adriss.exe

Discussion in 'Malware Help (A Specialist Will Reply)' started by gnatsum39, Nov 16, 2006.

  1. gnatsum39

    gnatsum39 Private E-2

    Ok I have been firing an arsanal of Spy ware virus programs at this SOB and I can't get rid of it. Its on my dads computer and my dumb A** forgot to bring the HJT log back from his house so I can't post it ATM. Does any one know off the top of their heads how to get rid of Adriss.exe? Any way apprieciate any thoughts on the matter. :)

    Thanks
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    That's good because it is the last thing that we would want to see any way. You need to run the below steps for us to help you! Otherwise all we could suggest is that you use a program like PocketKillbox to delete the file at reboot. But this may or may not resolve your problems.


    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. gnatsum39

    gnatsum39 Private E-2

    I already ran your excellent cleaning guide that you linked me before I posted this thread. I just was wondering if any one had heard of Adriss.exe since I can't seem to get much info on it from google. It says its running in the windows task manager as a system item and won't let me end it and I know that Adriss.exe is no Windows system item. It appears to just be filling the HD up with random .T files (T files) with just random letters (aaae.t for ex.) Any way I will post all the results from all the tests I ran yesterday when I go get them from my pops house today. Just thought maybe some of you have seen this before as I have not.

    Thanks
     
  4. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Just for your interest Adriss.exe is linked/related to this trojan Trojan.Crypt.F.Gen or another named Troj/Lager-O

    But as Chaslang mentions, you'll need to not only run the guide but attach all the requested logs as well, so he can assist you in removing this once and for all, as many trojans not only have their own payload, but also download others to multi infect you, which is where all the logs come in.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Halo is correct about what the file you named may be, but if you did not spell the name correctly, it could also be:

    Adirss.exe -->> Troj/Spamsrv-E backdoor Trojan
     
  6. gnatsum39

    gnatsum39 Private E-2

    Ok I ran all the programs again in safe mode but this is bad :( I kept getting the windows error message that you get when programs fail and want to send reports to windows. They appear to be legit windows error messages but I don't believe they really are. Any way I ran all the programs and when it came time to run Bitdefender it crashed after running for 2hrs 21min. The last results that were on screen were 19 virus found 23485 files infected, 616 files disenfected, 19154 files deleted. So I wasn't able to save a log file as it froze up due to the window error message popping up over and over again. I always told it don't send report since it may just be a virus.

    The main error report was always for a DrWatson Postmortem Debugger wich I have no such program on the computer.

    Any way on to panda and it did the same thing it crashed and started spamming the DrWatson error over and over to the point that I couldn't do any thing. Not even run HJT. This is all in safe mode too.

    Any way before panda crashed out it had found 2580 viruss and :rolleyes: 1 hacking tools. As before I couldn't get a report so I don't know what to do other than nuke the HD at this point......

    I have done my best to follow all the steps in your guide and I will understand if you have no more advice for me. At this point I am not even sure if nuking the HD will fix this........;

    Thanks for all your help

    :(
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you do! It is part of Windows!

    Boot into safe mode an get three logs (as stated in the READ ME) if possible:

    - GetRunKey
    - ShowNew
    - HijackThis

    These are very fast logs to get. Let's see what they show. However if Bitdefender and Panda our showing so many files being infected, you may be in big trouble unless those files being found are not required for your PC or software to run.
     
  8. gnatsum39

    gnatsum39 Private E-2

    Ok attached are the HJT log and the get run key log..

    As for the Shownew log.. It runs and just says "The process cannot acces the file because it is being used by another process" and it just keeps repeating that over and over until finally another windows error window pops up and says "Attribute Utility has encountered a problem and needs to close" then the usual DrWatson error just keeps popping up till I have about 10 of them on my screen. So needless to say the Shownew file wont work.

    All of this was done in safe mode so this look hope less :(
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are not running GetRunKey and ShowNew properly as instructed in their download pages. You MUST extract ALL of the files from the ZIP file and you must run the .bat files from OUTSIDE of the ZIP as instructed.

    Let's try fixing some stuff based only on your HJT log.

    Make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
    O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [UpdateService] C:\WINDOWS\system32\wservice.exe
    O4 - HKCU\..\Run: [UpdateService] C:\WINDOWS\system32\wservice.exe
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/2870acebe959fe7a9519/netzip/RdxIE601.cab

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\system32\wservice.exe

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  10. gnatsum39

    gnatsum39 Private E-2

    Ok sorry about how long it took me to respond back. I had to work all weekend out of town :(

    Well it appears that with your help I am making some progress. I believe there are no virus or spy ware any more but there may be some other windows issue now. I did all the above mentioned in your reply and it helped alot. The problem is that when I went to run GetRunKey and ShowNew I got a windows error saying "NTVDM.exe has encoutered an error and will shut" and then it shuts down the window. I did extract all the files as per your instructions and I ran the .bat files.

    I did manage to run HJT again as per instructions with the changed .exe to analyze.exe.

    The main problem I am having at this point is Litteraly hundereds of DrWatson Postmortem debugger errors. The exact message is "DrWatson Postmortem Debugger has encountered a problem and needs to close. We are sorry for the inconvenience" Any way this happens over and over again alond with a host of other random error logs listed below

    "Application Layer Gateway service"
    "Automatic Updates" (which I turned off to try and fix this issue)

    So to sum it all up the only issue I am having at this point is that damn DrWatson :mad:

    Again your help is very apprieciated

    :)
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds and looks like someone has been disabling and/or deleting necessary system services. Have you or anyone one else been hacking around doing things on your own? Please be honest as it may help to determine and fix your problems. I see two services (that are required Microsoft system services) in you HijackThis log that show as missing. There could be others and there could also be others that are not missing but that are just disabled.
    I may have to refer you to the Software Forum since this is really not a malware issue, but let me see if we can get some other info first.

    Download the attached psservice.zip file and extract the psservice.exe file to C:\
    Make sure you extract it to where I said or the following procedure will not work.

    After extracting the file click Start, Run and copy and paste the below text in the run box:

    C:\psservice config > C:\servicelist.txt

    and then click OK. This should run the psservice program which will dump a list of all services and their settings into the C:\servicelist.txt file. Upload this file here as an attachment.

    Also do the following, click Start, Run and copy and paste the below text in the run box:

    regedit /E C:\wow.txt "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WOW"

    and then click OK. This should run the regedit and dump the contents a the WOW registry key into a file named C:\wow.txt file. Upload this file here as an attachment. I want to see if the DisallowedPolicyDefault exists and is set to 1. This could be disabling NTVDM from running.
     
    Last edited: Nov 22, 2006
  12. gnatsum39

    gnatsum39 Private E-2

    :p Am i missing something ? I don't see an attachment on the post? :p

    To my knowledge no one has deleted any system files....but all the DrWatson errors did start after I started trying to get rid of the virus so I may have done somthing wrong as I am not a pro :(

    I managed to do panda scan and bitdefender and AVG and they didn't find any virus so thats a big + :)

    Is there a way to repair windows with the install CD without trashing the whole drive?

    Thanks again, without pros like all of you us lost people would be out of luck!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that! It is attached here!

    Get me those two logs as soon as you can.


    Yes if you have your Windows XP boot CD and not just a silly recovery CD from a PC manufacturer. However doing a repair install reverts the PC back to the level of the CD. Thus any updates that may have already been downloaded and installed will be gone.
     

    Attached Files:

  14. gnatsum39

    gnatsum39 Private E-2

    Thanks for the fast response I will run that first thing in the AM after I get home from work.

    As far as the CD goes I only have the silly recovery disk that my dad got with his Dell. I personally own Full copies of XP and XP pro but I doubt with the liscenes agreements that I can use them to restore his computer :rolleyes:

    Any way again I will run that file as per your instructions in the morning and post all the info ASAP.

    I can't thank you enough for all this help. It truly amazes me that in this world of hate and violence that there are still people out there like your self that are so kind and helpfull to others. Happy Thanksgiving to you and all your family :)
     
  15. gnatsum39

    gnatsum39 Private E-2

    Ok I ran the zip as per instructions and I copied and pasted C:\psservice config > C:\servicelist.txt into the Run box but when I clicked ok a message came up asking if I wanted to run psservice.exe and I cliked Run and a DoS window opened real fast and closed but there is no file named servicelist.txt any where on the HD. I used explorer with show hidden files turned on and I even used the file search engine and still couldn't find it?

    As for the WOW file I have attached that. Not sure why it won't make the servicelist.txt though?

    Thanks
     

    Attached Files:

    • wow.txt
      File size:
      2.8 KB
      Views:
      3
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Start, RUn, and enter cmd and click OK. This will open a command prompt window. In this window type the below commands.

    cd c:\
    psservice config > C:\servicelist.txt


    Does this work? If not, try just typing

    psservice config

    Do you see a lot of text scrolling up listing services?



    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  17. gnatsum39

    gnatsum39 Private E-2

    Ok got the other scan to work from the command window so I attached that report and I did the fixME.reg and merged it with the registry as per instructions. So far so good.

    Happy Thanksgiving by the way :)
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does that mean you are not getting NTVDM errors anymore?

    Can you get the new logs (GetRunKey & ShowNew) then?
     
  19. gnatsum39

    gnatsum39 Private E-2

    I just took a screen shot of the error messages in hopes that it may help.

    I have attached it :)

    Thanks
     

    Attached Files:

  20. gnatsum39

    gnatsum39 Private E-2

    Hmmm well I did run the Getrunkey fine and I have attached the file as for the Shownew... Well that seemed to piss off DrWatson and I had at least 15 of the DrWatson error messages pop up at once all the same message. Any way it did make a Shownew log but it seems to just have the Windows XP version # I will attach it any way

    Thanks

    (EDIT) Also the NTVDM errors came up when i ran runkeys
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not extract GetRunKey.bat and ShowNew.bat (and all the other files in the ZIP) from the ZIP files. You must follow the directions in the download links. I already said this previously!
     
  22. gnatsum39

    gnatsum39 Private E-2

    I will DL them and Unzip them again but as far as i know all the files unzipped

    Show new has 4 files grep.exe locate.com ltime.exe and the Shownew.bat

    Runkey has 4 also grep.exe locate.com ltime.exe and getrunkey.bat

    I extracted them to seperate folders in the root c: drive in folders of thier own named after them
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But you must run the .bat files from outside of the ZIP. According to your GetRunKey log, you did not do that.
     
  24. gnatsum39

    gnatsum39 Private E-2

    Ok Lol but they are unzipped and I am running them out side the zip file. They are in a folder named C:\getrunkey and C:\Shownew and the ZIP files they came from are in C:\DWLDS. I used PKZIP and the second time I used Winzip or what ever they call the one in windows.

    I will DL them again and re-Unzip them
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't need to download them again! That is not the problem. The problem is related to how the are run. Are you using Windows Explorer to locate the .bat files and are you double clicking on them from the Windows Explorer window to run them?

    If you double click on the ZIP file you are going to run your ZIP file extractor which will show you the file list but you cannot run the .bat files from this window.
     
  26. gnatsum39

    gnatsum39 Private E-2

    Yes absolutly

    I do understand that I said extract all to C:\shownew and C:\getrunkey folders that I made just for them
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Here is a another way to try it which cannot be wrong as long as all files are extracted.

    Click Start, Run, and enter cmd and click OK. Then enter the below commands in the command prompt window:

    cd C:\getrunkey
    getrunkey.bat

    Do you get any error messages in the command prompt window?

    Do similar for ShowNew.bat!

    cd C:\shownew
    shownew.bat
     
  28. gnatsum39

    gnatsum39 Private E-2

    One minute I am jumping from comp to comp to do this as it is real hard to type with 20 error messages in the screen so I am using my home net to com with you :)
     
  29. gnatsum39

    gnatsum39 Private E-2

    Ok I did the same thing only in the Command window and all I got was the NVTDM error on both then the command window froze
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please give me the exact word for word error message.

    Sounds like you have some major non-malware problems.
     
  31. gnatsum39

    gnatsum39 Private E-2

    On sec I will do a screeny for ya
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also from a command prompt, enter the below command

    set

    Do you get a bunch of text showing environment variables or do you get more errors?

    If it shows the environment, type set > env.txt and then upload the env.txt file (that command will create it) here as an attachment.
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'll be logging of in a moment! Time to start Thanksgiving activities!

    Another thing I want you to do from a command prompt is the below command

    sfc /scannow

    Does it ask for your CD? If so, put your CD in the CD drive.
     
  34. gnatsum39

    gnatsum39 Private E-2

    Chaslang I am so sorry.... I don't want to be cutting into your familys Thanksgiving so we can resume this another time :) I was actually really stunned to see a response today and I really apprieciate all the time you have put into this for a total stranger..... I will do what you posted above and I have attached some screens with this post. I had to Zip them as the file size was to big for the normal JPEG allowed on this site. I have to get some sleep as I have to work tonight but I am off tomorrow night maybe then we can work on this more.... I can also be skyped if you like but I will understand if not :)

    Thanks again and I really hope I didn't intrude on your family day :(

    Happy Thanks giving to you and your family!
     

    Attached Files:

  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Happy Thanks giving to you and your family too!

    I did not see a snap shot of the NTVDM errors you said you got.

    Did you have all other windows closed and no Windows opened (including notepad) with previous newfiles.txt and runkeys.txt logs before running the .bat files?
     
  36. gnatsum39

    gnatsum39 Private E-2

    Ok I ran the sfc /scannow and it asked for the disk so I put in my origanal XP pro cd and it ran and closed.

    I also included more screens with the NTVDM this time sorry

    Any way again enjoy thanksgiving with your family and don't give this another thought :)

    I must get sleep now I have to be up in 5hrs for work :( I work 12hr night shift as a tech at Shin-Etsu where we make silicon wafers for all the blasted computers that get these problems :p

    Thanks
     

    Attached Files:

  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you rebooted since doing this? If not, please reboot and see if any behavior has changed.

    Also run one of the below that most applies to your OS:

    For Windows XP Pro: download and run XPproFix
    For Windows XP Home: download and run XPHomeFix

    These should be extracted into the c:\windows\system32 folder

    That's it! I going now.....this time I mean it. :D

    You enjoy work while I go enjoy some turkey! :p
     
  38. gnatsum39

    gnatsum39 Private E-2

    Ok I ran the XPfixpro and I also did the command set. I have attached that file so you can view. The good news so far The good old DrWatson hasnt made a house call :p

    I will reboot the PC after this post and see what happens. The only error I have had since I booted it so far is the Application Layer Gateway Service error message.

    Also I talked to my pops last night and he told me that alot of this started when he tryed to install SP2 wich was a big piece of info he left out so maybe I should reinstall SP2? I have it on my File server HD ? thoughts on that? Sorry I didnt know about that before :( I chewed my pops out for it though

    How would one uninstall SP2? Just go to control panel and uninstall programs tab?

    Thanks again for all the help :)
     

    Attached Files:

    • env.txt
      File size:
      1.1 KB
      Views:
      1
  39. gnatsum39

    gnatsum39 Private E-2

    Wow I wonder if the SP2 could be the root of all the DrWatson and other errors. I went to the control panel and tried to do the remove of SP2 and DrWatson went nuts. There were over 100 of them popping up.... it also said uninstall encountered an error right before Dr came up. This was all within a fraction of a second of clicking remove.

    Any way just thought I would share that.
     
  40. gnatsum39

    gnatsum39 Private E-2

    Ok I think all the problems are gone :D I rebooted and did a repair install of XP pro and it appears that all is good.

    So I will have him running AVG for virus protection with auto scan and updates on and Zone alarm for fire wall and what else would you recomend?

    Again I can't thank you enough for all your help in this matter. Without people like you this world would be lost :)

    Thanks so very much
    Brian.
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. I'm happy to hear things are working. Everything we recommend is include in the link below after final cleanup instructions.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and ***ociated C:\combofix.txt log that was created.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    7. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds