missing)

    Update MBAM run a quick scan post the log, you might use the File Assassin feature in it to delete this C:\WINDOWS\system32\vtfahv.dll. Post that log and a new HJT.

  8. Hi there Rob91, and welcome to Malwarebytes.

    Make sure your running as an adminstrator on the machine. Allow email from Malwarebytes.org and set your preferences in the User Control Panel to email notifications for replies to your topics. This ensures you make prompt replies back and we get you cleaned in the fastest way possible.

    Please set your system to show

    all files; Click Start.

    Open My Computer.

    Select the Tools menu and click Folder Options.

    Select the View Tab.

    Under the Hidden files and folders heading select Show hidden files and folders.

    Uncheck the Hide protected operating system files (recommended) option.

    Click Yes to confirm.

    Click OK.

    If you haven't already, please get these programs, update and run a complete scan removing all items found.

    Spybot Search & Destroy Be sure to use the immunize feature. But do not enable TeaTimer at this time.

    Open SB S&D

    Make sure you are in Advanced Mode. Click on the Mode link at the top of the program and then Advanced Mode.

    Click on the Tools section and then Resident.

    You will see two items.

    1. Resident "SD helper" (Internet Explorer bad download blocker.) active

    2. Resident "Tea Timer" (Protection of over-all system settings.) active.

    Uncheck number 2..

    Leave number 1 checked always.

    You can enable Tea Timer again if you wish once all special fixes have been done.

    Please run a quick scan of your main drive, usually C with MBAM making sure you check all items found for removal. Please post that log in your next reply.

    Then go here and run a scan PandaActive Scan There is a full tutorial on how to to this at the top of this forum.

    Post the logs from the Panda and MBAM scans please, along with a log from this program HiJack This!

    You will post three logs. 1. MBAM scan. 2. Panda Active Scan. 3. HiJack This scan. Please run and post the scans in this order. You will finish the MBAM first so go ahead and post that log, then move on to Panda and so forth.

    I will analyze the logs and give you further instructions. Be sure to set your email to allow mail from Malwarebytes.org and your personal settings to send an email on reply to your topic. This will let you know when there has been an update to your topic and you can come and see what has been said.

    Be patient and persistent. These things can take time and many procedures.

  9. This new version of Vundo is extra nasty, we are struggling to get all of it into MBAM. It hides very well. Posslibly why you couldn't find it is McAfee took it before you looked? Are you able to access the quarantine files for McAfee and upload them? If you save the logs I would like to see the portion showing what was found, not the whole log just a copy paste of that part please.

    You don't have the latest definition version for MBAM, you have to update it every time you scan, often it updates 4 or more times a day. Let's get a new scan with it. Your log is looking good how are symptoms?

  10. Hi Ulysses and welcome to Malwarebytes. You have been stricken with the newest version of Vundo. I need you to please find these files C:\WINDOWS\system32\oanpfg.dll and C:\WINDOWS\system32\hssjyayr.dll

    put it in a zip file and attach here with your next post. Then delete them.

    Run HJT again in scan only with all programs closed. Put a check next to the items below and click fix when your done.

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html

    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com

    O2 - BHO: {8f5ea10d-17d1-a4cb-6544-b2e64f617690} - {096716f4-6e2b-4456-bc4a-1d71d01ae5f8} - C:\WINDOWS\system32\oanpfg.dll

    You are running an outdated and unsafe version of Java. You need to uninstall it via Add/Remove programs and delete the program file also. Then go here http://java.sun.com/javase/downloads/index.jsp and install the correct version for your system. Choose the offline installation.

    Your running an outdated and unsafe version of Adobe latest version. Or get the alternative faster lighter on resources Foxit PDF Reader and Editor Look at the Downloads tab here or if you don't want to see the features etc.

    Use the Secunia Inspector free scan to identify risks in outdated versions of all your other softwares ie QuickTime, RealPlayer and others.

    Update MBAM run a quick scan and post a new log from it and from HJT.

  11. I thought of putting it here instead of making another thread. But I think maybe you should include a dialog box that will pop-up when users do not select anything to remove saying something like 'You have selected nothing. Are you sure you wish to proceed?'. This suggestion came to mind as I noticed several users, when instructed to use your tool by HJT analysts, do the scan but do not remove the malware.

    I second the motion!! Over and over I see it, they just don't get they have to take action. This would really cut time in the HJT forum.

  12. Since this issue is resolved I will close the thread to prevent others from posting into it. If you need assistance please start your own topic and someone will be happy to assist you.

    The fixes and advice in this thread are for this machine only. Do not apply to your machine. Please start a thread of your own and someone will be happy to help you.

  13. Hi Angela and welcome to Malwarebytes. When you say "user" what do you mean? The user should join this forum and we can help them one on one to see if they are free of malware. Once they join they should follow the directions here http://www.malwarebytes.org/forums/index.php?showtopic=2936. It's impossible to give any sort of intelligent answer with just one line describing malware from who knows were.

Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.