Author Topic: Placed Malware in Chest but now start up programs looking for the dll  (Read 24104 times)

0 Members and 1 Guest are viewing this topic.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Placed Malware in Chest but now start up programs looking for the dll
« Reply #15 on: April 05, 2010, 12:09:03 PM »
Hi lets have a look at the registry to see where this is coming from

Download OTL  to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in
netsvcs
%SYSTEMDRIVE%\*.*
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys
symmpi.sys
adp3132.sys
mv61xx.sys
/md5stop
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav



  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

bong2x

  • Guest
Re: Placed Malware in Chest but now start up programs looking for the dll
« Reply #16 on: April 05, 2010, 12:15:58 PM »
 ::) im thinking if you are using paid mbam

mbam is not already on demand so it is needed to initialize in the start-up.

just try to re install your mbam and update it ;)

Regards!!

Altarir.

  • Guest
Re: Placed Malware in Chest but now start up programs looking for the dll
« Reply #17 on: April 05, 2010, 12:22:40 PM »
im thinking if you are using paid mbam

mbam is not already on demand so it is needed to initialize in the start-up.

just try to re install your mbam and update it

dude.

mbam doesn't have anything related with netdtoh.dll(normally)

neither do winlogon.exe and other windows system processes.

read before you post.

13thSlayer

  • Guest
Re: Placed Malware in Chest but now start up programs looking for the dll
« Reply #18 on: April 05, 2010, 12:23:21 PM »
ok can you fix or reinstall your mbam?

maybe its the system of mbam that is missing :D

Regards!!!
MBAM ain't related to this DLL. You fail.

bong2x

  • Guest
Re: Placed Malware in Chest but now start up programs looking for the dll
« Reply #19 on: April 05, 2010, 12:42:14 PM »
Quote
MBAM ain't related to this DLL. You fail.

yes its not related but viruses and malware not only formed by a programmer sometimes it is there because of error reading of the machine, the ability of your machine to translate the binary can cause also the error in reading of the actual file. just try search everywhere if you can find it. maybe because of the corrupted download of mbam need to download new one and re install it.

Regards!!!

 

superhans

  • Guest
Re: Placed Malware in Chest but now start up programs looking for the dll
« Reply #20 on: April 05, 2010, 01:33:44 PM »
Thanks essexboy

Attached are the files from running OTL

Interestingly internet explorer is one of the few programmes that doens't throw up the looking for netdtoh.dll error when i start it


13thSlayer

  • Guest
Re: Placed Malware in Chest but now start up programs looking for the dll
« Reply #21 on: April 05, 2010, 02:05:34 PM »
Quote
MBAM ain't related to this DLL. You fail.

yes its not related but viruses and malware not only formed by a programmer sometimes it is there because of error reading of the machine, the ability of your machine to translate the binary can cause also the error in reading of the actual file. just try search everywhere if you can find it. maybe because of the corrupted download of mbam need to download new one and re install it.

Regards!!!

 
You fail again. Coz this isn't a programming error in any way. And, once again, FFS, this IS NOT A MBAM DLL.

superhans

  • Guest
Re: Placed Malware in Chest but now start up programs looking for the dll
« Reply #22 on: April 05, 2010, 02:07:23 PM »
Definitely nothing to do with MBAM

I thought I'd put an empty file called netdtoh.dll where all the programmes are looking for it

here's the obvious error message that this caused attached

superhans

  • Guest
Re: Placed Malware in Chest but now start up programs looking for the dll
« Reply #23 on: April 05, 2010, 02:08:51 PM »
Firefox will not start at all - even after re-installing - though most other programmes do work even though they say they won't because they need that netdtoh.dll

bong2x

  • Guest
Re: Placed Malware in Chest but now start up programs looking for the dll
« Reply #24 on: April 05, 2010, 02:29:16 PM »
creating an empty file ???

but it cannot be executed because its empty, you can find only halt in initializing the application.

 ;)

thanks for sharing the problems!!!

i try to experiment here what cause of that dll.



Regards!!!!

superhans

  • Guest
Re: Placed Malware in Chest but now start up programs looking for the dll
« Reply #25 on: April 05, 2010, 02:47:51 PM »
All programmes that i start bring up the unable to locate netdtoh.dll component except for internet explorer which is the only programme which pulls up no error

firefox and other progammes which i think use firefox won't start at all (ableton, battery - music software that updates via the internet)

uninstalled firefox and a couple of them started working again but still asking for that dll

why does every single thing think it needs this dll!!!!

bong2x

  • Guest
Re: Placed Malware in Chest but now start up programs looking for the dll
« Reply #26 on: April 05, 2010, 03:01:58 PM »
what version is your net framework?

i've just run the empty netdtoh.dll(dynamic link library) and its connected to my netframework 3.0
 

if you don't mind try fixing also your netframwork if you have any version.

if failed then post what happen, we try experiment again ;)

Regards!!!



Offline .: L' arc :.

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1780
  • Thinking with Portals
Re: Placed Malware in Chest but now start up programs looking for the dll
« Reply #27 on: April 05, 2010, 03:02:59 PM »
Is the dll still in your avast! virus chest?
Windows 7 (64-bit) Home Premium SP1
avast! 9 RC1

superhans

  • Guest
Re: Placed Malware in Chest but now start up programs looking for the dll
« Reply #28 on: April 05, 2010, 03:03:57 PM »
yes it is still in the chest - i've forwarded it to AVAST


Offline .: L' arc :.

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1780
  • Thinking with Portals
Re: Placed Malware in Chest but now start up programs looking for the dll
« Reply #29 on: April 05, 2010, 03:11:32 PM »
Since it's a generic detection, it could be an FP. Here we go, this may be a long step.

1   Create folder in your Desktop and name it as Test
2   Now, open avast! Interface > Settings > Exclusions
3   Click Browse then search for the folder Test and put a check beside it
4   Click OK
5   Now, navigate to Maintenance > Virus Chest
5   Locate the dll then right click and select Extract..
6   Select the folder Test as the location for extraction
7   After extracting, go here
8   Upload the dll file in the folder Test
9   Provide us a link to the results
Windows 7 (64-bit) Home Premium SP1
avast! 9 RC1