Cannot remove trojans

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by irishred513, Apr 13, 2007.

  1. irishred513

    irishred513 Private E-2

    I have been trying to follow the steps required before posting in the forum, but this laptop has been unstable. After removing Java and trying to download the new version....everytime the download completes and I go to intstall it the computer goes to a black screen then reboots then gives me a BSOD saying there is a driver error. It takes me several attempts to reboot and get the computer to let me online again. I have performed as many of the steps I have been able to, but at this point I am having trouble with downloading some things. I had run a panda scan earlier, I have also run ewido and superantispyware. All tell me I have trojans but when I try to remove them, it doesn't seem to work.
    Also, the firewall has somehow become disabled and when I try to re-enable it I get a message telling me an unknown error has caused it not to open.
    Any help would be greatly appreciated.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You have some serious issues which will take some work to remove!!!

    It is important that steps in the READ & RUN ME be followed in the order written. I'm not sure what you meant about running Panda Active Scan earlier but it should have been one of the last things to run.

    Do you have a log from SuperAntiSpyware?

    If you can run HijackThis you can easily run GetRunKey and ShowNew. Please always attempt ALL steps. Run these two programs now and attach the logs. These logs are very important in providing us the information needed to cleanup your malware.


    Why aren't you using a real full blown antivirus program instead just an after the fact scanner from McAfee which is installed in a temp folder and will get deleted during cleanups?

    Please download LSP - Fix

    Do not attempt to use it yet! I just want you to have this on your PC incase you loose internet connectivity at any point. If you do loose connectivity the below steps will come in handy (but I repeat don't do them yet)!!


    Run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the msnetax.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move msnetax.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.
    If it is already in the Remove section, just click Finish.
     
  3. irishred513

    irishred513 Private E-2

    Hi, Thanks for your help.

    I had run a pandascan earlier on my own....before I found this site, thats what I meant. But then after I uninstalled Java and couldn't redownload it I couldn't run it again so thats why I posted the other one.

    As far as the antivirus program.....this is my daughters laptop and after trusting that she was doing what she needed to with it, I found out she was not and hence all these problems!!! She thought that her ewido antispyware and an antivirus program were the same thing. But she was also not updating that program so even though she had been running it, it was pretty usless without the updates. I plan on taking care of that if I get it straightened out.

    Ok I did get the other two programs to run the first time I tried it told me the file was corrupt and wouldn't run. So here are the logs for them as well as one from antispyware from this morning.
    Thanks!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay thanks for the additional info. I will probably have you try to re-run Panda again later after we fix a bunch of issues

    Some of your system files have become infected and we need to look for an uninfected replacement on your hard disk. Begin by right clicking Start and select Explore. This should open a Windows Explorer window. Make sure the Address bar indicates C:\

    • Now click the Seach icon
    • then select All files and folders
    • in the box title All or part of the file name: enter exactly the following with no spaces between any characters (the asterik belongs there at the end of the file name): ndis.sy*
    • tell me what matches you get when you come back. One will be c:\windows\system32\ndis.sys and that is the infected one.
    I will give you some stuff to install lated. A free antivirus which will auto update and save you some grief.

    Note that Ewido has been replace by AVG AntiSpyware! If you bought Ewido, you update to AVG AntiSpyware. You can only get permanent realtime protection and updates for it when you buy it (no different than Ewido).


    Let's Get Started!

    Since the instuctions are going to be very long, I will break this into a couple messages. Complete all of this message before the next one.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to ieupdater22
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteMicrosoft IEUpdater22 into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.


    Now run LSP-Fix which I had you download previously.

    Check the Box labeled "I know what I'm doing" and then click on the msnetax.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move msnetax.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.

    If it is already in the Remove section, just click Finish.

    Now repeat the above steps with LSP-fix while looking for ONLY EXACT NAME MATCHES to the below files (you may not find any).
    C:\WINDOWS\system32\credgui.dll
    C:\WINDOWS\system32\gdip32.dll
    C:\WINDOWS\system32\mcert.dll
    C:\WINDOWS\system32\msiphelp.dll
    C:\WINDOWS\system32\msnetax.dll
    C:\WINDOWS\system32\netp.dll
    C:\WINDOWS\system32\windll.dll
    C:\WINDOWS\system32\winload.dll
    C:\WINDOWS\system32\ws2_32(2).dll
    C:\WINDOWS\system32\wsock.dll
    C:\WINDOWS\system32\ws_imod.dll

    When finished, give me a list of the remain filenames you see in the Keep section. This will be the list for you to remember as being good and if you ever loose your internet connection while we are working on this malware, look to see if something new showed up in the list and remove it.

    Also download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
      [*]It will create a folder named HostsXpert in whatever folder you extract it to.
      [*]Run HostsXpert.exe, click Restore Microsoft's Hosts File and then click OK.
      [*]Click the X to exit the program

    Now move on to the next message!
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you complete the steps in message # 4 before doing the below.

    Uninstall Viewpoint Media Player which should have been uninstall in step 0 of the READ ME.

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Cleanup] C:\DOCUME~1\Courtney\LOCALS~1\Temp\200741318713_mcappins.exe /v=3 /cleanup
    O4 - HKLM\..\Run: [msci] C:\DOCUME~1\Courtney\LOCALS~1\Temp\20074131879_mcinfo.exe /insfin
    O20 - AppInit_DLLs:
    O20 - Winlogon Notify: jgmdlv - jgmdlv.dll (file missing)

    NOTE: HJT will popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Documents and Settings\Courtney\My Documents\HIJACKTHIS.EXE
    C:\Documents and Settings\Courtney\ie_updater.exe
    C:\WINDOWS\system32\CMMGR32.EXE
    C:\WINDOWS\system32\koos.exe
    C:\WINDOWS\system32\kprof
    C:\WINDOWS\system32\poof
    C:\WINDOWS\system32\update15050767.exe
    C:\WINDOWS\system32\update58336742.exe
    C:\WINDOWS\system32\update86927746.exe
    C:\WINDOWS\system32\update96307977.exe
    C:\WINDOWS\system32\winlogon(2).exe
    C:\WINDOWS\system32\credgui.dll
    C:\WINDOWS\system32\gdip32.dll
    C:\WINDOWS\system32\mcert.dll
    C:\WINDOWS\system32\msiphelp.dll
    C:\WINDOWS\system32\msnetax.dll
    C:\WINDOWS\system32\netp.dll
    C:\WINDOWS\system32\windll.dll
    C:\WINDOWS\system32\winload.dll
    C:\WINDOWS\system32\ws2_32(2).dll
    C:\WINDOWS\system32\wsock.dll
    C:\WINDOWS\system32\ws_imod.dll
    C:\WINDOWS\nnomjk.dll
    C:\cp1041.nls
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But if you do get this message, please let me know!)

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete if found:
    C:\Program Files\McAfee.com

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  6. irishred513

    irishred513 Private E-2

    Ok....
    On step 1 this is what came up on the search:
    NDIS.SY c:/windows/I386 89kb SY.File 8/4/2004
    ndis.sys c:/windows/system32/drivers 275kb systemfile 4/11/2007

    On step 2 after clicking ok I received this message:
    Service "MicrosoftIEUpdater22" was not found in the Registry, make sure you entered the short name of the service

    On step 3 These were the files left
    mswsock.dll Tcpip
    winmr.dll NTDS
    rsvpsp.dll {Protocol handler}

    *Sorry, I thought I had uninstalled all the viewpoint programs, I guessed I missed that one.

    I did NOT receive the Pendingfilerename message.

    During the reboot I got the BSOD with the Driver-IRQL-Not-Less-Or-Equal message twice....on the third try I was able to get back to windows and online.
    Thanks so much for all your help so far!:)
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Check this file name again! Was it NDIS.SY or was it NDIS.SY_ (yes the underscore is what I meant), or was it NDIS.SYS You don't need to do a search. Just use Windows Explorer to look in the c:\windows\i386 folder and look for yourself.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you uninstall Viewpoint Media Player? I still see it in your ShowNew log.
     
  9. irishred513

    irishred513 Private E-2

    It was NDIS.SY_ Sorry! I didn't realize that was important. :eek:
     
  10. irishred513

    irishred513 Private E-2

    Yes.....let me ck the uninstall programs again.
    Hmmmm, It was still there. I tried uninstalling it again.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Exact details are always important as you are learning.;)

    The underscore means that it is a compressed file and we will have to uncompress a copy.

    I'll get back to you on this! I need to get some sleep!

    As far as Viewpoint is concerned did you get it uninstalled? If not, run this ViewpointKiller to remove Viewpoint Media software.
     
  12. irishred513

    irishred513 Private E-2

    I did uninstall viewpoint again and sure enough when I checked this morning it was back, I was beginning to think I was losing my mind!
    I ran the viewpointkiller. So hopefully it is gone now.
    Noticed your location is Jersey...hope you are surviving the storm ok and
    getting some sleep, this site must keep you very busy!
    Thanks again.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No sleep last night at all! Too many flooding problems for me and neighbors and friends that needed help and they had worse problems then me. Thanks for asking! ;)


    Let's continue!

    Download the attached irishFix.zip file to your Desktop and extract the irishFix.bat file from it to your Desktop. Then double click on irishFix.bat to run it. This will create a log file named c:\FixND.txt

    Attach the FixND.txt file here along with a new log from ShowNew.
     

    Attached Files:

  14. irishred513

    irishred513 Private E-2

    Hope you guys are all starting to dry out.

    Ok....I was able to download the file, open it and then when I hit run the computer went black then to that same BSOD. Since then I can not get it to load. I can get to the windows screen then as soon as it tells me the computer has recovered from a serious error and I hit ok....it goes back to the BSOD and reboots. I have attempted to get it to reload over 10 times now but keep getting the blue screen, reboot. :cry

    *Obviously I am now posting this from my pc and not the laptop in question. lol
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Will it boot in safe mode?

    Do you a Win XP SP2 boot CD?
     
  16. irishred513

    irishred513 Private E-2

    Yes, I can get it to boot in safemode
    No, I dont think so.....the disk it came with that I thought was a xp disk is just a factory complete reinstall or just for going back to factory settings for the preinstalled programs? At least that what it sounds like to me. I do have a win xp upgrade cd from a old computer. I guess that is probably not much help. Should I try to run the irishfix in safemode?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! While in safe mode look in c:\windows\system32\drivers.

    Do you see ndis.sys and also ndis.sys.bad?

    Also look in C:\windows\i386

    Do you see ndis.sy_ and also ndis.sys

    Also does C:\FixND.txt exist?

    Not yet.
     
  18. irishred513

    irishred513 Private E-2

    In c:\windows\system32\drivers
    I see ndis.sys only

    I have c:\windows\i386 but I do not see a ndis in there at all, I also have c:\window\I386 and in that one I see NDIS.SY_ only

    And yes! I guess that file did run before the computer rebooted because I did find c:\fixND.txt!
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then the fixND.bat file did not work properly! But also, I don't understand why you cannot boot in normal mode if this file still exists. What is the file size in bytes and what is the file date. Right click on it and select Properties to get this information.

    This also means the script did not work. There is command in the script that should have produces and expanded version of this file and named it ndis.sys and but it in this i386 folder and then later copied it to the system32 folder.

    Get to a command prompt and type in expand and tell me what you see. You should see something like below:
    Can you get me the info that is in this file.
     
  20. irishred513

    irishred513 Private E-2

    Ok..I can't find fixND.bat file....I do have irishfix.bat...is that the one? I did a search for the other one and it said not found. The irishfix.bat is:
    Size: 2.22KB (2.278 bytes)
    Size on disk: 4.00KB (4.096 bytes)
    It says created Today April 16, 2007 6:04:25 PM


    Although I do appreciate your faith in me.....ummm....I am really not all that computer literate....I do not know how to get to a command prompt. :eek:

    Now that I can do:

    Changing attributes of c:\windows\system32\drivers\ndis.sys
    Sytem32 expand.exe found
    Expanded File Listing
    Volume in drive c is SQ003947
    Volume Serial Number is B4BD - A73c

    Directory of c:\window\i386

    Attempted killing of smss.exe completed

    Extra echoes inserted to add delay
    Running command to kill winlogon.exe
    Attempted killing of winlogon.exe completed

    Back up current c:\windows\system32\drivers\ndis.sys
    Deleting current c:\windows\system32\drivers\ndis.sys
    Copy i386 backup to c:\windows\system32\drivers\ndis.sys

    Good file listening
    Volume in drive c is SQ003947
    Volume Serial Number is B4BD - A73c

    Directory of c:\windows\system32\drivers

    4/11/07 11:09am 281,348 ndis.sys
    1 file(s) 281,348 bytes
    0 Dir(s) 49,848,832,000 bytes free.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm sorry! fixND.bat is a generic version fix file. For you, I renamed it, irishFix.bat but that is not what I wanted to know the size of. I was referring to c:\windows\system32\ndis.sys

    To open a command prompt click Start, Run, and enter cmd and click OK!
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmmmm! Based on what you attached from that log file. The irishFix.bat really did not do anything at all. So now, I have to wonder why your PC will not boot in normal boot mode.?????? However the log did help me figure out a problem in irishFix.bat. I had a typo and named ndis.sy_ as ndis.s_
     
  23. irishred513

    irishred513 Private E-2

    Oh lol, ok....you must really enjoy this stuff...people like me would drive me crazy. Ok for c:\windows\system32\ndis.sys:
    Size: 274KB (281.348 bytes)
    Size on disk: 276KB (282.624 bytes)
    Created: Tuesday August 09,2005
    Modified: Wednesday April 11,2007 11:09:02AM
    Accessed: Today April 16, 2007 10:50:31 PM

    Ok For that I see:

    Microsoft Windows XP [Version 5.1.2600]
    (c) Copyright 1985-2001 Microsoft Corp.
    C:\Documents and Settings\Courtney>Expand
    MicroSoft (R) File expansion Utiltiy Version 5.1.200.0
    Copyright (c) Microsoft Corp 1990-1999 All Rights Reserved.
    No Files Specified.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that means the old ndis.sys file is still there which means nothing changed!

    From the command prompt window. Type the below (besure to enter them correctly - note the one place where sy_ is used. Also note the spaces!! There is a space after the copy, after after the first ndis.sys, after the expand, and after the ndis.sy_)

    copy c:\windows\system32\ndis.sys c:\windows\system32\ndis.sys.bak
    expand c:\windows\i386\ndis.sy_ c:\windows\system32\ndis.sys

    After doing the above what is the size and date of the ndis.sys file that is in the system32 folder.
     
  25. irishred513

    irishred513 Private E-2

    Two stupid questions...is there a space between
    c:\windows\system32\ndis.sys.bak and expand? Or do I hit enter and put it on a seperate line?
    Also after typing that all in do I hit enter or just look at the system32 file?
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They are separate commands on separate lines. So yes, just hit enter after typing the first command. ;) And then type the second command and hit enter.

    After the above two commands have been run, use Windows Explorer (right click Start and select Explore) to look in the c:\windows\system32 folder

    You can then right click on the ndis.sys file in the system32 folder to get Properties (i.e., size and date)
     
  27. irishred513

    irishred513 Private E-2

    Ok:
    Size: 178KB (182,912 bytes)
    Size on disk: 180KB (184,320 bytes)

    Created: Today April 17, 2007 12:34:00AM
    Modified: August 03, 2004 11:14:30PM
    Accessed: Today April 17, 2007 12:34:00AM
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And does the c:\windows\system32\ndis.sys.bak also exist?

    What happens if you power down your PC now for a minute and then reboot? Can you get into normal boot mode? If you receive any error messages, please post the exact word for word message.
     
  29. irishred513

    irishred513 Private E-2

    Sorry, we were having high winds last night and the power was starting to glitch so I had to shut down.

    No
    Tried to boot up normal, still get the same BSOD. It says:
    Driver-IRQL-Not-Less-Or-Equal
    Then the generic if this is the first time you have seen this error stuff.
    Then the generic if it returns uninstall any new programs etc.

    *The first time this screen appeared she had not installed anything new.

    Under the Tech info it says:
    STOP: 0x000000D1 (0xFAAIE70,0x0000000,0X000000A)
    NDIS.SYS-Address FAA1E070 base at FA9F3000, Datestamp 41107ec3
    NDIS.SYS-Address FAA10BEC2 base at FA93000, Datestamp 41107ec3
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Was there anything under the Driver-IRQL-Not-Less-Or-Equal part of the message.


    I don't understand how the c:\windows\system32\ndis.sys.bak file does not exist.

    In message # 23 you said the April 11, 2007 version of ndis.sys existed.
    In message # 24 I had you copy the above ndis.sys file into ndis.sys.bak. Didn't you do this command first. Did you get an error message?

    From a command prompt window, enter the below command:
    dir /s/a-d ndis.* > c:\search.txt

    Note there are spaces here:
    after dir
    before ndis
    before and after >


    Now attach or post inline, the contents of the c:\search.txt file.
     
  31. irishred513

    irishred513 Private E-2

    No....well the only thing under that part of the message is the "If this is the first time you are seeing this message" etc.


    Yes, I did do that command first and it said the file does not exist or file not found. I dont recall which. I didn't know that it wasn't suppose to say that. It didn't say it was an error. Sorry.

    Microsoft Windows Version XP [Version 5.1.2600]
    <c> Copyright 1985-2001 Microsoft Corp

    C:\ Documments and Settings\Courtney>dir /s/a-d ndis.* c:\search.txt
    Volume is drive c SQ003947
    Volume Serial Number is B4BD-A73C
    File Not Found
    File Not Found
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot the greater than sign in between ndis.* and c:\search.txt

    But I also left something out.... a \ in front of ndis.*

    Use this

    dir /s/a-d \ndis.* > c:\search.txt
     
  33. irishred513

    irishred513 Private E-2

    Ok, added the greater sign now all it says is "File Not Found"
    oops you changed it! let me try again
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What do you get with just this:

    dir /s/a-d \ndis.*
     
  35. irishred513

    irishred513 Private E-2

    This time it says
    The System cannot find the path specified
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This does not make any sense!

    Does you prompt still show?

    C:\ Documments and Settings\Courtney>
     
  37. irishred513

    irishred513 Private E-2

    Ok with that one:
    Directory of C:\windows\I386
    8/4/2004 05:00am 90,321 NDIS.SY_
    1 file(s) 90,321 bytes

    Directory of c:\windows\system32
    8/3/2004 11:14pm 182,912 NDIS.SYS
    1 File(s) 182,912 bytes

    Directory of c:\windows\system32\dirvers
    4/11/2007 11:09am 281,348 NDIS.SYS
    1 File(s) 281,348 bytes

    Total Files Listed
    3 File(s) 554,581 bytes
    0 Dir (s) 50,046,617,648 bytes free
     
  38. irishred513

    irishred513 Private E-2

    Yes it does show that prompt....I think I am one post behind you because of the edit....check my last post before this one...maybe it makes more sense?
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's better! Let's do a few more things from the command prompt but I'm going to have you do this one stage at a time with a check using the dir command each time.


    copy c:\windows\system32\ndis.sys C:\windows\i386\ndis.sys

    dir /s/a-d \ndis.*


    Give me the output.
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In message # 13 you had the below text and I highlight in brown the important word.

    Directory of c:\windows\system32\dirvers


    • Was dirvers correct or was it a typo? It should be drivers
    • Are you re-typing these responses to the commands or are you using copy and paste in the command prompt window.
    You can use copy and past by right clicking on the top bar of the window and selecting Edit and then use Mark to highlight the lines. And then right click on the top again and select Copy. Now they are on your windows clipboard and you can paste them into your message here by hitting CTRL-V
     
  41. irishred513

    irishred513 Private E-2

    That was just a typo, it was drivers. I cannot copy and paste because I cannot get online from that laptop in safemode....dial-up. So I am posting from my pc.
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I still need the output from the instructions in message # 39!
     
  43. irishred513

    irishred513 Private E-2

    After this it says: 1 File(s) copied

    Volume in drive c is SQ003947
    Volume Serial Number is B4BD-A73C

    Directory of c:\windows\I386
    08/03/2004 11:14pm 182,912 ndis.sys
    08/04/2004 05:00am 90,321 NDIS.SY_
    2 File(s) 273,233 bytes

    Directory of c:\windows\system32
    08/03/2004 11:14pm 182,912 ndis.sys
    1 File(s) 182,912 bytes

    Directory of c:\windows\system32\drivers
    04/11/2007 11:09am 281,348 ndis.sys
    1 File(s) 281,348 bytes

    Total Files Listed:
    4 File(s) 737,493 bytes
    0 Dir(s) 50,047,954,944 bytes free
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I think we are getting close to where I want to be. I taking this slowly to avoid any possible confusion or mistakes.

    The next set of steps to run from the command prompt are below (there are spaces before the -r , before the -s, and before and after the -h

    del c:\windows\system32\ndis.sys
    attrib -r -s -h c:\windows\system32\drivers\ndis.sys
    copy c:\windows\system32\drivers\ndis.sys c:\windows\system32\drivers\ndis.sys.bad
    dir /s/a-d \ndis.*


    Can you boot in normal mode now? Either way we still are not finished replacing the malware version of ndis.sys. I just wanted to create some backups and get an uninfected vesion of the file ready to be copied, and that will be our next step after I see the results from above.

    By now you should be an expert at using the command prompt. ;)
     
  45. irishred513

    irishred513 Private E-2



    Ok....I hope I did that all right.
    Here is what I got:
    Directory of c:\WINDOWS\I386
    08/03/2004 11:14pm 182,912 ndis.sys
    08/04/2004 05:00am 90,321 NDIS.SY_
    2 File(s) 273,233 bytes
    Directory of c:\WINDOWS\system32\drivers
    04/11/2007 11:07am 281,348 ndis.sys
    04/11/2007 11:07am 281,348 ndis.sys.bad
    2 File(s) 562,696 bytes

    Total Files Listed:
    4 File(s) 835,929 bytes
    0 Dir(s) 50,048,118,784 bytes free

    I still cannot boot normally, I received that same BSOD before the welcome window appeared.
     
  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmmm! I don't understand why you cannot boot in normal mode but if we look back it started back in message # 6 where you said you
    And then on the third try everything was okay! Then in message # 14, you appear to have permanently entered this state. I starting to wonder if something other than malware happened.

    Let's do one more set of steps from the command line:

    copy c:\windows\i386\ndis.sys c:\windows\system32\drivers\ndis.sys
    dir /s/a-d \ndis.*

    Give me the results of the dir command! Can you boot normal now? If not, give me the exact information on the BSOD.
     
  47. irishred513

    irishred513 Private E-2

    After this step it says:
    Overwrite c:\windows\system32\drivers\ndis.sys? (Yes,No,All)
    I assume I am suppose to pick yes or all.....which one?
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just say yes!

    If you still cannot boot into normal mode, run System Restore and look for a restore point on April 14th or earlier and restore to that point in time. Then see if you can boot in normal mode.
     
  49. irishred513

    irishred513 Private E-2

    Ok:
    Directory of c:\WINDOWS\I386
    08/03/2004 11:14pm 182,912 ndis.sys
    08/04/2004 05:00am 90,321 NDIS.SY_
    2 File(s)
    Directory of c:\WINDOWS\system32\drivers
    08/03/2004 11:14pm 182,912 ndis.sys
    04/11/2007 11:09am 281,348 ndis.sys.bad
    2 File(s) 464,260 bytes

    Total Files Listed:
    4 File(s) 737,493 bytes
    0 Dir(s) 50,047,643,648 bytes free

    I was able to boot up normal
    In case you need this....
    After the system has recovered from a serious error under the click here part this is what it said:
    Error Signature
    BCCode: 1000008c BCP1:C0000005 BCP2:00000000 BCP3: F33EEB84 BCP4:00000000 OSVer: 5_1_2600 SP: 2_0 Product: 768_1
    Technical Information:
    c:\DOCUME~1\Courtney\Locals~1\Temp\WER5e82.dir.00\Mini041607-13.dmp
    c:\DOCUME~1\Courtney|Locals~1\Temp\WER5e82.dir.00\sysdata.xml
     
  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! This sounds promising! Then it seems that the root cause of not being able to boot in normal mode was the infected ndis.sys file that I was worried about and want to get replaced!

    Attach current logs from GetRunKey, ShowNew, and HJT (all from Normal Boot mode).

    How is everything currently working?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds