Author Topic: please help !  (Read 25771 times)

0 Members and 1 Guest are viewing this topic.

carlwt2007

  • Guest
please help !
« on: April 09, 2010, 07:39:21 PM »
i keep running my avast and i keep getting warnings that I'm infected with a Sign of "Win32:DllMod [Wrm]
i have put them in my virus chest and then deleted them but they keep coming back! there is so many files that this worm has infected that its a nightmare! i cant even find any info on this worm on the net?

i hope someone can help?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: please help !
« Reply #1 on: April 09, 2010, 07:46:53 PM »
Check your computer for Malware with

Malwarebytes Antimalware http://filehippo.com/download_malwarebytes_anti_malware/
after install click UPDATE and run quick scan, click on REMOVE SELECTED to quarantine anything found

SUPERAntiSpyware http://filehippo.com/download_superantispyware/
Are cookies really spyware and are they dangerous?
http://www.superantispyware.com/supportfaqdisplay.html?faq=26

If anything is found come back and post the scan logs here

carlwt2007

  • Guest
Re: please help !
« Reply #2 on: April 09, 2010, 07:49:43 PM »
ive tried both super and mal both dont find anything? only avast finds its?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: please help !
« Reply #3 on: April 09, 2010, 07:59:17 PM »
Norman Malware Cleaner http://www.norman.com/support/support_tools/58732/en-uk
Dr.Web CureIt! http://www.freedrweb.com/cureit/?lng=en
How Do I Use Dr.Web CureIt!? http://www.freedrweb.com/cureit/how_it_works/

If this does not work, then Essexboy is next.....

Follow this guide from Essexboy and post the log`s here so he can have a look
http://forum.avast.com/index.php?topic=53253.0

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: please help !
« Reply #4 on: April 09, 2010, 08:49:13 PM »
i keep running my avast and i keep getting warnings that I'm infected with a Sign of "Win32:DllMod [Wrm]
i have put them in my virus chest and then deleted them but they keep coming back! there is so many files that this worm has infected that its a nightmare! i cant even find any info on this worm on the net?

What is the infected file name, where was it found e.g. (C:\windows\system32\infected-file-name.xxx) ?
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

carlwt2007

  • Guest
Re: please help !
« Reply #5 on: April 09, 2010, 09:23:41 PM »
3/22/2010 5:28:05 PM   SYSTEM   1168   Sign of "Win32:DllMod [Wrm]" has been found in "C:\windows\system32\DmkoVvtb.dll" file. 

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: please help !
« Reply #6 on: April 09, 2010, 09:30:46 PM »
    Hi there lets have a quick look at the system first and see what the problem areas are

    Two programmes to run - if you could attach the logs it will make it easier on you

GMER Rootkit Scanner - Download - Homepage
  • Download GMER
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe.

  • If it gives you a warning about rootkit activity and asks if you want to run a full scan...click on NO, then use the following settings for a more complete scan..
  • In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED ...
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)

    Click the image to enlarge it
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "ark.txt" 
  • Save the log where you can easily find it, such as your desktop.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries

Please copy and paste the report into your Post.

THEN

Download OTL  to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in
netsvcs
%SYSTEMDRIVE%\*.*
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys
symmpi.sys
adp3132.sys
mv61xx.sys
/md5stop
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav



  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: please help !
« Reply #7 on: April 09, 2010, 09:35:49 PM »
3/22/2010 5:28:05 PM   SYSTEM   1168   Sign of "Win32:DllMod [Wrm]" has been found in "C:\windows\system32\DmkoVvtb.dll" file. 

I was half expecting it to be in the drivers sub-folder of system32 as I suspect there may be a rootkit at work hiding the source of the restoration of the file after removal.

Is it always the same location and file name that comes back or just what appears to be a randomly generated file name (zero hits on google) in the system32 folder ?

Now essexboy is on the case, hopefully he will get to the bottom of this.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

carlwt2007

  • Guest
Re: please help !
« Reply #8 on: April 09, 2010, 10:11:30 PM »
waiting on gmer to stop!

carlwt2007

  • Guest
Re: please help !
« Reply #9 on: April 09, 2010, 10:47:27 PM »
my computer shut itself down now i have to do this all over again :'(

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: please help !
« Reply #10 on: April 09, 2010, 11:07:55 PM »
OK skip GMER We will revisit that later

carlwt2007

  • Guest
Re: please help !
« Reply #11 on: April 09, 2010, 11:52:20 PM »
tried to post the otl  and the extras but it said that it exceeds the 10000 amount of space!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: please help !
« Reply #12 on: April 09, 2010, 11:54:47 PM »
Could you attach them - select the additional options on the left hand side when you are composing a reply  - then browse to the OTL log and then post both as attachments

carlwt2007

  • Guest
Re: please help !
« Reply #13 on: April 09, 2010, 11:57:04 PM »
ok here they are!

carlwt2007

  • Guest
Re: please help !
« Reply #14 on: April 09, 2010, 11:57:41 PM »
ok here they are!