• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

ernel32.dll Virus Removal

Joined
Jun 17, 2007
Messages
7,335 (1.19/day)
Location
C:\Program Files (x86)\Aphexdreamer\
System Name Unknown
Processor AMD Bulldozer FX8320 @ 4.4Ghz
Motherboard Asus Crosshair V
Cooling XSPC Raystorm 750 EX240 for CPU
Memory 8 GB CORSAIR Vengeance Red DDR3 RAM 1922mhz (10-11-9-27)
Video Card(s) XFX R9 290
Storage Samsung SSD 254GB and Western Digital Caviar Black 1TB 64MB Cache SATA 6.0Gb/s
Display(s) AOC 23" @ 1920x1080 + Asus 27" 1440p
Case HAF X
Audio Device(s) X Fi Titanium 5.1 Surround Sound
Power Supply 750 Watt PP&C Silencer Black
Software Windows 8.1 Pro 64-bit
I've googled this and followed the steps I found to remove it and it still comes back. I can't surf the net because of this Trojan.
I've ran malware bytes and it too can't remove it. I've tried Safe Mode manually deleting it and it still comes back. Right now I'm running super spyware removal to see if it can remove it.

Anyone ever had this or know how to get rid of it?

The virus is on a Laptop running windows xp.
 
Joined
Jun 17, 2007
Messages
7,335 (1.19/day)
Location
C:\Program Files (x86)\Aphexdreamer\
System Name Unknown
Processor AMD Bulldozer FX8320 @ 4.4Ghz
Motherboard Asus Crosshair V
Cooling XSPC Raystorm 750 EX240 for CPU
Memory 8 GB CORSAIR Vengeance Red DDR3 RAM 1922mhz (10-11-9-27)
Video Card(s) XFX R9 290
Storage Samsung SSD 254GB and Western Digital Caviar Black 1TB 64MB Cache SATA 6.0Gb/s
Display(s) AOC 23" @ 1920x1080 + Asus 27" 1440p
Case HAF X
Audio Device(s) X Fi Titanium 5.1 Surround Sound
Power Supply 750 Watt PP&C Silencer Black
Software Windows 8.1 Pro 64-bit
I know this is going to sound weird, but re-set your router. Then run Malwarebytes and see if it detects anything.

Got the idea from this thread - post 30:TDSS remnants - ERNEL32.DLL removal help please, Remnants of infection pop up on MBAM but aren't found in scan

Let us know how it works.:)

But this came from another house. Its not my laptop so this is a whole new router and internet connection for the laptop.

Super Anti Spyware remover found threats as well and removed it but it was still there on reboot in system 32. It also won't let me launch certain .exe's.
 

Mussels

Freshwater Moderator
Staff member
Joined
Oct 6, 2004
Messages
58,413 (8.19/day)
Location
Oystralia
System Name Rainbow Sparkles (Power efficient, <350W gaming load)
Processor Ryzen R7 5800x3D (Undervolted, 4.45GHz all core)
Motherboard Asus x570-F (BIOS Modded)
Cooling Alphacool Apex UV - Alphacool Eisblock XPX Aurora + EK Quantum ARGB 3090 w/ active backplate
Memory 2x32GB DDR4 3600 Corsair Vengeance RGB @3866 C18-22-22-22-42 TRFC704 (1.4V Hynix MJR - SoC 1.15V)
Video Card(s) Galax RTX 3090 SG 24GB: Underclocked to 1700Mhz 0.750v (375W down to 250W))
Storage 2TB WD SN850 NVME + 1TB Sasmsung 970 Pro NVME + 1TB Intel 6000P NVME USB 3.2
Display(s) Phillips 32 32M1N5800A (4k144), LG 32" (4K60) | Gigabyte G32QC (2k165) | Phillips 328m6fjrmb (2K144)
Case Fractal Design R6
Audio Device(s) Logitech G560 | Corsair Void pro RGB |Blue Yeti mic
Power Supply Fractal Ion+ 2 860W (Platinum) (This thing is God-tier. Silent and TINY)
Mouse Logitech G Pro wireless + Steelseries Prisma XL
Keyboard Razer Huntsman TE ( Sexy white keycaps)
VR HMD Oculus Rift S + Quest 2
Software Windows 11 pro x64 (Yes, it's genuinely a good OS) OpenRGB - ditch the branded bloatware!
Benchmark Scores Nyooom.
try kasperskys 30 day trial.

malware bytes aint designed for antivirus, its just a spyware remover and nowhere near as good as a real AV.
 

streetfighter 2

New Member
Joined
Jul 26, 2010
Messages
1,655 (0.33/day)
Location
Philly
combofix? If you've never used combofix before this is a good place to start.

MBAM is actually pretty weak in my experience and I use it mostly to let me know if somethings wrong, rather than to fix it. If something is messed up I switch to the hard stuff like manual removal and combofix.

A trick that works for me often enough is if you can gain complete control of the dll in question start by deleting it, then create a blank file named with the same name as the dll, then manually edit the permissions to prevent anyone (including yourself) from r/w/e. This has worked for me countless times when I just needed to get a virus to stop bugging me while I figured out what was spawning it.
 
Last edited:

95Viper

Super Moderator
Staff member
Joined
Oct 12, 2008
Messages
12,670 (2.24/day)
Hmmmm... Is it connected to a wired or wireless connection now?

Use the repairs under preferences in Superantispyware to reset all ie explorer and hi-jack related problems. Run it again. And, make a bootable usb\cd and run this portable version from it.

That ernel32 virus is a form of rootkit. Nasty little bugger. Try this to:Malicious Software Removal Tool
Download here: Microsoft® Windows® Malicious Software Removal Tool (KB890830)

Also, try these, Avira Antivir Rescue System(iso) or Avira AntiVir Rescue System(exe)
Or\And, Kaspersky Rescue Disk 10

If all else fails combofix(A guide and tutorial on using ComboFix) or re-install the OS.

Sorry, a little slow in typing.
 
Joined
Jun 17, 2007
Messages
7,335 (1.19/day)
Location
C:\Program Files (x86)\Aphexdreamer\
System Name Unknown
Processor AMD Bulldozer FX8320 @ 4.4Ghz
Motherboard Asus Crosshair V
Cooling XSPC Raystorm 750 EX240 for CPU
Memory 8 GB CORSAIR Vengeance Red DDR3 RAM 1922mhz (10-11-9-27)
Video Card(s) XFX R9 290
Storage Samsung SSD 254GB and Western Digital Caviar Black 1TB 64MB Cache SATA 6.0Gb/s
Display(s) AOC 23" @ 1920x1080 + Asus 27" 1440p
Case HAF X
Audio Device(s) X Fi Titanium 5.1 Surround Sound
Power Supply 750 Watt PP&C Silencer Black
Software Windows 8.1 Pro 64-bit
combofix? If you've never used combofix before this is a good place to start.

MBAM is actually pretty weak in my experience and I use it mostly to let me know if somethings wrong, rather than to fix it. If something is messed up I switch to the hard stuff like manual removal and combofix.

A trick that works for me often enough is if you can gain complete control of the dll in question start by deleting it, then create a blank file named with the same name as the dll, then manually edit the permissions to prevent anyone (including yourself) from r/w/e. This has worked for me countless times when I just needed to get a virus to stop bugging me while I figured out what was spawning it.

Yeah I did Combo fix and got rid of it. Now however Combo fix has messed up my internet connection.

I can't seem to get an IP. Typing IPconfig in CMD results in access denied.

Now to fix this and the laptop should be good.
 
Joined
Jun 17, 2007
Messages
7,335 (1.19/day)
Location
C:\Program Files (x86)\Aphexdreamer\
System Name Unknown
Processor AMD Bulldozer FX8320 @ 4.4Ghz
Motherboard Asus Crosshair V
Cooling XSPC Raystorm 750 EX240 for CPU
Memory 8 GB CORSAIR Vengeance Red DDR3 RAM 1922mhz (10-11-9-27)
Video Card(s) XFX R9 290
Storage Samsung SSD 254GB and Western Digital Caviar Black 1TB 64MB Cache SATA 6.0Gb/s
Display(s) AOC 23" @ 1920x1080 + Asus 27" 1440p
Case HAF X
Audio Device(s) X Fi Titanium 5.1 Surround Sound
Power Supply 750 Watt PP&C Silencer Black
Software Windows 8.1 Pro 64-bit

It also says

unable to open registry key for TCPIP

So I think the issue is deeper but I will try that.

I also tried WinSOC fix but that didn't do the trick either. :/

EDIT: That didn't work.

reading here they suggest its a driver issue. I think I remember the Combo fix deleting a driver something .sys
 

95Viper

Super Moderator
Staff member
Joined
Oct 12, 2008
Messages
12,670 (2.24/day)
You are using wireless, I assume, so go to your hardware device manager and check the wireless devices. You may need to update or re-install a driver or two.
 
Joined
Jun 17, 2007
Messages
7,335 (1.19/day)
Location
C:\Program Files (x86)\Aphexdreamer\
System Name Unknown
Processor AMD Bulldozer FX8320 @ 4.4Ghz
Motherboard Asus Crosshair V
Cooling XSPC Raystorm 750 EX240 for CPU
Memory 8 GB CORSAIR Vengeance Red DDR3 RAM 1922mhz (10-11-9-27)
Video Card(s) XFX R9 290
Storage Samsung SSD 254GB and Western Digital Caviar Black 1TB 64MB Cache SATA 6.0Gb/s
Display(s) AOC 23" @ 1920x1080 + Asus 27" 1440p
Case HAF X
Audio Device(s) X Fi Titanium 5.1 Surround Sound
Power Supply 750 Watt PP&C Silencer Black
Software Windows 8.1 Pro 64-bit
Joined
Jun 17, 2007
Messages
7,335 (1.19/day)
Location
C:\Program Files (x86)\Aphexdreamer\
System Name Unknown
Processor AMD Bulldozer FX8320 @ 4.4Ghz
Motherboard Asus Crosshair V
Cooling XSPC Raystorm 750 EX240 for CPU
Memory 8 GB CORSAIR Vengeance Red DDR3 RAM 1922mhz (10-11-9-27)
Video Card(s) XFX R9 290
Storage Samsung SSD 254GB and Western Digital Caviar Black 1TB 64MB Cache SATA 6.0Gb/s
Display(s) AOC 23" @ 1920x1080 + Asus 27" 1440p
Case HAF X
Audio Device(s) X Fi Titanium 5.1 Surround Sound
Power Supply 750 Watt PP&C Silencer Black
Software Windows 8.1 Pro 64-bit
Now device manger says the hardware is there but Windows Wireless Network manager say the hardware isn't. I could do all but the last time following that TCIP IP reinstall guide and that was uninstall Internet protocol TCP/IP. It just hides the uninstall button.
 

95Viper

Super Moderator
Staff member
Joined
Oct 12, 2008
Messages
12,670 (2.24/day)
As a side note you might want to run, in a (administrative)command prompt, the command "sfc /scannow" that is without the quotes; and, a space between the "c" and "/". To check your system files and repair any that may have been changed or altered, just to be on the safe side.

Edit: I had already started typing, before your post...

Have you re-booted yet?

I can't re-call to well on xp, but I believe you can un-install and install the protocols in the add\remove programs-add\remove components.
 
Last edited:
Joined
Jun 17, 2007
Messages
7,335 (1.19/day)
Location
C:\Program Files (x86)\Aphexdreamer\
System Name Unknown
Processor AMD Bulldozer FX8320 @ 4.4Ghz
Motherboard Asus Crosshair V
Cooling XSPC Raystorm 750 EX240 for CPU
Memory 8 GB CORSAIR Vengeance Red DDR3 RAM 1922mhz (10-11-9-27)
Video Card(s) XFX R9 290
Storage Samsung SSD 254GB and Western Digital Caviar Black 1TB 64MB Cache SATA 6.0Gb/s
Display(s) AOC 23" @ 1920x1080 + Asus 27" 1440p
Case HAF X
Audio Device(s) X Fi Titanium 5.1 Surround Sound
Power Supply 750 Watt PP&C Silencer Black
Software Windows 8.1 Pro 64-bit
I'm good guys thanks. Did win sock and uninstalled Wireless NIC drivers. Worked upon reinstall.
 
Top