masive problems everywhere

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by topman1, Oct 3, 2007.

  1. topman1

    topman1 Private E-2

    I have a number of issues on my pc and I have run your getting started post as best i can.

    i tried to run bit defender and panda and neither would work .
    get run key did


    Edit by bjgarrick: Inline log attached!


    and show new didn't.

    I had a pop up say error ntvdm.exe was being used elsewhere and would not run.

    Here are the only log files I have managed to acquire.


    counterspy log;

    Edit by bjgarrick: Inline log attached!

    please advise me accordingly

    regards

    dave k
     

    Attached Files:

    Last edited by a moderator: Oct 4, 2007
  2. topman1

    topman1 Private E-2

    this is my latest hjt log:

    thanks

    dave k
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to complete ALL steps in the READ & RUN ME sticky thread and you must ATTACH all 6 requested logs. Please do not post any logs inline.

    You need to rerun CounterSpy and this time Quarantine or Delete what it finds. You Ignored everything last time. You need to attach a new log.

    You also need to attach logs from BitDefender and PandaActiveScan.

    Also you need to download the proper versions of GetRunKey and ShowNew and then attach new logs from GetRunKey and ShowNew. Inline logs are not properly formatted and take too long to read. As a result, we cannot look at inline logs. Read the error messages described on the download pages and note the procedures used to fix this errors if you are getting them (and it sounds like you had one with ShowNew).

    Also it would be more helpful if you told us what problems you were having.
     
  4. topman1

    topman1 Private E-2

    urgent help required

    since posting my problem yesterday and had no response could somebody please assist me.

    I am now experiencing serious B.S.O.D errors of 0x0000008e and this is my first success in over 100 attempts to boot up my system.

    I have been trying to bootup since 13.00pm yesterday afternoon.


    aaagh.
    upon boot up in safe mode with networking i had two pop-ups saying

    1. error http1//vaavrquavy.net/uniq.php?id=371267806
    2. parser error 0x800700e.

    The system has slowed down to less than a snail's pace and i have no system restore in operation as an error says i need 200mb of free space required and yet i have 1.2gb so all of my drive's have been automatically suspended.

    HELP!!!!!!!!!!
     
    Last edited: Oct 4, 2007
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: urgent help required

    You had a response yesterday (see message # 3) and you still need to follow those instructions as best as possible.

    I will try to help you a little more without that info but this will be limited.

    First I see Spyware Doctor, Spy Sweeper, SUPERAntiSpyware, AVG AntiSpyware and Ad-Aware 2007 installed. Are any of these paid versions? If not, uninstall ALL trial programs now.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to SymWMI Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteSymWSC into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O20 - AppInit_DLLs: e:\windows\system32\ldcore.dll

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    1. GetRunKey - make sure you have installed the current version as requested
      [*]ShowNew - make sure you have installed the current version as requested
      [*]HJT


    Make sure you tell me how things are working now!
     
  6. topman1

    topman1 Private E-2

    hi chaslang

    i have tried to do as you instructed and I am having even worse problems trying to boot up my system.

    i can only access my system after numerous attempts in safe mode and when I try to reboot in normal mode it crashes with B.S.O.D.

    every time i try to boot up normally a b.so.d screen appears 0x0000008e appears.

    I then tried to boot up in safe mode with neytworking . this is my 20th+ attempt.

    I have carried out your instructions as far as the avenger.

    when I try to open avenger.exe a pop up error screens appears saying the application failed to initialize (0xc0000005).

    I have numerous pop ups stating I have insufficient memory when I try to open up ANY program or drive information.

    i have the following logs as you requested but the bit defender and panda links would not let me carry out a scan online.

    There was nothing found under Spybot and nothing found in AVG.


    Dave k
     

    Attached Files:

    Last edited: Oct 4, 2007
  7. topman1

    topman1 Private E-2

    this is the last hjt log but accessed under safe mode ( as per my previous comment as to why not in normal mode)
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You MUST rename HijackThis.exe to analyse.exe. Do this now!

    In my last instructions I said the below:
    You seem to have ignored this. At least you did not respond to it. This could explain your lack of memory. If any of these are paid versions, tell me which one but uninstall all others. If more than one is a paid version, then choose one and uninstall all others.


    Also you ran CounterSpy but you told it to Ignore everything!!! Why??? Don't you want to fix your problems? Run it again and this time Quarantine or Delete all the problems. Attach a new log.

    It appears that you did not remove the SymWMI Service as requested with services.msc and HijackThis. Did you follow all of my instructions?


    Also you need to uninstall the below old Sun Java versions :
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 9


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now delete the below file:
    E:\Documents and Settings\User\xrt_dsqj.exe

    If you cannot delete the above file then right click on it and select rename and try changing the name to xrt_dsqj.xxx
    If you cannot rename it either than after the below reboot retry deleting and renaming.

    Now reboot if possible.


    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
      [*]ShowNew
      [*]HJT
     
  9. topman1

    topman1 Private E-2

    I have purchased Spy Sweeper, SUPERAntiSpyware, AVG AntiSpyware and Ad-Aware 2007 .

    i have deleted spyware doctor.

    Counterspy showed no errors and i cannot get a new log file.

    the 3 java files will not delete as i am running in safe mode and it will not allow me to remove them from control panel.

    due to the fact i cannot reboot in normal mode.(B.S.O.D)

    the symwsc will not be deleted as it is system critical.

    I am now going to try and reboot.

    thanks

    dave k
     
  10. topman1

    topman1 Private E-2

    I have just tried to reboot a number of times and i get to windows is loading and then the log in page and as i type in my password the B.S.O.D pops up; windows is closing to prevent damage to your computer.

    upon reboot in safe mode with networking i had another popup window error stating drwtsn.exe failed to initialize.

    do you want me to attach hjt log etc from within current safe mode?

    oh and i forgot to tell you that xrt_dsqi deleted successfully.

    Dave k
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then as I have stated. Uninstall ALL but one of these now. They are eating up all of your system resource and can conflict with each other.

    Do you mean a new scan showed no malware? Because your previous scan did. If the new scan was clean, uninstall CounterSpy now.

    Okay you will have to uninstall if you can get back into normal boot mode.

    More than like this is not a malware problem. You will have to post the exact word for word error message in the Software Forum. Your probably may be related to what is discusses here: http://support.microsoft.com/kb/827663

    Not true and I did say to ignore error messages, however don't worry about this item now. It is possible that Symantec in their infinite stupidity need this service for their Norton Ghost program you have installed. It is stupid because this service is listed as being related to Norton/Symantec AntiVirus.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes attach the 3 logs I requested even if you must get them in safe boot mode.

    You remaining issues are more than likely things you will need to work in the Software Forum.
     
  13. topman1

    topman1 Private E-2

    here are the 3 log files .

    Also as I have used my spyware programs for quite a while and you say to use only ONE which of the ones that I have do you recommend to keep; as I have found them all of use in the past as they all seem to find different malware/programs.

    I could not get a shownew bat log .

    i got an error pop-up window on top of the screen display-ntvdm.exe has encountered a problem and needs to close and then when i click don't send this error message appears on the shownewbat screen

    the process cannot access the file as it is being used by another process.

    dave k
     

    Attached Files:

    Last edited: Oct 5, 2007
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not matter how long you have been using the programs and yes we know that one program can find things another does not. The problem is that running multiple realtime antispyware blocking tools cause conflicts between the programs and makes each program less effective at doing its job. In addition it can make it impossible to manually remove malware like you still have on your PC until all of the antispyware programs are removed. Keep either Spy Sweeper or AVG Antispyware and uninstall everything else. I also ask you to uninstall CounterSpy but I still see it trying to load. Uninstall it too.

    Once you have uninstall all of these, please attach the below new logs:
    • GetRunKey
    • ShowNew - if it runs. If it does not run, give me the exact word for word error message
    • HijackThis
     
  15. topman1

    topman1 Private E-2


    I have uninstalled as many of the programs as i was allowed under safe mode.

    I have attached getrunkey and hijack this log files and also the latest scans by the programs I deleted.

    show new still errors.

    I still get B.S.O.D if i try to reboot into normal mode.

    thank you for persevering with me.

    Dave K
     

    Attached Files:

  16. topman1

    topman1 Private E-2

    adaware log file as well

    these are the bad files/trojans found by

    Cc

    rabio browser
    netheal
    win32.kill.procs
    tto adware
    ciarat
    command service
    trojan unclassified.gen

    all of which I deleted.

    Spy sweeper
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are not using the correct versions of GetRunKey (or probably ShowNew) again. We already discussed this previously. Delete these old versions and only use the correct versions from now on. You need to attach new logs from the correct versions now. And if ShowNew does not run you must give me the exact word for word error message as I have already requested. Also you need to check to make sure it is not one of the errors listed on the download pages where there are fixes for possible errors.

    So am I to assume that you tried to uninstall Ad-Aware 2007 and CounterSpy, and SuperAntispyware in safe mode and they would not uninstall?
     
  18. topman1

    topman1 Private E-2


    I have just downloaded getkeys and show new again.

    I have attached a new hjt log as well.

    In answer to your last question that is correct. safe mode would not allow me to delete them.

    i still cannot access the system in normal mode.

    Dave K

    it looks to me like I have W32.Pagipef worm and smitfraud.(is that correct)
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They are not running properly! Are you sure you extracted ALL the files from the ZIP file and that you are running the batch files from outside of the ZIP file as requested. Also did you check to see if you are getting any of the error messages given on the download pages?


    No! You have Troj/Dloadr-AQG



    See if you can run this: AproposMedia Fix

    Also does the below file exist? If so, delete it.
    D:\install.exe
     
  20. topman1

    topman1 Private E-2

    Yes i did download all zip files as requested outside of the zipfile.

    I am afraid my system has CRASHED completely now and I cannot boot up my system at all.

    I am using a pc in an internert cafe at the moment.

    I have tried numerous ways to boot up my pc. safe mode with networking, safe mode, normal etc.

    The motherboard boot screen comes up and sits there.

    1.then another screen says windows did not start correctly last time.

    2.lower memory is 0% and needs 512 to operate.

    3.b.so.d. error 0x0000008e.

    4.Each time i reboot I get a different error but the system just locks up.

    i feel my hard drive is now corrupted and am gutted.

    dave k
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What have you done inbetween posting messages # 18 & 20?

    Do you have your Windows XP bootable CD?

    I'm not sure if you boot problem is due to malware or not but you did have malware problems. Also there is a chance that you had a Rustock Rootkit that could have caused problems. We may need to use the Recovery Console from your boot CD to run a procedure like show in the below link from Symantec:

    http://www.symantec.com/security_response/writeup.jsp?docid=2006-070513-1305-99&tabid=3

    Unless you can get your PC to boot and then we could run the below instead:

    Rustock.b - msguard, pe386, & lzx32 RootKit Removal


    There is also a possibility that you have some bad RAM. Do you have access to other RAM that you could try in this PC.
     
    Last edited: Oct 10, 2007

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds