Computing.Net > Forums > Security and Virus > AdClicker-af.dll, Thanks

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

AdClicker-af.dll, Thanks

Reply to Message Icon

Original Message
Name: uncertain
Date: December 22, 2004 at 07:10:42 Pacific
Subject: AdClicker-af.dll, Thanks
OS: WIN2000, SP4
CPU/Ram: X86Family6Model5Stepping
Comment:

Info. found in this form helped. Wanted to record my experience in case it might be useful to others.

Symptom was follows. At startup (from power-down or log-in from power-up) McAffee virus shield would find a trojan and give a message like the following

"A trojan has been detected and cleaned! The file C:\WINNT\system32\vzmhe70cxod.dll was infected by the AdClicker-AF.dll trojan and has been deleted to complete the Clean process."

Problem was that this message happened at every power-up or log-in with hash-named dll changing name each time. McAfee was apparently finding a symptomatic dll and eliminating it but was not eliminating root of the problem. Commanding a McAfee scan after the start up would find nothing 99% of the time.

Read some entries at McAfee forums. Quite a few people had experienced similar problems with AdClicker-AF trojan, though symptoms were somewhat variable. Didn't see any simple recipe for eliminating the problem.
Then started to look elsewhere. Along the way I learned about HijackThis.exe and recorded a few logs. I'll show a couple here for context.

FIRST HijackThis LOG:

<deleted, apparently we're not allowed to post logs here.>

SECOND HijackThis LOG:

<deleted, apparently we're not allowed to post logs here.>

Problem with logs was that I don't know enough to interpret them reliably and also I wasn't sure whether they would really reveal the underlying problem. You can see from the 2 logs, separated in time, that I tried eliminating a few things. But that didn't help.

I then googled for "AdClicker-AF" and found this item

http://reviews.cnet.com/5208-6132-0.html?forumID=32&threadID=47070&messageID=560135

which showed a HijackThis log entry as follows

O20 - AppInit_DLLs: w8c6s4xcm66s.dll

This alerted me to the notion of an "AppInit_DLL" which seemed related to
my problem. I googled again or "AppInit_DLL" and eventually found this
http://www.computing.net/security/wwwboard/forum/11527.html

of which the following entry was most helpful.

Name: steve1308
Date: May 11, 2004 at 17:07:10 Pacific
Subject: CWS Searchx

Apparently AppInit_DLLs execute at start up based on a registry key. The key can appear blank but may still have content. Deleting the key helps. But if you try a simple delete using regedit.exe it may not work. steve1308 described how it could keep coming back. What I found was that I simply could not delete it while running in normal mode. steve1308 suggested a trick to accomplish deletion. I tried simply:

restarting in safe mode;
starting regedit.exe;
attempting the delete.

That worked. I've tried a few restarts since then and McAfee is now finding nothing.

I still wonder if I have a garbage dll lying around somewhere. But at this point the worst symptom seems to have been eliminated.



Report Offensive Message For Removal


Response Number 1
Name: Derek
Date: December 22, 2004 at 15:16:19 Pacific
Reply: (edit)

This link might be of use:

HIJACKLOG AUTO ANALYZE
(just paste your log into it).

It's not that HJT logs are "banned" around these parts but it's to avoid this website becoming a log reading service like so many others (that's just my interpretation).

Any entries on your log that you are certain are safe (known or sussed out) should be marked to "ignore". That will cut your log down to size which makes life easier. In the ultimate when your system is totally clean it can be set to ignore everything listed.

This means that you only have to concern yourself about the odd thing that arrives later. Anything new will either be some "nasty" or something you know can be added to the ignore list.

Run "Ad-Aware" & "SpyBot Search & Destroy", try the link, manage HJT as suggested above, and I doubt anyone will object to you submitting the short remaining log for us to look at. It's just a matter of helping yourself first.

Derek.W


Report Offensive Follow Up For Removal

Response Number 2
Name: djabouti
Date: January 4, 2005 at 07:50:00 Pacific
Reply: (edit)

I have the same problem described above and don't know how to start Safe Mode or regedit.exe. Can anyone help me. I'm not that good with computers, but I really have to fix this problem. I'm supriosed Mcafee won't fix it. Any help would really be appreciated.


Report Offensive Follow Up For Removal

Response Number 3
Name: Derek
Date: January 4, 2005 at 14:41:27 Pacific
Reply: (edit)

djabouti

I assume you googled here.

No two problems are alike. You are best to start a new post by going to the Security & Virus forum (top left).

This post is now several days old and might not get any more attention as it was posted for information only.

Derek.W


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you have your own blog?

Yes
No
I did before
I will soon


View Results

Poll Finishes In 4 Days.
Discuss in The Lounge
Poll History




Data Recovery Software