Guys I need some help this is nasty.

Discussion in 'Malware Help (A Specialist Will Reply)' started by marko2112, Jun 5, 2007.

  1. marko2112

    marko2112 Private E-2

    Hi guys its good to be here. I got a huge problem. Well a bunch of them. First my computer: Dell Dimension E310 Pentium 4 Windows XP Media Center 2005 with 80 gig harddrive and 1 gig o ram. I contracted something nasty that made my Start toolbar dissapear, disable system restore, disable windows install wizard, lost my printer, ability to maneuver the internet with IE 6 but limited with firefox. Cannot use my cd burner capabilities to back up files because start bar is missing, cant even send anything to my floppy as any copying is not accessible. Please help me with this. I never received a Windows XP disc with my computer but I email them yesterday and they said that they are gonna send me one and it should be here quick in case if worse comes to worse, a complete reinstall. Please check out my HJ log and tell me if there is any hope of keeping my currently installed programs. Thanx huge in advance, Mark


    Edit by chaslang: Inline HJT log removed. READ & RUN ME sticky not followed.

    :cry
     
    Last edited by a moderator: Jun 5, 2007
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. marko2112

    marko2112 Private E-2

    Thanx chaslang for the response and sorry for not following the proper sequence. OK, I removed the start up items that were redundant and was able to download and run CCleaner and the registry cleaner tool and that was successful. Downloaded and ran IOBit Smart Defrag and that was successful. Went to add/remove programs to scout out malware and saw nothing resembling malware. Thats where the brakes got thrown on. Downloaded counterspy and spysweeper and and tried to install them and I get an error saying that my windows installer is disabled and cant install any programs. This also happenened before I posted my thread with you when I tried to run my system restore. It said that it was also dissabled. As I said in my first post, I have no start button to access any of my programs like my cd recording software so I can get programs off my drive that I may want to try to backup. Now this morning I am having trouble with my email saying that it couldnt find the server. I am on the computer that I think is infected right now and using Mozilla Firefox to contact you since my Internet Explorer is screwed up and very limited to what I can do on it. I have another computer set up that is good that I can get around on and access this forum in case this computer goes down in flames. I dont know what to do with this problem, except I can follow direction very well with quality advice provided by you and Im VERY open to what you might think this problem might be. Thanx for taking the time to review my situation chaslang. Sincerely, Mark
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Problems like this can be caused by many things! Some malware and some not. We need to get more information. A HijackThis log alone is not adequate. However as a start attach a HJT log. Please try to make sure it is installed and renamed as requested in step 7 of the READ ME otherwise, the infection that may be at the root of your problem will not completely show.

    What happens if you boot into Safe Mode?
    What happens if you use a different user account in normal boot mode?


    Note that even without a Start button, you can run many things from Task Manager. Just click File, New Task (Run...) and enter what what you want to run. Try these:
    explore.exe <--- this is Windows Explorer and may even bring up your Desktop if it runs
    iexplore.exe <-- Internete Explorer
    regedit.exe <-- the Windows Regitry Editor. I just want to see if it works.
    cmd.exe <--- the Windows command prompt. I just want to see if it works.


    Also can you download onto another PC and burn to CD, floppy, or flashdrive. If so, then do the below which are from the READ ME and then get them copied over to the problem PC from either a windows command prompt or from Windows Explore if you get it to run.

    Download GetRunKey.Zip and ShowNew.Zip from the below links and extract all files from both ZIP files into a folder of their own. You can extract both ZIP files into the same folder. Like C:\MGTools While these tools will run from your Desktop, we strongly recommend that you DO NOT extract them to your Desktop. Please install them where recommended.

    • Locate the getrunkey.bat file and double click on it to run it. It will create a file named runkeys.txt in the root of drive C: (C:\runkeys.txt) DO NOT attach any other file. The log is named runkeys.txt. We do not need any of the other 20 or so temp files that are created. They will all be deleted when you terminate GetRunKey by closing the notepad window. This log will also popup in a notepad window which your can just close. Upload the runkeys.txt file here as an attachment when you come back to post your results.
    • Please make sure you close the popup notepad window with the runkeys.txt log in it before running ShowNew in the below step.
    • Locate the shownew.bat file and double click on it to run it. It will create a file named newfiles.txt in the root of drive C: (C:\newfiles.txt) . This log will also popup in a notepad window which your can just close. Upload the newfiles.txt file here as an attachment when you come back to post your results.
     
    Last edited: Jun 6, 2007
  5. marko2112

    marko2112 Private E-2

    Hey chasling, booting into safemode gives me the same as if booting in normal mode no start/taskbar, and all of the other things listed in previous post. I did however when I got the computer made a shortcut to my windows explorer so i can get into that. I will try to run regedit and cmd.exe jut to see if it will work but for right now here are the logs from getrunkey and shownew as well as the hijack this log with renaming the program analyse.exe. Maybe you can look at this and tell me if this is a malware issue or not. I got my Windows XP reinstall disc today from Dell so if this is not a virus/spyware issue then it'll be time to dance with the operating system. Thanx for your patience. mark
    In answer to your questions about running regedit.exe and cmd.exe form task manager, both of them worked fine.
     

    Attached Files:

    Last edited: Jun 6, 2007
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    While I see a couple of things to fix, I do not expect that they would be the cause of all the problems you have describe. Let's fix them and see what happens, but I would expect no major change.

    First a question! When you run explorer.exe manually, does your Desktop (icons, start button...etc) return.

    Now see if you can uninstall this: Need2Find Bar

    Even if uninstall does not work, continue with the below.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: Need2Find Bar BHO - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - C:\Program Files\Need2Find\bar\1.bin\ND2FNBAR.DLL
    O2 - BHO: CIEObjectObj Object - {CA13D72F-2DAC-4D99-B08D-C5EA1C920E89} - C:\WINDOWS\IECodecPlg.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O18 - Filter: text/html - (no CLSID) - (no file)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\Need2Find <--- the whole folder:
    C:\WINDOWS\IECodecPlg.dll

    Now run Ccleaner

    Now attach the below new logs and tell me how the above steps went.

    1. ShowNew
    2. HJT


    Make sure you tell me how things are working now!
     
  7. marko2112

    marko2112 Private E-2

    Thanx chaslang for all the help youve given me. I contacted Dell and they were able to scan my computer and tell me that this wasnt a spyware/virus issue but a system issue. They are going to help me with a complete reinstall of XP. Thank you for your time and knowledge. Very much appreciated. Mark
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds