Name: Mike06j770 Date: March 25, 2008 at 18:48:58 Pacific Subject: Trojan Viruses & "bad image&qu OS: Windows XP CPU/Ram: Pentium 4 Model/Manufacturer: HP m380n
Comment:
I keep on getting bad image messages such as c:\windows\system32\jkkjh.dll & c:\windows\system32\eebqbvln.dll among many others. Also, I just tried to do system recovery and a blue screen popped up saying Session3_initialzation_failed and will not let me do recovery. Also, I ran spyware doctor and viruses are still showing up. I'm not sure how to go about this but any help would be greatly appreciated.
1. Save " HJTInstall.exe" to your desktop. 2. Double click on HJTInstall.exe to run the program. 3. By default it will install to C:\Program Files\Trend Micro\HijackThis. 4. Accept the license agreement by clicking the "I Accept" button. 5.Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log. 6. Click "Save log" to save the log file and then the log will open in Notepad. 7. Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log. 8. Paste the log in your next reply. 9. Do NOT have HijackThis fix anything yet! Most of what it finds will be harmless or even required.
Thanks for the quick response. I have the following viruses: Adware.Vundo, Trojan-Downloader.Agent.BL , Trojan-PWS.OnlineGames.ES, GEN, TEA, QPA; Trojan.Vaklik.ot, Trojan-Spy.Pophot.Wx, Trojan.Virtumode, Trojan.Agent!sd5 and Virus.Win32.Trats.
Here is my scan:
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 6:43:34 PM, on 3/28/2003 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Boot mode: Normal
Note It is important that it is saved directly to your desktop
Close any open browsers.
Double click on combofix.exe and follow the prompts. When it's finished it will produce a log. Post the entire contents of C:\ComboFix.txt into your next reply.
Note Do not mouseclick combofix's window while it's running. That may cause the program to freeze/hang. Note In case your Antivirus or any other realtime scanner is displaying an alert after you downloaded Combofix or while you use Combofix,please disable your scanner and redownload Combofix again. Some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them.
Open Task Manager and End these processes: (End process tree)
smss.exe 1a .exe sslxpes071126.exe
Now open MSConfig by typing it in Run box.
From Startup tab "Disable All" process from startup and restart your computer.
Delete combofix from your desktop, download and try again.
If same problem then do followings:
you need to change the name of Combofix. This cannot be done with the existing version, but needs to be done at the point of saving the download, see below: Please delete your existing version from the Desktop.
During the download, rename Combofix to Combo-Fix. It is important you rename Combofix during the download, but not after. Please do not rename Combofix to other names, but only to the one indicated. Close any open browsers. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
-
Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results". Click on this link (http://www.bleepingcomputer.com/forums/topic114351.html) to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it.
You need to change the name of Combofix. This cannot be done with the existing version, but needs to be done at the point of saving the download, see below: Please delete your existing version from the Desktop.
During the download, rename Combofix to Combo-Fix. It is important you rename Combofix during the download, but not after. Please do not rename Combofix to other names, but only to the one indicated. Close any open browsers. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
-
Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results". Click on this link (http://www.bleepingcomputer.com/forums/topic114351.html) to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it.
The information on Computing.Net is the opinions of its users. Such
opinions may not be accurate and they are to be used at your own risk.
Computing.Net cannot verify the validity of the statements made on this site. Computing.Net and Computing.Net, LLC hereby disclaim all responsibility and liability for the content of Computing.Net and its accuracy.
PLEASE READ THE FULL DISCLAIMER AND LEGAL TERMS BY CLICKING HERE