odafadufodizires.dll

Discussion in 'Malware Help (A Specialist Will Reply)' started by threecoins, Jul 25, 2010.

  1. threecoins

    threecoins Private E-2

    Long story short: I got some adware popups, so I scanned my system with: Spybot, Malwarebytes', Avira, and Dr. Web. I have gotten most of it off, however when I look into MSCONFIG I find two files that I cannot turn off, they keep turning on and creating new entries. odafadufodizires is one, it is located in the Windows folder as odafadufodizires.dll, and the other is Kethel3, also located in the Windows folder. I believe that Kethel3 has been removed, I cannot find it in the Windows folder, with hidden files on. I can turn it off now, but I still have the problem with odafadufodizires.dll. I cannot delete it. It says that access is denied, it may be write protected etc. It isn't write protected. I just renamed it, and it still turns itself on. I also removed everything I could find in the registry about it. Any help appreciated. Will post a hijack this log in a minute.
     
  2. threecoins

    threecoins Private E-2

    I am also being redirected in my browser, I checked the host file, it hasn't been modified.
     
  3. threecoins

    threecoins Private E-2

    Here is the Hijack this log, sorry about the tripple post.
     
    Last edited: Jul 25, 2010
  4. threecoins

    threecoins Private E-2

    I waited to long on posting the logs, after I tried to edit and post the whole MGlogs.zip file, sorry. Will post here.
     

    Attached Files:

  5. threecoins

    threecoins Private E-2

    Well, I was reading the XP cleaning guide, it said to change MSconfig to normal mode. I did, and it really messed me up. I couldn't do anything because "The file is infected" I ended up finding that if I lagged my system enough, I could get the programs I needed started. I turned those off, and am once again scanning my system. I also cannot go to ANY website in IE or Chrome. I have to use AOL. The HOSTS file is ok, it isn't blocking anything (besides spybot related things) I will post an update MGlogs.zip.
     

    Attached Files:

  6. threecoins

    threecoins Private E-2

    ComboFix cleaned most of it up, there were some remanents of it left I had to remove manually. I am able to use IE and Chrome again, i'm sure someone would have helped me soon. I trust this site :)
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Each time you post you are moved back to the end of the line for help. We work oldest thread to newest.
    You need to attach ALL the requested logs, which include:
    SAS
    MBAM
    ComboFix
    and RootRepeal if it runs.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds