Adware, malware, changing dll on reboot and more

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by dt196, Jul 17, 2006.

  1. dt196

    dt196 Private E-2

    I've done all the steps in the run me first post and I'm still having numerous problems.
    Every time I reboot, I get a rundll box that states "An exception occurred while trying to run "C:\windows\system32\mac70v.dll,dllgetversion"". I also get a box that says "error loading we404798.dll"

    Ad aware couldn't remove C:\windows\system32\hr6005j9e.dll. Each time I run ad aware it is a different named dll that it can't remove.

    Spybot can't remove "command service" but removes Smithfraud-C and Web Nexus. The next time I run Spybot after a reboot, they're all there again. So it appears that something is automatically reloading them.

    Norton Antivirus finds Ndotnet and look2me, along with others.

    After running all the malware tools in safe mode, all the above problems are still there along with a severe pop up problem.

    Cwshredder found nothing. Kill2me said I wasn't infected (although it keeps showing up in Norton)

    Microsoft malicious software removal tool found nothing.

    I couldn't get panda active scan to work. When on the page to click "local drives", I get a page error.

    I hope someone can help me straighten out this computer, as my last resort is to reformat, which I'm not looking forward to.
    TIA
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not empty your Norton Nprotect and Quarantine folders as requested in step 0 of the READ ME. PLEASE DO THIS NOW BEFORE continuing.

    Download DelDomains and unzip it to your desktop.

    Find the files from deldomains.zip on your Desktop and RightClick on the deldomains.inf file and select Install.

    Afterwards run Spybot and make sure you re-Immunize immediately.

    Now run this: Qoologic Removal Procedure

    Now run this: Look2Me VX2 Removal and attach the requested log to your next message.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Network Station Task Manager ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    TKNT

    If you receive any error messages just ignore them and continue.

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.


    Now complete the below procedure. Some items may no longer be seen in your HJT log. So if you do not see certain lines, just ignore and continue.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    C:\dfndrad_5.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\gabns.exe
    F2 - REG:system.ini: UserInit=userinit.exe,quirdmv.exe
    O3 - Toolbar: (no name) - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - (no file)
    O4 - HKLM\..\Run: [keyboard] C:\\kybrdad_5.exe
    O4 - HKLM\..\Run: [defender] C:\\dfndrad_5.exe
    O4 - HKLM\..\Run: [ctmc3b33] RUNDLL32.EXE we404798.dll,n 001c3b3200000003e404798b


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\gabns.exe
    C:\WINDOWS\system32\quirdmv.exe
    C:\WINDOWS\system32\we404798.dll
    C:\WINDOWS\tasknt.exe
    C:\kybrdad_5.exe
    C:\dfndrad_5.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  3. dt196

    dt196 Private E-2

    Chaslang,
    Thanks again for the help. The only thing I couldn't figure out how to do was the deldomains thing. A notepad box came up and I didn't know what to do with it. Some of the things, I had already done from the other post, but I ran them again per your instructions in this post. The look2me log is from the 2nd ( most recent) scan.

    Some of the things to fix in HJT and delete in windows were not there (maybe they were done from the first post).

    I then ran HJT for the log that I'm posting.

    After doing all the above, I ran Adaware, Spybot and Norton Antivirus. The results are as follows.

    Adaware found "Surfsidekick" and "VX2" and removed them. A subsequent scan after a reboot showed that they were indeed gone.

    Spybot finds "Command Service" and can't repair them. I also can't delete them manually in the registry.

    Norton found "Ndnuninstall7_22.exe" and "Aupdate32.exe" and said that they were an adware threat, but would not remove them. I was able to manually delete them.

    I don't know if the malware or the things I've done have messed up my network. This computer is my wife's and we share a printer via a router with my computer downstairs. Any idea's?
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    Now run your scans that you said were detecting problems! You must attach logs for any scanners that find problems! Just telling me things like below, does not give adequate information to help you:
    I will be on vacation until 7/31/06. One of the other Mods or Admins here may be able to pickup where I leave off.
     
  5. dt196

    dt196 Private E-2

    Restore is now off. Scans of AdAware come back clean.
    Spybot & Norton are still finding Adaware. Logs are provided.
    Thanks
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The recent scan from Norton only flagged things in your Recycle Bin. You need to keep that clean yourself.

    For what Spybot is finding, it cannot be fixed using Spybot because something modified who is the owner of the registry keys. The below should fix this:

    Download and Install Registrar Lite

    Run Registrar Lite navigate to the following keys and take ownership of them (explained further down):

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdService
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdService


    To take ownership of teh key do the following:
    • Copy & Paste one registry key from above into the address bar of Registrar Lite and hit the enter key. This will bring you to the regitry key.
    • Click-on Security in the Menu
    • Select Take Ownership
    • Now right click on the registry key and select delete
    • Repeat for all the above registry keys
    • Tell me the results. Any errors?
    Check a Spybot scan afterwards!

    If you are not having any other malware problems after doing the above, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!



    I will be on vacation until 7/31/06. One of the other Mods or Admins here may be able to pickup where I leave off.
     
  7. dt196

    dt196 Private E-2

    Chaslang,

    Thank you for helping me to regain control of my wife's computer. I did everything from the above post and both Spybot and Norton come back clean.

    The only thing I can't get working again is my network. I have 2 computers behind a router. I ran the setup for a home network and it's a no go. Is there anything the malware or we did to cause this? Any help in this matter would be greatly appreciated.
     
  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

  9. dt196

    dt196 Private E-2

    That Fracked the computer so bad that I'll have to reformat.
     
  10. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    A reformat is most likely unnecessary. Can you boot to Safe Mode?
     
  11. dt196

    dt196 Private E-2

    Yes, I can boot into safe mode, but a whole lot of things don't work. I can't access the net, I can't get into device manager. Please help. I tried to do a repair of windows, but F8 wouldn't work so I couldn't agree to the ula. Help please.
     
  12. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    From Normal Mode

    Start -> Run
    type sfc /scannow
    Click 'OK'
     
  13. dt196

    dt196 Private E-2

    Did the above and got the message "windows cannot find "sfc/scannow", make sure you typed the name correctly". Yes I typed it correctly.
     
  14. AbbySue

    AbbySue MajorGeeks Administrator

    If you typed it like you have it in your post quoted above you did not type it correctly. It is sfc /scannow note the space between sfc and the /.

    Leaving out the space or putting the space in the wrong place is a common error..have done it myself many times.:eek: :)
     
  15. dt196

    dt196 Private E-2

    AbbySue,
    Sorry, I thought that it showed a space, so I tried it both ways last night. I got a message about inserting windows SP2 disc and didn't think that was the correct thing to do. So this morning I did it through to completion. It ran something to verify that certain files were in the right place. Nothing has changed,as far as I can tell, even after a reboot. I have no net access, device manager is a blank box, the toolbar color has changed to beige instead of blue.
    Inserting the windows disc also brought up a screen that seems to give me the option to install windows. Can I just do a repair that will fix windows, but leave the programs. I have windows on it's own 15 g partition and most programs are installed on another partition. My wife only has a handful of programs installed and I have all discs, so would this be the easiest fix or do you want to walk me through the current repair?
    Thanks
     
  16. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    A Repair Install, is ceratinly an option; and most likely the fastest solution.
     
  17. dt196

    dt196 Private E-2

    Shadow,
    What did the "WinSock XpFix 1.2 do? Can it be undone or changed back, as that's when I lost access to the internet?
    An other thing that is strange is that the windows firewall is grayed out, unable to turn it off or on.
     
  18. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    All Winsock XP Fix does is rebuild Winsock2.

    We may have missied a piece of malware.

    Follow the directions for Running WinPfind by OldTimer.

    Post WinPFind.txt when finished.
     
  19. dt196

    dt196 Private E-2

    I want to thank Chaslong, AbbySue, and Shadow for all they're help.
    The easiest way for me to get everything working correctly was a format and a complete install of windows. Everything is back to normal now and the wife's happy. Thanks again.
     
  20. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    We aim to please. Sorry you had to reformat. Winsock XP FIx shouldn't have fraged your computer like that. Used it numerous times for the same problem.

    Wifes happy, that what really matters.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds