What is amtverox.dll?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Kiholo, Jul 10, 2007.

  1. Kiholo

    Kiholo Private First Class

    Hello,

    My son's laptop displays an RUNDLL error message when starting Windows XP Home. The message reads:

    Error Loading c:\Windows\system32\amtverox.dll. The specified module could not be found.

    Prior to seeing this message, the desktop takes a long time...a few minutes...to refresh and displays the icons on his desktop.

    I've found a registry entry HKEY_LOCAL-MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\

    Name: "DllRunning"
    Type: "REG_SZ"
    Data: "rundll32.exe "C:\WINDOWS\System32\amtverox.dll",setvm"

    Any ideas?

    Thanks,

    Blaine
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi and Welcome


    In the location of that file and not recognising it as a legit microsoft system files, I would suspect malware as the cause of this, apart from th eslow loading are you having any other issues as well, maybe strange popups or yhe browser re-directing to weird websites? if so please discribe them.


    BUT the below guide should be run and the requested logs attached then our malware experts can help you remove infection you have.


    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.




    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. Kiholo

    Kiholo Private First Class

    Halo,

    Wow, thanks for all the support and info. It will take me awhile to digest the info, perform the tasks, and provide the feedback. Providing the feedback may be a problem since the laptop does not have internet connectivity...another malady...so I'll be improvising with cut and paste via a thumb drive.

    Just to bring you up to date, I was able to install a copy of Registry Mechanic v5.1 and it did fix...more like removed...the amtverox.dll entry. However, the slowness of displaying the desktop icons still persists...about 2-3 minutes.

    Earlier this morning, I ran AdAware 2007 and it identified two locations for Win32.TrojanDownloader.Alphabet and two for Win32.Trojan.Agent. There is a long history regarding the first...I've run this app several times and it can't seem to get rid of this problem. The second one is new. This is just an aside...I will stop now and go on to your guidance.

    Again, thanks for the assistance. I will get back to you when I've completed the checklists you've provided.

    Blaine
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I will give you a couple of things to try before you work thru all of Halo's instructions. These new steps may or may not help get your internet connection back, but I think you need to do them anyway.

    Run this Virtumonde aka Trojan Vundo Removal and do not attach the requested log right away. Run it multiple times until it comes up clean and then attach the final log. ( See: HOW TO: Attach Items To Your Post )


    Now let's run another small and relatively fast cleaning tool.
    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log (c:\combofix.txt) for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After attach the above two logs, continue on with the other steps Halo gave to you.
     
  5. Kiholo

    Kiholo Private First Class

    WOW ::):dancer:dancer:dancer

    You guys are TERRIFIC! :clap:clap

    Per instructions, I ran Vundo several times without anything being found; next ComboFix found a gaggle of stuff...well, 7 pages of text with each entry having an ending of *.vir. As soon as ComboFix stopped running after the reboot, I saw immediate results as the screen flashed and displayed desktop icons. I couldn't believe it, so I hit restart just to make sure it was indeed performing normally. YEP...phew!! I wasn't looking forward to reformatting and reinstalling XP and him loosing all his stuff.

    Do you still want me to attach the files?

    Now, I have to address the internet connectivity question. AND of course make sure my son's laptop has operational and up-to-date virus/adware/spyware applications.

    Thank you very much,

    Blaine
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it would be in your best interest to attach the ComboFix log and then complete ALL the steps that Halo gave you and attach those 6 logs.
     
  7. Kiholo

    Kiholo Private First Class

    Chaslang,

    I've attached results from Vundu and ComboFix; working thru the other items previously recommended.

    I'm also going to try and remedy the internet connectivity problem since it would simplify downloads and negate the need use a thumb drive.

    Thanks,

    Blaine
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see a few problems indicated by ComboFix that probably remain and there could be more. After you get as much of the READ & RUN ME done (obvioulsy you cannot do online scans) we will more than likely be able to resolve this issue. Make sure you try to get the below logs for me:
    - CounterSpy or AVG AntiSpyware since they run offline
    - GetRunKey
    - ShowNew
    - HijackThis

    The last three logs are MUST haves inorder for us to continue.
     
  9. Kiholo

    Kiholo Private First Class

    Chaslang,

    Here are the results of CounterSpy, GetRunKey, ShowNew, and HJT.

    I also have report from CCleaner which I will attach to another response.

    Thanks,

    Blaine
     

    Attached Files:

  10. Kiholo

    Kiholo Private First Class

    Chaslang,

    Here are HJT and CCleaner history files.

    Amazing what these tools find...but more amazing how much stuff gets loaded onto unprotected computers of unsuspecting users.

    I presume you will let me know what stuff I need to do regarding getting rid of the nasties.

    Thanks,

    Blaine
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must rename HijackThis.exe to analyse.exe as requested in step 7 of the READ ME. Then you will need to attach a new log. Some forms of malware will not show up unless this is done.

    Also you need to uninstall the below:
    J2SE Runtime Environment 5.0 Update 3
    Viewpoint Media Player (Remove Only)


    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
     
  12. Kiholo

    Kiholo Private First Class

    Chaslang,

    Thanks for guidance. Here's the new "analyze" log from HJT.

    Blaine
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note: You are running your PC with no antivirus, no true firewall, and no antispyware blocking tool. This is very dangerous! Why are you running this way?


    First uninstall the CounterSpy trial program since we are finished with it now.

    Continue by downloading a tool we will need

    - Process Explorer

    Extract it to its own folder somewhere that you will be able to locate it later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    Make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of any of the below DLL files (if found) and then click the kill button.
    mdptd.dll
    ntload32.dll

    After you have killed all instances of any of the above DLLs under winlogon click ok.
    (If you do not find these DLLS, just continue on.)

    Next double click on explorer.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button.
    mdptd.dll
    ntload32.dll

    After you have killed all instances of any of the above DLLs under Explorer click ok.
    (If you do not find these DLLS, just continue on.)

    Next double click on iexplore.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button.
    mdptd.dll
    ntload32.dll

    After you have killed all instances of any of the above DLLs under iexplore click ok.
    (If you do not find these DLLS, just continue on.)

    Now just exit Process Explorer.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {2DAAAC37-4A03-4DC8-BB45-2660401B5A72} - blank (file missing)
    O2 - BHO: CIEPl Object - {F3727275-224F-4AB0-8642-7D461EFB82D8} - C:\WINDOWS\system32\mdptd.dll
    O20 - Winlogon Notify: mdptd - C:\WINDOWS\SYSTEM32\mdptd.dll
    O20 - Winlogon Notify: ntload32 - ntload32.dll (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  14. Kiholo

    Kiholo Private First Class

    Hey guy,

    You're up late? But that's good for me...thank you for your persistance.

    As to why no antivirus, antispyware, or firewall, I don't have any connectivity so wasn't concerned at this point. I was planning to install these, especially on this computer which is my son's, after I got it clean and running properly but BEFORE restoring internet capabilities.

    I now attend to your list of fixes.

    Blaine
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Typically! ;) But now I'm heading off to get a couple hours of sleep.


    Okay! My final instructions will give you a link to How to protect yourself and this will include a list of tools (many of which are free).
     
  16. Kiholo

    Kiholo Private First Class

    Chaslang,

    Here's the files for Avenger, GetRunKey, and ShowNew. HJT is the same as sent previously...but I will attach in next message.

    Nothing in particular to report or deviations, except I did not find an iexplorer.exe entry in the section on Process Explorer.

    Blaine
     

    Attached Files:

  17. Kiholo

    Kiholo Private First Class

    Attached is the HJT file.

    I am really blown away by how much individual attention and detailed analysis you're providing. Thank you very much.

    Blaine
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  19. Kiholo

    Kiholo Private First Class

    Chaslang,

    Phew! What a relief to hear you say that...and to see my son's laptop performance back up to par. I've downloaded and installed the intrusion protection cocktail described in the other thread.

    Now, I need to focus my attention to fixing whatever is preventing his laptop from connecting to the internet. I will go to the appropriate forum.

    Again, Chaslang, thank you for your assistance in resolving these problems. Do you mind my asking what you do for a living? If you're in the IT business, then you surely know your job! If you're not and in some other business, I am amazed at how much time and effort you put into helping folks like me resolve our problems.

    Thanks a bunch!!!

    Blaine
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you still having this problem? You may need to try the Networking or Hardware Forum. Perhaps you have a driver issue. It may be worth giving the below a try:

    XP TCP/IP Repair


    You're welcome.

    No I'm not in the IT Business. I do research & development work for telecommunications.
     
  21. Kiholo

    Kiholo Private First Class

    Chaslang,

    Thanks for the tcp/ip fix...I'll give it a try. Hopefully, we'll be just as successful!

    Wow, I'm very impressed that all this IT knowledge and skill is an interest rather than career.

    Again, you personal involvement is much appreciated.

    Blaine
     
  22. Kiholo

    Kiholo Private First Class

    Chaslang,

    As with your success in resolving the malware, the TCP/IP repair software you recommended did the trick.

    Thanks again for everything,

    Blaine
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome Blaine. I'm happy to hear that it worked.

    Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds