EDOW.EXE removal help please

Discussion in 'Malware Help (A Specialist Will Reply)' started by GCBabe, Mar 28, 2005.

  1. GCBabe

    GCBabe Private E-2

    Hi,
    Can anyone help me please,
    About a week ago i had a pop up on my McAfee asking to grant access to EDOW.EXE which i blocked straight away. Now ever since i have had an error message pop up every now and again saying EDOW.EXE has encountered a problem and do i wish to send problem to microsoft ?

    I have run Spybot, Ad-aware, Pest Patrol, Spyware Blaster and a full scan with McAfee and nothing has been picked up about EDOW.EXE at all ???

    Can anyone tell me anything about it and how i can get rid of it please ?

    I have also attached a hijack this log file

    I found the EDOW.EXE in a folder on my C drive called Temp, i did delete yesterday but it has come back this morning and ive had 4 pop ups in 20 mins.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have HijackThis installed incorrectly and you did not exit your browser before running HijackThis. You are running HJT from your Desktop.

    Please follow the below guidelines from now on:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Look in Add/Remove programs for the below and uninstall them if found:
    Admanager Controller
    SAHBundle or Bundle

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\Program Files\Admanager Controller\AdManCtl.exe
    C:\Documents and Settings\Administrator\Local Settings\Temp\bundle.exe
    C:\Program Files\Admanager Controller\AdManKeep.exe
    C:\temp\EDowPack.exe
    C:\temp\EDowPack.exe
    C:\temp\EDowPack.exe


    After killing all the above processes, click "Back".

    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
    O4 - HKLM\..\Run: [Admanager Controller] C:\Program Files\Admanager Controller\AdManCtl.exe
    O4 - HKLM\..\Run: [SAHBundle] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\bundle.exe

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\Admanager Controller <--- the whole folder
    C:\Documents and Settings\Administrator\Local Settings\Temp\bundle.exe
    C:\temp\EDowPack.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  4. GCBabe

    GCBabe Private E-2

    Hi,
    I have followed your instructions, here is my log file now attached

    Thanks
    Em
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! That looks better! Are you having any problems?

    But note your OS and IE are way out of date! You must update! See and run the steps in the below link:

    How to Protect yourself from malware!

    Also your Ad-Aware 6 is out of date.
     
  6. primal

    primal Private E-2

    Hi

    I have loaded up HJT as set out above and have attached the txt log that has resulted. Is there anything wrong with this and if there is what do I do next.

    I have had a problem with 108search and a whole pletherer of annoying spyware and have managed to remove all barring this Edow.exe file which in fact will not delete as there is something stopping it.

    Regards

    Primal
     

    Attached Files:

  7. GCBabe

    GCBabe Private E-2

    Thanks for all your help, i have downloaded the new version of ad-aware and it detected another file i was trying to get rid of also, the EDOW.exe has now gone also from following your instructions re: going into safe mode

    fingers crossed now it stays that way

    Many thanks again
    Emma :D
     
  8. GCBabe

    GCBabe Private E-2

    Primal,
    If you follow instructions in #3 EDOW will be gone ! worked for me anyway :)
     
  9. primal

    primal Private E-2

    Hi GCBAbe

    Thanks for pointing me in the right direction, EDOW is no longer. These things are becoming a bit of a bind but at least there is a way to remove these niggling nags.

    Regards

    Rob
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! But you must follow all the steps in the How to protect thread I referred you to.
    If you do not, you will find yourself back here again looking for help.
     
  11. Bert

    Bert Private E-2

    I have the same thing, EDow.exe on my computer. I have tried to get rid of it using Ad-Aware 6, Spybot S&D, and McAfee virus scan, but it has not come out. I have blocked it with the McAfee firewall. I have deleted it in my temporary folder, but it comes back. An error message also pops up every so often, saying that it has encountered a problem. I am running windows XP SP1 home edition. If anyone could help me, I would appreciate it.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ad-Aware 6 is old and out of date. Are the rest of your tools out of date too? Please start your own thread for your problem. But run ALL the steps in the sticky thread first:

    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
     
  13. Bert

    Bert Private E-2

    Thank you. I have gotten rid of Ad-Aware 6 and downloaded Ad-Aware SE. I ran a scan and it has seemed to have gotten rid of the problem. EDow.exe no longer exists in the Temp folder.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! If you have anymore problems related to this, please put them into a new thread of your own.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds