cant remove win32trojandropper or win32.adware.onestep, please help

Discussion in 'Malware Help (A Specialist Will Reply)' started by Contagion, Nov 1, 2008.

  1. Contagion

    Contagion Private E-2

    I just ran ad-aware and it found numerous infections, it had cleared them all except for Win32trojandropper and win32.adware.onestep

    Quarantine does nothing, remove does nothing.

    Any help would be extremely appreciated, thanks.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide

    Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. Contagion

    Contagion Private E-2

    What is Browser Activity Monitor and IEPR.exe process

    Ive noticed that when i go to alt tab out of something, something called browser activity monitor is running. It does not appear under applications in the task manager and when i tab over to it, it does nothing.

    I found a suspicious process running called IEPR.exe and i ended the process, which got rid of the browser activity monitor.
     
  4. Contagion

    Contagion Private E-2

    alright did all the housecleaning but im on a tight schedule atm.

    I'll post a log tomorrow after work.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'll be here when you are ready...:(
     
  6. Contagion

    Contagion Private E-2

    ...yeah sorry for the delay, ive been running the scanners tonight, i'll have the logs in a day or two thanks for being patient, ive been a little busy.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem. :)
     
  8. Contagion

    Contagion Private E-2

    I started getting problems about 2 weeks ago when i went to a site and my computer locked up and then crashed. Since then my computer has been running slowly, and all streaming media i try to play online lags considerably at first, then at random intervals throughout the stream. All streams have always played smoothly before.

    When starting windows, the music which plays is laggy and distorted, although it is fine when logging off usually. It has been distorted at times but rarely, and the distortion/lag in the music is minimal.

    I have ran numerous scans from various programs before comming to this site and the programs gave varying results. Ad aware at times would come up with nothing, then find something. I would have difficulty removing the viruses which at first were win32trojandropper and win32.adware.onestep. Eventually the program did confirm they were removed, but various scans afterwards brought them back up, in addition to other programs which i dont recall the names of.

    I have completed all the requested scans and have attached the logs below. No improvement to my startup music or video streams.

    Before after i started my pc i would have to alt tab to find a program running called browser activity monitor. Selecting it did nothing, and the process did not appear under the applications in task manager. I eventually tracked down the process through trial and error and it was called IEPR.exe the only process in all caps. Ending it would remove the browser activity recorder.

    After running the scans you suggested, this no longer appears when i alt tab after startup like before, and IEPR process is no longer there.

    Another issue has arisen after my attempts of removing the malware before trying your scan methods.

    2 error messages come up upon startup which read:

    C:\windows\system32\nucp\dll
    The specific module could not be found.

    the second one reads:
    C:\windows\system32\nvmctray.ll
    The specific module could not be found.

    When running MG tools i got an error which read

    Error has occured at modregistry_inigetstring(sfile=system.ini.sSection=boot,svalue=shell
    Error #5 invalid procedure call or argument.
     

    Attached Files:

  9. Contagion

    Contagion Private E-2

    here is my final log, mg logs
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean....:)

    Since you uninstall AVG, you should find and delete:
    C:\Documents and Settings\All Users\Application Data\AVG7

    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking fix, just exit HJT.

    As to this error:
    C:\windows\system32\nvmctray.dll ---> Taskbar icon loader for all NVidia brand AGP PCI card driver software configurations. Not critical to load at start up.

    What problems are you still having?
     
  11. Contagion

    Contagion Private E-2

    The only problem i am still having is delayed computer sound effects, like clicks or little noises that play for window prompts and whatnot.. and my streams still stream slowly, with distorted sound.

    My pc was fine before the viruses, all streams were fine sound effects were fine...

    Could the viruses have messed up system files or something? I cant really reformat because i dont have xp discs..
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is possible, however, with only 512 of ram you could not be certain that the steams are downloading and being processed fast enough.

    Without your xp disc, you can check that all system files are intact. :(

    If you could borrow your version, you could run an sfc scan. You may wish to post in the software forum for guidance.
     
  13. Contagion

    Contagion Private E-2

    well as i said before, my streams always ran fine up to the point my pc crashed and i got malware. I visit the same sites i have been to weeks before with consistent streaming problems when none were present before my malware removal attempts.

    I will try to get ahold of an xp disc to reformat. Its not just with streaming media as ive said.. The default windows startup chime thing is all laggy and distorted as well, and there are delays in simple sound affects such as mouse clicks and window promps.... None of which were present before the malware problem.

    Anyway i appreciate your help, thanks a lot.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is possible also that any attempts to remove malware may have removed some system files....I would suggest first running the sfc scan when you get a disc. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds