Virus found sprt_ads.dll

Discussion in 'Malware Help (A Specialist Will Reply)' started by mskt, Mar 4, 2008.

  1. mskt

    mskt Private E-2

    Hi,
    I followed some of the threads by anat1 and i kind of got lost and stuck.
    Please help.
    I got a file attached scan in HijackThis and im unsure which to fix check and what else do i need to do?
    Thanks!
     

    Attached Files:

  2. Lev

    Lev MajorGeek

  3. mskt

    mskt Private E-2

    Hi,
    im done step 4 of the Windows XP Cleaning Procedure but im unsure if the system is still having problems.
    attached are the files.
    thanks!
     

    Attached Files:

  4. mskt

    mskt Private E-2

    Hi,
    now whenever i close my internet explorer browser there will be a popup message error:
    "IEXPLORER.EXE - Application Error"
    apparently it states that the instruction at "0x0352396a" referenced memory at "0x0356b1bc" could not be "read".
    it goes on the request for me to click on OK to terminate the program or cancel to debug it but neither does anything except to close the message.
    also, i ran a few scans recently after the cleaning up and some other malwares were detected.
    is there something wrong?
    thanks
     
  5. mskt

    mskt Private E-2

    a similar one also popped up:
    "0x06670530"
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These last two message cost you 2 additional days of waiting time. Whether intentional or not it is still like a bump. You shoud read the below sticky thread:

    Don't Bump! It Only Hurts You!!!


    Are the below things you need. These are bad locations to save them if you do need them.
    Code:
    2007-12-26 17:22 48,128 ----a-w C:\Program Files\EXEC_ST.EXE
    2007-12-26 17:17 48,128 ----a-w C:\EXEC_ST.EXE
    Also it is a bad idea to save the below here:
    C:\Program Files\LimeWireWin.exe


    Your error message may not be malware related. But let's see what happens after we remove the rest of your malware.


    Uninstall the below software:
    Search Assistant Dcads

    If it does not uninstall or you don't find it, just continue.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {0BE1FD6F-2224-40DB-A202-96323329AE37} - C:\WINDOWS\system32\mcicd.dll
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [bm] "C:\Program Files\Common Files\TrustedAntivirus\bm.exe" dm=http://trustedantivirus.com ad=http://trustedantivirus.com sd=http://ykeeper.trustedantivirus.com
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
    O4 - HKCU\..\Run: [TrustedAntivirus] C:\Program Files\TrustedAntivirus\pgs.exe /min
    O4 - HKCU\..\Run: [MSI Configuration] msiconf.exe

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\maxi\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. mskt

    mskt Private E-2

    oops... so sorry... i didnt know...
    anyway, thanks a million!
    cheers
     
    Last edited by a moderator: Mar 13, 2008
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you going to answer my question and also follow the instructions I gave you?
     
  9. mskt

    mskt Private E-2

    Hi,
    apparently my IE cant connect to the internet after i followed the instructions.
    im using firefox now instead and there's no internet connection problem except for IE.
    attached are the logs and sorry for the delay
    thanks

     

    Attached Files:

  10. mskt

    mskt Private E-2

    Hi,
    sorry the IE problem has been solved
    thanks

     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why did you install Avast? You now have two antivirus programs installed and as we stated in the READ & RUN ME, you must not do this. You must uninstall one of these now. If you already uninstall Norton/Symantec then the uninstall did not work properly. Let me know.


    Also uninstall the below:
    MySidesearch Search Assistant


    After doing the above, run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  12. mskt

    mskt Private E-2

    hi,
    i installed avast because norton/symantec expired and its no longer working but i cant uninstall it.
    attached are the files requested.
    thanks
     

    Attached Files:

    Last edited by a moderator: Mar 13, 2008
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then let's see if we can get rid of it.

    First look in Add/Remove programs for any of the below and uninstall if found. If not found just continue.
    ccCommon
    Internet Worm Protection
    Symantec KB-DocID:2003093015493306
    Symantec

    Now run this Norton Removal Tool (SymNRT) and then reboot.

    After reboot continue with the below.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  14. mskt

    mskt Private E-2

    hi,
    attached is the log after completing your instructions. apparently there was some application error at the end of running C:\MGtools\GetLogs.bat .
    thanks
     

    Attached Files:

    Last edited by a moderator: Mar 13, 2008
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Norton is now gone. But you did not tell me how things are working so I will assume everything is okay.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     
  16. mskt

    mskt Private E-2

    thank u very very much!
    if there's any other problems i'll post it
    cheers!
     
    Last edited by a moderator: Mar 15, 2008
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds