"Error loading E6F1873B.DLL" at start-up, sometimes causing continuous rebooting

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by aikox2, Jul 13, 2005.

  1. aikox2

    aikox2 Private E-2

    My daughter's pc apparently got infected, despite my running AV, AdAware, Spyware Guard, Spybot S&D, and Spyware Blaster (and being behind a router).

    I get the error in the subject line, then the computer reboots, checks it drives, fails...
    If I cancel the error checking at reboot, it will boot up. Upon scanning and cleaning and rebooting, it fails again, always giving the above error.

    I followed the instructions re: "Before Asking for Support...", and I believe I am ready for help. I have a Hijack This log ready if anyone wishes to see it.

    In advance, thanks for any help,
    Scott
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please install and use HijackThis per the following instructions:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. aikox2

    aikox2 Private E-2

    Hmm, I don't know why I didn't get an email alerting me to your reply. I was actually just coming back to post that I used Help2Go to analyze my log myself, and it seems to have fixed my problem. Following is my most recent log in case there are still vestigial problems, but it boots fine and the E6F1873B.DLL Error is gone.
    Thanks for responding, and thanks in advance for any further advice.
    Scott
    P.S. - Why doesn't everyone just analyze their own logs?

    Inline log attached!

    Here is the original log before Help2Go:

    Inline log attached!
     

    Attached Files:

    Last edited by a moderator: Jul 15, 2005
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must only use one antivirus program. I see McAfee and Avast items in your log. Pick the one your prefer and removal the other.

    You still have problems. That's the reason why everyone does not analyze their own logs. They have no idea what they are looking for. And while automatic analyzers have gotten better they are far from perfect and they do not tell you how to actually fix the problems. It is not always that straight forward.

    First disable Spybot's Teatime because it can get in the way during cleanup.

    To disable TeaTimer, run Spybot and click Mode and select Advanced Mode. Then click Tools and select Resident. Now in the right window pane, uncheck TeaTimer.
    Also while this is open, in the left column now select IE Tweaks and then in the right pane make sure all the Miscellaneous locks are unchecked.
    Now quit Spybot!

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINNT\system32\devmgr78.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: (no name) - {30FD3E0A-B84C-789E-8750-60550887723D} - (no file)
    O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
    O4 - HKLM\..\Run: [09071c61d176] C:\WINNT\system32\d3dxof09.exe
    O4 - HKLM\..\Run: [Uninstall_TBPS] C:\WINNT\Temp\TBuninst.exe /remove
    O4 - HKLM\..\Run: [Uninstall_WinTools] C:\WINNT\Temp\WTuninst.exe /remove
    O4 - HKLM\..\Run: [540432c9d421] C:\WINNT\system32\devmgr78.exe
    O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) -

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINNT\system32\E6F1873B.DLL
    C:\WINNT\system32\devmgr78.exe
    C:\WINNT\system32\d3dxof09.exe
    C:\WINNT\Temp\TBuninst.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. aikox2

    aikox2 Private E-2

    Thanks for responding.

    I must have posted the wrong log, because some of the items you told me to remove I have eliminated (devmgr78.exe, TBuninst.exe, and others), but I did follow all the directions you gave where applicable (disabled TeaTimer, used HJT as indicated on all files I could), safe mode, CCleaner, IE cleanup.

    One thing: I am not running McAfee in any form. I uninstalled it before I switched to Avast, and deleted the folder as well. There are no signs of it, except for apparently some registry entries. I see some references to Symantec AV as well, which I also do not have installed or running (note running processes). What would you recommend to clean up the registry?

    Here is the HJT log from after all of the above:

    Edit by chaslang: Inline log removed.

    Thanks again,
    Scott
     

    Attached Files:

    Last edited by a moderator: Jul 15, 2005
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not post HJT logs inline. They will normally be deleted.

    Are your saying these folders do not exit:
    D:\McAfee VirusScan 6.0
    C:\Program Files\McAfee\McAfee Shared Components

    Are you also saying you no longer have the below installed:
    O23 - Service: Speed Disk service - Symantec Corporation - D:\Norton Speed Disk\nopdb.exe


    Have HJT fix the below lines and delete the folders if they exist:

    O4 - HKLM\..\Run: [Alogserv] D:\McAfee VirusScan 6.0\alogserv.exe
    O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
     
  7. aikox2

    aikox2 Private E-2

    In response to your questions: No, none of those folders exist! Upon opening Hijack This, the only entry there to delete was the 04 - HKCU McAfee InstantUpdateMonitor..., which I deleted. Seems clean now:

    Edit by chaslang: Another inline log! This time deleted!

    Thanks,
    Scott
     
    Last edited by a moderator: Jul 15, 2005
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  9. aikox2

    aikox2 Private E-2

    sorry

    Forgot about not posting the log.

    Thanks for the help.

    Scott
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: sorry

    Posting is fine but they must be attached! You're welcome.

    Make sure you follow the steps in the link I just gave to you.
     
  11. aikox2

    aikox2 Private E-2

    Believe it or not, I actually do all of those things (learned it here), and have been very stable on all five of my pcs till this one somehow got compromised. Even then, it was easily repaired. I always keep up to date on MS update. I run Avast and Sygate, SG and Spyware Blaster, and scan with Spybot and AdAware. The only thing I stopped using regularly was CCleaner, after another tech forum said it was horrible and would cause more problems than it solved.
    Scott
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not true! It is a great program. I use it all the time. No problems.

    Just don't use the registry fix stuff. No programs like that are truly safe. But if you do a backup of your registry first it is still not a problem.
     
  13. aikox2

    aikox2 Private E-2

    CCleaner

    Maybe it was the registry issue that they didn't like. Makes sense.

    Thanks again for all the advice.

    Scott
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: CCleaner

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds