Unable to complete steps in removal guide, HELP

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by captain_justin, Nov 13, 2006.

  1. captain_justin

    captain_justin Private E-2

    I have been infected with spyware for two months, mostly because I haven't been serious about fixing the problem, but now I am. Last time I posted a HJT log, and was then asked to do the removal instructions to arrive at a known state. However I am unable to complete the entire task. I have done primary cleaning, removed some items, ran ccleaner a few different times always with different results. I can run ewido, spybot, adaware, and they remove different items. I have done the Qoofix and removed that. I have no antivirus currently, and when I attempt to run McAfee Stinger I get this message: "Shut Down by: NT Authority/System, c:\\windows\system32\services.exe" I then attempted to locate that file, and viewed hidden aswell, however there was no such file. Also I am unable to turn on a windows firewall, it has been disabled. My symptons are popups, the NT Authority Shutdown, and when the computer first starts up and loads windows I receive two .dll errors. One reads: "error loading w2a8a52d.dll , not found"


    Please help, I have HJT and am able to run it, nothing obvious seems wrong in it. Also, I can only run the antispy software while in safemode, NT Authority shuts me down normally.
     
  2. captain_justin

    captain_justin Private E-2

    Oh Boy, I just went into my WINDOWS folder under the C drive and see about 30-40 new files created today that are hidden, but their titles are blue, and not black like the rest. They are all titled : "$NtUninstal***$" and I just recovered the pc from a screen that said I had a serious error, and must restart and if the message happened again I had a serious problem, but the PC loaded fine thirty seconds later, but now there are 30-40 $NTuninstall$ files that don't sound good.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those are all valid folders related to Windows Updates.
     
  5. captain_justin

    captain_justin Private E-2

    After attempting to complete as many steps as possible, I now get a blue screen error once the desktop has been loaded for a few minutes and after executing some type pf program. The Blue screen says it has stopped my computer from causing more damage to the system. If it happens more than once, there is a major problem. Well, the problem has grown from once, to everytime my pc starts. MY system is a 2004 Inspiron XPS, will it be safe to wipe the hard drive and start over with my dell support cd's?
    Is this the fastest/easiest way to restore my pc? I don't need any of the data on it, I save most of my work to a network drive.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does your PC boot up okay in safe mode? If so, attach the requested GetRunKey, ShowNew and HijackThis logs from safe boot mode. Then we will decide what to do.

    If it does not boot in safe mode either, yes it would probably be easier just to reinstall from your original CDs. You will need to dwonload and reinstall all necessary updates too.
     
  7. captain_justin

    captain_justin Private E-2

    It runs in safe mode, however I've decided to start from scratch, I think. The problem will definately be resolved if the hard drive is wiped and windows is reinstalled, correct?

    Thanks for the help, Once my pc is fixed I'll be back here to learn how to prevent the same thing form happening again.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but make sure you delete the partition on the hard disk and repartition again before formatting and reinstalling.

    After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds