Advertisement

03.24.2006 at 10:19AM PST, ID: 21787760
[x]
Attachment Details
[x]
The Solution Rating System

With so many solutions, how can you tell which solutions are most likely to help you and which ones are not? To provide you with a tool to use, we rate our solutions based on various elements that most accurately determine if a solution is a quality solution. To explain what factors affect the solution rating, here are the elements we take into consideration when formulating our solution rating.

  • The Grade of the Solution
  • The Zone Rank of the Expert Providing the Solution
  • The Number of Author and Expert Comments
  • The Number of Experts Contributing
  • The Feedback of the Community

Your Input Matters
Because of the way the system is set up, the most important variable in this equation is you. As a member of Experts Exchange, you are able to cast your vote on the quality of the solutions in regard to how complete, accurate, helpful and easy to understand each solution is. When you provide your feedback, each rating is adjusted accordingly. So, if you see a solution that has a poor rating that you think is a good solution, let us know by rating it. As you do, the rating will be adjusted and will become more accurate for other members of our site.

If you have any suggestions that you would like to make for our rating system, please ask a question in the Suggestions Zone of Community Support.

Thank you!

3.8

Adware Spyware + Killbox killed explorer shell

Asked by JasonCGW in Networking Security Vulnerabilities

Hi. So I think I have Adware.Look2Me and something involving many Tracking.Cookies that have persistenly stayed on my system. Let me go through what I've done so far. Prior to the steps below, I installed Prevx1 and its currently running on my computer. It has not interrupted with any alerts or errors.

**Random Windows Explorer Error** Address bar is checked as being visible, but its invisible. I never noticed this before...but the address bar in IE is missing too. Address bar in Firefox is unaffected.

1. Ran Ad-aware SE
As instructed in the "Before You Post."
Results: 0 New Critical Objects

2. Ran CWShredder
In safe mode, as instructed.
Reported removing CWS.Msconfig varient

Upon restarting normally, ewido reported "wuadefui.dll" as an infection of Adware.Look2Me from C:windows\system32. Chose "Clean" as the action.
Had to restart again and ewido reported "wfdrmsdk.dll" as an infection of Adware.Look2Me from C:\Windows\system32. Chose "clean."

3. Ran Spybot S&D
As instrcuted.
Reports removing registry entries for "Windows Security Center.AntiVirusDisableNotify" and "WindowsSecurityCenter.FirewallDisableNotify". Fixed selected problems. (But Spybot has repeatedly said it cleared these problems and they keep reappearing.)

4. Attempted to run TrendHousecall. Page would not load. Perhaps this could be the result of higher security settings that I installed in response to the infection(s)?

5. Ewido scan
Attempted to update in regular mode. No update was available.
Ran in safe mode
Results: Finds infected files. Most of them are *.dll's. Most are cleaned. "C:\windows\system32\dqwave.dll" has an "error" and cannot be deleted. I tried to delete with Windows explorer and that doesn't work. Also noted pvp.dll and o4nsle571h.dll and 04pqle751h.dll. Cannot delete these process!
Scan log from most recent running is below:
[804] C:\WINDOWS\system32\pVp.dll -> Adware.Look2Me : Error during cleaning
[880] C:\WINDOWS\system32\pVp.dll -> Adware.Look2Me : Error during cleaning
:mozilla.7:C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\akzixo1s.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\akzixo1s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\akzixo1s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.6:C:\RECYCLER\S-1-5-21-3880028103-2268992153-1497372460-500\Dc1.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.7:C:\RECYCLER\S-1-5-21-3880028103-2268992153-1497372460-500\Dc1.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.18:C:\RECYCLER\S-1-5-21-3880028103-2268992153-1497372460-500\Dc1.txt -> TrackingCookie.Cpvfeed : Cleaned with backup
:mozilla.54:C:\RECYCLER\S-1-5-21-3880028103-2268992153-1497372460-500\Dc1.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.55:C:\RECYCLER\S-1-5-21-3880028103-2268992153-1497372460-500\Dc1.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.58:C:\RECYCLER\S-1-5-21-3880028103-2268992153-1497372460-500\Dc1.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.59:C:\RECYCLER\S-1-5-21-3880028103-2268992153-1497372460-500\Dc1.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.66:C:\RECYCLER\S-1-5-21-3880028103-2268992153-1497372460-500\Dc1.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.67:C:\RECYCLER\S-1-5-21-3880028103-2268992153-1497372460-500\Dc1.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.68:C:\RECYCLER\S-1-5-21-3880028103-2268992153-1497372460-500\Dc1.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.69:C:\RECYCLER\S-1-5-21-3880028103-2268992153-1497372460-500\Dc1.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.70:C:\RECYCLER\S-1-5-21-3880028103-2268992153-1497372460-500\Dc1.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.78:C:\RECYCLER\S-1-5-21-3880028103-2268992153-1497372460-500\Dc1.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.79:C:\RECYCLER\S-1-5-21-3880028103-2268992153-1497372460-500\Dc1.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.80:C:\RECYCLER\S-1-5-21-3880028103-2268992153-1497372460-500\Dc1.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.81:C:\RECYCLER\S-1-5-21-3880028103-2268992153-1497372460-500\Dc1.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.82:C:\RECYCLER\S-1-5-21-3880028103-2268992153-1497372460-500\Dc1.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.83:C:\RECYCLER\S-1-5-21-3880028103-2268992153-1497372460-500\Dc1.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.84:C:\RECYCLER\S-1-5-21-3880028103-2268992153-1497372460-500\Dc1.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.85:C:\RECYCLER\S-1-5-21-3880028103-2268992153-1497372460-500\Dc1.txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\WINDOWS\system32\azamlij118o.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\lt4027hmg.dll -> Adware.Look2Me : Cleaned with backup


6. Ran Symantac Deep/Extended Scan in safe mode
Result: Found and deleted 1 threat. When it examined dqwave.dll, it did not pickup a threat (even though ewido did)

7. Trojan Hunter.
Attempted to install. At the last moment before complete installation, received following error message:
CoCreateInstance failed; code 0x80040154. Clicked ok. Error repeated five times. Then, installation reported as "complete."

Ran test. Found only one problem but indicated that it could not scan pVp.dll since it was in use by another program. This file was identified by ewido as containing the Adware.Look2Me infection.

REBOOT AND TEST
Random note: After several cleaning steps, my "Quick Launch" disappeared. After putting back the "quicklaunch" and choosing Firefox, computer takes a long time to advance. When Firefox has loaded, and a page is visited, a popup begins opening in another tab. Could the malware be doing this?
Also, Prevx1 interrupts once to ask if I want to allow mpas-fe.exe from C:\windows\softwaredistribution\... to be installed. I selected "Do not run."
Address bar still invisible in IE and Explorder

HIJACKTHIS LOG

Deleted files on reboot from HJT w/ Killbox. Chose to "End Explorer Shell while Killing" and did NOT choose "Keep Dummy File":
enjml1111.dll
__delete_on_reboot_mefted.dll
pvp.dll
o4pgle751h.dll
streamhlp.dll
sporder.dll
wpa.dbl

I used KillBox! -- without the explicit instruction of this board's staff -- and now I am paying for my stupidity.

I used KillBox! to "delete on reboot" a variety of DLLs that were causing problems.
I chose "End Explorer Shell While Killing" or some option like that.

KillBox rebooted and everything started normally (Normal XP graphic. Normal XP login screen.)

I clicked on my name, "Jason" and the standard music sounded up but the page didn't advance to the normal windows screen. It was stuch on "loading your personal settings" for a much longer time than ever happened before.

When that screen went away, I saw the standard XPS windows background. But no start menu. No desktop icons of any kind.

I hit CTL ALT DEL and started up task manager, which listed 47 processes working but no programs.

I launched a "New Task" for explorer.exe and the start briefly appeared on the bottom on the screen....and then immediately disappeared.

I went back into KillBox to attempt to restore the files I had deleted, but when I chose File>Open Backups the start menu briefly appeared, and then disappeared again.

I have no idea what to do...my system appears to exist and my files all appear to be there ...but I cannot get any of my original settings, my start menu, or anything.

I'm using my backup (very old) computer....and I need help asap!Start Free Trial
[+][-]03.24.2006 at 10:23AM PST, ID: 16282739

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.24.2006 at 01:03PM PST, ID: 16284227

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.24.2006 at 01:24PM PST, ID: 16284386

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.24.2006 at 01:34PM PST, ID: 16284477

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.24.2006 at 01:35PM PST, ID: 16284485

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.24.2006 at 01:37PM PST, ID: 16284507

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.24.2006 at 01:52PM PST, ID: 16284638

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.24.2006 at 01:56PM PST, ID: 16284657

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.24.2006 at 02:02PM PST, ID: 16284702

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.24.2006 at 02:06PM PST, ID: 16284729

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.24.2006 at 02:21PM PST, ID: 16284848

Assisted solutions are selected by the member who asked the question as a comment that contributed to their question's solution.

Start your 7-day free trial to view this Assisted Solution or ask the Experts your question.

 
[+][-]03.24.2006 at 02:26PM PST, ID: 16284882

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.24.2006 at 02:26PM PST, ID: 16284884

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.24.2006 at 02:28PM PST, ID: 16284898

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.24.2006 at 02:31PM PST, ID: 16284914

Assisted solutions are selected by the member who asked the question as a comment that contributed to their question's solution.

Start your 7-day free trial to view this Assisted Solution or ask the Experts your question.

 
[+][-]03.24.2006 at 02:36PM PST, ID: 16284941

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.24.2006 at 02:38PM PST, ID: 16284959

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.24.2006 at 02:41PM PST, ID: 16284975

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.24.2006 at 03:20PM PST, ID: 16285325

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.24.2006 at 03:36PM PST, ID: 16285412

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.24.2006 at 03:46PM PST, ID: 16285455

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zone: Networking Security Vulnerabilities
Sign Up Now!
Solution Provided By: rpggamergirl
Participating Experts: 3
Solution Grade: C
 
 
[+][-]03.24.2006 at 03:54PM PST, ID: 16285488

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.24.2006 at 04:03PM PST, ID: 16285532

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03.24.2006 at 04:06PM PST, ID: 16285548

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03.24.2006 at 04:24PM PST, ID: 16285654

Assisted solutions are selected by the member who asked the question as a comment that contributed to their question's solution.

Start your 7-day free trial to view this Assisted Solution or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32