Super-Spider garbage!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by AA_Freeze, Sep 17, 2004.

  1. AA_Freeze

    AA_Freeze Private E-2

    maybe someone can help me out... I did everythign described in the spyware solutions on this site and have had no luck getting rid of the Super-Spider/Kitasearch garbage. Can someone lend me a hand.... let me know and I will post my HiJackThis log as an attachment. I believe this is something I am manually going to have to remove . Thanks!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please tell me exactly what you have tried and did they find and repair anything. What do you mean by the "spyware solutions"?

    There are many links here where super-spider problems have been resolved. You could try searching for them to see if any of them help. We may still get to a HijackThis log but first I need to make sure you have run ALL the steps from READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
     
  3. AA_Freeze

    AA_Freeze Private E-2

    Hey ! Thanks for the reply. I did everything in the Spyware tutorial in this forum. I have DL'd all of the applications needed also. I even got rid of the "WINLOGIN" as I thought that might be the problem. I am free of any pest according to the virus scans, adware,spybot and so -forth..until I got to a site that requires a login such as ebay that uses active x controls....then the Super-Spider page pops up. What I get when I do a Adware and Spybot clean afterwards are the "wwwcoolsearch" problems. ANy Ideas?

    thanks again!!
     
  4. AA_Freeze

    AA_Freeze Private E-2

    Also, I did take a look at some of the other posts on this subject and tried some of the ideas that you came up with....I think I am close to a sloution, so I hope this might be a speedy fix.

    thanks!
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds promising. Post a HijackThis log as a .txt file attachment if you want some help.
     
  6. AA_Freeze

    AA_Freeze Private E-2

    Ok, I went ahead and let my cpu get infected again...lol. The more I am on the internet the worse it gets...to a point. Mainly Coolwebsearch and a few others... I can get them with adware and spybot in safe mode... but they do return after awhile. Notice in the log that "WinLogin" is back... but shouldnt be a problem removing it again...seems to show up with browser Hijackers and coolwebsearch show in the adware and spybot searches. :rolleyes:
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have enabled viewing of hidden files and folders per the read me first tutorial.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowws.cc/hp.htm?id=9
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - C:\WINDOWS\System32\ZIF3V9~1.DLL
    O4 - Global Startup: winlogin.exe
    O20 - AppInit_DLLs: h6gp3sjkczmdr.dll

    Now use Windows Explorer and go to C:\WINDOWS\system32 and look for h6gp3sjkczmdr.dll.
    If you find it, right click on it and select rename. Change it to h6gp3sjkczmdr.bad
    Tell me the results of these steps.

    Reboot into safe mode and delete:
    C:\WINDOWS\System32\ZIF3V9~1.DLL
    C:\Documents and
    Settings\All Users\Start Menu\Programs\Startup\winlogin.exe

    Now reboot normal and come back with the results of these steps. Post a new HJT log.
     
  8. AA_Freeze

    AA_Freeze Private E-2

    Ok, everything went smooth, renamed the System32 file without any probs, also, the DLL file you asked me to delete in safe mode was not there.

    When I came back to post this I noticed that my home page is now "about:blank" I have not tried any other pages yet.
    Thanks for your help!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Reset Web Settings by clicking Start, Control Panel (for some systems it may be Start, Settings, Control Panel) and select Internet Options. Then click Programs and click the Reset Web Settings button. Then go back to the General tab and set your home page back to what you like (i.e., www.majorgeeks.com).

    Now see if your home page works okay (should be majorgeeks).
     
  10. AA_Freeze

    AA_Freeze Private E-2

    Ok, things are improving somewhat, I am able to block the pages when they popup, but the infection is still on my cpu somewhere obviously. I inclosed my Aware SE log and Hijack this log. I used Adware and Spybot in safe mode before I got back online after your last post to me. Hijack this was used just before this post. Thanks!
     

    Attached Files:

  11. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Are you removing these with the browser closed? Also, did you notice the part about installing spyware when you installed Messenger Plus? If not, get rid of it. You said you could not find the file to delete, is hidden file viewing enabled per the tutorial? I see quite a few returned:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowws.cc/hp.htm?id=9
    O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - C:\WINDOWS\System32\ZIF3V9~1.DLL
    O20 - AppInit_DLLs: h6gp3sjkczmdr.dll
     
  12. AA_Freeze

    AA_Freeze Private E-2

    Hidden file viewing is enabled , also, I dont have messenger plus, only Yahoo messenger. They did return , so any ideas? Also, browser is closed when scanning for anything. Thanks!!
     
  13. AA_Freeze

    AA_Freeze Private E-2

    I have Efax Messenger..its an email option, doesnt have anything to do with the browser. Let me know if this might be a problem.
    Also, what happens is that when I goto Ebay, and after I close my browser, when I reopen the browser my homepage is the "www.windowws.com" and if I do a Scan w/ Spybot and Adware, the log looks exactly like in my previous post. Any ideas? It seems like it is an ActiveX issue, I dont know if this happens on any other pages , but is really annoying non the less.

    I really appreciate everyones help! ;)
     
  14. AA_Freeze

    AA_Freeze Private E-2

    after renaming h6gp3sjkczmdr.dll , it come back just the same, so it is replicating itself, I deleted it in the registry, but I am still having the same issues with coolwwwsearch and these popups that install crap on my cpu.
    Anyhelp?


    thanks!
     
  15. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Check for where it is starting up with a tool like StartupCPL in our admin section. Thats a good bet. Safe mode, delete startup, delete files, Hijack This.
     
  16. AA_Freeze

    AA_Freeze Private E-2

    Ok...Used Registrar Lite and FINDnFix.
    Applnit_Dlls Value was h6gp3sjkczmdr.dll as I suspected.

    View FinDNFix log below. Ran FINDnFiX offline, no network connection.
    See Log below....let me know what you think. I will try what you suggested as well. Let me know if you need a HIjAck this log.

    Thanks!
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not need to run FINDnFix to know that file was in AppInit_DLLs. HijackThis had told you that all along.

    However if you look at your FINDnFIX log you will see 7 problem files indicated in the c:\windows\system32 directory. One of which is zif3v9~1.dll which I asked you to delete and you said you could not find it. Perhaps you not looking for it the right way because as you can see it is there. How did you look for it?

    Run Registrar lite again but this time do the following:
    - copy the following into the address bar or expand the same key by hand:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs

    - Rename the Folder Windows to NotWindows (in the left hand pane of reglite)
    - Double Click "AppInit_DLLs" again and clear the data value:
    c:\windows\system32\h6gp3sjkczmdr.dll < delete this line , 'Apply' and 'ok' to set.
    - Rename the NotWindows folder back to its original name Windows

    - Make sure viewing of hidden files and system files is enabled.
    - Boot in safe mode.
    - While in safe mode. Run HijackThis again and have it fix:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowws.cc/hp.htm?id=9
    O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - C:\WINDOWS\System32\ZIF3V9~1.DLL
    O20 - AppInit_DLLs: h6gp3sjkczmdr.dll

    Now click Start > Run, and enter cmd so you should see a command prompt.

    At the prompt type and enter: cd c:\windows\system32

    Now enter the following commands and keep track of the results for each step and let me know exactly what happens. Make sure you type lines properly and if you get an error, tell me what line you just typed and the exact error message.
    attrib -h -r -s bridge.dll
    ren bridge.dll bridge.bad

    attrib -h -r -s d2kpax.dll
    ren d2kpax.dll d2kpax.bad

    attrib -h -r -s h6gp3s~1.dll
    ren h6gp3s~1.dll h6gp3s~1.bad


    attrib -h -r -s h6gp3s~2.dll
    ren h6gp3s~2.dll h6gp3s~2.bad


    attrib -h -r -s jac.dll
    ren jac.dll jac.bad


    attrib -h -r -s msxslab.dll
    ren msxslab.dll msxslab.bad

    attrib -h -r -s zif3v9~1.dll
    ren zif3v9~1.dll zif3v9~1.bad


    Reboot normal
    Also let me know the resuluts of all the above steps.

    Post a new HJT log.
     
  18. AA_Freeze

    AA_Freeze Private E-2

    I searched in the Win32 Directory, there was a similar file, but not that exact one.

    I ran Registrar Lite and changed what you asked, now I cannot rename the NotWindows folder back to Windows... I get an Error.."Error Renaming"

    Then on all of the lines at the command prompt, I get a syntax error when I use ~

    haha, sorry I wasnt much help this time, is there another way to use a Syntax at the command prompt?

    Let me know and I will redoe the command prompt issue.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There should be no problem renaming back to Windows. Check to see if that registry key (with Windows) still exists and the AppInit_DLLs is still under it.

    There is also no reason why you should be getting a syntax error message at the command prompt when using a tilda (~). It is a valid character for a filename. Go back to that directory using the cmd prompt and type exactly what follows below and tell me what you see

    dir /X h6gp*

    It should be similar to the below but with your filenames:
    Directory of C:\WINNT\system32
    07/22/2002 01:05p 294,160 filemgmt.dll
    09/21/2004 02:20p 11 FILENA~1.TXT FILENAME1.TXT
    09/21/2004 02:20p 11 FILENA~2.TXT FILENAME2.TXT
    3 File(s) 294,182 bytes
    0 Dir(s) 18,569,084,928 bytes free

    You can use Mark, Copy and Paste by clicking on the cmd prompt window's title bar. There is an Edit selection after you right click where you will see these features.
     
  20. AA_Freeze

    AA_Freeze Private E-2

    attrib -h -r -s bridge.dll--Not Found
    ren bridge.dll bridge.bad--Cannot find the file Specified

    attrib -h -r -s d2kpax.dll---Not Found
    ren d2kpax.dll d2kpax.bad--A duplicate Filename exist or Filename cannot be found


    attrib -h -r -s h6gp3s~1.dll ---Not Found
    ren h6gp3s~1.dll h6gp3s~1.bad

    attrib -h -r -s h6gp3s~2.dll---Not FOund
    ren h6gp3s~2.dll h6gp3s~2.bad

    attrib -h -r -s jac.dll---No Error
    ren jac.dll jac.bad---No Error

    attrib -h -r -s msxslab.dll---No Error
    ren msxslab.dll msxslab.bad--No Error

    attrib -h -r -s zif3v9~1.dll--No Error
    ren zif3v9~1.dll zif3v9~1.bad---No Error

    (No Error) meaning I didnt get any message after entering the filename.

    I Can Not change back the Folder "NotWindows"...I get an error message "error changing" when running Registrar Lite

    CMD prompt--for Dir /x h6gp* I get " Volume in drive c has no label"

    HJT log ran after reboot.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay some of those commands have worked okay then. Just do one more thing. Get back to a cmd prompt and go to the c:\windows\system32 directory and run the following and give me the output:

    dir *.bad
     
  22. AA_Freeze

    AA_Freeze Private E-2

    Microsoft Windows XP [Version 5.1.2600]
    (C) Copyright 1985-2001 Microsoft Corp.

    C:\Documents and Settings\Administrator>cd c:\windows\system32


    C:\WINDOWS\system32>dir *.bad
    Volume in drive C has no label.
    Volume Serial Number is D401-DE7C

    Directory of C:\WINDOWS\system32

    09/20/2004 11:10 PM 0 d2kpax.bad
    09/20/2004 11:10 PM 0 jac.bad
    09/20/2004 11:10 PM 0 msxslab.bad
    09/15/2004 10:59 AM 73,216 zif3v9~1.bad
    4 File(s) 73,216 bytes
    0 Dir(s) 35,184,850,432 bytes free

    C:\WINDOWS\system32>
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now go back to c:\windows\system32 and delete:
    d2kpax.bad
    jac.bad
    msxslab.bad
    zif3v9~1.bad

    Then post a new HJT log attachment. And give me an idea of any problems that are still present.
     
  24. AA_Freeze

    AA_Freeze Private E-2

    alright....Deleted those files..but...next to each one was another Dll file with the same name.

    I did everything in safe mode also, then rebooted, cleaned up HijackThis, went to the www.majorgeeks homepage, got offline, cleaned up Hijack this and copied log.
    Im going to get online and see what happens.. will let you know.

    thanks!!!!!!
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you put the below restrictions in place using SpywareBlaster or another tool like that:

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    The O20 line has the file that was hidden before in AppInit_DLLs. I thought we fixed it.
    Fix the below line. And then boot into safe mode and delete the file.
    O20 - AppInit_DLLs: h6gp3sjkczmdr.dll

    This is the long filename of what we were trying to delete when we were using a name like h6gp3s~1.dll


    Also, your comment that said,
    "alright....Deleted those files..but...next to each one was another Dll file with the same name."

    has me worried we did not get all of those files fix.
    You need to delete all the .bad versions as well as the .dll versions (or any other
    matching names with a different extension).
     
  26. AA_Freeze

    AA_Freeze Private E-2

    Yup, thats the mystery here my friend...I will delete the .dll file, and less than 5 seconds later it reappears... :mad:

    I would like to solve this problem as it seems many more have the same issues. I think we are close...H6pg3s~ seems to be the common denominator
    , it alwasy reappears in HIjackThis no matter what we do. I will go try what you suggested and see what happens....those other .dll files respawned after deletion also...
     
  27. AA_Freeze

    AA_Freeze Private E-2

    Yeah, SpywareBlaster.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I want to see if that registry key would looked at earlier with Registrar Lite is back.

    Run Registrar lite again and do the following:
    - copy the following into the address bar or expand the same key by hand:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs

    Tell me if this is found. If so, double click on AppInit_DLLs and check the Value field again and see if the same file is listed.
     
  29. AA_Freeze

    AA_Freeze Private E-2

    yup, same .DLL and same Value...the folder "NotWindows" is still there also, but the value is not present in that folder.

    After all the time we have spent on this it might have been easier to wipe out my Hardrive and start over... :eek:
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yeah! Some of these problems are real buggers. You have to be able to locate the bad files and delete them. The problem that you were not able to locate the c:\windows\system32\h6gp3sjkczmdr.dll file and we were not able to stop the AppInit_DLLs from getting re-populated. We need to get this to work.

    So to start with we must be absolutely positive that viewing of hidden files and system files is enabled.

    Now run Windows Explorer and go to C:\WINDOWS\system32 and look for h6gp3sjkczmdr.dll. If it is there, try to delete it. Let me know what happens.

    If you can find it AND you were able to delete it, run HijackThis and fix the below line
    And then skip down to where it says Last Step then stop here and tell me the results:
    :
    O20 - AppInit_DLLs: h6gp3sjkczmdr.dll

    If you could not find it or could not delete it, run the below:
    Run Registrar lite again but this time do the following:
    - copy the following into the address bar or expand the same key by hand:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs

    - Rename the Folder Windows to MyWindows (in the left hand pane of reglite)
    - Double Click "AppInit_DLLs" again and clear the data value:
    c:\windows\system32\h6gp3sjkczmdr.dll < delete this line , 'Apply' and 'ok' to set.

    - Now run Windows Explorer and go to C:\WINDOWS\system32 and look for h6gp3sjkczmdr.dll. If it is there, try to delete it. Let me know what happens.

    - If you can find it AND you were able to delete it, run HijackThis and fix the below line:
    O20 - AppInit_DLLs: h6gp3sjkczmdr.dll

    - Rename the MyWindows folder back to its original name Windows


    Last Step
    Reboot and come back with the results and a new HJT log.
     
  31. AA_Freeze

    AA_Freeze Private E-2

    I have done this a hundred times so far it seems...the file reappears after 5 seconds...lol....its a mystery man. Any suggestion on how to keep this thing from reappearing?
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download ProcessExplorer from: http://www.sysinternals.com/files/procexpnt.zip
    Unzip it and now run ProcessExplorer and click on File and then Save As. And save the process list. Post it back here as an attachment. Also, from now on if I say to kill a process, use ProcessExplorer instead of Task Manager. Sometimes ProcessExplorer can kill things that Task Manager cannot.
     
  33. AA_Freeze

    AA_Freeze Private E-2

    I use Process Viewer..will that work, I have it already.
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please use ProcessExplorer.
     
  35. AA_Freeze

    AA_Freeze Private E-2

    Ok, here ya go!
     

    Attached Files:

  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't see anything strange in the processes list could we try it again after changing some options?

    With ProcessExplorer running click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked. Now click on explorer.exe. Now also under the View menu choose "Select columns" and put a check mark on "Image Path" now save the process list again and post it.

    Now also download and run RegMon from SysInternals too: http://www.sysinternals.com/files/ntregmon.zip

    Leave Regmon running and also leave ProcessExplorer running and fix the stuff related to h6gp3sjkczmdr.dll again. Watch process explorer and regmon to see if you can observe something that is writing this data back into the registry.
     
    Last edited: Sep 24, 2004
  37. AA_Freeze

    AA_Freeze Private E-2

    Ok..check out the log...nothiing facy going on there...BUT, When I ran Regmon I found about 16 Lines with the h6gp3s~.

    I deleted them all, and have the filter set to that Value ...but am still having the same issues... maybe I used it incorrectly...lol.

    This is very straining on my brain :eek:
     

    Attached Files:

  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see nothing in the ProcessExplorer output. What was Regmon showing you for Process, Path, and other relating to the h6gp3s info.

    You should probably filter on h6gp3sjkczmdr.

    Please disable those restrictions you put in place using SpywareBlaster. I'm wondering whether it is causing problems repairing this problem.
     
  39. AA_Freeze

    AA_Freeze Private E-2

    I did notice that HiJackThis still shows the dll file H3gp6~....any ideas...even with the filters on how does this thing still show up?
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Regmon filters does not stop anything. It is just a filter on what to show you. In other words, it shows you only keys being modified or touched that have H3gp6 in it.

    You need to answer my questions from my last post.

    The problem you are having is that you are never getting the AppInit_DLLs data value and the file itself deleted. I'm not sure why, but something is not working correctly.
     
  41. AA_Freeze

    AA_Freeze Private E-2

    Ok, take a look at the Regmon log, notice the first 2 entries at SVCHOST. Those were set Values before I opened IE...after opening IE the rest appeared. Any thoughts? Filters were off
     

    Attached Files:

  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    - Make sure viewing of hidden files and system files is enabled.
    - Make sure system restore is disabled
    - Make sure you have updated version of Ad-Aware SE, SpyBot S&D, & CWShredder
    - Print these instructions or save them locally. YOU MUST make sure you are disconnected from the Internet & exit all Internet Explorer browser sessions now. Do not open any until I ask you to.
    - Run Registrar lite again an do the following:
    - copy the following into the address bar or expand the same key by hand:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs

    - Rename the Folder Windows to NotWindows (in the left hand pane of reglite)
    - Double Click "AppInit_DLLs" again and clear the data value:
    c:\windows\system32\h6gp3sjkczmdr.dll < delete this line , 'Apply' and 'ok' to set.
    - Rename the NotWindows folder back to its original name Windows

    - Run SpyBot S&D and Ad-Aware SE and clean anything they find.
    - Run CWShredder and make sure you select Fix

    - Now use Windows Explorer and delete: c:\windows\system32\h6gp3sjkczmdr.dll
    - If you have a problem deleting this file, right click on it and select Properties. Make sure Read Only and Hidden are NOT checked.
    - Now run HijacThis and fix: O20 - AppInit_DLLs: h6gp3sjkczmdr.dll


    - Now restart in safe mode without networking support.
    - Now use Windows Explorer and verify that the c:\windows\system32\h6gp3sjkczmdr.dll file is really deleted. If not, delete it again. Run HijackThis and delete the O20 line again.

    - Now reboot normal
    - Perform a new HijackThis scan and save the log
    - Run your browser and come back here and let me know the results of these steps and post your new HJT log as an attachment.
     
  43. AA_Freeze

    AA_Freeze Private E-2

    Ok, all done...can not delete H6gp3s~ , I can change the name to H6gp3s~.bad , but even after that I cannot delete the file. 020 Line appears everytime I exit my browser. I think we are very close....I did all that you listed...this is a real bugger.
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:

    regsvr32 /u c:\windows\system32\h6gp3sjkczmdr.dll

    then click OK. If a dialog box confirming this action appears, click OK.
    Tell me if this works or do you get an error message.

    If it works, try removing the HJT line now and deleting the file.
     
  45. AA_Freeze

    AA_Freeze Private E-2

    ---------------------------
    RegSvr32
    ---------------------------
    c:\windows\system32\h6gp3sjkczmdr.dll was loaded, but the DllUnregisterServer entry point was not found.

    This file can not be registered.
    ---------------------------

    This is what the error said
     
  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Damn! There have been several problems like this lately. I think there is a new breed of AppInit_DLLs around that are extremely difficult to remove. Please try out the program below:

    a-squared (a²) Free edition free but requires an email address to register

    Let me know if it finds anything and what.

    In fact, please go back to the Read Me First tutorial sticky and run all the items I added to a new section today. The section is titled Alternative Scans - If still having problems.
    Tell me the results of these scans.
     
  47. AA_Freeze

    AA_Freeze Private E-2

    Alrighty...did everything...alternative programs found a few mailware items, but nothing substancial. That Applit_DLL file is a Melkosoft product. so I went to the website....DONT DO THAT! Its a russian website, and its full of the same garbage , pop-up city and installs all kinds of garbage on your cpu..lol.

    I got it all clean again, but the Applit_DLL is still there for now.
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure it was Melkosoft. I have had a few people telling me of things from Malcosoft and Melcosoft. Is your spelling correct? In each case the problems are similar, an AppInit_DLL that just will not go away.

    Is h6gp3sjkczmdr.dll actually visible in c:\windows\system32 ? What are the file attributes set to?
    (Right click on it a select Properties to determine that.)
     
  49. AA_Freeze

    AA_Freeze Private E-2

    Read Only and Hidden are UNCHECKED....100% positive its Melkosoft

    File is visible, and connot be deleted..it does delete, then reappears after 3-4 seconds....lol.
     
  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Search your registry using Registrar Lite for Melkosoft and tell me what you get.

    Also look in c:\windows , c:\windows\system, and c:\windows\system32 for strange file names like this dll. They do not have to match the exact name. Anything that looks strange and of random nature in characters used. There may be some .exe files too. Tell me what you find.
     
    Last edited: Oct 3, 2004

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds