This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Cannot Access McAfee Website

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OK - Dr. Web CureIt scan is complete. Here is the log. Do I need to restart my PC now? I attempted to upload the file. Again, it didn't work. Hopefully this works just as well. BTW - Word Wrap is off. This is how it pasted into the message. Sorry: admdll.dll;c:\program files\radmin;Program.RemoteAdmin.21;Incurable.Moved.; r_server.exe;c:\program files\radmin;Program.RemoteAdmin;Incurable.Moved.; disneyprincesswp.exe\data019;C:\Documents and Settings\Amy\My Documents\disneyprincesswp.exe;Adware.NewDotNet;; disneyprincesswp.exe\data020;C:\Documents and Settings\Amy\My Documents\disneyprincesswp.exe;Adware.NewDotNet;; disneyprincesswp.exe\data021;C:\Documents and Settings\Amy\My Documents\disneyprincesswp.exe;Trojan.MulDrop.3633;; disneyprincesswp.exe\data022;C:\Documents and Settings\Amy\My Documents\disneyprincesswp.exe;Adware.Ezula;; disneyprincesswp.exe\data023;C:\Documents and Settings\Amy\My Documents\disneyprincesswp.exe;Adware.Gator;; disneyprincesswp.exe;C:\Documents and Settings\Amy\My Documents;Archive contains infected objects;Moved.; reference.exe\data008;C:\Documents and Settings\Laura\Desktop\reference.exe;Adware.Starware;; reference.exe;C:\Documents and Settings\Laura\Desktop;Archive contains infected objects;Moved.; Faexpl32.dll;C:\Documents and Settings\Tim\Old D Drive\Backup 011020\Program Files\the HelpSpot!;Adware.Nexus.origin;; delfolder.exe;C:\Program Files\DellSupport\GTCoach;Trojan.MulDrop.30652;Deleted.; raddrv.dll;C:\Program Files\Radmin;Program.RemoteAdmin;; radmin.exe;C:\Program Files\Radmin;Program.RemoteAdmin;; AdmDll.dll;C:\Program Files\Remote Viewer;Program.RemoteAdmin.21;; raddrv.dll;C:\Program Files\Remote Viewer;Program.RemoteAdmin;; radmin.exe;C:\Program Files\Remote Viewer;Program.RemoteAdmin;; r_server.exe;C:\Program Files\Remote Viewer;Program.RemoteAdmin;; Remote Administrator 2.1y.msi\stream008;C:\Program Files\SELFHEAL\Remote Administrator 2.1y\Remote Administrator 2.1y.msi;Program.RemoteAdmin;; Remote Administrator 2.1y.msi\stream009;C:\Program Files\SELFHEAL\Remote Administrator 2.1y\Remote Administrator 2.1y.msi;Program.RemoteAdmin;; Remote Administrator 2.1y.msi\stream010;C:\Program Files\SELFHEAL\Remote Administrator 2.1y\Remote Administrator 2.1y.msi;Program.RemoteAdmin;; Remote Administrator 2.1y.msi\stream012;C:\Program Files\SELFHEAL\Remote Administrator 2.1y\Remote Administrator 2.1y.msi;Program.RemoteAdmin;; Remote Administrator 2.1y.msi/stream013\radmin.exe;C:\Program Files\SELFHEAL\Remote Administrator 2.1y\Remote Administrator 2.1y.msi/stream013;Program.RemoteAdmin;; Remote Administrator 2.1y.msi/stream013\AdmDll.dll;C:\Program Files\SELFHEAL\Remote Administrator 2.1y\Remote Administrator 2.1y.msi/stream013;Program.RemoteAdmin.21;; Remote Administrator 2.1y.msi/stream013\r_server.exe;C:\Program Files\SELFHEAL\Remote Administrator 2.1y\Remote Administrator 2.1y.msi/stream013;Program.RemoteAdmin;; Remote Administrator 2.1y.msi/stream013\raddrv.dll;C:\Program Files\SELFHEAL\Remote Administrator 2.1y\Remote Administrator 2.1y.msi/stream013;Program.RemoteAdmin;; stream013;C:\Program Files\SELFHEAL\Remote Administrator 2.1y;Archive contains infected objects;; Remote Administrator 2.1y.msi;C:\Program Files\SELFHEAL\Remote Administrator 2.1y;Archive contains infected objects;Moved.; VPN-RA Combo 3.0.msi/stream009\admdll.dll;C:\Program Files\SELFHEAL\VPN-RA Combo 3.0\VPN-RA Combo 3.0.msi/stream009;Program.RemoteAdmin.21;; stream009;C:\Program Files\SELFHEAL\VPN-RA Combo 3.0;Archive contains infected objects;; VPN-RA Combo 3.0.msi;C:\Program Files\SELFHEAL\VPN-RA Combo 3.0;Archive contains infected objects;Moved.; A0074756.dll;C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP1560;Program.RemoteAdmin.21;; A0074757.exe;C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP1560;Program.RemoteAdmin;; A0074758.exe\data008;C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP1560\A0074758.exe;Adware.Starware;; A0074758.exe;C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP1560;Archive contains infected objects;Moved.; A0074759.exe;C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP1560;Trojan.MulDrop.30652;Deleted.; A0074761.msi\stream008;C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP1560\A0074761.msi;Program.RemoteAdmin;; A0074761.msi\stream009;C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP1560\A0074761.msi;Program.RemoteAdmin;; A0074761.msi\stream010;C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP1560\A0074761.msi;Program.RemoteAdmin;; A0074761.msi\stream012;C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP1560\A0074761.msi;Program.RemoteAdmin;; A0074761.msi/stream013\radmin.exe;C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP1560\A0074761.msi/stream013;Program.RemoteAdmin;; A0074761.msi/stream013\AdmDll.dll;C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP1560\A0074761.msi/stream013;Program.RemoteAdmin.21;; A0074761.msi/stream013\r_server.exe;C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP1560\A0074761.msi/stream013;Program.RemoteAdmin;; A0074761.msi/stream013\raddrv.dll;C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP1560\A0074761.msi/stream013;Program.RemoteAdmin;; stream013;C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP1560;Archive contains infected objects;; A0074761.msi;C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP1560;Archive contains infected objects;Moved.; A0074762.msi/stream009\admdll.dll;C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP1560\A0074762.msi/stream009;Program.RemoteAdmin.21;; stream009;C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP1560;Archive contains infected objects;; A0074762.msi;C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP1560;Archive contains infected objects;Moved.; ac7fbb1.msi\stream009;C:\WINDOWS\Installer\ac7fbb1.msi;Program.RemoteAdmin;; ac7fbb1.msi\stream010;C:\WINDOWS\Installer\ac7fbb1.msi;Program.RemoteAdmin;; ac7fbb1.msi\stream011;C:\WINDOWS\Installer\ac7fbb1.msi;Program.RemoteAdmin;; ac7fbb1.msi\stream012;C:\WINDOWS\Installer\ac7fbb1.msi;Program.RemoteAdmin;; ac7fbb1.msi;C:\WINDOWS\Installer;Archive contains infected objects;Moved.; ras02110_RemoteAdministratorviewer.exe;C:\WINDOWS\Installer\{E8B4F9A7-4A62-4521-A94C-EBCC577AB24C};Program.RemoteAdmin;; ras02110_SettingsforRemoteAdministratorserver.exe;C:\WINDOWS\Installer\{E8B4F9A7-4A62-4521-A94C-EBCC577AB24C};Program.RemoteAdmin;; ras02110_StartRemoteAdministratorserver.exe;C:\WINDOWS\Installer\{E8B4F9A7-4A62-4521-A94C-EBCC577AB24C};Program.RemoteAdmin;; ras02110_StopRemoteAdministratorserver.exe;C:\WINDOWS\Installer\{E8B4F9A7-4A62-4521-A94C-EBCC577AB24C};Program.RemoteAdmin;; admdll.dll;C:\WINDOWS\SYSTEM32;Program.RemoteAdmin.21;; nobuyeli.dll;C:\WINDOWS\SYSTEM32;Trojan.Siggen.568;Deleted.; zusenene.dll;C:\WINDOWS\SYSTEM32;Trojan.Siggen.568;Deleted.;
Could you now retry AVZ - I will put the instructions here again to save you searching for them. But this time I would like the first run in safe mode and the second in normal. And yes reboot now :)


We will now do a deep search of your processes and files

Download avz4.zip from here
  • Unzip it to your desktop to a folder named avz4
  • Double click on AVZ.exe to run it.
  • Run an update by clicking the Auto Update button on the Right of the Log window: [external image: Posted Image]
  • Click Start to begin the update
Note: If you recieve an error message, chose a different source, then click Start again


  • Start AVZ.
  • Choose from the menu "File" => "Standard scripts " and mark the "Healing/Quarantine and Advanced System Investigation" check box.
  • Click on the “Execute selected scripts”.
  • Automatic scanning, healing and system check will be executed.
  • A logfile (avz_sysinfo.htm) will be created and saved in the LOG folder in the AVZ directory as virusinfo_syscure.zip.
  • It is necessary to reboot your machine, because AVZ might disturb some program operations (like antiviruses and firewall) during the system scan.
  • All applications will work properly after the system restart.

When restarted

  • Start AVZ.
  • Choose from the menu "File" => "Standard scripts " and mark the “Advanced System Investigation" check box.
  • Click on the "Execute selected scripts".
  • A system check will be automatically performed, and the created logfile (avz_sysinfo.htm) will be saved in the LOG folder in the AVZ directory as virusinfo_syscheck.zip.

Attach both zip files to your next post

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post
Well, I ran the first AVZ scan in the Safe Mode, rebooted and ran the second scan in the Safe Mode, rebooted and ran the first scan in regular mode and got an error - similar to the first error I redeived this morning. Can't upload the error, but here's the verbiage: "Access violation at address 004012F2F in module 'avz.exe'. Read of address 04A09824." I'm open to any other ideas. In the meantime, here are the two logs I generated form the Safe Mode scans:

virusinfo_syscure (the xml file is shown - I cannot upload (sorry):


- –>
-
-



-


















-







-














-





































-
































-








-














-




-
http://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab" Descr="Shockwave ActiveX Control" LegalCopyright="Copyright © 1985-2003 Macromedia, Inc." Size="54480" Attr="rsAh" CreateDate="8/21/2004 9:53:23 AM" ChageDate="5/28/2004 12:38:00 AM" MD5="408F53722D9C1280BF4EDD70341EA7F2" />

http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.0.6.5.cab" Descr="Download Manager ActiveX Control" LegalCopyright="Copyright © 2006" Size="397312" Attr="rsAh" CreateDate="10/6/2006 11:10:12 PM" ChageDate="10/6/2006 11:10:12 PM" MD5="E9FD95773526EBC3FB4EAEE061C931D7" />

http://i.dell.com/images/global/js/scanner/SysProExe.cab" Descr="Utility to introspect the hardware capabalities of the computer" LegalCopyright="" Size="42952" Attr="rsAh" CreateDate="1/18/2008 12:28:10 PM" ChageDate="1/18/2008 12:28:10 PM" MD5="6074C2710A7F75BDF1C084BCC5EF6C8E" />

http://software-dl.real.com/2405419e1e5e12df3506/netzip/RdxIE601.cab" Descr="" LegalCopyright="" />
http://www.amiuptodate.com/vsc/bin/1,0,0,9/McUpdatePortal.cab" Descr="McAfee Am I Up To Date? ActiveX Module" LegalCopyright="Copyright © 1998-2004 Networks Associates Technology, Inc." Size="109568" Attr="rsAh" CreateDate="1/5/2006 6:49:00 PM" ChageDate="1/5/2006 6:49:00 PM" MD5="862F9B928FA7802E2019CE412C7A17FC" />
http://h30155.www3.hp.com/ediags/dd/install/guidedsolutions.cab" Descr="HPCommunication object for eSupport Diagnostics" LegalCopyright="©Hewlett-Packard All rights reserved." Size="221184" Attr="rsAh" CreateDate="10/7/2005 3:50:32 PM" ChageDate="10/7/2005 3:50:32 PM" MD5="0D77834247451B1EC7739397633538F1" />
http://download.yahoo.com/dl/installs/bkm/prod/yregcfg.cab" Descr="YRegCfg Module" LegalCopyright="Copyright 2002" Size="94208" Attr="rsAh" CreateDate="11/18/2002 12:02:42 PM" ChageDate="11/18/2002 12:02:42 PM" MD5="A86BB17876E4D0EE4710BF87FD6BB492" />
http://download.yahoo.com/dl/installs/ymail/ymmapi.dll" Descr="YMMAPI Module" LegalCopyright="Copyright © 2001-2006 Yahoo! Inc." Size="190496" Attr="rsAh" CreateDate="11/12/2006 9:08:55 AM" ChageDate="10/30/2006 2:50:00 PM" MD5="A0C86DB296BBE76145377D56C5975175" />
https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx" Descr="get_ActiveX ActiveX Control Module" LegalCopyright="Copyright © 2004 by Netopsystems AG" Size="88136" Attr="rsAh" CreateDate="12/26/2006 9:50:47 AM" ChageDate="12/26/2006 9:50:48 AM" MD5="200E3189656F9A29FB5BC7F71AB3F283" />


http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab" Descr="YPhotos Photo Uploader Module" LegalCopyright="Copyright © 1999-2003" Size="468128" Attr="rsAh" CreateDate="8/23/2004 4:23:56 PM" ChageDate="6/9/2003 3:52:08 PM" MD5="B367D4316F0C8EFF50FEEABD9F01E5E5" />
http://www.trueswitch.com/sbc/TrueInstallSBC.exe" Descr="" LegalCopyright="" />

-



-


-




-













-







and the virusinfo_syscheck log in the Safe Mode:


- –>
-
-



-

























-







-














-





































-
































-








-














-




-
http://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab" Descr="Shockwave ActiveX Control" LegalCopyright="Copyright © 1985-2003 Macromedia, Inc." Size="54480" Attr="rsAh" CreateDate="8/21/2004 9:53:23 AM" ChageDate="5/28/2004 12:38:00 AM" MD5="408F53722D9C1280BF4EDD70341EA7F2" />

http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.0.6.5.cab" Descr="Download Manager ActiveX Control" LegalCopyright="Copyright © 2006" Size="397312" Attr="rsAh" CreateDate="10/6/2006 11:10:12 PM" ChageDate="10/6/2006 11:10:12 PM" MD5="E9FD95773526EBC3FB4EAEE061C931D7" />

http://i.dell.com/images/global/js/scanner/SysProExe.cab" Descr="Utility to introspect the hardware capabalities of the computer" LegalCopyright="" Size="42952" Attr="rsAh" CreateDate="1/18/2008 12:28:10 PM" ChageDate="1/18/2008 12:28:10 PM" MD5="6074C2710A7F75BDF1C084BCC5EF6C8E" />

http://software-dl.real.com/2405419e1e5e12df3506/netzip/RdxIE601.cab" Descr="" LegalCopyright="" />
http://www.amiuptodate.com/vsc/bin/1,0,0,9/McUpdatePortal.cab" Descr="McAfee Am I Up To Date? ActiveX Module" LegalCopyright="Copyright © 1998-2004 Networks Associates Technology, Inc." Size="109568" Attr="rsAh" CreateDate="1/5/2006 6:49:00 PM" ChageDate="1/5/2006 6:49:00 PM" MD5="862F9B928FA7802E2019CE412C7A17FC" />
http://h30155.www3.hp.com/ediags/dd/install/guidedsolutions.cab" Descr="HPCommunication object for eSupport Diagnostics" LegalCopyright="©Hewlett-Packard All rights reserved." Size="221184" Attr="rsAh" CreateDate="10/7/2005 3:50:32 PM" ChageDate="10/7/2005 3:50:32 PM" MD5="0D77834247451B1EC7739397633538F1" />
http://download.yahoo.com/dl/installs/bkm/prod/yregcfg.cab" Descr="YRegCfg Module" LegalCopyright="Copyright 2002" Size="94208" Attr="rsAh" CreateDate="11/18/2002 12:02:42 PM" ChageDate="11/18/2002 12:02:42 PM" MD5="A86BB17876E4D0EE4710BF87FD6BB492" />
http://download.yahoo.com/dl/installs/ymail/ymmapi.dll" Descr="YMMAPI Module" LegalCopyright="Copyright © 2001-2006 Yahoo! Inc." Size="190496" Attr="rsAh" CreateDate="11/12/2006 9:08:55 AM" ChageDate="10/30/2006 2:50:00 PM" MD5="A0C86DB296BBE76145377D56C5975175" />
https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx" Descr="get_ActiveX ActiveX Control Module" LegalCopyright="Copyright © 2004 by Netopsystems AG" Size="88136" Attr="rsAh" CreateDate="12/26/2006 9:50:47 AM" ChageDate="12/26/2006 9:50:48 AM" MD5="200E3189656F9A29FB5BC7F71AB3F283" />


http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab" Descr="YPhotos Photo Uploader Module" LegalCopyright="Copyright © 1999-2003" Size="468128" Attr="rsAh" CreateDate="8/23/2004 4:23:56 PM" ChageDate="6/9/2003 3:52:08 PM" MD5="B367D4316F0C8EFF50FEEABD9F01E5E5" />
http://www.trueswitch.com/sbc/TrueInstallSBC.exe" Descr="" LegalCopyright="" />

-



-



-







Should I attempt to run the Advanced System Investigation sacn in the regular mode even though the Healing/Quarantine did not complete.? I was REALLY hoping this would work. Thanks again for your effort.
Within the AVZ folder should be a syscure and syscheck zip folders could you attach both of them please as they contain the information I need. Could you try to attach them from safe mode with networking. This one is being really stubborn :pullhair:
OK gotcha :P I notice you have Adobe 7 at the moment there is a new malware that exploits Adobe all versions so unless you are using the purchased version I would recommend replacing it with Foxit reader ASAP

AVZ FIX

  • Double click on AVZ.exe
  • Click File > Custom scripts
  • Copy & paste the contents of the following codebox in the box in the program (start with begin and end with end )
    begin
    SearchRootkit(true, true);
    SetAVZGuardStatus(True);
     RegKeyDel('HKLM','SOFTWARE\Microsoft\Code Store Database\Distribution Units\{2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B}');
     BC_DeleteFile('08223B03.dll');
     DeleteFile('08223B03.dll');
     BC_DeleteFile('3474A8C2.dll');
     DeleteFile('3474A8C2.dll');
     BC_DeleteFile('369774CA.dll');
     DeleteFile('369774CA.dll');
     BC_DeleteFile('4BF9CBA3.dll');
     DeleteFile('4BF9CBA3.dll');
     BC_DeleteFile('5184B75C.dll');
     DeleteFile('5184B75C.dll');
     BC_DeleteFile('7ADC2AB1.dll');
     DeleteFile('7ADC2AB1.dll');
     BC_DeleteFile('9CA963CA.dll');
     DeleteFile('9CA963CA.dll');
     BC_DeleteFile('C5350C93.dll');
     DeleteFile('C5350C93.dll');
     BC_DeleteFile('C:\WINDOWS\DOWNLO~1\DOWNLO~1.OCX');
     DeleteFile('C:\WINDOWS\DOWNLO~1\DOWNLO~1.OCX');
    BC_ImportDeletedList;
    ExecuteSysClean;
    BC_Activate;
    RebootWindows(true);
    end.
  • Note: When you run the script, your PC will be restarted
  • Click Run
  • Restart your PC if it doesn't do it automatically.

ON COMPLETION

  • Start AVZ.
  • Choose from the menu "File" => "Standard scripts " and mark the “Advanced System Investigation" check box.
  • Click on the "Execute selected scripts".
  • A system check will be automatically performed, and the created logfile (avz_sysinfo.htm) will be saved in the LOG folder in the AVZ directory as virusinfo_syscheck.zip.

Attach the zip file to your next post

AS SOON AS YOU HAVE RUN AVZ

Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2
Link 3

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–

Double click on Combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt along with a OTListit log so we can continue cleaning the system.
Murphy isn't my name, but should be. I uninstalled Adobe and installed FOxIt reader. Then I was able to run the custom script, then the Advanced System Investigation. I donwloaded the ComboFix.exe, and renamed it before saving it to my desktop. I double-clicked on Combo Fix, read the disclaimer, started it and received the "ble screen of death". Please tell me my PC isn't fried OR FOR THAT MATTER, my hard drive. The screen stated "A problem has been detected and windows has been shut down to prevent damage to your computer. If this is the first time…etc". What now???
I'm a little gunshy right now. I have saved a lot of important files to an external hard drive. WOuld it be possible to save others before I run combofix?
I should have mentioned that furing my running of the AVX Advanced System Investigation, a couple of virus warning pop-ups form McAfee regarding Generic.dx happened. Does this impact what we're doing?
I tried accessing the website last night and couldn't - same thing. I haven't tried since we did the stuff this morning. I think that the updating is tied into the access of the web site. If I can't access the website, I can't update. WHen I try to download the update, it just keeps running and finally times out. THe weird thisng is I still think the malware is present. McAfee is taking forever to kick in whan I boot up.
Tried running COmboFix again. Now it's telling me that I can't rename it as Combo-Fix and recommentding using Alphanumeric. SHould I download ComboFix again and rename it something else?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI