cp1041.nls help

Discussion in 'Malware Help (A Specialist Will Reply)' started by juantuu, May 23, 2007.

  1. juantuu

    juantuu Private E-2

    hello, like many people here i am posting after researching a problem and having little success. I tried to start at the beginning ("read and run this first") and am having limited success. i seem to be able to access ccleaner and have downloaded getrunkey and shownew. i thought i downloaded spybot and counterspy as well as hijackthis. i booted in safemode but cant find anything except getrunkey and shownew. i'm guessing that i just dont know how to find them? prior to doing all this i did try to download superantispyware but the ndis.sys will not let me finish the download and restarts my computer. any help to get me on track would be greatly appreciated. :)
     
  2. juantuu

    juantuu Private E-2

    Anyone??? i'd just like to know how to properly download ccleaner...
    thanks
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Two important pieces of information:
    1. you must also install, update and configure the applications as requested in step 4 of the READ ME before you boot into safe mode.
    2. when you boot into safe mode, you need to be logging into the same user account as you were logging into in normal mode. That is the account you are trying to clean. If you login to a different account, you may not see some of the tools you downloaded and installed especially if you did not follow our directions and install them where suggested. If you install things or even just download them to the Desktop or the documents folders for a particular user account, they will not be available when logged into a different user account.
    You have an infection that infects as many as 4 different Windows system files. ndis.sys is just one of the infected files. We will need to replace it later. But we need you to run all steps of the READ ME and attach the requested logs before we can give you the correct proedure to run.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Posting this message cost you about 15.5 hours of additional waiting time to get an answer. Read the stickies! In particular, this one: Don't Bump! It Only Hurts You!!!
     
  5. juantuu

    juantuu Private E-2

    Hi, Thank you for your response. I was wondering if I save what i have on my hard drive on an external drive if i will infect the external drive? I imagine that you may not be able to say either way until you see how i'm infected.

    i have downloaded everything except panda. since i have downloaded and installed bitfinder i cant even connect to the internet anymore so i havent been able to download and install it. everything that i have downloaded seems to slow me down more and more. it seems like mcaffee really doesnt like all this new stuff?

    when i ran spybot, it came up with a ms windows firewall bypass but that is it. i immunized but do not know where the sdhelper function is. counterspy didnt come up with anything but i dont know if it actually finishes because it doesnt scan any cookies maybe they are all deleted with the previous scans? it doesnt allow me to view> spyware scan etc. is it all downloaded? i am going to run everything again in safemode and see what i can come up with.

    thank you
    eugene
     
    Last edited: May 29, 2007
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Correct! Since I don't know all of your problems, I cannot say for sure. And it also depends on what you plan on copying. The cp1041.nls file is from an infection that does infect one or more Windows system files. I would bet that your ndis.sys file is infected. Also I would bet that you cannot access the internet because of either or both of the below:
    • your LSP chain is broken (this will show in your HJT log)
    • the infected ndis.sys file is causing problems with your connection
    I have fixed more than a dozen of these already, so I know we can fix it. Some are easier than others and it also depends on how good you are at following directions too.

    You should try booting in safe mode to see if you can connect to the internet that way. This sometimes works. Use safe mode with networking!

    Yes some of the new stuff will cause additional slow downs but that is temporary. After we get the malware removed we will be uninstalling certain tools. If you would attach the logs from the below, we can get started:
    • GetRunKey
    • ShowNew
    • HijackThis
    I'm ignoring Bitdefender and Panda since you have problems getting online.
     
  7. juantuu

    juantuu Private E-2

    i was able to connect to the internet again and ran bitfinder. it said it blocked Trojan.Agent.AOJ and i am not infected. it also said that i am infected with C:\windows\system32\x.dll disinfection failed and the move failed. mcaffee reported i'm infected with spam_Xarvester. after running bitfinder i havent been able to connect to the internet again in safe or regular mode. i am was able to generate runkeys.txt and newfiles.txt in safemode. the internet cannot be connected because of a C:\WINDOWS\system32\shdoclc.dll/dnserror.htm. any suggestions how i can connect to the internet and show the files to help fix my computer?

    thank you
    eugene
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have exactly what I said you would have in message # 6. Until you start following directions, we are not going to get anywhere. I cannot help you if you never get any of the logs we need and that are requested in the READ ME. If you had immediately completed the instructions in message # 6 we could have avoided this problem. You need to get the below program onto the problem PC somehow and run it as requested.

    Now download LSP - Fix

    Run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the x.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move x.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.
    If it is already in the Remove section, just click Finish.


    Also tell me everything you see listed in the Keep section and in the Remove section.
     
  9. juantuu

    juantuu Private E-2

    Thank you for your expertise, I realize that your time is valuable and have no desire to waste a second of it. the keep section has mswsock.dll, winrnr.dll, rsvpsp.dll i put x.dll in remove and now it is gone. what is the next step?
     
  10. juantuu

    juantuu Private E-2

    not sure if this attatchment will work?
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run ALL of the READ & RUN ME and attach all 6 logs. You only attached two. Also your GetRunKey versions is now out of date. Download and use the current version.


    Are you able to connect to the internet after removing the x.dll file. As I suspected, your ndis.sys file is infected.
     
  12. juantuu

    juantuu Private E-2

    I have been able to connect to the internet. I ran ccleaner, spybot and immunized. I ran counterspy and there was nothing found so there was nothing to attach. I am attaching updated getrun and shownew. I also ran hijackthis. I dont have panda downloaded and didnt run bitfinder because it crashed my connection crashed last time I tried. I know you asked for all 6 attachments but since i had trouble with my internet connection I'm a bit gun-shy. Is this sufficient for now or should I try download panda and run bitfinder? thank you!!!
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have the same old version of GetRunKey. You need to download and use the current version as requested in my previous message.

    You have two antivirus programs installed! Why? See step 3 of the READ ME. You must uninstall either McAfee or BitDefender10. Note if you are going to say you installed BitDefender 10 while running the READ ME, we did not ask you to install their antivirus program. We ask you to run an online scanner. Perhaps this explains why you crashed your PC.

    After uninstalling one of the AVs, attach 3 new logs! (Make sure you use the new GetRunKey which is currently version 1.67). Also make sure you do not run ShowNew until you have terminated GetRunKey by closing the notepad popup!

    Do you know how to use a Command Prompt window and do you know how to use DOS type commands to copy, rename and delete files?
     
    Last edited: Jun 10, 2007
  14. juantuu

    juantuu Private E-2

    I have uninstalled bitdefender. I do know how to open the command prompt window but am not familar with using the commands. when i tried to download the getrunkey from "read and run me first section" it says it is version 1.64. where do i get 1.67 from? thank you.
     
  15. juantuu

    juantuu Private E-2

    I have been successful in getting the proper version of getrunkey. I hope i have properly attached the requested logs. sorry about the previous post but i couldnt edit or delete it once i was able to get the proper version. i hope i have finally followed your instructions correctly so we can make some progress. thank you for your patience:)
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the mwdhf.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move mwdhf.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.
    If it is already in the Remove section, just click Finish.

    Download the attached JuanFix.zip file to your Desktop and extract the JuanFix.batfile from it to your Desktop. Then boot into safe mode and make sure you log into your normal user account that is used in normal boot mode (otherwise you will not find the JuanFix.bat file) . After booting in safe mode, double click on JuanFix.bat to run it. This will create a log file named c:\FixND.txt

    NOTE: After running this you will not be able to shutdown or restart your PC in the normal fashion. You will have to hold in the power button on your PC until it powers down.
    • Now close ALL open windows now!!!!!
    • Power down your PC now. Wait about 15 seconds and then power back up.
    • After reboot Attach the c:\FixND.txt file here. Then continue on to the below instructions!
    • Also attach new logs from ShowNew and HJT
     

    Attached Files:

  17. juantuu

    juantuu Private E-2

    I did all this from safe mode. i'm shutting down for the night. thank you again for your help.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The JuanFix.bat script did not work. Did you notice any error messages? You should have! I forgot to put another file into the ZIP file to kill processes.

    Also note that while it probably was not the reason for the script not woring, I did not ask you to do everything from safe boot mode. You should have started in normal boot mode and ran LSP-fix and then downloaded JuanFix.zip. Then you should have boot into safe mode to run JuanFix.bat. After shutting down you PC, you should have booted back into to normal mode and obtained new logs. The logs you posted are not useful since you were not in normal boot mode.

    Download and use this new version of JuanFix.zip. Repeat the procedure for using it and attach new logs from NORMAL boot mode afterwards. You don't need to redo the LSP-fix part because that particular file may have renamed itself by now.
     

    Attached Files:

  19. juantuu

    juantuu Private E-2

    Let's hope we're on our way now? :) thanks again.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! It still did not work! Are you noticing any error messages?
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you running the procedure in safe boot mode as requested? It will not work if run in normal boot mode.
     
  22. juantuu

    juantuu Private E-2

    hi, i ran fixnd from safe mode and attached it now, i cant remember if i did it in normal mode or safe last night as it was very late. should i redo shownew and hjthis again. i know last night that i ran them in normal mode. thank you!
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay for some reason, we are having a problem replacing the infected ndis.sys file with a good copy. This normal works okay when run in safe mode. We are going to have to do this manually from a command prompt windows while in safe boot mode. You better print the below instructions since you will have to make sure that no browsers opened also make sure you are disconnected from the internet too before you try to do the below steps.

    • boot into safe mode
    • run the JuanFix.bat file
    • open a command prompt window by clicking Start, Run and enter cmd and click OK
    • in the command prompt window enter the below commands one at a time and hit enter after each command. Make sure you take notes at each command and tell me what happens. I need good feedback here just incase this still does not work. ( the text in purple are helpful comments and are not part of the commands you enter)
      • cd c:\windows\system32\drivers <-- there is a space after the cd
      • copy ndis.sys ndis.sys.bad <-- there is a space after the copy and after the first ndis.sys
      • copy C:\WINDOWS\system32\dllcache\ndis.sys ndis.sys <-- there is a space after the copy and after the first ndis.sys
    • now shutdown you PC by holding down the power button
    • reboot after 15 seconds and then get a new log from ShowNew and attach it here.
    • Also tell me the results of running the above commands. If you received any error messages be sure to tell me exactly what you received and when.
    If you lose internet access, get a new HJT log and look for lines similar to the below:

    O10 - Unknown file in Winsock LSP: c:\windows\system32\amfzuumautl.dll

    The amfzuumautl.dll file name may have changed. Whatever you see there for a file name will have to be fixed using the LSP-fix procedure you have previous used but substitute in this new file name.
     
  24. juantuu

    juantuu Private E-2

    i ran juanfix in safe mode, then opened into the command prompt screen and successfully typed in the first command line. the copy ndis.sys line did not work. it said that the process cant access the file because it is being used by another process 0 files were copied. i tried the next line and it gave me the same message. i then turned off the computer and it opened in safe mode again and i went to run msconfig and restarted in normal mode. i did a new shownew and attached it here. internet is working so i did not run hjt. thank you :) i hope we can make some progress.
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you have all browsers closed and were you disconnected from the internet?

    In the folder where juanfix.bat is installed, tell me what other files you see.
     
  26. juantuu

    juantuu Private E-2

    all browsers were closed and i did not reconnect to internet until after i was done running shownew so i could email the results. juanzip was directly downloaded onto my desktop and juanbat extracted to the desktop as instructed. i am not sure of the other files that may show with it? would you like to know what i have on my desktop? i really do appreciate your help and i hope we can get to the bottom of this. unfortunately i will be away until next week until then my computer will sit idly. zzz
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then that is the reason this has not been working all along! You did not extract ALL THE FILES from the ZIP file. The process.exe file that is inside of the zip is not on your Desktop and thus the juanfix.bat file cannot find it and should be giving you error messages . You must extract ALL files from the ZIP and then run it. If you do not see process.exe in the same folder as juanfix.bat, the procedure definitely will not work.
     
  28. juantuu

    juantuu Private E-2

    i connected to the internet and mcaffee said that it cleaned cp1041.nls. i have no idea where this leaves me? i have extracted the necessary files and ran the juanfix and it seemed to work fine and had no error messages. I also reran shownew and hjt.
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you not understanding my instructions about extracting process.exe from the JuanFix.zip file before running JuanFix.bat? I do not see process.exe on your Desktop. The fix will not work until you do this. Also did you run it in safe mode the last time? It must always be run in safe mode. Also you must not attempt to run the JuanFix.bat file from inside of the ZIP file.

    Do you have your Windows XP SP2 bootable CD?
     
  30. juantuu

    juantuu Private E-2

    i did extract process.exe from juanzip and ran juanfixbat.exe in safemode. unfortunately i did not run process.exe prior to running juanfix the last time. this time i ran process then juanfix in safemode. i then powered off started up then booted in normal. i then ran shownew and hjt. i have been running juanfix and process from the desktop not the zip. the newfiles is still not showing the process.exe? it is on the desktop and when i checked the properties it says it was accessed at around the same time i ran it and juanfix? the fixnd is the same log as the last one i posted so i'm guessing it is still not working? i do appreciate your help, i'm trying not to be an idiot and waste your time...honest. i'm going to try download juanfixzip again and extract files to see if i can get process.exe to show on the desktop. i did have an xp cd but not too sure how easily i can find it.
     

    Attached Files:

  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay thanks for addressing all of my concerns! Since this is not working for you and it as worked just like this in about 10 other threads where I have used the same approach, we have no other way to fix this other than using your Windows XP SP2 CD to boot to the recovery console and then replace the file from the command prompt of the recovery console. This should work without a problem since Windows will not be running.

    All I can think of is that something on your PC (even in safe mode) is blocking the change to the ndis.sys file. This could be McAfee. So you have to possible courses.

    1. Uninstall all of McAfee and then retry the fix (always run in safe boot mode) we have been using
    2. Find your Windows XP CD and tell me when you have it. Make sure your PC is set in the BIOS to boot from CD before booting from the harddisk.
     
  32. juantuu

    juantuu Private E-2

    i have downloaded juanfix again and this time process.exe shows up on shownew. unfortunately the fixnd to me does not appear to fix the problem. i'll just attach the logs fyi. i am good with uninstalling mcaffee once you confirm that the fix isnt working.
     

    Attached Files:

  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The fix seems to have worked. Hangon while I look at the rest of the logs.
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why do I see BitDefender Antivirus running in your HJT log? You must uninstall this!! Remember step 3 of the READ ME. Uninstall it now while a prepare a fix for remaining issues. OR is this an old log. The date shows it to be old?

    I need a current HJT log!!
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry I think I may have been look at an old log some how. Your last HJT log is from June 20th. Working up a fix now.
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 2
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME


    Now run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the amfzuumautl.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move amfzuumautl.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.

    If it is already in the Remove section, just click Finish.

    Repeat the above for mwdhf.dll if seen in LSP-Fix.


    Now run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    I also recommend that you also fix the below BigFix process. It is a massive resource hog and does not need to run at boot up. Run it when you need it which will probably be never.
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Now please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.


    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  37. juantuu

    juantuu Private E-2

    :) Excellent. I have to go to work in a couple of hours so i am going to bed now and will work on this tomorrow. should this be done in normal mode?
    thnx and goodnight.
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes in normal boot mode! It would be best if you do not shut down your PC before doing this. So if you are in safe boot mode, don't shut off your PC tonight, just run it from that mode. If you are in normal mode right now, again do not shutoff your PC or reboot, just wait until you can run the procedure and reboot where requested.
     
  39. juantuu

    juantuu Private E-2

    after i left my last message last night i shut down the computer. should i still do the fix now? thanks
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes give it a try anyway. But after you attach the new logs, do not shutdown or reboot until you here back from me.
     
  41. juantuu

    juantuu Private E-2

    well, everything went smoothly. i'll attach the logs and see what you can tell me. computer is running fine. thank you!:)
     

    Attached Files:

  42. juantuu

    juantuu Private E-2

    here's the last log.
     

    Attached Files:

  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean!

    Uninstall the CounterSpy trial now!

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds