also @ TechSpot: A List of PC Game Classics Available Free of Charge
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > Tech Support > Virus and Malware Removal

Viruses/Spyware/Malware, preliminary removal instructions

Closed Thread
Page 2 of 3 1 2 3
Bookmark Thread Tools
  #21  
Old 04-01-2008
Newcomer, in training
 
Member since: Mar 2008, 43 posts
Will do. Thanks.
  #22  
Old 04-02-2008
Newcomer, in training
 
Member since: Mar 2008, 43 posts
Help

Hi Ran Hijackthis, deleted both files after scan only.

Re started windows - Avast on-access protection won't run and internet connection won't work either. Message error 711 The remote access service manager could not start. Further detail - check plug and play or remote access connection manager. On checking plug and play was running but remote access wasn't. Tried to start but further error 1084 - "This service cannot be started in Safe Mode"

Hence not downloaded Vundofix.
To remove this ad, sign in. To register for a new account, click here.
  #23  
Old 04-02-2008
Newcomer, in training
 
Member since: Mar 2008, 43 posts
Sorry note computer wasn't and isn't in safe mode.
  #24  
Old 04-02-2008
TimeParadoX's Avatar
TechSpot Guru
 
Location: DE_Dust 2
Member since: Aug 2006, 2,488 posts
System specs
Quote:
Originally Posted by shiva64
Hi Ran Hijackthis, deleted both files after scan only.

Re started windows - Avast on-access protection won't run and internet connection won't work either. Message error 711 The remote access service manager could not start. Further detail - check plug and play or remote access connection manager. On checking plug and play was running but remote access wasn't. Tried to start but further error 1084 - "This service cannot be started in Safe Mode"

Hence not downloaded Vundofix.
Download the programs he requested while still online, Once you boot into safemode you will not have Internet connection or your anti-virus protection programs running. Don't worry though, in safemode many services do not run except the ones made by Microsoft to keep your computer stable.
  #25  
Old 04-02-2008
Newcomer, in training
 
Member since: Mar 2008, 43 posts
Hi i'm only on-line on my laptop not on main computer. Also i wasn't in safe mode.
  #26  
Old 04-02-2008
Newcomer, in training
 
Member since: Mar 2008, 43 posts
Also windows media won't play any music and some games (e.g. fifa08) won't load.
To remove this ad, sign in. To register for a new account, click here.
  #27  
Old 04-02-2008
kritius's Avatar
TechSpot Guru
 
Member since: Feb 2008, 2,088 posts
System specs
I cant say anything till I see the logs for those programs
  #28  
Old 04-03-2008
Newcomer, in training
 
Member since: Mar 2008, 43 posts
Programs?

Which programs? If your talkin abaout Vundofix, i can't download directly as i can't get on internet on main pc.
  #29  
Old 04-03-2008
kritius's Avatar
TechSpot Guru
 
Member since: Feb 2008, 2,088 posts
System specs
Can you download them on the laptop and then transfer them to the main pc? Also post a fresh HJT log.
  #30  
Old 04-03-2008
Newcomer, in training
 
Member since: Mar 2008, 43 posts
Will try. Get back to you soon.
  #31  
Old 04-03-2008
Newcomer, in training
 
Member since: Mar 2008, 43 posts
Help

Tried to run Vundofix from cd, received message- runtime error 339, component "comdlg.32.ocx" or one of it's dependencies not correctly registered; a file is missing or invalid.
  #32  
Old 04-03-2008
Newcomer, in training
 
Member since: Mar 2008, 43 posts
logs

Please find logs of Virtumondo and HJT. Vundofix didn't find any errors. Therefore not tried going on internet or running any problem programs yet.
  #33  
Old 04-03-2008
Newcomer, in training
 
Member since: Mar 2008, 43 posts
Sorry, here's the logs attached.
Attached Files
File Type: txt VBG.TXT (5.5 KB, 1 views)
File Type: log hijackthis.log (9.1 KB, 2 views)
  #34  
Old 04-03-2008
kritius's Avatar
TechSpot Guru
 
Member since: Feb 2008, 2,088 posts
System specs
Ill look over your log now and get back to you.
  #35  
Old 04-04-2008
Newcomer, in training
 
Member since: Mar 2008, 43 posts
Hi, did you find anything?
  #36  
Old 04-04-2008
kritius's Avatar
TechSpot Guru
 
Member since: Feb 2008, 2,088 posts
System specs
Go to start>run and type combofix /u

reboot if required

Fix entries using HiJackThis
  • Launch HiJackThis
  • Click the Do a system scan only button
  • Put a check next to the entries listed below
O2 - BHO: (no name) - {C5AF49A2-94F3-42BD-F434-2604812C897D} - (no file)
O4 - HKLM\..\Run: [BM37097977] Rundll32.exe "C:\WINDOWS\system32\oidlmehb.dll",s
O16 - DPF: {395E58B9-090C-461A-8F27-087D1C727945} (Web Conferencing) - http://metastock.epopcentral.com/joinie.cab
O16 - DPF: {6697AFA6-1CD3-462E-AC0A-363EF8BCD102} (SyScan2 Control) - http://www.evga.com/Support/SyScan/SyScan.cab
  • IMPORTANT: Do NOT click fix until you exit all browser sessions including the one you are reading in right now
  • Click the Fix checked button and close HiJackThis
  • Reboot HijackThis if necessary

Delete Files and Folders
  • Right Click on the start button and chose explore
  • Show all hidden files and folders, see how HERE
  • Navigate to the following files and folders and delete them(if still present)
C:\WINDOWS\system32\oidlmehb.dll<---------This File
[/color]
  • Empty the recycle bin.
If that does not work then repeat the process in safe mode. See how to boot into Safe mode HERE.
***DO NOT USE MSCONFIG TO BOOT INTO SAFE MODE***


Download and Run ComboFix
  • Download this file from either of the two below listed places :

    HERE or HERE
  • Then double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Attach that log in your next reply
WARNING: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
To remove this ad, sign in. To register for a new account, click here.
  
  #37  
Old 04-04-2008
Newcomer, in training
 
Member since: Mar 2008, 43 posts
Done HJK, couldn't find oidlehb file in normal mode. Will try in safe mode and then i'll download/run combofix.
  #38  
Old 04-04-2008
kritius's Avatar
TechSpot Guru
 
Member since: Feb 2008, 2,088 posts
System specs
if you cant find it in safe mode we'll get it with combo.
  #39  
Old 04-04-2008
Newcomer, in training
 
Member since: Mar 2008, 43 posts
combofix

Hi, please find combofix log attached. Had to download using laptop as computer main computer still as before. Please note mentioned earlier that the oidlmehb.dll file error message was coming up on startup "error loading, module not found".
Attached Files
File Type: txt combofix1.txt (12.2 KB, 1 views)
  #40  
Old 04-04-2008
kritius's Avatar
TechSpot Guru
 
Member since: Feb 2008, 2,088 posts
System specs
Is combofix installed on the desktop? It needs to be there.
Closed Thread
Page 2 of 3 1 2 3

Thread Tools


Similar Topics
Topic Category Replies Last Post
UPDATED 8-step Viruses/Spyware/Malware Preliminary Removal Instructions Virus and Malware Removal 2 09-11-2008 02:21 PM
Viruses/Spyware/Malware, preliminary removal instructions by howard_hopkinso Virus and Malware Removal 9 01-26-2008 09:17 AM
Viruses/Spyware/Malware, preliminary removal Virus and Malware Removal 1 01-22-2008 07:45 AM
Viruses/Spyware/Malware, preliminary removal Virus and Malware Removal 0 01-12-2008 04:25 AM


All times are GMT -4. The time now is 04:33 AM.