Windows Explorer shuts down on me: ntdll.dll

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by qriusjorj, Feb 28, 2006.

  1. qriusjorj

    qriusjorj Private E-2

    Hey guys!

    Man, I've had a frustrating couple of days trying to solve my problem. I'm hoping someone here might be able to give me a hand with it.

    When I'm in Windows Explorer viewing files I get an error message with the following error signature:

    AppName: Explorer.exe
    ModVer:5.1.2600.2180
    AppVer: 6.0.2900.2180
    Offset: 0003426D
    ModName: ntdll.dll

    Sometimes this error pops up as soon as I open Explorer, and other times it may give me several minutes before it appears. Once the error appears Windows Explorer shuts down.

    After scouring the net for help I came the realization that I might be infected with malware even though I pride myself in safe-computing. :)

    I read through Post #1 in the Malware Removal forum titled "READ & RUN ME FIRST Before Asking for Support." I've spent a good portion of the day following each of the steps outlined in the post. CCleaner, Ad-Aware SE, Spybot, MS Windows Defender, MS Windows Software Removal Tool and Bitdefender all show me that I have a clean computer. Nice to know but doesn't explain why I'm having the error I'm getting.

    However, when I ran the Panda ActiveScan I got 14 "incidents." I'm not sure why none of the other scans picked up on these. (?) Anyway, I haven't handled any of these incidents because I'm not sure exactly what the best way is to do it. You'll find the ActiveScan log attached to this post as well as my HijackThis log and my Bitdefender log.

    Please let me know if I can provide any further information. Also, am I correct in assuming that the error message I'm receiving in Windows Explorer is related to malware?

    Thanks so much for your time and help.
    Sam
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're only problems in these logs is with junk Dell stuck you with. First look in Add/Remove programs for anything that has MyWay or MyWay Serarch....etc in it. If found, uninstall it. We double check with the below fixes. But note, these have nothing to do with your ntdll.dll error. And I doubt it is related to malware. You should dicuss this one in the Software Forum.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DE
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
    O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\MyWaySA <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings (do not set it back to the dell4me.com/myway link):
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  3. qriusjorj

    qriusjorj Private E-2

    Thanks for your help! I really appreciate it!

    I followed the steps you gave me and am attaching a new HijackThis log.

    Am I free from malware now? :)

    Also, thanks for pointing me to the Software Forum regarding my ntdll.dll error!

    Sam
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    You forgot to attach the new HJT log!
     
  5. qriusjorj

    qriusjorj Private E-2

    Oops! Sorry. Here it is...
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's clean! Make sure you checkout the below too.

    How to Protect yourself from malware!
     
  7. qriusjorj

    qriusjorj Private E-2

    Thanks so much!!!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  9. qriusjorj

    qriusjorj Private E-2

    chaslang,

    I just reviewed your "How to Protect yourself from malware!" posting.

    Why do you recommend Firefox over MS IE?

    Sam
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Because:
    1. it has fewer security holes than IE
    2. has built-in popup blocking
    3. tabbed browsing capability
    4. it's faster than IE
    5. fewer hackers attach it than IE
    You will still need IE for certain websites including (of course) Microsoft.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds