The 2014 Corvette Stingray Forum
News / Blog Register Social Groups Calendar Search Today's Posts Mark Forums Read

Go Back   Chevrolet Corvette Stingray C7 Forum > Members Area > Off-topic Discussions

Reply
 
Thread Tools
Old 09-16-2009, 03:13 AM   #1
Mindz
E.B.A.H.
 
Mindz's Avatar
 
Drives: you wild...
Join Date: Mar 2007
Location: In the happy padded room wearing a jacket that makes me hug myself...
Posts: 18,420
Tech support needed...Protect.dll, Autochk.dll...

Anyone had any encounters with these two bastards of a problem?

Well last night, I fired up my computer since I had the internet working again and I go to check my e-mail which got redirected to thefeedyard.com. hmmmmm. Hit back, clicked another link (inbox) from hotmail and it went to globexonline.com or something. Interesting. Clicking back and hovering over all the hyperlinks on the page, they all lead to one of the two websites. I ran AVG and malware bytes and both came up with 6 files: 4 belonging to autochk.dll, 1 protect.dll and one other one (can't remember but it's a .bak file). After reading up online, I installed f-secure online scanner and deleted the registry keys manually, but while restarting, the files would just stay there. I'm currently locked in a battle with these two files which run the 4 other ones and I can't do anything online at home anymore.

Does anyone have any info I might not have read about or has anyone dealt with this problem before?

I'm posting this while at work if you're wondering how I was able to visit this site.
__________________
Blue Rush, 2010 SS [Car of the Week 3/22/2010] Traded in on...ZLZBUBB, 2013 ZL1
Mindz is offline   Reply With Quote
Old 09-16-2009, 07:18 AM   #2
texan
 
texan's Avatar
 
Drives: people crazy
Join Date: Aug 2009
Location: duh
Posts: 191
try runnning cleanup.exe in safe mode
http://www.stevengould.org/index.php...tent&task=view

then run malwarebytes again
texan is offline   Reply With Quote
Old 09-16-2009, 08:24 AM   #3
Xanthos
PWA Relapse
 
Xanthos's Avatar
 
Drives: Formerly-Stick
Join Date: Mar 2008
Location: Oklahoma
Posts: 12,588
Which antivirus are you using? Sounds like you have a Trojan dropper and some random malware.

I'd recommend downloading AdAware SE and Spybot Search & Destroy if you don't already have them. Run a full virus scan in safe mode, as well as scans from AdAware and SB and then reboot back into normal mode. Once back into normal mode, run a Windows Defender scan (assuming you have XP or higher) and then run another virus scan. HOPEFULLY that should have gotten rid of everything. If not, you'll have to find a more specialized removal tool.

The utility listed in texan's post won't help you in the slightest. All it removes is temporary internet files, which you can get rid of by clearing your browser cache. Not going to clear up your little... "infestation."
- X
__________________

2017 1LT/RS A8 Hyper Blue Metallic

Xanthos is offline   Reply With Quote
Old 09-16-2009, 10:01 AM   #4
Mr Twisty


 
Mr Twisty's Avatar
 
Drives: the 2nd amendment home
Join Date: May 2008
Location: OK
Posts: 14,763
Why a .bak file??? Open it with notepad see if it's readable.
Maybe the spammer was nice enough to backup your original files for you before he bent you over LOL
__________________
"They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety."
-- Benjamin Franklin

lib·er·ty
/ˈlibərdē/
noun
1.
the state of being free within society from oppressive restrictions imposed by authority on one's way of life, behavior, or political views
Mr Twisty is offline   Reply With Quote
Old 09-16-2009, 10:06 AM   #5
texan
 
texan's Avatar
 
Drives: people crazy
Join Date: Aug 2009
Location: duh
Posts: 191
The cleanup.exe clears out files to make scans faster, if someone isn't doing their housekeeping it cuts scan times exponentially...it does a lot more than Internet temp files

Without knowing someone's experience level it's hard to give specific instructions sometimes

Ad-aware and Spybot are still okay, they used to be great but on a weekly basis of cleaning bugs I've had greater success with malwarebytes recently. Using them all is a last resort to blowing the OS. If it is a rootkit you may not ever get it out if it has a recycle trigger.

Another good tool for rootkit removal on windows is GMER - http://www.gmer.net/

This want do anything about the dll's but you might want to check your hosts file in c:\windows\system32\drivers\etc..open hosts with notepad and see if it has entries to those sites. The browsing to undesired sites is know as hijacking. Trend Micro had a utility called CWShredder that I'm not sure who maintains it now http://www.softpedia.com/get/Interne...Shredder.shtml

If you are on Vista disable the System Restore first.

Again, in my bank environment if these slip past my IPS and AV I will rebuild the PC just to be on the safe side. These bugs can be time consuming. Good luck...btw, don't blame me if it goes to hell in a handbasket please!

Last edited by texan; 09-16-2009 at 10:29 AM.
texan is offline   Reply With Quote
Old 09-16-2009, 10:10 AM   #6
texan
 
texan's Avatar
 
Drives: people crazy
Join Date: Aug 2009
Location: duh
Posts: 191
one more tool, hijackthis will give you a more detailed list than msconfig to see what is starting up http://download.cnet.com/Trend-Micro...-10227353.html

if you really want to get down and dirty check out some winternals and a sniffer

http://technet.microsoft.com/en-us/s...s/default.aspx
http://www.wireshark.org/

last tip and I have to get productive...you can download firefox or chrome to usb and install it on the pc, if you can get out with another browser it is not network related but IE targeted and before disabling system restore you might try going back in time

Last edited by texan; 09-16-2009 at 10:35 AM.
texan is offline   Reply With Quote
Old 09-16-2009, 04:18 PM   #7
Mindz
E.B.A.H.
 
Mindz's Avatar
 
Drives: you wild...
Join Date: Mar 2007
Location: In the happy padded room wearing a jacket that makes me hug myself...
Posts: 18,420
Thanks for the links Texan. I formatted and re-installed last night (I keep most of my files on my external hard drive which I only connect if I want to listen to music or whatever.

I'm downloading Hijackthis as I type this.
__________________
Blue Rush, 2010 SS [Car of the Week 3/22/2010] Traded in on...ZLZBUBB, 2013 ZL1
Mindz is offline   Reply With Quote
Old 09-17-2009, 09:06 AM   #8
texan
 
texan's Avatar
 
Drives: people crazy
Join Date: Aug 2009
Location: duh
Posts: 191
good call
texan is offline   Reply With Quote
Old 09-18-2009, 07:44 AM   #9
manimsoblack

 
manimsoblack's Avatar
 
Drives: 04 Pontiac Grand Am, 08 Ninja 650r
Join Date: Jan 2009
Location: Bradenton/Ruskin FL
Posts: 1,165
watch out i had one that attached itself to any removable drives once, that was a frustrating week.
__________________
Quote:
Originally Posted by Kyle2k View Post
You take a shit on everything fun and good on this forum.
manimsoblack is offline   Reply With Quote
Old 09-18-2009, 09:50 AM   #10
Xanthos
PWA Relapse
 
Xanthos's Avatar
 
Drives: Formerly-Stick
Join Date: Mar 2008
Location: Oklahoma
Posts: 12,588
This is one of the reasons why I love my school laptop.

Runs on Linux.
- X
__________________

2017 1LT/RS A8 Hyper Blue Metallic

Xanthos is offline   Reply With Quote
Old 09-18-2009, 10:11 AM   #11
Camaro509

 
Camaro509's Avatar
 
Drives: 2010 2SS/RS Black
Join Date: Mar 2009
Location: Kansas
Posts: 1,085
Just fixed a laptop that was saturated with trojans and malware crap using this:
http://www.techmixer.com/kaspersky-r...009-using-dos/

It says it is 2009, it isn't. It's the 2008 version that will need to be updated online for a more thorough scan/remove once up and running. It boots off the CD (its an ISO image)
and loads a streamlined version of linux so you don't need to worry about propagating the malware and virii. Real easy to use, but the scans can take a long while since it is running off the CD and memory.
__________________
Understeer, Oversteer, Wheel Alignment (Camber etc), Torque, Horsepower, Camaro

Fold for team 11108 to help find a cure!
Folding@home Stanford's Research DC Program.
Camaro509 is offline   Reply With Quote
Old 09-18-2009, 10:18 AM   #12
Xanthos
PWA Relapse
 
Xanthos's Avatar
 
Drives: Formerly-Stick
Join Date: Mar 2008
Location: Oklahoma
Posts: 12,588
Quote:
Originally Posted by Camaro509 View Post
Just fixed a laptop that was saturated with trojans and malware crap using this:
http://www.techmixer.com/kaspersky-r...009-using-dos/

It says it is 2009, it isn't. It's the 2008 version that will need to be updated online for a more thorough scan/remove once up and running. It boots off the CD (its an ISO image)
and loads a streamlined version of linux so you don't need to worry about propagating the malware and virii. Real easy to use, but the scans can take a long while since it is running off the CD and memory.
Hmm - bookmarked.
- X
__________________

2017 1LT/RS A8 Hyper Blue Metallic

Xanthos is offline   Reply With Quote
Old 09-18-2009, 10:48 AM   #13
texan
 
texan's Avatar
 
Drives: people crazy
Join Date: Aug 2009
Location: duh
Posts: 191
kaspersky is good stuff, I've used several times, the only downside I could find was the footprint..it's almost as bloated and memory hog as Norton, at my last use

I'm an idiot..I forgot to meniton Hiren's. It's like the Snap-On truck for computer mechanics
http://www.hiren.info/pages/bootcd
texan is offline   Reply With Quote
Old 09-18-2009, 10:54 AM   #14
Camaro509

 
Camaro509's Avatar
 
Drives: 2010 2SS/RS Black
Join Date: Mar 2009
Location: Kansas
Posts: 1,085
Quote:
Originally Posted by texan View Post
kaspersky is good stuff, I've used several times, the only downside I could find was the footprint..it's almost as bloated and memory hog as Norton, at my last use

I'm an idiot..I forgot to meniton Hiren's. It's like the Snap-On truck for computer mechanics
http://www.hiren.info/pages/bootcd
The above Kaspersky isn't bloated at all, it is a streamlined version of their 'retail' version designed for bootable scans, not installation.

Norton's used to be bloated bad, their newest products are much, much thinner and faster. Give the new stuff a try, you may be pleasantly surprised.
__________________
Understeer, Oversteer, Wheel Alignment (Camber etc), Torque, Horsepower, Camaro

Fold for team 11108 to help find a cure!
Folding@home Stanford's Research DC Program.
Camaro509 is offline   Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Tech geek help needed Hemlawk Off-topic Discussions 8 06-16-2009 12:58 AM
Not Good, GM wants another 16 or is it 9 Billion to Survive. Scott@Bjorn3D General Automotive + Other Cars Discussion 226 02-20-2009 05:13 PM
Tech Gurus needed ASAP for bios questions. Mindz Off-topic Discussions 1 11-28-2007 10:48 AM


All times are GMT -5. The time now is 03:17 AM.


Powered by vBulletin® Version 3.8.9 Beta 4
Copyright ©2000 - 2026, vBulletin Solutions, Inc.