shell32.dll kernell

Discussion in 'Malware Help (A Specialist Will Reply)' started by jammyt, Sep 19, 2006.

  1. jammyt

    jammyt Private E-2

    i recently did a scan with avg and found that shell32.dll and kernel.dll were marked as changed under status and it warned of a possible trojan!!!... i don't know if this something or nothing... i have followed the procedures laid
    out for cleaning up malware and post the result of the scans...nothing was found but if someone could take a look and confirm i've got no dodgey processes going on i'd appreciate it muchly as i've noticed a real drop off in performance whilst using IE (CPU 80+%)..also get multiple iexplore.exe processes in the task mgr....i have a hijackthis report as well but not attached...thanks
     

    Attached Files:

  2. jammyt

    jammyt Private E-2

    here's the hijackthis report..
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please attach the other logs requested in the READ ME:
    • Bitdefender - from step 6
    • Panda Scan - from step 6
     
  4. jammyt

    jammyt Private E-2

    here are bitdefender and panda reports..thanks
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is your copy of Spyware Doctor (which is old by the way) a paid version or a free version? If free, uninstall it now.

    And while in Add/Remove programs, uninstall the below two old versions of Sun Java:
    J2SE Runtime Environment 5.0 Update 6"
    Java 2 Runtime Environment, SE v1.4.2_12"


    I don't see any major malware issues. You just have some minor cleanup to do. The reason for those files being changed is probably due to installing some Windows updates recently.

    Make sure viewing of hidden files is enabled (per the tutorial).
    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    c:\program files\common files\Totem Shared <--- the whole folder:

    Now reboot in normal mode.

    Now attach a new HJT log and tell me how the steps went.

    Also attach a new logs from GetRunKey.

    Make sure you tell me how things are working now!
     
  6. jammyt

    jammyt Private E-2

    ok here are the remaining logs..stills seems a little sluggish when on the interenet on certain sites but has improved..........thanks for your help.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not answer my question about Spyware Doctor and I still see it installed. Does that mean it is a paid version?

    Did you add the fixWLK.reg registry patch to the registry?
    Did you get a success message?

    The reason I ask is because it does not look like it was added.

    Please do the below:

    • Click Start, Run, and enter MSconfig and click OK.
    • Now click Normal Start then click Apply and then OK.
    • Now reboot.
    • Now add that fixWLK.reg registry patch to the registry again and make sure you tell me exactly what happens.
    • Now attach a new log from GetRunKey.
     
  8. jammyt

    jammyt Private E-2

    Yes, i do have the paid version of spyware doc...still licensed but i can uninstall it if need be.

    Double clicked the fixWlk.reg file and got the following information dialogue: "fixWLK.reg has been successfully entered into the registry". Ran getrunkeys again afterwards... log attached.

    thanks
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! Keep it but uninstall Windows Defender to avoid conflicts. Then reboot before continuing to the below.

    It still did not work. Possibly this is due to Windows Defender & Spyware Doctor blocking the changes. Or it could be due to you not having permission to change those registry keys. Now the Windows Defender is uninstalled, disable (shutdown) Spyware Doctor and do the below:

    • run MSconfig and select Normal Startup (if already selected just tell me). Exit MSconfig but do not reboot if it tells you to do so.
    • now reapply the registry patch one more time
    • Now reboot into safe mode and run the registry patch one more time from safe mode
    • Now reboot into normal mode and attach a new GetRunKey and a new log from ShowNew
     
  10. jammyt

    jammyt Private E-2

    i had already uninstalled windows defender and spyware doctor doesn't run by default. ran the registry patch in normal and then safemode. Got the same message as before to say it has been entered with success, in both cases. logs attached.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the signatures too!

    Not true! Observe direct from your HJT log:
    It does not runn the scanner by default but the service for the program and active protection are always loaded and running at startup.


    Yes but this time it worked!

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds