Well this popup has been happening for a few days it reads:
"The application or DLL C:\WINDOWS\system32\jozebohu.dll is not a valid Windows image. Please check this against your installation diskette."

There was more but Norton took care of it (I think). It was a fake Windows program that told us to buy an antivirus from them and obviously wanted our credit card numbers.

Now I cannot run any other programs besides internet and Norton. I try to open it and it tells me to choose how to open it, and I cant find anything that will actually open it.
It says something about it not being able to be opened because it has been damaged or something.

So I can't run MalwareBytes or anything like that. I'm not sure what to do.

Umm main problem at the moment is I can't open anything but internet because it says something like: choose how to open this file: give me a bunch of options such as internet explorere and adobe, and nothing will actually open it, it says its damaged for everything.

Dani AI

Generated

Good first steps — ran Malwarebytes and reports the popups and the damaged .DLL behaviour are gone. That pattern (fake AV popups, Vundo-style DLLs and hijacked .EXE associations) is common: the initial clean often fixes the visible symptoms, but a careful follow‑up is needed to be confident the machine is clean and that persistence mechanisms aren’t left behind. (bleepingcomputer.com)

Follow-up checks to run now (order matters):

  1. Update Malwarebytes and run a full scan with “scan for rootkits” enabled; if Malwarebytes won’t launch, use Malwarebytes’ Chameleon helper to get it running. (malwarebytes.com)
  2. Run a second-opinion offline/boot scan (Microsoft Defender Offline or a reputable on‑demand scanner) so active rootkits can’t hide. Let the tool remove anything it finds and reboot. (howtogeek.com)

Persistence and cleanup (things that commonly survive the first pass):

  • Run Autoruns and inspect the Run/RunOnce, AppInit_DLLs, Winlogon Notify and BHOs; disable suspicious entries before deleting files. Use the Autoruns “jump to” to find files on disk. (learn.microsoft.com)
  • Check every user profile — MBAM may need to be run for each user because HKEY_CURRENT_USER entries are per account. Remove toolbars/PUPs (My Web Search) from Add/Remove Programs as suggested, then reboot and re-scan. (forums.malwarebytes.com)
  • Clean System Restore: delete old restore points (Disk Cleanup → More Options) and create a new restore point after the system is clean. This prevents reinfection from an infected snapshot. (learn.microsoft.com)

If registry tools or running cleaners are still blocked, re-enable them or run the registry command from an elevated prompt (only if comfortable doing this). Example to re-enable Regedit:

reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v DisableRegistryTools /t REG_DWORD /d 0 /f

Follow that by another full scan. Finally, change important passwords from a known-clean device and monitor banking/login activity for a few weeks — credential theft is a real risk even when visible symptoms vanish. (howtogeek.com)

Recommended Answers

All 4 Replies

Ok so I figured out how to run Malwarebytes Antimalware. I had to browse and go to that specific program. So it's scanning now and I will post results if needed.

By all means definitely post the MBA-M log. Be sure to have it Remove all found and Reboot.
Post back here with the log. I will watch for it.

Malwarebytes' Anti-Malware 1.44
Database version: 3767
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

2/20/2010 1:02:58 PM
mbam-log-2010-02-20 (13-02-58).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 271105
Time elapsed: 1 hour(s), 58 minute(s), 26 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 7
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 7

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a3ba40a2-74f0-42bd-f434-00b15a2c8953} (Trojan.BHO) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\idstrf (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\winid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\nofolderoptions (Hijack.FolderOptions) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\my web search bar search scope monitor (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mywebsearch email plugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mywebsearch email plugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\asg984jgkfmgasi8ug98jgkfgfb (Trojan.Downloader) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CLASSES_ROOT\.exe\(default) (Hijacked.exeFile) -> Bad: (secfile) Good: (exefile) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\jozebohu.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\seburehi.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\senisefe.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator\Local Settings\Temp\ncuiiog.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator\Local Settings\Temp\cohppuec.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\mswintmp.dat (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator\Local Settings\Temp\jisfije9fjoiee.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.


Everything seems to be working fine now. I think that did the trick. I will keep running scans all week to ensure nothing else occurs :).

Based on items noted in the MBA-M scan you should do the following:
First, uninstall the My Web Search option from Add/Remove Programs

1) Click on Start, Settings, Control Panel

2) Double click on Add/Remove Programs

3) Find "My Web Search" in the list of installed programs and click on Change/Remove to uninstall it. You may also want to uninstall any of the following items associated with FunWebProducts.

* My Web Search (Smiley Central or FWP product as applicable)
* My Way Speedbar (Smiley Central or other FWP as applicable)
* My Way Speedbar (AOL and Yahoo Messengers) (beta users only)
* My Way Speedbar (Outlook, Outlook Express, and IncrediMail)
* Search Assistant - My Way

4) Reboot your Computer

There is a very good chance that what was found by MBA-M may not be all of it. Please also do the ESET Online scanner, you will have to turn off your av program and also run the scan from Internet Explorer and have it remove all that is found.
Reboot. Then run HiJackThis and post both logs here.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.