Dcads Virus Removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by GeekSquad143, Jan 2, 2008.

  1. GeekSquad143

    GeekSquad143 Private E-2

    I have somehow infected myself with the Decads virus. I have been following the topic "Can't Get Rid of Dcads Popups" at
    www. someplace else

    I followed the instructions on the first two pages, but have still been unable to remove the virus.

    Please Help!!!
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. GeekSquad143

    GeekSquad143 Private E-2

    Here are the logs...AVG is still scanning and I will send it ASAP.
    I am having a hard time accessing the internet.
    Everytime I open Firfox, it shuts down after only a few seconds, so I am using Internet Explorer now...we will see how long it lasts!
     

    Attached Files:

  4. GeekSquad143

    GeekSquad143 Private E-2

    Here is the AVG Scan Log...
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Have you uninstalled Firefox and tried re-installing? Tell me how things are running.
     
  6. GeekSquad143

    GeekSquad143 Private E-2

    Disabled anti-virus and anti-spyware.
    Ran C:\MGtools\analyse.exe and did system scan.
    Fixed O2 - BHO: (no name) - {1648E328-3E5A-4EA5-A9C6-E5F09EE272DA} - (no file)
    Exited HJT
    Copied new entry to notepad, then merged with registry.

    Things have been running better, but not as they should.
    I still get random popup ads a few times a day from Dcads.

    Internet Explorer is driving me crazy...
    I am in the process of uninstalling and reinstalling Firefox.

    Can I re-enable my anti-virus and anti-spyware now?
     
  7. GeekSquad143

    GeekSquad143 Private E-2

    I uninstalled and reinstalled Firefox, but as soon as it opens to my homepage, it shuts down a few seconds later.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's reset your IE defaults and then I want you to run a BitDefender online scan:

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Bitscan link: agree to the license and then select Scan. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files. Once Bitdefender completes the scan:

    Click-on the Detected Problems tab. Then select Click here to export the scan report

    When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.
     
  9. GeekSquad143

    GeekSquad143 Private E-2

    Error Message from Bitscan:
    Could not load the Online Scanner! Click here for other possible fixes.

    I think this is because my internet explorer is running with add-ons disabled.
    I have tried enabling add-ons but with no luck.
    Suggestions?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go Here and enter your email addy then download the program when you get the reply. Run it and save the log.
     
  11. GeekSquad143

    GeekSquad143 Private E-2

    Thanks...
    The scan is currently running.
    I am sure it will take quite a while...usually the scans go up to over 200,000 objects.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know what it finds. :)
     
  13. GeekSquad143

    GeekSquad143 Private E-2

    The scan is still running...
    I was able to get Internet Explorer with add-ons to run...
    So, I can give you either the BitDefender or the Malwarebytes logs.
    Which one would you prefer...or both?
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Both would be sweet ...let one finish before you start the other.
     
  15. GeekSquad143

    GeekSquad143 Private E-2

    Here is the Malware Log...
    BitDefender is currently running.
     

    Attached Files:

  16. GeekSquad143

    GeekSquad143 Private E-2

    BitDefender finished and found nothing. It would not let me save the scan as you directed...
     
  17. GeekSquad143

    GeekSquad143 Private E-2

    I did one more additional scan from my regular anti-virus software just for kicks...

    Logfile is attached!
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That was good....you really need to uninstall Limewire ...it is known to have malware.

    Are you still having problems?
     
  19. GeekSquad143

    GeekSquad143 Private E-2

    I have uninstalled LimeWire...as soon as I realized I got this virus, actually.
    The computer is about the same...it still shuts down FireFox the majority of the time and I have random popups...

    I just wish I could get this fixed before I go back to college on Sunday! :(
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download AdAware.

    Tell me if that kills it.
     
  21. GeekSquad143

    GeekSquad143 Private E-2

    I have AdAware already and have updated it and run the program.

    I just got another popup...they no longer say they are from Dcads.
    Now is says "http://login.tracking101.com"

    What do you think?
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download Navilog1 by IL-MAFIOSO:
    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.zip
    • Extract its contents to the desktop.
    • Double click on navilog1.exe to install it on your computer.
    • When the installation is complete, the tool will start automatically.
    • If it doesn't start automatically, please double click on Navilog1 shortcut on your desktop to run it.
    • Press E for English from the language Menu.
    • Type 1 in the next Menu to select Search and press Enter.
    • Wait for the Scan to finish (It may take a reasonable amount of time)
    • Press any key as requested .
    • A new document will be produced: fixnavi.txt.
    • Please copy/paste the contents of this report in your next reply.
    The report is also saved in the root of the directory, "%SystemDrive%\fixnavi.txt". (usually C:\fixnavi.txt)
     
  23. GeekSquad143

    GeekSquad143 Private E-2

    I will do this in just a moment...
    Just for fun, I went ahead and updated my AdAware and it is running now.
    I ran it yesterday and it found nothing...it is halfway done now and has found 85 total infections!
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That may just do it! :)
     
  25. GeekSquad143

    GeekSquad143 Private E-2

    Here is my log from AdAware.
    I just ran the other program as well.

    Let me know what you think...
     

    Attached Files:

  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I see AdAware found the ad-yield cookies among a host of others ....how are you running now?
     
  27. GeekSquad143

    GeekSquad143 Private E-2

    Running fine except for the inability to run firefox... :(
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  29. GeekSquad143

    GeekSquad143 Private E-2

    Ok...I will try that now.

    Can you look at my Add/Remove List to see if anything else needs to go?
    Thanks... :)
     

    Attached Files:

  30. GeekSquad143

    GeekSquad143 Private E-2

    I am running Mozilla FireFox right now and it appears to be working fine!
    I hope that it lasts! :)
     
  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Everything looks good ...If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  32. GeekSquad143

    GeekSquad143 Private E-2

    Done!

    Thanks so much...everything seems to be running well. :)
     
  33. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know ....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds