What Have I Done? System Config Error

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by dna48, Nov 30, 2004.

  1. dna48

    dna48 Private E-2

    I read the spyware directions and followed them all exactly. I think most of the problems were eliminated. However, after a long weekend away, I came back to a slow PC again. I tried to reboot in safe mode (which I always did by typing in msconfig.sys in Run, then choosing safe boot), but my PC displays a System Configuration Error when I check the safe box. I went ahead and ran the spyware programs in regular mode, and then I checked my Registry for remnants. I found huge lists of naughty sites in my history and domain files, which I deleted. (How do they reinstall themselves?) Then I ran HiJack this, and found a couple of more bad items, which I deleted. There are still 2 items on my logfile which I am unsure of.
    I am so confused! I am not a power user at all; we use the computer to do online homeschooling, and the only other thing I do is look up Christmas gifts and do a little ebaying and enter a few contests. I don't let anyone download anything anymore (I think most of this started when my daughter was looking up cheat codes for her gameboy and she clicked on an ActiveX link), and I never visited ANY of the sites in my Registry history/domain sites (they looked very porn-related.) What should I do now? Can my System Configuration Utility be fixed? Why does my cursor constantly "shiver"? :confused: Any help is appreciated!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal and you still have a problem, do the below.

    Make sure you have HJT Version 1.98.2 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. dna48

    dna48 Private E-2

    My Logfile: Config Sys Error

    I posted an earlier thread, and wasn't sure if I should start a new one or not, so I did;) I really am new to this, so excuse me if I did the wrong thing.

    EDIT by chaslang: Inline log changed to attachment

    My other main concern is my sudden, inexplicable inability to reboot in safe mode. Any thoughts on that?
    Thanks for your help!
     

    Attached Files:

    • hjt.txt
      File size:
      3.8 KB
      Views:
      3
    Last edited by a moderator: Nov 30, 2004
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: My Logfile: Config Sys Error

    No you should not be in a new thread. And please post logs as requested. That is as an attachment. Not inline text. I'm merging you back to your old thread. Notice how I changed your log to an attachment in your message.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have system restore disabled and viewing of hidden files enabled.

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find the below processes and End them:
    C:\windows\system32\clumac.exe


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [t34T36X] clumac.exe
    O4 - HKCU\..\Run: [c0v3RWbth] appwchx.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)


    Boot into safe mode and use Windows Explorer to delete:
    C:\windows\system32\clumac.exe
    C:\windows\system32\appwchx.exe

    No reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  6. jarcher

    jarcher I can't handle a title

    Re: My Logfile: Config Sys Error

    well, there ya go
    I was repling as chaslang did. . .he replied first

    but since he's here
    I didn't like that either,but I do not know what it is(couldn't find it anywere).
    O4 - HKLM\..\Run: [t34T36X] clumac.exe

    what is it?
     
    Last edited: Nov 30, 2004
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: My Logfile: Config Sys Error

    jarcher, didn't you read my message below before posting.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: My Logfile: Config Sys Error

    It's what we put into the category of unknown trojans because they have no specific names in many cases. Sometimes they eventually earn one when they are around long enough to cause many problems. There are literally a thousand or more of these. Sometimes they look somewhat similar to a Peper Trojan.
     
  9. dna48

    dna48 Private E-2

    I followed all your instructions exactly, except the above. I cannot boot into safe mode! When I try the msconfig.sys method, it just gives me a System Configuration Utility error and shuts it down. I tried rebooting and hitting the F8 key, but it takes me to setup and I don't know how to deal with that. Also, when I restart the computer a message comes on the top of the screen that reads "invalid boot.ini file starting from windows c:\".

    Should I delete the above in normal mode?

    Thanks for all your help; this is an amazing resource for gals like me.
     
  10. dna48

    dna48 Private E-2

    I am wondering: could I have taken something out with one of the spyware programs that affected the boot.ini file? How would I find out and fix it if I did?
    Also, I went ahead in normal mode and deleted the clumac.exe file from c:\windows\system32\clumac.exe, but the appwchx.exe wasn't in system32. I ran a search and found it in a folder called prefetch, but I didn't touch it. Also, in my windows folder, there are two files
    b2_t_CAN%27T+DELETE+ZUL177.xml
    b2_t_CAN%27T+DELETE+EZULA&859.xml
    I remember trying to get ezula off my machine and I hope these aren't some hidden way of keeping them on.
    Thanks again!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you try following the instructions here for safe mode boot: http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406?OpenDocument&src=sec_doc_nam

    Copy your boot.ini file back here to a message.

    By the way, it's not msconfig.sys. It's msconfig.exe and all you type into the run box is msconfig.

    It's okay that you deleted the files in normal mode. You should also delete similar named files from Prefetch also empty your Recycle Bin.

    I would get rid of those two xml files too.
     
  12. dna48

    dna48 Private E-2

    This is where my knowledge hits a wall. (Most of what I've learned about spyware comes form your site, plus a few other internet searches, so I have learned a little about the nasties infecting us, but otherwise I am a total neophyte.)
    How do I copy a boot.ini file? I actually have two; one (a Configuration Settings file) is located in c:\ and the other (a backup file) is in c:\WINDOWS\pss. The backup was created on Nov. 8, 2004, and the Configuration Settings file was apparently modified on Nov. 30. I have never touched these files (to my knowledge), so why were they modified? Is it part of the spyware problem?
    Anyway, if you tell me how to do it, I'll copy them here.

    How often do I have to run all these cleaners? It makes me nervous always turning off the System Restore; should I worry about that? How can people get away with creating all this spyware, and who pays to create it? Is it inevitable? Just wondering (and steaming...)

    YOU ROCK, BY THE WAY!
     
  13. Kodo

    Kodo SNATCHSQUATCH

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I want to see the boot.ini file that is in c:\

    Just do the following, click Start, Run, and enter notepad c:\boot.ini into the box and click OK.
    The hit CTRL-A to select all the text, CTRL-C to copy it, and the use CTRL-V to paste it into a new message here.

    I would suggest running Ad-Aware SE and Spybot at least once every two weeks. Unless you do a lot of surfing. If so, once per week. You should perform a full system virus scan once a month too. Obviously, if you run into problems, run everything immediately.
     
  15. dna48

    dna48 Private E-2

    I did what you said and the above is what appeared...nothing! I think the data is gone.
    How in the world did this happen? I never touched that file.

    How do you go about getting a file like that restored? (I looked at the backup file in WINDOWS\pss, and it was also empty.)
    Thanks again!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds to me like you must have erased the contents of the file and then you wrote the file. That's not quite what I asked you to do.

    We may have to create a boot.ini file by hand. Does your system boot up and let you get logged in? Or does the System Config error stop you from logging in? If so, can you boot up in safe mode?
     
  17. dna48

    dna48 Private E-2

    I really don't know how I did anything to that file. One day when I went to run the spyware in safe mode, the computer started giving me a System Configuration Utility Error message.
    I am having no trouble running the computer; it starts up fine, although when it is booting up a message does flash on the screen saying "invalid boot.ini file starting from windows c:\"
    I just can't get it into safe mode.
    If there is a way to rebuild it, I would be grateful for your help.
    Thanks!
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have WinXP home or Pro?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds