Q?_disk.dll

Discussion in 'Malware Help (A Specialist Will Reply)' started by thedagem, Sep 3, 2005.

  1. thedagem

    thedagem Private First Class

    Hey there,
    It's me Thedagem I just signed up today so bear with me. I am usually very good at fixing things myself as I visit this page a lot and read the forums and such. I have what I believe is a version of the coolwebsearch that comes up in my Symantec AntiVirus Corporate Edition as Disk.dll. Actually it comes up as a Q followed by a series of numbers then _disk.dll. As well as Norton I have the purchased version of Ad-Aware, as well as SpybotS&D, the Microsoft AntiSpyware program, and you guessed it HijackThis. I'm not too good with HijackThis so I don't use it often, I don't want to delete anything that shouldn't be deleted but certain cases call for it. Upon advisement of my friend who is also good with computers (but obviously couldn't help me this time) I recently deleted Ewido and Xoftspy for some odd reason. I have also been advised to delete Spybot and ad aware but that would only leave me with microsofts program and I don't trust it too much yet so here I am. I guess that the virus I have, after detection and "deletion" renames itself as the other CoolWebSearch items do and, well comes back I guess. This is the first time I have been unable to successfully get rid of the thing, and it drives me nuts with all the popup windows and virus warnings from norton. Please help. You guys are the best, I know you can do it.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps below (do not skip any steps in the READ ME FIRST):

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. thedagem

    thedagem Private First Class

    After doing everything stated on that page I still have the problem. I attatched my HJT log like you asked. there is a file that still comes up in Nortons anti virus scan entitled Q????????_Disk.dll the question marks refer to a series of numbers that change everytime. I don't know how to get rid of it. please help.
     

    Attached Files:

  4. thedagem

    thedagem Private First Class

    There are 7 numbers after the q. I don't know if this is helpful or not. but a recent example was q2887402_disk.dll Hope this information helps.
    Thedagem
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Goto Add/Remove programs and uninstall the below if found:
    Daily Weather Forecast
    winCMAPP
    PartyPoker

    Note: Some of the items below may no longer exist if the uninstalls worked. I'm including them as a backup plan.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\Program Files\Daily Weather Forecast\weather.exe
    C:\Program Files\winCMAPP\wincmapp.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R3 - Default URLSearchHook is missing
    O2 - BHO: PicShow Class - {4487598C-2EC7-43A2-870E-6D8D720FDD9F} - C:\WINDOWS\system32\pkshxlvw.dll
    O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll (file missing)
    O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
    O4 - HKLM\..\Run: [Daily Weather Forecast] C:\Program Files\Daily Weather Forecast\weather.exe
    O4 - HKCU\..\Run: [pshower] C:\WINDOWS\system32\pshwr.exe
    O4 - HKCU\..\Run: [wincmap] "C:\Program Files\winCMAPP\wincmapp.exe"
    O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\Daily Weather Forecast <--- the whole folder
    C:\Program Files\PartyPoker <--- the whole folder
    C:\WINDOWS\system32\pkshxlvw.dll
    C:\WINDOWS\system32\pshwr.exe
    c:\windows\system32\qxxxxxx_disk.dll <-- For those qxxxxxx_disk.dll type files,look for all possible matches and delete them.

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  6. thedagem

    thedagem Private First Class

    Ok I have posted my new hijack this log, but there were a few steps you asked me to do that I could not complete. they are as follows
    Boot into safe mode and use windows explorer to delete
    C:\WINDOWS\system32\pkshxlvw.dll
    the file wasn't there
    also I could not find any versions of c:\windows\system32\qxxxxxx_disk.dll
    the only thing I saw that related to disk.dll was perfdisk.dll and I didn't know if I should delete that or not. As far as still having the virus, I won't know until my norton either finds it again, or not. Should know within the hour. Unless you can tell from my log.
    Thanks for your help.
    Thedagem
     

    Attached Files:

  7. thedagem

    thedagem Private First Class

    It seems that everything is gone, thank you very much, I came back to my house just a bit ago, I had no items in quarantine in my Symantec, I ran a scan with spybot and adaware as well as my microsoft antispyware program each one detected something titled ccaccess or something of that nature and I deleted them. I believe the problem with q???????_disk.dll is gone. thank you very much for your hard work and help you guys are the best.
    Thedagem
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean! It may be a good idea to go back to the READ ME FIRST and run the online scanners that you never ran.
     
  9. thedagem

    thedagem Private First Class

    I was unable to run those scanners for some reason. They didn't work the way the read me first had stated. And how did you know I never ran them?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Because they would leave signs in you HJT log if they were run.

    Do you use Internet Explorer to run them as stated in the READ ME? They work just fine for most people when using IE.
     
  11. thedagem

    thedagem Private First Class

    nope! used firefox, that explains a lot thank you I will run them
    Thedagem
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Let me know the results.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds