Announcement

Collapse
No announcement yet.

How do u get rid of malware

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • #46
    no to norton macfee yes and avg only when i select to
    When you find yourself arguing with an idiot, you might want to rethink who the idiot really is.
    "It can't rain all the time"-Eric Draven
    Being dyslexic is hard work. I don't even try anymore.

    Comment


    • #47
      ok how do i rid them
      When you find yourself arguing with an idiot, you might want to rethink who the idiot really is.
      "It can't rain all the time"-Eric Draven
      Being dyslexic is hard work. I don't even try anymore.

      Comment


      • #48
        Originally posted by Urban Ranger
        Run msconfig to turn off everything you don't need so far.

        BTW why are you running Norton, McAfee andAVG? Wouldn't your computer be a little slow?

        These look fishy:




        O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
        O20 - Winlogon Notify: pmkjj - C:\WINDOWS\system32\pmkjj.dll
        You also got this, though it looks like the file got nuked already.
        Pmkjj is indeed the problem, iirc. IGFX is a graphics card accelerator. I'll look a bit more at the list, but Pmkjj is definitely related to Winfilefix.
        <Reverend> IRC is just multiplayer notepad.
        I like your SNOOPY POSTER! - While you Wait quote.

        Comment


        • #49
          Originally posted by Mrs. Tuberski
          ok how do i rid them
          Run msconfig to see if you can find them in the startup panel.

          If not, run regedit as snoopy369 says and check under run, runonce, and runex (something like this).
          (\__/) 07/07/1937 - Never forget
          (='.'=) "Claims demand evidence; extraordinary claims demand extraordinary evidence." -- Carl Sagan
          (")_(") "Starting the fire from within."

          Comment


          • #50
            O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\system32\pmkjj.dll * This is WinFileFIx related.

            O4 - HKLM\..\Run: [AdwareAlert] C:\Program Files\AdwareAlert\adwarealert.Exe -boot * This is a dubious program, not a happy camper

            O20 - Winlogon Notify: pmkjj - C:\WINDOWS\system32\pmkjj.dll * as above noted, this is bad and related to your problem

            Those are the only trouble spots I could identify, i searched a few others out but they were fine.

            HJT should be able to remove these for you (checking the box and then saying "remove") ... I think that pmkjj.dll can probably be deleted directly to at least somewhat fix this problem, although it's probably loaded by Windobs so you'd have to load up in Safe Mode to delete it first. It's in \windows\system32\ (as you can see in the O4 item).


            To do this:

            Boot in Safe Mode (hold down F5 or F8, I always forget which, during startup, and in the DOSlike menu, select "Safe Mode")

            Once it loads, start menu -> run -> cmd.exe

            cd \
            cd windows
            cd system32
            del pmkjj.dll

            that should fix it. If you want to be safer, you can do:
            move pmkjj.dll pmkjj.bak

            as to not delete it - but it's not anything useful as far as I can tell, and most of the internet searches agree it's malware.
            <Reverend> IRC is just multiplayer notepad.
            I like your SNOOPY POSTER! - While you Wait quote.

            Comment


            • #51
              UR, I don't think these are found in the /run etc. registry entries ... I think they're in other areas, ones i'm not as familiar with - but i'm not really sure. However, the lack of specific directions on other sites about using regedit to fix this particular problem (places where they usually tell you to use regedit) indicates to me it's probably not there ...
              <Reverend> IRC is just multiplayer notepad.
              I like your SNOOPY POSTER! - While you Wait quote.

              Comment


              • #52
                Nevermind, false alarm.
                (\__/) 07/07/1937 - Never forget
                (='.'=) "Claims demand evidence; extraordinary claims demand extraordinary evidence." -- Carl Sagan
                (")_(") "Starting the fire from within."

                Comment


                • #53
                  Those are related to her printer, lexmark
                  <Reverend> IRC is just multiplayer notepad.
                  I like your SNOOPY POSTER! - While you Wait quote.

                  Comment


                  • #54
                    Thanks snoopy il try this
                    When you find yourself arguing with an idiot, you might want to rethink who the idiot really is.
                    "It can't rain all the time"-Eric Draven
                    Being dyslexic is hard work. I don't even try anymore.

                    Comment


                    • #55
                      IIRC, BHO (as in O2) stands for "browser help object."

                      After a short google, i got to:


                      This might be worth considering. It will probably delete the winfilefixer dll for you if you want, and might notice any other problems as well
                      <Reverend> IRC is just multiplayer notepad.
                      I like your SNOOPY POSTER! - While you Wait quote.

                      Comment


                      • #56
                        Originally posted by snoopy369
                        Those are related to her printer, lexmark
                        Don't you just hate it when vendors just dump files in System32? That's usually what malware and slimware do.
                        (\__/) 07/07/1937 - Never forget
                        (='.'=) "Claims demand evidence; extraordinary claims demand extraordinary evidence." -- Carl Sagan
                        (")_(") "Starting the fire from within."

                        Comment


                        • #57
                          Honestly I wish they'd ALL use system32 ... and not create directories all over the place. How many printer companies really need their own directory for the minimal software most include
                          <Reverend> IRC is just multiplayer notepad.
                          I like your SNOOPY POSTER! - While you Wait quote.

                          Comment


                          • #58
                            tuber did the bho and found the pmkjj as u said snoop, and disabled it i shall see if this does the job thanks for the help guys
                            When you find yourself arguing with an idiot, you might want to rethink who the idiot really is.
                            "It can't rain all the time"-Eric Draven
                            Being dyslexic is hard work. I don't even try anymore.

                            Comment


                            • #59
                              Hopefully it works
                              <Reverend> IRC is just multiplayer notepad.
                              I like your SNOOPY POSTER! - While you Wait quote.

                              Comment


                              • #60
                                Originally posted by Urban Ranger


                                Run msconfig to see if you can find them in the startup panel.

                                If not, run regedit as snoopy369 says and check under run, runonce, and runex (something like this).
                                We had to do safe mode startup and remove that way by running Norton anti-virus



                                tried through regular statup but it would not remove

                                all seems fine since doing it in safe mode

                                Remember to play it safe and let the professionals handle this nasty buggar for their may be more than one



                                Attached Files
                                Hi, I'm RAH and I'm a Benaholic.-rah

                                Comment

                                Working...
                                X