also @ TechSpot: Samsung starts mass producing super fast PCIe SSDs for ultrabooks

Virus is causing a SHDOCWV error?

Discussion in 'Virus and Malware Removal' started by djackson84, Jul 4, 2010.

  1. djackson84 Newcomer, in training Posts: 87

    I'm having a bit of trouble finding that folder. I'm in C:\Windows...but nothing labeled system32.
  2. djackson84 Newcomer, in training Posts: 87

    NEVERMIND! Found it. sorry I seem so inept, I'm just really stressed about this whole thing. Thanks so much for helping me out thus far.
  3. Broni Malware Annihilator Posts: 40,022   +187

    You're very welcome :)

    When you're done....

    Do this on the computer you are posting from:
    Copy the text in the codebox below:


    Code:
    :OTL
    O2 - BHO: (Internet Explorer Plugin) - {DFC1A8D5-F5A4-453D-BB54-0A886678B9B0} - File not found
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
    O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/downlo...8f/wvc1dmo.cab  (Reg Error: Key error.)
    O33 - MountPoints2\E\Shell - "" = AutoRun
    O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe -- File not found
    [2010/07/07 00:23:09 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Mom_2\Local Settings\Application Data\prvlcl.dat
    [2010/07/07 00:23:09 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Mom\Local Settings\Application Data\prvlcl.dat
    [2010/07/06 16:00:00 | 000,000,296 | ---- | M] () -- C:\WINDOWS\tasks\nyihntpn.job
    [2010/03/03 23:56:01 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Mom_2\Local Settings\Application Data\prvlcl.dat
    [2010/01/16 07:01:19 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Mom\Local Settings\Application Data\prvlcl.dat
    
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    
    Open Notepad and paste it.
    Save the document as Fix.txt on to a USB flash drive


    On the infected computer the following...

    Run OTLPE

    • Insert USB stick and find the file Fix.txt. Drag the file Fix.txt and drop it under the Custom Scans/Fixes box at the bottom.
      • (The content of Fix.txt should appear in the box)
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post the log produced (you'll need to transfer it with USB stick)
    • Attempt to reboot normally into windows and let me know how it goes.
  4. djackson84 Newcomer, in training Posts: 87

    I can't click on your attachments.
  5. Broni Malware Annihilator Posts: 40,022   +187

  6. djackson84 Newcomer, in training Posts: 87

    Reatogo is telling me there's not enough memory to open the attachment in B: and you open in another. It also won't allow me to open my flash drive, so I dont' know for sure if the txt or the attachment are on it. I get the same message about there not being enough room.
     
  7. Broni Malware Annihilator Posts: 40,022   +187

    Did you put my file on USB stick?

    Tell me what exactly you're doing.
  8. djackson84 Newcomer, in training Posts: 87

    I dragged both your file and the txt file onto the icon for my flash drive. I just can't open my flash drive to confirm that they're on there because I get an error messages saying there's no room. So if I reboot, I can't access them to upload. I tried copying the attachment to the desktop and again I get the error that there is no room. When I try to open it it says "there is not enough room on the disk to save B:\YFFN5a4J.zip.part."
  9. Broni Malware Annihilator Posts: 40,022   +187

    You're not reading my instruction well.
    Unzip shdocvw.zip on working computer. Copy UNZIPPED shdocvw.dll file into USB flash drive. Put nothing else there.

    Boot bad computer with OTLPE and transfer shdocvw.dll file from your USB flash drive to C:\WINDOWS\System32 folder.
  10. djackson84 Newcomer, in training Posts: 87

    Oh ok. I got confused because when I first made the CD it didn't matter what computer I used. I've been on the bad one still. I'll have to borrow a laptop. I know what to do now.
  11. Broni Malware Annihilator Posts: 40,022   +187

    Very well :)
  12. djackson84 Newcomer, in training Posts: 87

    Almost have everything done. When you say "reboot the PC when it is done" Am I restarting it with the CD or without?
  13. Broni Malware Annihilator Posts: 40,022   +187

    Remove CD, start Windows normally and let me know what are the current issues.
  14. djackson84 Newcomer, in training Posts: 87

    Here's the log. I also saved in to my usb. Restarting without the CD now and I've added the dll to the system32 like you said as well. Here goes nothing.


    ========== OTL ==========
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DFC1A8D5-F5A4-453D-BB54-0A886678B9B0}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFC1A8D5-F5A4-453D-BB54-0A886678B9B0}\ deleted successfully.
    Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoSetActiveDesktop deleted successfully.
    Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully.
    Starting removal of ActiveX control {31435657-9980-0010-8000-00AA00389B71}
    C:\WINDOWS\Downloaded Program Files\wvc1dmo.inf moved successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{31435657-9980-0010-8000-00AA00389B71}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31435657-9980-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{31435657-9980-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31435657-9980-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Active Setup\Installed Components\{31435657-9980-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31435657-9980-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_USERS\Administrator_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{31435657-9980-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31435657-9980-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_USERS\LocalService_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{31435657-9980-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31435657-9980-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_USERS\Mom_2_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{31435657-9980-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31435657-9980-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_USERS\Mom_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{31435657-9980-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31435657-9980-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_USERS\NetworkService_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{31435657-9980-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31435657-9980-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_USERS\systemprofile_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{31435657-9980-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31435657-9980-0010-8000-00AA00389B71}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\ deleted successfully.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\ not found.
    E:\LaunchU3.exe moved successfully.
    C:\Documents and Settings\Mom_2\Local Settings\Application Data\prvlcl.dat moved successfully.
    C:\Documents and Settings\Mom\Local Settings\Application Data\prvlcl.dat moved successfully.
    C:\WINDOWS\tasks\nyihntpn.job moved successfully.
    File C:\Documents and Settings\Mom_2\Local Settings\Application Data\prvlcl.dat not found.
    File C:\Documents and Settings\Mom\Local Settings\Application Data\prvlcl.dat not found.
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    ========== FILES ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Administrator
    ->Temp folder emptied: 346865 bytes
    ->Temporary Internet Files folder emptied: 402 bytes
    ->FireFox cache emptied: 92979561 bytes
    ->Flash cache emptied: 53583 bytes

    User: All Users

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes
    ->Flash cache emptied: 41620 bytes

    User: LocalService
    ->Temp folder emptied: 65984 bytes
    ->Temporary Internet Files folder emptied: 32969 bytes
    ->FireFox cache emptied: 4171663 bytes

    User: Mom
    ->Temp folder emptied: 526562534 bytes
    ->Temporary Internet Files folder emptied: 263853 bytes
    ->FireFox cache emptied: 200095377 bytes
    ->Flash cache emptied: 179290 bytes

    User: Mom_2
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes
    ->FireFox cache emptied: 92697392 bytes
    ->Flash cache emptied: 45645 bytes

    User: NetworkService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 89050844 bytes
    ->Flash cache emptied: 19014 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 2162283 bytes
    %systemroot%\System32 .tmp files removed: 2577 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 2471431 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 64672602 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes

    Total Files Cleaned = 1,026.00 mb


    OTLPE by OldTimer - Version 3.1.39.0 log created on 07072010_202106
  15. djackson84 Newcomer, in training Posts: 87

    Ok....there's a new error now. It says that 325 could not be found on the link SHDOCVW.dll. There's still no desktop.
  16. Broni Malware Annihilator Posts: 40,022   +187

    Please post exact error, word by word.

    Will CTRL+ALT+DEL bring Task Manager up?
  17. djackson84 Newcomer, in training Posts: 87

    "the original 325 could not be located in the dynamic link library Shdocvw.dll" is what it says. But after I logged off and back on again to replicate the problem the desktop showed up. Everything seems to be working fine now except for the virus that lead me to to the system recovery which led to the desktop problem. Now I can just focus on the virus. Thank you for everything
  18. Broni Malware Annihilator Posts: 40,022   +187

    Great news :)
    Let me go through our thread, so we can figure out next step.
  19. Broni Malware Annihilator Posts: 40,022   +187

  20. djackson84 Newcomer, in training Posts: 87

    Ok...I'm going through the list. My particular virus seems to redirect websites, and cause popups. Does this sound like anything you know personally? Just checking.