Fishy Symptoms! (help please!)

Discussion in 'Malware Help (A Specialist Will Reply)' started by heartinhands, Feb 16, 2009.

  1. heartinhands

    heartinhands Private E-2

    Hello All! First off, I just want to say thanks for having a body of knowledge like this, and a support group to help "get shit done". I've relied on this website many times to fix problems on friends computers, but now, mine is possibly under attack.

    I've done the initial cleaning procedure, up until Combo fix, because my CMD isnt working, see below for more on that.

    I can't access "run" on the start menu, and have tried to fix it numerous times, but for whatever reason, which I assume is a virus or something important missing from my system, I cannot. I am also unable to access CMD through any means, my registry is locked (im admin and have permission, but it says I dont have authority to change it) My windows explorer is also funky, and doesnt allow searching anymore it seems.

    Now, Im a college student who works hard and I depend on my computer not only for school, but also for work as I do graphic/web design from it.

    Another side note, when my computer starts, it says something to the effect of "csrcs.exe isnt there anymore and can't start" which i've been told are viral remnants. Not sure really.

    Combofix couldn't work because I couldnt access CMD, so that was the only step, minus the final step after combo fix i wasn't able to do. Ill be attaching logs shortly.

    Thanks for all your help everyone!
     
  2. heartinhands

    heartinhands Private E-2

    Here are my logs.

    Let me know if you require anything else.

    Thanks everyone!
     

    Attached Files:

  3. heartinhands

    heartinhands Private E-2

    Windows Won't Update

    I have SP2, and until the past month, my computer was in storage. Anyhow, that may have been useless information..

    I had installed SP3 a while ago, successfully, but then I thought it was messing with my DVD reader/writer, so I uninstalled it.

    Now I am trying to reinstall SP3 per some recommendations, but it says that the components "couldn't be installed". .

    Not sure if this is useless info, but I hope it may help instead of confuse!
     
  4. heartinhands

    heartinhands Private E-2

    Not sure if this helps much, but I've attached my HJT log too.

    There seems to be issues with Windows Explorer, as accessing the C:/ drive has to be done with right click > explore instead of just double clicking.

    Im also having issues copying DVD's (data) to my computer as well. . . HP said that it was because the disk is protected, which I know isnt true.

    Thanks for your help everyone! =)
     

    Attached Files:

    • HJT.txt
      File size:
      9.4 KB
      Views:
      3
  5. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    http://www.majorgeeks.com/images/grenade.gifWelcome! to MajorGeeks.com!http://www.majorgeeks.com/images/grenade.gif

    There are a few more items I need. Please attach the set of logs from running MGTools. Also, try again to run ComboFix by downloading the updated copy below.

    ComboFix

    Also, as a reference I will post our initial instructions.
     
  6. heartinhands

    heartinhands Private E-2

    Hey Big Arrick! Thanks for your help!

    Downloaded the updated version of Combofix, but it wouldn't work again. It did the progress bar where it was "loading" and then nothing happened, no additional screens. . Im assuming because my cmd.exe isn't working, that combofix is having issues too. . I do not receive any errors, it just doesnt start up entirely and I can't use it. . .

    I also tried MGTools, but it says that I am missing GetLogs.bat. "make sure you typed the name correctly, then try again. Or search for the file. Etc. Etc."
    I saved MGtools to my root (c:\) drive. . .

    After that first "windows error" type thing, it also says "error: Failed to run GetLogs.bat, working dir = \MGTools (check to see if this file is in the EXE)


    Thanks again, sorry I couldnt technically complete all those steps. ..

    Let me know if there is anything else I can or should do.
     
  7. heartinhands

    heartinhands Private E-2

    Im really trying to deal with this on my own, but I just can't seem to go any further!

    Now, sometimes trying to upload a file to an email doesnt work, and i need to restart my browser. Other times Illustrator won't open and I have to restart the entire computer.

    Its just a big hassle and really hinders my work. . .

    Any other ideas from anyone? As i said before Combo Fix and MGtools wouldnt work. .


    Thanks again everyone!
     
  8. heartinhands

    heartinhands Private E-2

    Still not working: can only start in safe mode

    Hello Again!

    So, things have progressively gotten worse. Now, I am unable to start my computer, except in safe mode. However, even in safe mode, nothing works.

    My antivirus software, i.e. everything in the "Read me before posting", will not work. The only peice of software that was responding was HJT.

    Every other program would either not open, try to open something random like Adobe Acrobat (unable to open that), or it would open my default browser which has obviously been hijacked as it brings me to this link: http://onlinenotify.net/land/eurl/1.html?code=00000005ruler_on=1exlude_urls=antivirusxp-pro2009.com

    Im not sure. I can't do anything, combofix still doesnt work, SSD, SAS, MG, MB, nothing works except HJT, which I will attach my log.

    Im very much screwed without my computer on so many levels: school, work, family. However, sadly, the priorities are on school and work at this point.

    I was also given these two errors when trying to start windows normally, however, it wouldnt work:
    logonui.exe 0x00840660 referenced something at 0x00840660 - memory couldnt be 'written'. . or something to that effect.

    same message with these numbers: 0x00610660


    Please help.

    with thanks
    HIH


    PS Running this in safe mode on IE without addons, so I can't attach the HJT log. It will be posted beneath this. I apologize in advance:


    Logfile of Trend Micro HijackThis v2.0.2
     
    Last edited by a moderator: Feb 21, 2009
  9. Lev

    Lev MajorGeek

    Please keep your posts for the same ongoing problem in the one thread. Do not start a second thread.

    Threads merged and inline HJT removed - Read & Run Me First not followed.
     
  10. heartinhands

    heartinhands Private E-2

    sure thing, as long as I can get some assistance =)

    i figured since the problem has grown spread and multiplied that perhaps it deserved another thread ;-)

    thanks
    HIH
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hello

    bjgarrick is away at the moment, so I have come to see if you still require assistance, let me know.

    If you are struggling to run MGTools.exe and Combofix please try renaming them to something like 123.com or abc.com and try running again.

    Kestrel13
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds