detected NTDLL code modification

Discussion in 'Malware Help (A Specialist Will Reply)' started by elalevko, Feb 1, 2008.

  1. elalevko

    elalevko Private E-2

    Dear Geeks,
    I am in need of your help.
    After running numerous spyware/malware/carp removers (and after doing all that I could that was mentioned in the "READ & RUN ME FIRST. Malware Removal Guide" - some was simply uninstallable on my machine for some reason), I still get "detected NTDLL code modification" and of course other not so great stuff on the ComboFix.txt

    Can you offer salvation before I turn to knocking my head on something very hard (oh, wait - I already tried that...)
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to explain what you mean by some of the Read and Run was uninstallable ...what happened exactly.

    First Disable Spybot's TeaTimer as requested in the READ ME

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!



    Now we need to use a new tool.

    * Download and save to RenV.exe from following link to Desktop (
    must be on the Desktop)
    * Now Copy the bold text in the below code box to notepad. Save it as Log.txt to your desktop. (It must be on your Desktop).

    Code:
    C:\Program Files\MSN Messenger\msnmsgr .exe
    C:\Program Files\Skype\Phone\Skype .exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
    C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FATICAR .EXE
    
    * Now using your mouse, drag Log.txt onto RenV.exe
    * When finished, RenV.exe will produce a new log names Log.txt on your Desktop I will ask for this log later.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.
    Then attach the new logs:

    * AVG Antispyware log
    * Log.tx from running RenV
    * C:\MGlogs.zip
     
  3. elalevko

    elalevko Private E-2

    Dear TimW,

    Regarding the uninstallables from the Read & Run I discovered that the problem was that I downloaded them in regular mode. When I entered "Safe mode with Networking" the installs where downloaded correctly (I guess) and I was able to install them.

    I disabled Spybot's TeaTimer as requested in the Read & Run.

    I used the Log.txt (I created from the code box) on the RenV.exe but it gave a lot of "Could not find ..." messages (I attached the log file).

    I ran C:\MGTools\GetLogs.bat and attaches C:\MGlogs.zip

    I also ran Avg Antispyware scan and attached the report (I hope this is what you meant by Avg Antispyware log)
     
  4. elalevko

    elalevko Private E-2

    And here are the attached files...
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to re-run AVG and have it fix all that it finds!

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Tell me what these are:
    C:\Documents and Settings\Jaime Franzese\Local Settings\Application Data\PSPcsB6Fm0N ---> if you don't know, delete it.


    Now use windows explorer to find and delete:
    C:\WINDOWS\system32\gebyv.exe
    C:\WINDOWS\system32\gebyv.dll_old
    C:\WINDOWS\system32\vybeg.ini
    C:\WINDOWS\system32\vybeg~1.ini

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this ...and tell me if you have any problems doing the above.
     
  6. elalevko

    elalevko Private E-2

    Hello TimW,

    I think you mixed me with another post - I don't have any gebyv.exe problems in my HijackThis log...
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is very strange ....your logs will not open....please delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip ...now redownload it and run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  8. elalevko

    elalevko Private E-2

    Sorry for the delay,

    Here is the MGlogs.zip and the error message I got when I ran it:

    ---------------------------
    ProcessDll.exe - Application Error
    ---------------------------
    The application failed to initialize properly (0xc000007b). Click on OK to terminate the application.
    ---------------------------
    OK
    ---------------------------

    Regards,
    Elalevko.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have a program that is disabling startup items:

    and also here:
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is called AutoRuns Tim. See: Autoruns
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds