Help with popups

Discussion in 'Malware Help (A Specialist Will Reply)' started by dt196, Jul 17, 2006.

Thread Status:
Not open for further replies.
  1. dt196

    dt196 Private E-2

    I have gone thru the whole process listed in the sticky before posting this. It started with clicking on link which seemingly took over the puter. Any help would e greatly appreciated.
     

    Attached Files:

  2. dt196

    dt196 Private E-2

    Sorry, I missed some information on the first post.
    There seems to be a dll file in windows\system32 that changes it's name on each reboot. Search & destroy comes up with a "command service" that it can't remove.
    Ad aware finds a " C\windows\system32 dnl6013se.dll" that it can't get rid of and the name of this file changes with every reboot.
    When rebooting in normal mode, I get a box stating " Error loading we404798.dll" along with another box that states " An exception occurs while trying to run "C\windows\system32\tepelib.dll,dllget version"
    I couldn't get Panda Active scan to work, I kept getting an error on page when clicking on local drives.
    I couldn't upload the Hijack this text file after seemingly following all the instructions.
    This seems to have all started when a link redirected to a site named zestyfind.com
    Thanks
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run the below two procedures!

    First run this Look2Me VX2 Removal and then attach the requested log to your next message.

    Then run this Qoologic Removal Procedure


    Now look in Add/Remove programs for ToolBar888 and uninstall if found.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Network Station Task Manager ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    TKNT

    If you receive any error messages just ignore them and continue.

    Now exit HJT and reboot when it tells you it needs to.

    After reboot, look for the below file and delete it if found.
    C:\WINDOWS\tasknt.exe

    Now attach a new HJT log.
     
  4. dt196

    dt196 Private E-2

    Chaslang,
    Thanks for the help. I posted again late last night after getting no response from anyone. I was afraid that I didn't supply the right information or did something wrong in the first(this one) post. I didn't want to offend anyone.
    I did everything you said to do in the above post. The only thing that didn't work as planned was thatLook2Me Destroyer didn't automatically reopen on the first or any subsequent reboot. I ran it again and it didn't find any other modules and I did check Run this program as a task.
    I'm still getting a Rundll box on every reboot that says "Error loaing we404798.dll The specified module could not be found"
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I also responded to your other thread. Please remain in that thread. This thread is closed.
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds