Unable to run online virus software

Discussion in 'Malware Help (A Specialist Will Reply)' started by spazgirl, Apr 26, 2006.

  1. spazgirl

    spazgirl Private E-2

    Hello,

    I have "downloader.ay" on my computer. I have removed it with Windows Defender and AdAware multiple times, but it keeps coming back. I am following the protocol in the "Read and Run Me First" thread - I have done all of step 5 - but I am unable to run the online virus software. On both sites, I get the information bar telling me that the ActiveX installation was blocked, but when I choose to install, I never get the prompt to continue. The information bar just goes away. I have changed the security settings to allow all the ActiveX requests, but that doesn't seem to help.

    Also, I am unsure about something in the protocol instructions. After the malware was removed by AdAware and Windows Defender, I disabled the System Restore, restarted, rescanned (nothing was found) and then enabled the System Restore again. Was I supposed to wait to do this until after I ran the online programs? Do I need to start all over again?

    Windows Defender popped up again while I was trying to use the online programs to tell me that it had found the downloader.ay again. It says it's located at C:/Windows/system32/taskdir.dll, if that is helpful.

    Any help would be greatly appreciated!

    Thanks!

    Dana
     
  2. spazgirl

    spazgirl Private E-2

    Oops, I forgot to include my system information. I ran a program to generate the info, so I am attaching the reports.

    Thanks!
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    No you should not have done this. The READ ME says
    Which I believe clearly states After Malware has been removed. If you are posting here for help, that would mean malware has not been removed since you still have problems.

    First let's just try something simple, boot into safe mode and located the below file and delete it:
    c:\Windows\system32\taskdir.dll

    DO NOT delete taskdir.exe !!!!

    Were you able to find and delete taskdir.dll? Is everything OK now? If not, continue on to the below:

    Run this: Running Ewido Anti-Malware and attach the Ewido log

    Then complete step 7 of the READ & RUN ME and attach a HijackThis log.
     
  4. spazgirl

    spazgirl Private E-2

    Thank you for getting back to me! Here is what I have done:

    In safe mode, I tried to delete the file as instructed but I was unable to find it. I do have my settings to show hidden and system files.

    I downloaded and installed Ewido. I ran CCleaner. I did the update for Ewido. When it finished updating, it told me it found an infection at the same place (C:\windows\system32\taskdir.dll) - I told the program to ignore this and then I rebooted into safe mode and ran Ewido. Then I rebooted into normal mode and Ewido told me that it found the same infection in the same place. I ignored this and then ran HJT.

    While in normal mode, I tried to just browse to the file in Windows Explorer to see if it was still there. When I opened the System32 folder, Windows Explorer crashed.

    Thank you again for your continued help!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It looks to me like Ewido removed the taskdir.dll file. You should not be telling Ewido to ignore problems, you should be telling it to fix problems.

    You have no major issues in your HJT log. Just some minor fixes to do.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file)
    O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"

    After clicking Fix, exit HJT.:

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.
     
  6. spazgirl

    spazgirl Private E-2

    I ran HJT and fixed those items. Then I reset the web settings. I rebooted in normal mode, and then Ewido gave me the message that it had found a proxy.lager.aq infection in C:\Windows\system32\taskdir.dll. I cleaned that and then ran HJt for a new log, which is attached.

    Please let me know what I should do next. Thanks again for all the help!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm a little baffled as to why all the below still appear if you reset web settings:
    Did you get any messages from Windows Defender or another program about changes to your start pages? You have to approve them or the changes will not be made. So this time while doing the below if you get any messages while after resetting web settings (even if after reboot) make sure you approve them. Also please make sure for now that you set your home page to www.majorgeeks.com. That way I know that the reset worked. You can always change it to something els later.

    Okay now that you let Ewido fix your taskdir.dll problem, the real root problem has shown it self. We will fix this below.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\WINDOWS\system32\taskdir.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=presario&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=presario&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/wdgt3/*http://www.yahoo.com/ext/search/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/wdgt3/*http://www.yahoo.com/ext/search/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/wdgt3/*http://www.yahoo.com
    O4 - HKCU\..\Run: [taskdir] C:\WINDOWS\system32\taskdir.exe
    O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
    O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
    O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\system32\taskdir.exe
    C:\WINDOWS\system32\taskdir.dll
    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Again make sure you allow/accept changes to start/search pages if you get any messages about this!
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  8. spazgirl

    spazgirl Private E-2

    Okay, I followed all your instructions, but I should tell you that prior to getting your last response, my boyfriend uninstalled Avast and installed AVG; he found and cleaned several problems with it and I suppose that resulted in the changes I found when I followed your instructions. So here is what happened:

    In HJT, I did not find C:\WINDOWS\system32\taskdir.exe - I was able to fix all the other line items you listed.

    In safe mode, I did not find C:\WINDOWS\system32\taskdir.exe or .dll, but I did delete everything in c:\windows\Prefetch. Then I ran CCleaner. Then I reset the web settings and rebooted into normal mode. I did not get any program notifications about changing my settings (I uninstalled Yahoo Central, which had asked me last time and I did allow it at that point.) I strayed from the directions slightly - I launched Firefox before running HJT and set it as the default (sorry, I wanted to look at the post again) and then I ran HJT.

    I think that the problem is solved (I hope so, that is, and if you agree, please let me know and I will go ahead and do the System Restore process) and I really and truly appreciate all of your help. Another thing we did while we were waiting for your response was to review the post about protection from malware, and we installed ZoneAlarm and today I will substitute the Sun Java for the MS one. My boyfriend has promised to stop using IE - will it be safe to export his bookmarks and import them to Firefox? We have done everything else on the list, so hopefully we will be able to avoid future infections.

    Thanks again for your patience and your amazing help!

    Dana
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I believe you only had AVG installed. And I still see it running. You must make sure you keep an antivirus installed and running.


    You will still need to use IE for some websites (including Microsoft to get updates). Yes you can import the bookmarks. Just be careful that there are no bad ones in the list.

    You already have Sun Java but you are running an old version. Install the new version then uninstall all old versions.

    You should uninstall Ewido since it is a trial version. You have Windows Defender as your real time blocker.

    Your log is basically clean! Only the below should not be there! Not sure why it appeared:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm

    It is not really malware but I'm not sure why it did not get fixed with the Reset. It could be that Windows Defender blocked the change to it.

    Yes make sure your toggle System Restore as recommended. and complete the How to protect thread steps.
     
    Last edited: Apr 28, 2006
  10. spazgirl

    spazgirl Private E-2

    Okay, I removed that file and systematically went through every step in the How To Protect... and the Understanding... posts. I have learned so much and I really appreciate all the help!

    Thanks again!

    Dana
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds