HELP: Virus is keeping my computer alive?


Recommended Posts

Hi guys, been a while since I last posted :)

Anyways I've a funny problem with my Win7 laptop that's leaving me stumped!

Well here's how the story goes.....

I bought myself an iPad, which I loved until I decided to try to connected to this laptop. Unfortunately I got this error that "Apple Mobile Device" couldn't start, so I followed instructions on how I should remove this program called "Megakey" that was interfering with the service.

I HAD megakey installed, but obviously it wasn't uninstalled properly as a normal search popped up this file:

C:\Programdata\Megamedia\Megakey\msadm.dll

I couldn't delete it as it was being used by a whole load of other programs (As Unlocker told me so).

What I did next was to extract the megakey.exe file from their website using 7zip, transferred the uninstall.exe from megakey.exe into that folder containing msadm.dll and executed uninstall.

After rebooting, msadm.dll was removed, like finally :)

However!!

Once msadm.dll was removed, for some strange reason my browsers such as Firefox and IE couldn't work. When typing any address (google.com, facebook.com, neowin.net) into the web browser, FF would just leave me stuck in the empty tab while IE just says there's a connection problem (where conducting any diagnostics doesn't work, as usual).

After much thought I realised that it could be the msadm.dll that's affecting it, so I created the same folder in program data and transferred msadm.dll from my previously extracted megakey.exe back into the SAME folder.

Strangely, after putting that .dll file back, I could use firefox and IE all over again!

Does anyone know why this is occuring? I'm stumped, and so are my friends. Could it be that msadm.dll is actually supporting my computer and has become an infectious, cancerous-like parasite? Is there a way for me to remove msadm.dll without losing connectivity and thus allowing me to connect the iPad?

Hope to hear from you guys!

Thanks :)

The virus has corrupted your browsers, to force you to go to other sites.

I would try System Restore first, if you use it.

Next you could uninstall Megakey, and delete msadm.dll, then run the Registry cleaner, such as the one with CCleaner (free download).

That can get rid of the useless registry entry that is causing a problem, that you 'need' the msadm.dll file.

You could run a good anti-virus scan as well.

Lastly I would save your bookmarks, and remove Firefox, then Reinstall.

good luck ....

Thanks for your reply :)

I did try to do a system restore but megakey was uninstalled like months ago, and I only realised there's remnants of it lying around today. So restoring my system back to when I did not have megakey installed is...impossible? Not sure about that =/

I can't delete msadm.dll as it's being 'used' by many other programs such as services.exe, firefox.exe, svchost.exe and some norton process. The only way I could delete it was using the uninstaller, and also by using my old dual boot of iATKos to delete it.

I tried deleting it, running CCleaner AND a virus scan using Norton Internet Security, but I still cannot use the browser.

@gaara sama you're suggesting SAFE mode, then running malwarebytes?

Remove the file, folder, and anything else that shouldn't be there

Reset IE, make sure FF and other browsers are not set to run through any proxy

Run Malwarebytes

Empty temp folders

Disable anything suspicious in msconfig

Everything in msconfig that I don't need/not sure what they are, are already disabled. Temp folders are clean. Running malwarebytes now :)

Sounds like a rootkit or something of that ilk. Take a look at your browser's connection settings and confirm it isn't using a proxy of some kind.

Firefox says no proxy is being used! :(

Try Kaspersky labs TDSS killer too, just to be sure.

Thanks! Trying out now....

Kaspersky TDSS Killer detected "sptd" as suspicious, from C:\Windows\system32\Drivers\sptd.sys

It will remove after reboot...gonna reboot now :)

Anyway so far Malwarebytes hasn't churned up anything yet.

Yeap, Safe mode but either download all the updates before rebooting into safe mode of go safe mode with networking. Safe mode only sarts with services that are required to run, this usualy leaves most 'locked' files and folders open to be deleted. I would also clear out all your restore points too (turn off system restore then turn it back on).

Have you removed Firefox and reinstalled to see if it works then?

Firefox says no proxy is being used! :(

Thanks! Trying out now....

Kaspersky TDSS Killer detected "sptd" as suspicious, from C:\Windows\system32\Drivers\sptd.sys

It will remove after reboot...gonna reboot now :)

Anyway so far Malwarebytes hasn't churned up anything yet.

sptd is not something to worry of as it used by dameon tools and probley other programs though not sure which if i remember rightly sptd also have there own uninstaller website wise

Yeap, Safe mode but either download all the updates before rebooting into safe mode of go safe mode with networking. Safe mode only sarts with services that are required to run, this usualy leaves most 'locked' files and folders open to be deleted. I would also clear out all your restore points too (turn off system restore then turn it back on).

Have you removed Firefox and reinstalled to see if it works then?

At that point when I deleted the .dll file, reinstalling didn't work o.o

I will go into safe mode tomorrow morning as it's already 12.13am now =/ Sorry but thanks soo much for all your generous help thus far!

sptd is not something to worry of as it used by dameon tools and probley other programs though not sure which if i remember rightly sptd also have there own uninstaller website wise

So I shouldn't remove it?

At that point when I deleted the .dll file, reinstalling didn't work o.o

I will go into safe mode tomorrow morning as it's already 12.13am now =/ Sorry but thanks soo much for all your generous help thus far!

So I shouldn't remove it?

that really depends the only time i seen sptd get installed is for virutal cd - dvd emulation software like alchol 120 dameon tools if you don't used such tools it not needed if you do your gonna need it

Hi,

I'm currently on safe mode with networking. Tried to delete but it still says it cannot be deleted as it is being used by another program. Unlocker doesn't seem to be working in safe mode and hence I cannot find out which program is using the .dll file in safe mode. My guess is svchost.exe? =/

Update: I used megakey's uninstall.exe to remove the .dll file. When restarted back to safe mode with networking, I got the message "windows help and support cannot start". Thereafter, any attempts to use firefox and ie yields no results, I'm just stuck on an empty tab.

Kaspersky tdss and malwarebytes scans yield no results as well, they say my computer has no malware or rootkits.

Tried reinstalling firefox as well, but once again I still can't connect to the Internet.

The only way I can connect to the Internet again is to put back the megakey .dll file into program data.

Ahhhhh! Any ideas? :/

The virus most likely set a proxy server in your web browser... In IE go to internet options > connections > lan settings and uncheck proxy, make sure only "automatically detect settings" is checked.

In firefox its options > advanced > network > connection > settings

The virus most likely set a proxy server in your web browser... In IE go to internet options > connections > lan settings and uncheck proxy, make sure only "automatically detect settings" is checked.

In firefox its options > advanced > network > connection > settings

Yes, on firefox it's no proxy, and in IE "automatically detect settings" is checked.

You could try a portable version of the browsers- also try spybot search and destroy-

http://portableapps.com/apps

Spybot? I haven't used that in years.....I thought malwarebytes and others were more efficient! Anyway I've already used Kaspersky TDSS, malwarebytes AND norton full system scan....still nothing!

Will try your portable apps suggestion now :)

have you tried an "sfc /scannow" yet?

if you haven't yet, run that in an admin level cmd window in safe mode or if you can from the recovery mode command prompt on the Windows 7 install disk

'Nuke it, it's the only way to be sure' - Aliens.

Backup using a Linux live CD to whatever media you want or partition and move what you need over.

Format the OS partition and reinstall.

I wouldn't ever trust a rooted version of windows. Especially if you use passwords/credit card/bank information on the internet.

The thing is the .dll file isn't causing me any problems, aside from not being able to connect to my iPad. Seems too much of a hassle, but yeah, I'll probably do it if I can't get the file out by next week.

Anyways sfc /scannow gave a report that "Windows Resource Protection found corrupt files but was unable to fix some of them"

^That is a good indication that the only way you are going to recover is to do a format and reinstall. It seems that this virus has corrupted core windows files and the only for sure way of recovering from this would be to reinstall windows. It is a PITA to do, but faced with everything else your choices seem rather slim.

Can you "ping" a website? Open cmd prompt-> type ping www.google.com and hit Enter. If you get a reponse, then maybe try rebuilding your TCP/IP stack:

http://support.microsoft.com/kb/299357

http://answers.microsoft.com/en-us/windows/forum/windows_7-networking/how-to-reset-tcpip-stack-in-windows-7/82560f98-de0c-4e75-ae48-9938bc980f47

Make sure to run the cmd prompt as admin by right-clicking cmd and selecting to run as admin.

This topic is now closed to further replies.
  • Posts

    • How many other companies will follow Ford's lead? Or, have they already gotten lazy and become enslaved to AI--and now can't figure out how to get out of that mess.
    • Why would any self-respecting intelligent person follow any recommendation by Donald's GOP administration? With almost two years of fabrications, deceit, and blatantly illegal behavior, why believe them now? They had best be gone after the November 2026 election, so we'll wait and see.
    • AltSendme 0.4.1 by Razvan Serea AltSendme is a minimal, cross-platform application designed for fast, secure, and private peer-to-peer file transfers. It allows users to send files or entire directories directly between devices without relying on cloud servers, accounts, or any personal information. Everything is encrypted end-to-end using modern protocols like QUIC and TLS 1.3, ensuring both strong security and low-latency performance. Transfers are verified with BLAKE3 for data integrity, and interrupted downloads automatically resume, making the experience reliable even on unstable connections. You can transfer anything—images, videos, documents, and more. Integrity checks are performed on both ends, so your files are automatically verified for correctness during both sending and receiving. AltSendme works seamlessly across local networks or long-distance links, capable of saturating multi-gigabit connections for extremely fast delivery. With built-in NAT traversal and encrypted relay fallback, it connects devices almost anywhere. The app integrates with the Sendme CLI and will soon support mobile and web platforms. Fully free and open-source, AltSendme offers a lightweight, privacy-first alternative to traditional cloud-based services, removing size limits, upload costs, and unnecessary data exposure. AltSendme 0.4.1 changelog: Release Highlights Self-hosted relays: Run your own iroh relay so transfers don't rely on public infrastructure. Includes a full deployment template in deploy/relay/ with Docker Compose for a VPS and configuration examples for production use. Fly.io support: One-click deploy template for Fly.io, including a quick-start config (fly.dev.toml) for testing without a custom domain, plus production setup with Let's Encrypt and your own hostname. Relay settings UI: New Settings → Network panel to choose how AltSendme connects: automatic public relays, custom self-hosted URLs (with optional auth token), or disabled. Test connections, verify latency, and see live relay status in the footer. Disable relays: Turn off relay servers entirely when you only need same-network transfers (e.g. LAN). Direct connections only. No relay hop required when devices can reach each other. Android graduates from beta: Android is now part of the regular release cycle alongside desktop. APKs ship with each version (universal, arm64, and armv7). Other improvements Private relay access control via shared auth token Relay fallback notifications when a custom relay is unreachable Broadcast mode toggle in sharing settings Android release build fixes (split-per-ABI APKs, universal APK preservation) UI polish: mobile safe-area insets, dropzone layout, transfer progress animation Bug fixes for minification-related serialization issues and system tray icon loading What's Changed feat(relay): add relay status functionality and settings UI (a120cdf) feat(relay): implement custom relay server configuration and verification (51276c7) feat(relay): add configuration for private relay access and enhance observability features (48fbabf) feat(relay): enhance relay URL validation, display connection status (d4fffa0) feat(relay): add RelayChangeGuard component and enhance relay-related translations (16ba514) feat(broadcast): add toggle setting for broadcast mode in sharing UI (ca6d977) fix(relay): correct QUIC discovery port, pin image, templatize fly.dev (52a2ba5) fix: More broken serialization due to minification (67491a9) fix(android): preserve true universal APK across per-ABI builds (e9f256f) fix(ui): conditional safe-area insets padding on mobile (1182f0e) refactor(transfer): CircularRing component animation fix (944572b) chore(android): drop x86 and x86_64 release APKs, keep universal+arm64+armv7 (34ada0b) Download: AltSendme 0.4.1 | ARM64 | ~9.0 MB (Open Source) Download: AltSendme for MacOS | Android Links: AltSendme Home Page | GitHub | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • You are mostly right about the ephemeral nature of it. As I mention in the article, if you dont add a second device or take a backup of your account before uninstalling it, then yes you will lose access to your account. That said, in terms of actual user experience when you sync multiple devices your message history carries across and there's also a Saved Messages chat like there is on Telegram to send messages and attachments between your installs. But yh, what you point out are correct and its not trying to emulate Messenger or Telegram.
    • OK so SearXNG is a meta search engine that you can install locally or use via a public instance. It scrapes other search engines which you choose and then sorts the results. Not as complicated as multiple relays
  • Recent Achievements

    • Week One Done
      flexorcist earned a badge
      Week One Done
    • One Month Later
      Woland13 earned a badge
      One Month Later
    • Week One Done
      Woland13 earned a badge
      Week One Done
    • One Year In
      bernmeister earned a badge
      One Year In
    • Week One Done
      Scoobystu earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      492
    2. 2
      +Edouard
      224
    3. 3
      PsYcHoKiLLa
      150
    4. 4
      Steven P.
      75
    5. 5
      FloatingFatMan
      71
  • Tell a friend

    Love Neowin? Tell a friend!