Virus, adware, now no internet connection, please help!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by SHAGGYSGIRL, Jul 12, 2004.

  1. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I guess you did not understand what I meant by "disconnect your network connection". I told you in the sentences before that bold print it meant to physically unplug your analog modem's telephone line (if you use dial-up) or unplug the ethernet cable into your PC from your ADSL or Cable modem or router if you have a permanent connection. This is critical to the FINDnFIX step. Also, I wanted you to run FINDnFIX after booting in normal mode. That got lost in the instructions because I had inserted the new link to the fullscan method for Ad-aware which was to be run in safe mode. I have to be sure that there are no super hidden bad files, so let's try again:

    - boot normal mode
    - physically disconnect your connection
    - run the FINDnFIX !log!.bat files
    - post the log.txt file back here as an attachment

    Then do this. Open a command prompt window by clicking Start, Run, and in the Open box enter "cmd" without the quotes.
    At the command prompt type "cd \windows\system32" without the quotes.
    Now type "attrib -r -h -s qdvnmy.dll" without the quotes. Tell me if this gets an error message.
    Now type "dir qdvnmy.dll" without the quotes" and tell me what you get.
    Now type "del qdvnmy.dll" without the quotes and tell me what you get.
    If the del command (which is short for delete) works, skip down to where I say post a new HijackThis log attachment
    If the del command does not work, try a rename of the file:
    type "ren qdvnmy.dll qdvnmy.bad" without the quotes and tell me what you get.
    If the rename works, open up a Windows Explorer session and navigate your way to the c:\windows\system32 directory and right click on the qdvnmy.bad file and while holding down the right mouse key drag the file to your desktop. Let go of the mouse button and select Move here. Let me know if this works.
     
  2. SHAGGYSGIRL

    SHAGGYSGIRL Private E-2

    I did your instructions and here is what I got:

    Now type "attrib -r -h -s qdvnmy.dll" without the quotes. Tell me if this gets an error message. did not do anything, took me back to the prompt, no error message

    Now type "dir qdvnmy.dll" without the quotes" and tell me what you get.
    Dir has 1 file

    Now type "del qdvnmy.dll" without the quotes and tell me what you get.
    The process cannot access the file because it is being used by another process.


    type "ren qdvnmy.dll qdvnmy.bad" without the quotes and tell me what you get.
    The process cannot access the file because it is being used by another process.


    Here is my findnfix log.

    I have a program downloaded at my house that is supposed to allow you to remove dll's at next startup. I may try to bring it over here and load it and see if it works. Cannot remember the software name.
     

    Attached Files:

    • log.txt
      File size:
      9.1 KB
      Views:
      1
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you tried to delete or rename that DLL, did you have all Windows Explorer and Internet Explorer sessions closed (not minimized, totally stopped)?

    Download ProcessExplorer from here: http://www.sysinternals.com/files/procexpnt.zip
    and unzip it to a directory where you can find it easily.

    Now run ProcessExplorer and click on File and then Save As. And save the process list. Post it back here as an attachment. Also, from now on if I say to kill a process, use ProcessExplorer instead of Task Manager. Sometimes ProcessExplorer can kill things that Task Manager cannot.
     
    Last edited: Aug 9, 2004
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Below is another item I want you to do after getting me that ProcessExplorer list.

    Download and install APM from: http://www.diamondcs.com.au/index.php?page=apm

    Then start APM.
    In the upper window select explorer.exe
    In the lower window see if you can find C:\WINDOWS\System32\qdvnmy.dll
    If you find it, rightclick on it and select Unload DLL and click OK on the prompts that follow.

    If this works, goto to the c:\windows\system32 directory and now try to rename
    the file to qdvnmy.bad
    Let me know what happens.
     
  5. SHAGGYSGIRL

    SHAGGYSGIRL Private E-2

    I did the Process Explorer and the APM.

    Here is my Process Explorer file

    I ran APM and unloaded the DLL and tried to rename the file but it still said it was in use.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I really want to know what this file is for. Can you see if you can put a copy of C:\WINDOWS\System32\qdvnmy.dll into a ZIP file and post it pack here as an attachment.
     
  7. SHAGGYSGIRL

    SHAGGYSGIRL Private E-2

    Here is the zip file of the qdvnmy.dll and another dat file called qdvnmy.

    Also moveonboot is the program that I am thinking about trying to use to delete this file.

    Let me know what you think.
     

    Attached Files:

    Last edited: Aug 13, 2004
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They most likely will not help. There could be other related files too that keep respawing them.

    I cannot even extract from you ZIP file to look at them because my virus scanner (McAfee) immediately complains about the COREFLOOD.DLL Trojan . This is a real baddie. Are you absolutely positive you have the current Virus Definitions for your Norton Antivirus? Please double check the versions you have (not just the virus scanner's version but also the reference or virus definitions file version. If they are up to date, do the following:
    1) disable system restore but when it asks for a reboot you must boot in safe mode
    2) perform a full system scan with Norton (make sure it is set to scan the whole hard disk. See if it finds this file and maybe others.

    Is there a coreflood.dll or coreflood.exe on your system anywhere?

    For the education read the info in the links below from Symantec, McAfee, and TrendMicro:
    http://securityresponse.symantec.com/avcenter/venc/data/backdoor.coreflood.html
    http://vil.nai.com/vil/content/v_100312.htm
    http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_AFCORE.M

    I found some links that indicated McAfee could find this trojan but Norton did not (the link was a few months old. Hopefully a newer definitions list finds it.)

    We are going to have to remove some stuff from the registry.

    By the way, back a number of messages you indicated that Ad-aware found and cleaned: Win32.Backdoor.afcore ! Maybe it did not clean it all.
     
    Last edited: Aug 13, 2004
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I also have a question! Do you know your Administrator password for your PC? I'm not asking you to tell me what it is. I want to verify that you can boot up with the user name as Administrator. This is leading towards my next steps but I need to know you can login as the Administrator.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  11. SHAGGYSGIRL

    SHAGGYSGIRL Private E-2

    I had not been back to see your posts until now.

    I had just manually walked through the registry removal tools from Norton's website and removed all the things that I found. There were about 10 registry entries with the qdvnmy.dll in it. I removed everything with the .dll, .dat and the .zip. After doing this, I rebooted and was able to delete the actual file in the C;\Windows\Sytem32\qdvnmy.dll that I was unable to delete prior to now.

    I just read your posts and ran the sophos. It came back clean.

    I am going to start another Norton Scan, I just manually did live update. The norton scans have run every night and have not found anything since 8/9 where it found an adware threat.

    Let me know what else to do or if you would just like to see a new hijack list.

    The computer does seem to be running better but we have NOT opened Outlook Express. I told her to stay out of her email until I was finished trying to clean the computer.

    Gayla
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Gayla,

    Yes, attach one more HJT log for me and yes it is about time to run Outlook Express. Becareful of what may be lurking in the email files since last being read. Be very careful on any email having attachments.
     
  13. SHAGGYSGIRL

    SHAGGYSGIRL Private E-2

    Sorry it has been so long, have not been to her house in over a week.

    Norton is still scanning and coming back clean.

    Attached is the HJT log.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds