Unheard of .dll file?

Discussion in 'Malware Help (A Specialist Will Reply)' started by 3663, Feb 22, 2011.

  1. 3663

    3663 Private E-2

    Hi all, Just a query.
    New to the forums just found it yesterday while looking for this file, found some pretty useful info, especially the Malware removal post, some really good tools, bummer that for my main machine i use 64bit XP pro.
    As off yesterday ESET is bringing up a warning of a Trojan. I cannot find this file mentioned on the net
    I have ran through what i could of the malware removal and i have logs if you would like to see. I have booted into safe to try and delete the file which didnt work, i also tried to deny the file any privileges to stop it running but also to no avail.
    I have ran a safe boot scan and also several in depth scans , but this only seems to come up on the "start up scanner" which im considering disabling. No virus found when the file is scanned individually.
    Now its just annoying me as it wont let me delete it and i have no idea what its for, touch screen equipment? i own nothing touchscreen haha.
    It has been installed since 2007 , there is also another mystery file that appeared at the same time as that one.
    a bit strange dont you think?
    Had a look around the ESET site, in the recent definitions Win32/Kryptik.KNA was added on the 21st. This was when the alert started appearing, so.. False positive maybe? Files maybe acting weird on startup which is upsetting ESET?

    21/02/2011 22:55:15 Startup scanner file
    C:\WINDOWS\udusesuzuzese.dll a variant of Win32/Kryptik.KNA trojan
    error while cleaning RICHARD-2A271F5\Administrator

    udusesuzuzese.dll
    C:\WINDOWS
    353 KB (361,984 bytes)
    DMC9000 Serial Touch Screen Driver
    Copyright (c) Salt Int'l Corporation. All rights reserved.
     
    Last edited: Feb 22, 2011
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Looks like malware to me. We can always get a closer look at it. Have you followed through with the below?

    READ & RUN ME FIRST. Malware Removal Guide

    If so then please attach the logs. I can be of no use to you without seeing those.
     
  3. 3663

    3663 Private E-2

    Yes i followed though the steps listed, however unable to run Combofix or RootRepeal due to 64Bit.
    I have taken 2 different logs, one in safe boot and on in normal on MGtools , dont know if youll need them i was just trying to see any different processes that were running.
    Thanks for the quick reply
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Combofix is 64 bit compatible so do not know what the problem is there.
     
  5. 3663

    3663 Private E-2

    Oh ok. Ill try run it now and ill post a log
     
  6. 3663

    3663 Private E-2

    It says it isnt compatible with XP 64 Bit
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well it is. never mind, we do not even need Combofix because I see the offending file, plus another, so let's begin removal.

    Java(TM) 6 Update 13 <--- UNinstall, outdated.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O4 - HKLM\..\Run: [Kxilesavadeb] rundll32.exe "C:\WINDOWS\udusesuzuzese.dll",Startup
    O4 - HKCU\..\Run: [Kvowikicilucip] rundll32.exe "C:\WINDOWS\anedxft.dll",Startup
    O15 - ESC Trusted Zone: http://runonce.msn.com

    After clicking Fix exit HJT.

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "Kvowikicilucip"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "Kxilesavadeb"=-
    
    :files
    C:\WINDOWS\anedxft.dll
    C:\WINDOWS\udusesuzuzese.dll
    C:\WINDOWS\Hgoparipeciluvun.bin
    C:\WINDOWS\Thudesicogotobuh.dat
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  8. 3663

    3663 Private E-2

    Followed the steps provided , BSOD error on startup followed by BIOS failing to boot. Started up ok now, just was worried when i saw that haha.
    Couldnt locate
    O4 - HKLM\..\Run: [Kxilesavadeb] rundll32.exe "C:\WINDOWS\udusesuzuzese.dll",Startup
    O4 - HKCU\..\Run: [Kvowikicilucip] rundll32.exe "C:\WINDOWS\anedxft.dll",Startup
    Thanks for your help.
    How do you know what you are looking for? I do not consider myself computer illiterate , but i have never used software like that, any ideas for places to research and lookup?
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Lots of practice I suppose. Some people are interested in hardware, software, malware removal appeals to me.
    Yep, I'll chuck you a good link.

    Becoming A Malware Forum Helper
    Unless you meant just researching files?

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  10. 3663

    3663 Private E-2

    Worked down through that, new restore point created. Hopefully BSOD was a one off. Ive only ever seen 2 on this machine.
    Yeah ill deffo have a read through that, ive always been interested in computers whether its building or restoring them. Never had an issue with malware removal, but then again all ive ever done is used spysweeper, ESET and a system restore to a safe point if all other attempts at cleaning failed.
    I would like to get an understanding of how to read and understand the logs provided throughout the malware removal process on the forums.
    Time to get reading i think.
    Thanks very much, PC booted first time, no problems and no annoying ESET popups!
    See you around on the forums. :cool
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Take care and surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds