Trojans, Viruses, spyware.....oh my

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Dmin11, May 12, 2007.

  1. Dmin11

    Dmin11 Private E-2

    So, I'm helping a neighbor out. It's all the usual stuff, single mother raising 2 teenage sons downloading who knows what. I know a little more about computers than they do, and I'm trying to help them get their system cleaned.
    I've followed the "read and run me first" thread. Although I can't connect to the internet I had a copy of "Avast" on an "Ultimate Boot Disk" that I was able to run on the system. I had a lot of trouble even getting the computer to run, as it kept freezing and/or crashing after only a few minutes of operating.
    Now, that doesn't happen as fast but, I'm getting an error message after several minutes stateing the....
    "Services and controller app has encountered a problem and needs to close". Also another message comes up shortly after that stateing......
    "A shutdown has been initiated by "NT Authority\System"
    C:\\Windows\System32\services.exe has Terminated Unexpectedly
    status code - 1073741819 ".

    These are new messages and were not comming up before, although usually the system didn't stay active for as long as it is now before crashing. So I can't be positive.

    On boot up there's a window stateing a ".protected" file cannnot be found. Also "Active Desktop" needs to be recovered upon boot up.
    And, while now I can at least get to a colored desktop again, it wouldn't change at all before, when I try to change the wall paper for the desktop, it bounces back to the "none" regardless of which image I choose.
    At this point I'm not sure whether there are any software issues but, while I don't know a lot about reading "HiJack This" it seems there are several problems that still need to be addressed. Consequently I'm posting here to ask for the technical help I know this forum can provide.
    As I said, I've followed all the instructions in "read and run" with the exception of the online virus scan as I cannot access the internet on the infected computer. CCleaner was run, SpyBot and CounterSpy all in
    "safe mode". And as I said "Avast" was run from a UBCD. Hopefully I haven't forgotten anything.
    I am attaching 3 logs here. And one more in the next post.
    The Computer is an Intel P-4 2.0 ghz with 256 mgs of RAM, running Windows XP with SP-1.

    I'm a bartender and work over the weekend but, will check in as often as I can for instructions.
    Many thanks in advance for your help

    Later on,
    Dmin11[​IMG]
     

    Attached Files:

  2. Dmin11

    Dmin11 Private E-2

    Counter Spy log attached here

    Thanks again ,

    Dmin11[​IMG]
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    This PC is very badly infected. This is going to take some time to work up a procedure for you. Please be patient while I put something together. There are many different infections and some of them have even infected necessary Windows system files. We have to be careful on the approach to fixing this. If anything is done in the wrong order, you will loose the ability to connect to the internet at all and also you may only be able to boot in safe mode if not very careful.

    As a starting point please run the below procedure which is only beginning. It will fix some problems but there will be a ton still remaining. So don't expect it to be perfect after running this.

    First run this procedure: ChodeFix - How download and run

    Now let's remove a malware service!
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to winsock32
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pastewinsock32.exe into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot if it tells you it needs to.

    Now let's continue with the below steps.
    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT

    Okay that is just a start! After getting the new logs I will continue to work up a procedure. As I repeatedly stated, there is a lot to do.
     
  4. Dmin11

    Dmin11 Private E-2

    chaslang.....[​IMG]

    Nice to have help from someone in my own state. I'm in Middlesex county.

    Looks like this is as bad as I was afraid it was. Got home late from work and decided to wait till the morning to run this. I'm off to work again later this afternoon but, will be back again late tonight and will work your next set of instructions Monday morning before I go to work on a day shift. I'll be back early evening and will look for you then. Please understand, I realize this will take a while and am not rushing you. Just want you to know when to expect me to reply so we don't miss each other. If it takes you longer to "work up a procedure" ....no worries. Whenever you can get here is fine.

    So:

    Ran ChodeFix per your instructions. I did see the "message" you mentioned. No other error messages.
    Moved on to the "services.msc". When I got to the "winsock32 - Properties" window the service was already stopped. There was only a "start" option showing ......so I did nothing, there. Went on to "set the Start-up Type to 'Disabled' ". Clicked apply and then okay.
    Ran HJT per your instructions and followed "Delete an NT Service".....etc.
    Rebooted
    The next step is where I ran into problems.
    Trying to run "combofix.exe" I got the (for lack of better description) "DOS" box showing "Please Wait" then an error window showed up ......
    Titled = "Terminal Error"
    In the window was this message = " C:\WINDOWS\regedit.exe is missing".
    Consequently I have no log for that.

    I am attaching the 3 new versions of the other logs you requested.

    I'm off to work around 3 PM today, so I'll check back and try to run any other instructions you may get to. If not I'll check in again around midnight when I get home. Again, I am not trying to rush you only to let you know when I will be checking in so that we don't miss each other. I know my work schedule in different from most people so I always try to let someone know why I may not be around when most people are.
    I know I'll be continuing to thank you as we go through this situation, so please just consider it my being polite to someone who is trying to help someone else ......."just because they can"

    Later on,
    Dmin11
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay the missing regedit.exe explains why GetRunKey and ShowNew logs are incomplete and also why ComboFix failed.

    You need to search the PC (using Windows Search) for regedit (without the .exe) and tell me what you find. We need to replace this file. Do you have a Windows XP CD where you can get a backup from?

    Let's see if we can start some fixes even though we are missing info we need and we need regedit to work.

    Now download LSP - Fix

    Run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the vdr.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move vdr.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.

    If it is already in the Remove section, just click Finish.

    If you do not see the above vdr.dll file, take a look in a new HJT log for lines like below:

    O10 - Unknown file in Winsock LSP: c:\windows\system32\vdr.dll

    Substitute into the LSP-fix whatever the DLL file name is now.


    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)
    F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\ftoxa.exe
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,qpubkcp.exe
    O2 - BHO: Shell Event Object Class - {00534B55-3155-CA4F-B41D-0E922121D03C} - C:\WINDOWS\System32\cscentfy.dll (file missing)
    O2 - BHO: (no name) - {13141EAA-5B67-EB40-5FBA-02CD37DE687B} - C:\WINDOWS\System32\icfcjg.dll (file missing)
    O2 - BHO: ofb1 - {3E1500AC-87A5-416b-A211-82E848649DA9} - C:\PROGRA~1\Ofb11\Ofb11.dll (file missing)
    O2 - BHO: 0 - {42770559-731D-42AA-EEB3-E09BB3AC4C7F} - C:\Program Files\MSN Gaming Zone\lavuhaxos.dll (file missing)
    O2 - BHO: (no name) - {7049EDAC-89C6-42F0-9394-0518667FE7D3} - C:\Program Files\Messenger\hokenow.dll (file missing)
    O4 - HKLM\..\Run: [Configuration Manager] C:\WINDOWS\cfg32.exe
    O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu27.exe 61A847B5BBF72810358B2B27128065E9C084320161C4661227A755E9C2933154389A28452DA545E9B1894E754BE54C29159A7DA682D7735667D926033AAC01F09DDF7618419154310B87659CA5E04E5067DF690232BC13E4DCD66A47
    O4 - HKLM\..\RunServices: [winsock32] winsock32
    O4 - HKCU\..\Run: [winsock32] winsock32
    O4 - HKCU\..\Run: [Ultimate Cleaner.install] "C:\Documents and Settings\Valerie Haynes\Local Settings\Temporary Internet Files\Content.IE5\0H2N4XI7\ucleaner_dvvln2MBxL[1].exe" continue
    O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
    O4 - Startup: .protected
    O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\swinsndv.exe
    O4 - Global Startup: .protected
    O9 - Extra button: (no name) - {A4F64D63-3576-4754-8DD5-4D0A49345FD5} - (no file) (HKCU)
    O20 - Winlogon Notify: A3dxq - C:\WINDOWS\System32\a3dxx.dll (file missing)
    O21 - SSODL: RootSys32 - {AAAAAAB3-ACD5-4144-982E-895D4C68A50C} - C:\WINDOWS\System32\svcrt32.dll
    O21 - SSODL: XLiMxUcK - {B45C7A14-1EF6-D0BE-E888-4C68A3C43FDC} - C:\WINDOWS\System32\mzqux.dll (file missing)

    After clicking Fix, exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Documents and Settings\Valerie Haynes\Local Settings\Temporary Internet Files\Content.IE5\0H2N4XI7\ucleaner_dvvln2MBxL[1].exe
    C:\Documents and Settings\Valerie Haynes\Start Menu\Programs\Startup\Think-Adz.lnk
    C:\cp1041.nls
    C:\WINDOWS\gregrehgtrh.exe
    C:\WINDOWS\ythgewytjhre.exe
    C:\WINDOWS\system32\qvxga7met4.exe
    C:\WINDOWS\system32\vexga3me2.exe
    C:\WINDOWS\cfg32.exe
    C:\WINDOWS\inetdctr.dll
    C:\WINDOWS\mtwirl32.dll
    C:\WINDOWS\nfeaq.dll
    C:\WINDOWS\retadpu27.exe
    C:\WINDOWS\system32\qpubkcp.exe
    C:\Windows\xpupdate.exe
    C:\WINDOWS\system32\fontqxet.dll
    C:\WINDOWS\System32\ftoxa.exe
    C:\WINDOWS\system32\ldbxoxt.dll
    C:\WINDOWS\system32\o.dll
    C:\WINDOWS\system32\rasqervy.dll
    C:\WINDOWS\system32\swinsndv.exe
    C:\WINDOWS\system32\sdfinacs.dll
    C:\WINDOWS\system32\svcrt32.dll
    C:\WINDOWS\system32\vdr.dll
    C:\WINDOWS\system32\wnc.dll
    C:\WINDOWS\system32\wuasirvy.dll
    C:\WINDOWS\system32\ksys.sys
    C:\WINDOWS\system32\spoolsvv.sys
    C:\WINDOWS\system32\drivers\etc\hosts.20070511-163048.backup
    C:\WINDOWS\system32\drivers\etc\hosts.20070511-170039.backup
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But if you do get this message, please let me know!)

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete if found:
    C:\Documents and Settings\Valerie Haynes\Application Data\Viewpoint
    C:\Documents and Settings\All Users\Application Data\Viewpoint

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  6. Dmin11

    Dmin11 Private E-2

    Sorry I didn't get back to you sooner, wasn't expecting you that fast.

    Okay,
    Tried to use windows search....the window opens up blank, with nothing showing. As I mentioned I have a UBCD. Booted using that and used it's MS Explorer to search the C drive. Found this.....
    regedit.exe in C:\WINDOWS\$NtServicePackUninstall$
    regedit.exe in C:\Windows\Service Pack Files\i386
    And, yes, I have a WindowsXP cd if I need it. Just not my friends version.
    However, I rebooted into regular mode and went to the "service pack" folder in WINDOWS. Clicked on the regedit.exe in there and the regedit window appeared. I'll await your instructions for this.

    Ran LSP-Fix......BTW, love the rest of the "I know what I'm doing (or enjoy re-installing my operating system)......LOL
    Repair Summery gave me = 19 Protocol Provider Entrys Removed
    The other 3 report lines were = 0

    Ran HJT......
    Had error messages while "fixing" the files you listed. I am including copies of the 3 messages. There may have been a 4th. Don't know if I copied them all or if I missed the first one by clicking okay before I copied it.
    Finished HJT and......
    Ran Pocket Killbox ......
    Instructions followed. There was a window that popped up after the delete button was pushed but, while it happened so fast it said something about verifying regestry ....etc.... Sorry, I'm running back and forth physically between computers and missed this.
    Rebooted and located the "Viewpoint" folders and deleted them per your instructions.

    Ran ATF-Cleaner.....
    No problems. Received message "Done Cleaning!! ATF-Cleaner has freed 144,656 MBs.

    Thanks as before, I'll be getting ready for work soon but, will check back before I leave. Don't know if I'll have more time to run any more instructions from you but, will try if I can. Otherwise, I'll be home around midnight tonight and will check in here again then.

    Later on,
    Dmin11[​IMG]

    Attached here are 3 error files from HJT "fixing session"
     

    Attached Files:

  7. Dmin11

    Dmin11 Private E-2

    Attaching new versions of:
    GetRunKey
    ShowNew
    HJT

    Thanks again,

    Later on,
    Dmin11[​IMG]
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay we made a bunch of progress but have more to do. We need to get the Registry Editor working properly so we can get more info from the logs and so we can fix things.

    Copy regedit.exe in C:\Windows\Service Pack Files\i386 to C:\windows

    Hopefully you know how to do that. If not you can easily do it from a Windows Explorer window by right clicking on the regedit.exe in C:\Windows\Service Pack Files\i386\regedit.exe file and selecting copy. Then navigate to the C:\windows folder and hit CTRL-V to paste it into that folder.

    Then just to test to make sure it is copied properly, click Start, Run, and enter regedit and click OK. If the Registry Editor opens, we should be good to continue with the below.

    So if the aboved worked, please get new logs from GetRunKey and ShowNew and attach them so we can continue. Also just to be complete, attach a current HJT log now.

    Is the O4 - HKCU\..\Run: [Ultimate Cleaner.install] line items in HJT due something your are running from your Ultimate Boot CD? If so please try to avoid running it. If not, fix any lines like that before attaching a new HJT log since it seems to still be there even though I had you fix it last time.
     
  9. Dmin11

    Dmin11 Private E-2

    Wow, chaslang,
    Either you work strange hours like me or you were up very early today.....

    Copied "regedit" over to "Windows" folder. Operating properly now.

    No I am not running anything from UBCD. Tried to "fix" "O4 - HKCU\..\Run: [Ultimate Cleaner.install]" again. It's still there.

    Attached are new logs for:

    GetRunKey
    ShowNew
    HJT

    Back tonight,

    Later on,
    Dmin11[​IMG]
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are still many many malware items to remove. Pocket Killbox must have received that Pending Operations error I mentioned because none of the items I had you deleting with Killbox were actually deleted.

    Let's continue with a few other steps!

    First please download FindAWF by noahdfear and save it to your desktop:

    Please double-click FindAWF.exe to run it.
    If a security alert shows, allow the program to run.
    When the tool has completed, a report will open in Notepad.
    Please post the results of the awf.txt in your next reply.


    I'm going to have you run a procedure below which will attempt to delete two infected Windows Systems files. One is winlogon.exe and the other is ws2_32.dll. We are going to replace them with a good copies from your DLLcache folder.
    • Print or save the below instructions locally because you need to close all browsers later.
    • Downloadthe attachedFixWL.zip file to your Desktop.
    • Now double click on FixWL.zip and extract the contents to your Desktop.
    • This should create two files on your Desktop. FixWL.bat and process.exe.
    • Note some antivirus programs may falsely detect process.exe as malware. It is not malware. Don't worry about it if you see a message about process.exe. Allow it to run later when we run the procedure.
    • Now you need to boot into safe mode to run the below. It is necessary that when you login to safe mode that you login to the same user account where you just extracted the above files on the Desktop or else you will not find them.
    • Once in safe mode, shutdown ALL unnecessary applications including browsers
    • Now double click on the FixWL.bat file to run the fix.
    • It will create a log file named: c:\FixWL.txt
    • After running this you will not be able to shutdown or restart your PC in the normal fashion. You will have to hold in the power button on your PC until it powers down.
    • Close ALL open windows now!!!!!
    • Power down your PC now. Wait about 15 seconds and then power back up.
    After power up make sure you attach the FixWL.txt and awf.txt log files.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After completing the instructions in message # 10, continue with the below.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt please attach that log here.

    Now attach the below new logs and tell me how the above steps went.

    1. avenger.txt
    2. GetRunKey
    3. ShowNew
    4. HJT
     
  12. Dmin11

    Dmin11 Private E-2

    Hi chaslang,
    Had to work late so this is coming a little later than I thought it might.

    Ran FindAWF ....
    No problems. Posting log here.

    Ran FixWL.....
    Also no problems,
    Attaching log.

    Followed your instructions for "fixME.reg"
    Everything went well. However before I could run Avanger, I got this again = "Services and controller app has encountered a problem and needs to close".
    Then = "A shutdown has been initiated by "NT Authority\System"
    C:\\Windows\System32\services.exe has Terminated Unexpectedly
    status code - 1073741819 ".
    I'm sure this is one of the problems we still have to deal with. Not concerned just letting you know exactly what's happening.

    I let the computer reboot and found that the "real" desktop wallpaper is back.
    Then I ran Avenger per your instructions....
    Again no problems running. Rebooted and ran the reports for you.

    Continued thanks for all of this work you're doing for us. I do find myself learning a few things, although it's going to take a while for me to digest it all.

    I look forward to your next set of instructions.

    Later on,
    Dmin11[​IMG]
     

    Attached Files:

  13. Dmin11

    Dmin11 Private E-2

    Posting the rest of the reports...

    Thanks again,

    Later on,
    Dmin11[​IMG]
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well we are making progress and have deleted loads of malware but have more to do. This is going to be long!!!

    The FixWL.bat file only fixed one of the infected files. winlogon.exe is now fixed but ws2_32.dll is still the infected file. Let see if we can manually fix this from safe boot mode. You must make sure you are booting in safe mode.
    • boot to safe mode
    • click Start, Run, and enter cmd to open a command prompt window
    • enter the below command in the command prompt window
    copy C:\WINDOWS\system32\dllcache\ws2_32.dll C:\WINDOWS\system32\ws2_32.dll
    • this should replace the infected copy with a clean one if the copy command is successful. Be sure to tell me if the copy works properly.
    • then reboot into normal mode and continue with below.
    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now we need some special steps to fix the WinCom infection showing in your GetRunKey log.

    Please download and install Registrar Lite Make sure you select a Majorgeeks download link and not the Authors!

    Run Registrar Lite navigate to each of the following keys (one at a time) and take ownership of them (I explained how to do that further down).

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINCOM32\0000\LogConf
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINCOM32\0000
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINCOM32
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINCOM32\0000\LogConf
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINCOM32\0000
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINCOM32
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINCOM32\0000\LogConf
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINCOM32\0000
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINCOM32

    To take ownership of the key do the following:
    • Copy & Paste the registry key from above into the Address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    • Click-on Security in the top Menu
    • Select Take Ownership
    • Repeat these steps for all of the registry keys given above before continue to the next steps below.
    • Now leave RegistrarLite running and continue
    • Now run the fixWC.reg REGISTRY PATCH below in this message.
    • Tell me the results. Any error messages?
    • Now in RegistrarLite click View and then Refresh
    • Now navigate one at a time to each of the above keys we took ownership of to make sure they were deleted.
    • If any of the keys still exist, move on down to PART 2 - Setting Permissions for Everyone below!.
    Here is the Registry Patch

    Now Copy the bold text below to notepad. Save it as fixWC.reg to your desktop. Be sure the Save as; type is set to all files Once you have saved it double click it and allow it to merge with the registry.

    PART 2 - Setting Permissions for Everyone
    Run the below if some of the registry keys still exist after running the above steps.

    Now I want you to use Registar Lite again to navigate to each of the below keys (one at a time) by pasting them into the Address Bar and hitting return. But this time click the Security menu item and select Edit Permissions so we can change permissions to everyone ( I describe this down below the list of registry keys).
    After click Edit Permissions , here is what I expect you to see in the Group or user names area of the form:

    Everyone
    SYSTEM

    Select Everyone by clicking on it. Now at the bottom in the Permissions box click the check box for Full Control. The click Apply and then OK to get back to the main Registrar Lite screen. Nowright click on the registry key and select Delete. The click View and Refresh. Check to see if the registry key just deleted truly deleted. If so, move on to the next to work thru the whole list. If it does not delete, I want you to boot into safe mode and repeat these exact same steps to see if we can do it from safe mode.


    Now run avenger.exe by double-clicking on it.
    Check the 'Input script manually' box.
    Click on the magnifying glass icon.
    Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt please attach that log here.
    After reboot, attach new logs from ShowNew and GetRunKey (also attach the new avenger.txt log)! Also tell me how things are working. Can the PC boot properly now in normal boot mode?
     
    Last edited: May 14, 2007
  15. Dmin11

    Dmin11 Private E-2

    Moving right along.
    Booted into Safe mode. Ran into a problem however, whenever I tried to type anything into the "run" window the screen froze. But, anything that was already typed into the drop down window would run. So I booted back into reg. mode and entered "cmd" into the run window.Booted back into safe mode and saw the command. Thought I had it beat but, still when I tried to type the copy command the screen froze on me again. So, I booted into my UBCD and ran a cmd from there. Everything went well. Was asked if "overwrite" was okay. Typed "yes" received "1 file<s> copied."

    Booted back into regular mode on the computer. UBCD was removed.

    Followed instructions for "fixME.reg" .
    No problems.

    Installed Registrar Lite.
    Took ownership of each link per your instructions.
    While starting to run "fixWC.reg REGISTRY PATCH" the "Services and controller app has encountered a problem and needs to close". message came up. I was able to run the "Registry Patch" before Windows was rebooted.
    Started up RegLite. Navigated one at a time to each of the keys we took ownership, ALL were still there except for the last one = "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINCOM32" . That one defaulted back to the = "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root".
    Followed your "PART 2 - Setting Permissions for Everyone"
    All keys were deleted succesfully. Checking each one I found the address "defaulted" to the "\Enum\Root" folder.

    Ran Avenger. Input = Drivers to unload.
    Avenger Rebooted.
    Attaching new "avenger.txt"
    Also attaching:
    ShowNew and GetRunKey

    More thanks again,

    Later on,
    Dmin11[​IMG]
     

    Attached Files:

  16. Dmin11

    Dmin11 Private E-2

    PS,
    Sorry, forgot you wanted to know how the computer was running.
    It's been booting normal for a while. However, I just looked at the "Start-up" tab in "msconfig". All the old and "Bad" entries are gone....So we're definitely getting somewhere. However, I'm still getting the "Services and controller app has encountered a problem and needs to close". message, and windows reboots.

    Thanks again,
    Later on,
    Dmin11[​IMG]
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not according to your GetRunKey log! Check the end and you will see all the keys! Try fixing this again if you can step by step. Use safe mode if you can. The when you think you have them removed, run GetRunKey and look in the log to make sure the Wincom lines do not show. Then reboot in normal mode, and check another GetRunKey log to make sure they have not come back. Let me know the results.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Exactly when does this occur? Can you get a screen snapshot of the message?

    Does this also happen if you boot in safe mode?



    Also see if you can do the below steps!

    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 10
    Java 2 Runtime Environment, SE v1.4.1_02
    Viewpoint Media Player (Remove Only)

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Now Run Pocket Killbox and select File, Cleanup, Delete All Backups


    Now please download F-Secure's BlacklightBeta
    • Download fsbl.exe and save it to the Desktop.
    • Once saved... double click fsbl.exe to install the program.
    • Click accept agreement and Click scan
    • This application may trigger a warning from your antivirus. Let the driver load. Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the BlackLight log.

     
  19. Dmin11

    Dmin11 Private E-2

    I swear I checked and they were gone. Don't know what happened. And I thought I was doing so well, following your instructions.:cry

    Went through the directions again rebooted and checked another GetRunKey log. They seem to be gone.

    Deleted the three programs using "Add Remove Prorgrams".
    Rebooted. Checked to see if programs were still gone and also ran another GetRunKeys log to make sure the Wincom lines were still gone also. They were.
    Installed the current version of Sun Java from your link.
    Ran Pocket Killbox . Deleted all backups.
    Ran fsbl.exe. 2 Hidden items found. Hit Close per your instructions.
    Attaching the log from it.


    The error messages I mentioned seem to come up while I'm running a process. But, not every time. I got the Services window while running Black Lite. I thought I had it saved but, messed it up while trying to capture the second window that came up. I'm attaching a copy of that window for you. Had to zip it to comply with forum "size" limitations. The interesting thing is that the window says the system will shut down and restart but, it didn't. I don't think I can "force" the error and while it has occasionally popped up on it's own, I've had the computer running for several minutes now and still no re-occurance of the "services" error window. If/when it happens again I will make a copy of it and let you know.

    Later on,
    Dmin11[​IMG]
     

    Attached Files:

  20. Dmin11

    Dmin11 Private E-2

    Attaching new GetRunKeys log and new ShowNew log, just in case.

    Later on,
    Dmin11[​IMG]
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run BlackLight again and see if it can remove those two hidden files! They are related to the Wincom (Trojan.Peacomm) infection.

    Then reboot and scan again with BlackLight to make sure they stay gone.
     
  22. Dmin11

    Dmin11 Private E-2

    Sorry chaslang,
    Missed the fact that we were on a second page....Duhhh. Also traveled to upstate NY today to visit family. Brought my neighbors tower with me so we can continue to work on it.

    Ran BlackLight again. Followed instructions on "renameing" the two "hidden" files. Ran BlackLight again to see if they were gone.
    "no hidden files found".
    I'm attaching the latest log from BlackLight.
    Also, that "Services and Maintenance"error window popped up again. Sorry, now I see it's "Services and Controller". This time I was able to get a screen capture of it. I'm attaching that image also. You should already have the second window from that error from my post yesterday.
    I'll be checking in later today as usual.
    Thanks again,

    Later on,
    Dmin11
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Exactly when does this occur? Next time click on the click here link next to the text saying To see what this error report contains

    Attach the report here? This may not be due to malware but rather due to problems within the Windows OS itself.
     
  24. Dmin11

    Dmin11 Private E-2

    Well, a watched kettle never boils and Windows never crashes when you want it to.......
    Tried several things today to try to get that window to pop up .....nothing worked. There was never any pattern to it that I was able to see. Sometimes it just popped up while the computer was idle. Other times it popped up when I started running a program. But it never popped up when I ran the same program again. If/when it pops up again I will follow through with your instructions and let you know.

    Continued thanks,

    Later on,
    Dmin11
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    So other than that potential popup, how is eveything else working?
     
  26. Dmin11

    Dmin11 Private E-2

    Well.

    I kept thinking while I was opening and closing programs to try to "force" that poppup, "Don't tell me everything else is fixed".....LOL.
    I'm back at my own place now. Which gave me a chance to try internet as my family I was visiting the last two days is still on "dial-up" (shudder)...LOL.
    Internet won't connect yet but, my neighbor is on DSL with Verizon and I'm on Cable with Optimum. While both connections use a "nic" interface I'm not familiar enough with the particulars to know whether I can just plug in my network connection and have my neighbors computer hit the internet. Other than that, everything else is running smothly. No poppups, no slow down....etc.
    You didn't ask but, just in case, I'm attaching new:
    GetRunKey
    ShowNew
    HJT

    But, I'm guessing we're not done yet, cause looking at the GetRun log I see.....
    "Trojan.Peacomm windev form found in the registry!"

    And in ShowNew I see a lot of files under .....
    "Show all occurrences of specific system files that may be infected with
    SpamTool.Win32 and Trojan.Win32.Patched.g"
    So I await further instructions from you.

    Thanks again,

    Later on,
    Dmin11[​IMG]
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In some cases DSL connections have some software to run to get authenticated on their PPPoE connections. If they connect to a router first before going to a DSL modem, then it should probably work just like at your place.

    You did not attach any logs.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may just be reading the logs wrong. For example. ShowNew says:
    Note the key words are may be.
     
  29. Dmin11

    Dmin11 Private E-2

    "You did not attach any logs."[​IMG]
    Sorry....[​IMG]

    Later on,
    Dmin11[​IMG]
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you did develop another form of the Peacomm infection. First we will try the simple removal steps and hopefully they will remove some of the registry keys which will simplify the procedure that will ultimately be required using Registrar Lite like we previously did with the WinCom32 form.



    Now Copy the bold text below to notepad. Save it as fixWD.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now reboot and then attach a new log from GetRunKey so we can see what remains to be fixed. You can look in the GetRunKey log and see these for yourself. If you feel very confident that you know how to use Registrar Lite to fix these (like last time) then give it a try before posting a log.
     
  31. Dmin11

    Dmin11 Private E-2

    Thanks for the vote of confidence but, I'd rather continue with your guidence so I know I get it right and I don't make things worse thinking I know what to do....LOL.
    However, if I'm following you correctly, my next step would be to take the files still remaining in the new GetRunKeys log from the ones we listed in the "fixWD.reg" and "Set Permissions for Everyone" using Registrar Lite like last time. Then navigate to each of the keys and delete them. If possible, if not try it again in safe mode.
    Looking at the log I can see a few of the original files were deleted but, most of them still remain so we have to delete them by hand rather than the easier "reg merge" way you've been having me use.
    I'm posting the new GetRunKeys log and will wait for your instructions before doing anything else. Again, it'd be nice to know I'm learning something but, I'd rather not "assume" and make things worse.

    As before ....
    Many Thanks,

    Later on,
    Dmin11[​IMG]
     

    Attached Files:

  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but for your education, they are not files. They are registry keys. Sort of like line entries in a database. ;)


    Run Registrar Lite navigate to each of the following keys (one at a time) and take ownership of them (I explained how to do that further down).

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-11FE-1C17
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-1D5C-6549\0000\LogConf
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-1D5C-6549\0000\Control
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-1D5C-6549\0000
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-1D5C-6549
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-3BC9-685E
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-4333-7D60
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-4A04-763D
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-62D1-5274
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\windev-1d5c-6549\Enum
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\windev-1d5c-6549

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-11FE-1C17
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-1D5C-6549\0000\LogConf
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-1D5C-6549\0000
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-1D5C-6549
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-3BC9-685E
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-4333-7D60
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-4A04-763D
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-62D1-5274
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\windev-1d5c-6549
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINDEV-11FE-1C17
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINDEV-1D5C-6549\0000
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINDEV-1D5C-6549
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINDEV-3BC9-685E
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINDEV-4333-7D60
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINDEV-4A04-763D
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINDEV-62D1-5274


    To take ownership of the key do the following:
    • Copy & Paste the registry key from above into the Address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    • Click-on Security in the top Menu
    • Select Take Ownership
    • Repeat these steps for all of the registry keys given above before continue to the next steps below.
    • Now leave RegistrarLite running and continue
    • Now run the fixWC.reg REGISTRY PATCH below in this message.
    • Tell me the results. Any error messages?
    • Now in RegistrarLite click View and then Refresh
    • Now navigate one at a time to each of the above keys we took ownership of to make sure they were deleted.
    • If any of the keys still exist, move on down to PART 2 - Setting Permissions for Everyone below!.
    Here is the Registry Patch

    Now Copy the bold text below to notepad. Save it as fixWD.reg to your desktop (yes, overwrite the previous file). Be sure the Save as; type is set to all files Once you have saved it double click it and allow it to merge with the registry.

    PART 2 - Setting Permissions for Everyone
    Run the below if some of the registry keys still exist after running the above steps.

    Now I want you to use Registar Lite again to navigate to each of the below keys (one at a time) by pasting them into the Address Bar and hitting return. But this time click the Security menu item and select Edit Permissions so we can change permissions to everyone ( I describe this down below the list of registry keys).
    After click Edit Permissions , here is what I expect you to see in the Group or user names area of the form:

    Everyone
    SYSTEM

    Select Everyone by clicking on it. Now at the bottom in the Permissions box click the check box for Full Control. The click Apply and then OK to get back to the main Registrar Lite screen. Nowright click on the registry key and select Delete. The click View and Refresh. Check to see if the registry key just deleted truly deleted. If so, move on to the next to work thru the whole list. If it does not delete, I want you to boot into safe mode and repeat these exact same steps to see if we can do it from safe mode.

    After reboot, attach new a log from GetRunKey!
     
  33. Dmin11

    Dmin11 Private E-2

    Yes, I knew that, just was negligent with my vocabulary. Thanks.
    More education......
    Yes, expected all the instructions to be what you sent me. I noticed you re-arrainged the files so that the internal folders were worked on before the external folders were. (Again, folders as in the "tree" of the registry.) So....
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-1D5C-6549\0000\LogConf
    Before......
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-1D5C-6549\0000\Control
    Before.....
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-1D5C-6549\0000

    So:
    Took "ownership" of the keys one by one.
    Ran "fixWC.reg REGISTRY PATCH" and had no error messages.
    Checking all the keys, I found only the following three were gone......
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\windev-1d5c-6549\Enum
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\windev-1d5c-6549
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\windev-1d5c-6549

    Again, education, I assume because these three were in a different location ("services" rather than "enum\root") they were able to be removed more easily.

    Followed your instructions for "PART 2 - Setting Permissions for Everyone"
    Edited Permissions and followed the rest of the proceedures. Checked all after refresh.
    All were gone.
    Ran GetRunKeys again.
    Noticed that one of the "keys" was showing up in the report.....
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINDEV-62D1-5274
    Opened up RegistrarLite.
    Checked and didn't find the key....?????Hidden.....????
    So followed your instructions to reboot in safe mode.
    Found the little bugger....
    Set permissions again and deleted key.
    Gone.
    Rebooted.
    Ran new GetRunKeys and am attaching log.

    Continued Thanks.....

    Later on,
    Dmin11[​IMG]
     

    Attached Files:

  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yeah there is a reason for:
    • me rearranging the tree order as you noticed
    • and also those step being written in the order written so we cover all the possible areas where things may fail and what to do next ;)
    Looks like you got them all. Good job! :)

    How are things running now?
     
  35. Dmin11

    Dmin11 Private E-2

    Thanks.....

    Everything seems to be running fine. Still no internet but, I'll try that when I get the computer back to my neighbor. If it's not the DSL connection then I'll be concerned but, for now I'm assuming that's the reason.
    BTW, how do you feel about the "Verizon Internet Security Suite" my neighbor is running. It wasn't installed properly and was not running prior to my looking at it so, all these things you've been helping me with had easy entry. I will run through all the proper instructions for keeping the computer safe from "malware" when I return it to them. Just wondering if I should suggest something else instead.

    Thanks again,

    Later on,
    Dmin11[​IMG]
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hate any Internet Security Suite from anyone. They are all massive resource hogs and do not work that well anyway. We prefer to use separate tools for protection. Very good free ones are available.

    I have to give my final instructions anyway and they include all the tools we recommend.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  37. Dmin11

    Dmin11 Private E-2

    [​IMG]
    I'm going to miss you......[​IMG]
    It's been great working with you.....[​IMG]
    I appreciate all the help with the malware.....[​IMG]

    And the instructions too......[​IMG]
    Many thanks again......[​IMG][​IMG][​IMG]

    Good luck in the future......[​IMG]

    Later on,
    Dmin11[​IMG]
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You welcome! Surf safely & tell your neighbor to do the same. Make sure they also review and understand the info in the How to protect yourself link.
     
  39. Dmin11

    Dmin11 Private E-2

    Hi chaslang, [​IMG]

    This is an update with a further problem.[​IMG]
    Everything is running well, with the exception of that internet connection I mentioned before. As we weren't sure if it was because I'm on cable and my neighbor is on DSL, I wasn't sure if there was a problem. Finally had a chance to return my neighbors computer and try to connect to the internet on that connection. No luck. Checked with the provider = connection is active and solid. So back to my place. Since it's the computer, I started looking further as I now know I should be able to connect from here also.
    Here's where I'm at.....
    It seems to be a driver related problem. I'm attaching 2 screen captures of the problem messages. The "Windows cannot load the device drivers" message is the same for all the device lines that have the exclamation mark next to them.
    I have already tried to uninstall and reinstall....
    I can only do that to the "Intel(R) Pro" as the other 2 show "Necessary for system to operate" error messages. Seems consistent as, I have found in "searches" that the "Wan-Miniport" is part of the Windows OS.
    I've reinstalled the "Intel(R) Pro" device and installed updated drivers.
    I've also tried:
    WinsockxpFix.exe
    xptcprep.exe
    Installed SP 2
    Installed IE 7
    Also ran SuperAntiSpyware, and tried to "Repair broken network connection (Winsock LSP Chain)"

    No joy in my neighborhood......[​IMG]
    So back to you for next recomendation. I have found several forum threads relating to this problem but, all have detailed instructions on specific tools that I'm not familiar with and would rather not try to work with, without guidance. Since this is quite possible not specifically "malware" I'm aware you may refer me to another forum/thread. Just looking for some "directions" on exactly where to go.

    As before,
    Many thanks for all your help.[​IMG]

    Later on,
    Dmin11

    Lost attached jpegs.....back in a few min.
     
  40. Dmin11

    Dmin11 Private E-2

    Okay, I'm back.
    I can't edit my previouse post or I'd do this there.
    While I was typing the last post I realized I hadn't tried a full Windows Repair from the installation disk. Did that, seems to have worked. No "errors" in the Device Manager. So that's fixed. Reinstalled Service Pack 2. Still having trouble with IE and for some reason my thumb drive is no longer being recognized but, there are Windows updates downloading ( so my internet connection is working ...LOL) and I've had trouble with XP being able to do anything else while that's going on so I'm waiting till the updates are done to see if I'm still having problems. Other wise I'm doing well.
    So again, sorry for the last post, although at the time I was reaching my level of what to do.
    As always, many many thanks for all your help and support....[​IMG][​IMG][​IMG]

    Later on,
    Dmin11[​IMG]
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good job in figuring out what to do and getting it fixed! ;)

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds