HELP: Virus is keeping my computer alive?


Recommended Posts

Hi guys, been a while since I last posted :)

Anyways I've a funny problem with my Win7 laptop that's leaving me stumped!

Well here's how the story goes.....

I bought myself an iPad, which I loved until I decided to try to connected to this laptop. Unfortunately I got this error that "Apple Mobile Device" couldn't start, so I followed instructions on how I should remove this program called "Megakey" that was interfering with the service.

I HAD megakey installed, but obviously it wasn't uninstalled properly as a normal search popped up this file:

C:\Programdata\Megamedia\Megakey\msadm.dll

I couldn't delete it as it was being used by a whole load of other programs (As Unlocker told me so).

What I did next was to extract the megakey.exe file from their website using 7zip, transferred the uninstall.exe from megakey.exe into that folder containing msadm.dll and executed uninstall.

After rebooting, msadm.dll was removed, like finally :)

However!!

Once msadm.dll was removed, for some strange reason my browsers such as Firefox and IE couldn't work. When typing any address (google.com, facebook.com, neowin.net) into the web browser, FF would just leave me stuck in the empty tab while IE just says there's a connection problem (where conducting any diagnostics doesn't work, as usual).

After much thought I realised that it could be the msadm.dll that's affecting it, so I created the same folder in program data and transferred msadm.dll from my previously extracted megakey.exe back into the SAME folder.

Strangely, after putting that .dll file back, I could use firefox and IE all over again!

Does anyone know why this is occuring? I'm stumped, and so are my friends. Could it be that msadm.dll is actually supporting my computer and has become an infectious, cancerous-like parasite? Is there a way for me to remove msadm.dll without losing connectivity and thus allowing me to connect the iPad?

Hope to hear from you guys!

Thanks :)

The virus has corrupted your browsers, to force you to go to other sites.

I would try System Restore first, if you use it.

Next you could uninstall Megakey, and delete msadm.dll, then run the Registry cleaner, such as the one with CCleaner (free download).

That can get rid of the useless registry entry that is causing a problem, that you 'need' the msadm.dll file.

You could run a good anti-virus scan as well.

Lastly I would save your bookmarks, and remove Firefox, then Reinstall.

good luck ....

Thanks for your reply :)

I did try to do a system restore but megakey was uninstalled like months ago, and I only realised there's remnants of it lying around today. So restoring my system back to when I did not have megakey installed is...impossible? Not sure about that =/

I can't delete msadm.dll as it's being 'used' by many other programs such as services.exe, firefox.exe, svchost.exe and some norton process. The only way I could delete it was using the uninstaller, and also by using my old dual boot of iATKos to delete it.

I tried deleting it, running CCleaner AND a virus scan using Norton Internet Security, but I still cannot use the browser.

@gaara sama you're suggesting SAFE mode, then running malwarebytes?

Remove the file, folder, and anything else that shouldn't be there

Reset IE, make sure FF and other browsers are not set to run through any proxy

Run Malwarebytes

Empty temp folders

Disable anything suspicious in msconfig

Everything in msconfig that I don't need/not sure what they are, are already disabled. Temp folders are clean. Running malwarebytes now :)

Sounds like a rootkit or something of that ilk. Take a look at your browser's connection settings and confirm it isn't using a proxy of some kind.

Firefox says no proxy is being used! :(

Try Kaspersky labs TDSS killer too, just to be sure.

Thanks! Trying out now....

Kaspersky TDSS Killer detected "sptd" as suspicious, from C:\Windows\system32\Drivers\sptd.sys

It will remove after reboot...gonna reboot now :)

Anyway so far Malwarebytes hasn't churned up anything yet.

Yeap, Safe mode but either download all the updates before rebooting into safe mode of go safe mode with networking. Safe mode only sarts with services that are required to run, this usualy leaves most 'locked' files and folders open to be deleted. I would also clear out all your restore points too (turn off system restore then turn it back on).

Have you removed Firefox and reinstalled to see if it works then?

Firefox says no proxy is being used! :(

Thanks! Trying out now....

Kaspersky TDSS Killer detected "sptd" as suspicious, from C:\Windows\system32\Drivers\sptd.sys

It will remove after reboot...gonna reboot now :)

Anyway so far Malwarebytes hasn't churned up anything yet.

sptd is not something to worry of as it used by dameon tools and probley other programs though not sure which if i remember rightly sptd also have there own uninstaller website wise

Yeap, Safe mode but either download all the updates before rebooting into safe mode of go safe mode with networking. Safe mode only sarts with services that are required to run, this usualy leaves most 'locked' files and folders open to be deleted. I would also clear out all your restore points too (turn off system restore then turn it back on).

Have you removed Firefox and reinstalled to see if it works then?

At that point when I deleted the .dll file, reinstalling didn't work o.o

I will go into safe mode tomorrow morning as it's already 12.13am now =/ Sorry but thanks soo much for all your generous help thus far!

sptd is not something to worry of as it used by dameon tools and probley other programs though not sure which if i remember rightly sptd also have there own uninstaller website wise

So I shouldn't remove it?

At that point when I deleted the .dll file, reinstalling didn't work o.o

I will go into safe mode tomorrow morning as it's already 12.13am now =/ Sorry but thanks soo much for all your generous help thus far!

So I shouldn't remove it?

that really depends the only time i seen sptd get installed is for virutal cd - dvd emulation software like alchol 120 dameon tools if you don't used such tools it not needed if you do your gonna need it

Hi,

I'm currently on safe mode with networking. Tried to delete but it still says it cannot be deleted as it is being used by another program. Unlocker doesn't seem to be working in safe mode and hence I cannot find out which program is using the .dll file in safe mode. My guess is svchost.exe? =/

Update: I used megakey's uninstall.exe to remove the .dll file. When restarted back to safe mode with networking, I got the message "windows help and support cannot start". Thereafter, any attempts to use firefox and ie yields no results, I'm just stuck on an empty tab.

Kaspersky tdss and malwarebytes scans yield no results as well, they say my computer has no malware or rootkits.

Tried reinstalling firefox as well, but once again I still can't connect to the Internet.

The only way I can connect to the Internet again is to put back the megakey .dll file into program data.

Ahhhhh! Any ideas? :/

The virus most likely set a proxy server in your web browser... In IE go to internet options > connections > lan settings and uncheck proxy, make sure only "automatically detect settings" is checked.

In firefox its options > advanced > network > connection > settings

The virus most likely set a proxy server in your web browser... In IE go to internet options > connections > lan settings and uncheck proxy, make sure only "automatically detect settings" is checked.

In firefox its options > advanced > network > connection > settings

Yes, on firefox it's no proxy, and in IE "automatically detect settings" is checked.

You could try a portable version of the browsers- also try spybot search and destroy-

http://portableapps.com/apps

Spybot? I haven't used that in years.....I thought malwarebytes and others were more efficient! Anyway I've already used Kaspersky TDSS, malwarebytes AND norton full system scan....still nothing!

Will try your portable apps suggestion now :)

have you tried an "sfc /scannow" yet?

if you haven't yet, run that in an admin level cmd window in safe mode or if you can from the recovery mode command prompt on the Windows 7 install disk

'Nuke it, it's the only way to be sure' - Aliens.

Backup using a Linux live CD to whatever media you want or partition and move what you need over.

Format the OS partition and reinstall.

I wouldn't ever trust a rooted version of windows. Especially if you use passwords/credit card/bank information on the internet.

The thing is the .dll file isn't causing me any problems, aside from not being able to connect to my iPad. Seems too much of a hassle, but yeah, I'll probably do it if I can't get the file out by next week.

Anyways sfc /scannow gave a report that "Windows Resource Protection found corrupt files but was unable to fix some of them"

^That is a good indication that the only way you are going to recover is to do a format and reinstall. It seems that this virus has corrupted core windows files and the only for sure way of recovering from this would be to reinstall windows. It is a PITA to do, but faced with everything else your choices seem rather slim.

Can you "ping" a website? Open cmd prompt-> type ping www.google.com and hit Enter. If you get a reponse, then maybe try rebuilding your TCP/IP stack:

http://support.microsoft.com/kb/299357

http://answers.microsoft.com/en-us/windows/forum/windows_7-networking/how-to-reset-tcpip-stack-in-windows-7/82560f98-de0c-4e75-ae48-9938bc980f47

Make sure to run the cmd prompt as admin by right-clicking cmd and selecting to run as admin.

This topic is now closed to further replies.
  • Posts

    • Microsoft Edge 149.0.4022.80 by Razvan Serea Microsoft Edge is a super fast and secure web browser from Microsoft. It works on almost any device, including PCs, iPhones and Androids. It keeps you safe online, protects your privacy, and lets you browse the web quickly. You can even use it on all your devices and keep your browsing history and favorites synced up. Built on the same technology as Chrome, Microsoft Edge has additional built-in features like Startup boost and Sleeping tabs, which boost your browsing experience with world class performance and speed that are optimized to work best with Windows. Microsoft Edge security and privacy features such as Microsoft Defender SmartScreen, Password Monitor, InPrivate search, and Kids Mode help keep you and your loved ones protected and secure online. Microsoft Edge has features to keep both you and your family protected. Enable content filters and access activity reports with your Microsoft Family Safety account and experience a kid-friendly web with Kids Mode. The new Microsoft Edge is now compatible with your favorite extensions, so it’s easy to personalize your browsing experience. Microsoft Edge 149.0.4022.80 changelog: Fixes Fixed an issue that prevented QR code generation from working. Feature updates Intune MAM Protected Downloads. The protected downloads feature for Intune MAM will now save downloaded files to the Documents > Microsoft Edge > Downloads folder in OneDrive. Extensions monitoring in the Edge management service. The Microsoft Edge management service now allows admins to gain visibility into extensions installed across their managed users. From the extensions monitoring page, admins can see which extensions have been installed as well as manage user requests for blocked extensions. For more information, see Microsoft Edge Extensions Monitoring. Validate Edge builds early with enterprise preview. Enterprise preview provides a simpler way for admins to flight pre-release Edge builds to their users. To reduce friction and bolster usage, users will receive pre-release builds directly inside of their Stable Edge application. Admins can allow users to easily opt-out of the preview experience, using built-in rollback to switch between their pre-release and stable channels with ease. Microsoft 365 admin center users can configure the feature, view their flighting population, and receive personalized recommendations all in one place. For more information, see Get started with Enterprise Preview in Microsoft Edge. Download: Microsoft Edge (64-bit) | 193.0 MB (Freeware) Download: Microsoft Edge (32-bit) | 170.0 MB Download: Microsoft Edge (ARM64) | 188.0 MB View: Microsoft Edge Website | Release History Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • The machines are starting to fight back any way they can.
    • No news articles about the Arch Linux repo being majorly infected with malware?!?
    • Waymo recalls self-driving software after cars enter closed freeway work zones by Paul Hill Waymo, the self-driving car maker owned by Alphabet – the parent company of Google –, has recalled some of its fifth-generation Automated Driving Systems (ADS). It did so after some of its cars drove through closed construction zones. According to the National Highway Traffic Safety Administration (NHTSA), the affected vehicles were capable of driving through a closed freeway construction zone and continuing to drive at speed. The listing on the NHTSA website says that Waymo is currently developing a solution to fix this issue, but in the meantime, freeway driving is being restricted. Waymo will update its ADS software so that vehicles can detect when they can avoid entering construction zones. According to the Safety Recall Report, on April 20, 2026, Waymo’s Field Safety Committee began meetings reviewing an event from April 11, 2026, and five events from April 19, 2026, where Waymo’s autonomous vehicles didn’t recognize and drove past ramp closure signs into the pre-planned freeway construction zones. This took place in Phoenix, Arizona. Separately, on May 18, 2026, seven Waymo vehicles entered freeway lanes with active construction in the San Francisco Bay Area by driving between cones that were placed to show the lane was closed. On the back of both of these events, Waymo restricted freeway driving until it could address the issue. In June, Waymo’s Safety Board reviewed the issue and additional information related to ADS performances around construction zones; then, as a result, it decided to conduct a recall. This development is not good for Waymo as it adds to a growing list of technical hiccups its cars have experienced. Ultimately, it will lead to more scrutiny from lawmakers around the world who will be more cautious about letting autonomous vehicles on their roads without tighter regulation. For readers in areas where Waymo operates, does this news make you more wary about stepping into one of these vehicles?
    • I'm still on Windows 10 22H2 because I didn't want to deal with all the issues in Windows 11, so I waited almost a week before installing the latest Patch Tuesday update (KB5094127), I went ahead and did it, and it was a huge mistake—ever since then, my File Explorer has seen a performance drop of about 30% when transferring large files... Once again, Microsoft has outdone itself! This update cannot be uninstalled, either through the Control Panel (via Settings) or by accessing Advanced Startup Options. The only possible alternative would be to use system restore points, but I’d have to reinstall all app and driver updates (and there’s no guarantee it would work). Or there’s the “nuclear option” of a in-place repair without losing files or apps, but even then, all my customizations would be lost! Microsoft just can’t help but mess everything up! Way to go, Microsoft! But I still don’t want your c****y Windows 11!
  • Recent Achievements

    • Week One Done
      Eurosoft10 earned a badge
      Week One Done
    • One Month Later
      Eurosoft10 earned a badge
      One Month Later
    • One Year In
      Skeet Campbell earned a badge
      One Year In
    • One Month Later
      Sharbel earned a badge
      One Month Later
    • First Post
      BizSAR earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      599
    2. 2
      +Edouard
      190
    3. 3
      PsYcHoKiLLa
      79
    4. 4
      Michael Scrip
      77
    5. 5
      Steven P.
      69
  • Tell a friend

    Love Neowin? Tell a friend!