New Conficker Variant: PC contantly saying it needs DLL

Thread Solved

Join Date: Sep 2007
Posts: 27
Reputation: bdb4269 is an unknown quantity at this point 
Solved Threads: 0
bdb4269 bdb4269 is offline Offline
Light Poster

New Conficker Variant: PC contantly saying it needs DLL

 
0
  #1
Feb 14th, 2009
How can I stop this PC from thinking it needs an infected dll whenever ANYTHING is run?

Literally whenever you open any exe, it says that it can't run because of missing DLL, repeatedly, (like you click OK, and same message comes up again -- between 3-20 times) but then the app eventually opens most of the time. It's like somehow this msjmjh.dll got set as a requirement for all exe's or something.

msjmjh.dll is a randomly named DLL that is identified as Conficker/Downadup/Kido. A few days ago, it was only identified by 4 AV's ( http://www.virustotal.com/analisis/b...e88a960e2a23d0 ), and now it's identified by 8 AV's. ( http://www.virustotal.com/analisis/c...ce9df578745be9 )

The PC in question does not appear to be infected, in that it does not show symptoms of conficker (i.e. disables services etc) -- The only symptom, is that it seems to think it needs this dll to do anything, but the dll is not a real DLL file, google search returns nothing.



p.s. Here is a previous thread from before I was sure it was not a false positive.
http://www.experts-exchange.com/Viru..._24135283.html
Reply With Quote Quick reply to this message  
Join Date: Jul 2008
Posts: 3,051
Reputation: jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all 
Solved Threads: 173
Moderator
Featured Poster
jholland1964 jholland1964 is offline Offline
Posting Sensei

Re: New Conficker Variant: PC contantly saying it needs DLL

 
0
  #2
Feb 14th, 2009
I would like to see all new scans please.
Update MBA-M and do a FULL System scan, allow it to REMOVE all found. Save the log.
REBOOT the computer.
Run the ESET Online Scanner and post the ScanLog with your post for assistance.

* You will need to use Internet Explorer to to complete this scan.
* You will need to temporarily Disable your current Anti-virus program.
* Be sure the option to Remove found threats is Un-checked at this time (we may have it clean what it finds at a later time), and the option to Scan unwanted applications is Checked.
* When you have completed that scan, a scanlog ought to have been created and located at C:\Program Files\EsetOnlineScanner\log.txt. Please post that log for us as directed below.
REBOOT the computer
Run a Full System Scan with HJT and save the log. Exit HJT
Post back here with ALL three logs.
Reply With Quote Quick reply to this message  
Join Date: Sep 2007
Posts: 27
Reputation: bdb4269 is an unknown quantity at this point 
Solved Threads: 0
bdb4269 bdb4269 is offline Offline
Light Poster

Re: New Conficker Variant: PC contantly saying it needs DLL

 
0
  #3
Feb 20th, 2009
So I was actually away from the office on vacation until today (was hoping to get some idea's to try once I got back) -- I had not actually tried system restore yet, because the first thing I had noticed was AVG quarantined a file as Downadup/Conficker -- and I didn't think it could be that easy. Anyway -- for some reason, I felt I should at least give it a try, and it did actually work.

I'm still a bit confused as the whole thing was kind of weird. With windows thinking it needed the infected/randomly named dll file for everything. It's like AVG did catch the DLL file, but not whatever something did before that to make windows call the DLL whenever anything is opened.

Anyway -- the problems seems to be resolved. Thanks for all the input!!
Reply With Quote Quick reply to this message  
Join Date: Jul 2008
Posts: 3,051
Reputation: jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all 
Solved Threads: 173
Moderator
Featured Poster
jholland1964 jholland1964 is offline Offline
Posting Sensei

Re: New Conficker Variant: PC contantly saying it needs DLL

 
0
  #4
Feb 21st, 2009
You should not assume the problem is solved. The computer thought it needed this infected file because the infected file "told it" it was needed. It probably was listed as an auto start, possibly a starting service, very possibly have disabled all of your security programs, though they can look to you like they are working. They may even SAY they are working. System Restore isn't going to fix damaged programs. It might return "some" of the system files back but if your security programs were damaged, it is very possible they are still damaged. You said every program you opened wanted this file...what does that tell you?

You said this is a business computer, though not what operating system you have but you are taking a BIG chance not completing the clean up steps listed. MS issued a security patch several months ago which could possibly have prevented this. But most people who installed the patch were home users, businesses didn't bother, as of mid January, according to the article HERE, it is possible that 1 in every 16 business computers have been infected by this.

I just worked for over ten days on a computer that was highly infected, and ONE of the infections was the Conficker Trojan. Every single security program on the computer was totally trashed and to begin with every single new one I tried was infected immediately. The owner HAD used System Restore to try to correct the fact that her security programs were no longer working and many of her other programs were requesting some strange .dll file in order to run. With her System Restore she did get the programs to stop requesting this file, but her the security programs were damaged.
It is your choice, but if it were my computer I would run the steps.
Last edited by jholland1964; Feb 21st, 2009 at 12:49 am.
Reply With Quote Quick reply to this message  
Join Date: Sep 2007
Posts: 27
Reputation: bdb4269 is an unknown quantity at this point 
Solved Threads: 0
bdb4269 bdb4269 is offline Offline
Light Poster

Re: New Conficker Variant: PC contantly saying it needs DLL

 
0
  #5
Feb 21st, 2009
The computer is (and was to begin with) up to date with patch's.

I did check to see, and the computer has never shown any symptoms of being infected with Conficker. (http://en.wikipedia.org/wiki/Conficker)

The only thing you suggest that I didn't already do, is run ESET online scan. But that is not going to do me much good since ESET (NOD32) is STILL not detecting any infection in the dll file in question. http://www.virustotal.com/analisis/8...9c847da52f407a (as you can see, still only 14/39 AV's flag the file)

AVG quarantined the DLL before it was even run, resulting in the the error message that the DLL was missing. How did it get set to run? I don't know. Why did AVG let it somehow get set to run, but then caught it before it ran. I don't know

I mean -- I appreciate the warning -- If you have something to suggest that I have not already done, and does not involve an AV brand that doesn't even detect the infected dll at all -- I would be happy to try it. More assurance is great. (I just don't want to waste time running an online scan, that doesn't even detect the infected dll yet. )
Reply With Quote Quick reply to this message  
Join Date: Jul 2008
Posts: 3,051
Reputation: jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all 
Solved Threads: 173
Moderator
Featured Poster
jholland1964 jholland1964 is offline Offline
Posting Sensei

Re: New Conficker Variant: PC contantly saying it needs DLL

 
0
  #6
Feb 21st, 2009
The choice is yours. I gave you my best advice, which is always it is better to be safe than sorry. You feel this was incorrect and that is fine.
Other scans we recommend here if ESET isn't an option are
• Kaspersky Online Scanner

• Panda Active Scan

• Trend Micro HouseCall


• F-Secure Online Virus Scanner
Some of those onlines will clean some will not. ESET has been recommended most of the time because it will clean what it finds.
But it is your option.
Thanks for posting back.
Last edited by jholland1964; Feb 21st, 2009 at 3:59 pm.
Reply With Quote Quick reply to this message  
Join Date: Sep 2007
Posts: 27
Reputation: bdb4269 is an unknown quantity at this point 
Solved Threads: 0
bdb4269 bdb4269 is offline Offline
Light Poster

Re: New Conficker Variant: PC contantly saying it needs DLL

 
0
  #7
Mar 4th, 2009
Just to update....

I did an online scan with Kaspersky**. Also did new scans with MBAM, HJT, and ComboFix, and everything is looking good.



**(last I checked ESET/NOD32 was still not detecting anything in the infected DLL according to virustotal - despite the fact I sent them samples (at samples at eset dot com) way back on 2/12 -- (which was before I even started this thread))
Last edited by bdb4269; Mar 4th, 2009 at 8:44 pm.
Reply With Quote Quick reply to this message  
Join Date: Nov 2006
Posts: 7
Reputation: EsoxLucius is an unknown quantity at this point 
Solved Threads: 1
EsoxLucius's Avatar
EsoxLucius EsoxLucius is offline Offline
Newbie Poster

Re: New Conficker Variant: PC contantly saying it needs DLL

 
0
  #8
Mar 12th, 2009
Win32.Worm.Downadup.C is a new variant that seems to be even harder to trace and to stop. I found out about www.bdtools.net website, from bitdefender that is a site not yet on Downadup's blacklist.
Some info from site:
BitDefender Labs has detected a new and more aggressive Downadup version on Saturday, 07.02.2009. It spreads using a Windows RPC Server Service vulnerability and is called Win32.Worm.Downadup.Gen.
Reply With Quote Quick reply to this message  
Reply

This thread has been marked solved.
Perhaps start a new thread instead?
Message:



Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC