HELP! Lost Control Panel and Cannot Enter Program Properties

Discussion in 'Malware Help (A Specialist Will Reply)' started by gunrunner, Sep 8, 2007.

  1. gunrunner

    gunrunner Private E-2

    The other day everything went crazy. I ran Norton anti-virus which found a virus/malware but could not fix a Backdoor Trojan. Windows Defender found Two (2), both some form of a trojan and/or vicious malware (Trojan Downloader: Win32/Renos) this is the only one that I caught to write down. Went to Major Geeks site followed all (I am pretty sure) instructions on the READ & RUN ME FIRST post. Still cannot find conrol panel or gain access to properties, get message "This operation has been cancelled due to restrictions in effect on this computer. Please contact your system administrator". Could only access System Restore in Safe Mode, but when I enter, it initially tells me my keyboard has failed. After unconnecting and reconnecting the USB I get it to work. This only happens when I enter Safe Mode. My operating system is XP Pro SP2. Please Help I am attaching the files as told in the READ & RUN ME FIRST THREAD. I know that I can only attach Three at a time so I will follow this up with the other attachments.

    Thanks in Advance.
     

    Attached Files:

  2. gunrunner

    gunrunner Private E-2

    The follow-up attachments for this new post.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Start by uninstalling the CounterSpy trial program now since we are finished with it. Then delete the below folders which may be left behind by the uninstall:
    C:\Documents and Settings\DAD\Application Data\Sunbelt Software
    C:\Documents and Settings\All Users.WINDOWS\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Uninstall the below software:
    Java 2 Runtime Environment, SE v1.4.2_03
    Viewpoint Manager (Remove Only) <-- should have been uninstalled in step 0 of the READ ME
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME
    Viewpoint Toolbar <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment




    Now download this file - combofix.exe
    1. Double click combofix.exe & follow the prompts.
    2. When finished, it will produce a log ( C:\combofix.txt ) for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    4. the ComboFix log
    Make sure you tell me how things are working now!
     
  4. gunrunner

    gunrunner Private E-2

    Unable to enter Control panel. Went into Safe Mode and was able to uninstall:
    Viewpoint Manager (Remove Only) <-- should have been uninstalled in step 0 of the READ ME
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME
    Viewpoint Toolbar <-- should have been uninstalled in step 0 of the READ ME

    Still unable to remove Counter Spy and Java 2 Runtime Environment, SE v1.4.2_03 even in Safe Mode. Should I run what you have recommended above anyway?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes just continue.
     
  6. gunrunner

    gunrunner Private E-2

    A couple of things happened before I got back to this point. One, my Norton found two viruses (I guess it woke itself up or the viruses exposed themselves). They were identified as hadjajr.ini and vtr.dll. They were both quarantined. hadjajr.ini is still quarantined but I was able to forward the vtr.dll to symantec.
    Next, I followed your above instructions but when I was running combofix, counter spy and norton continuously detected it and was forever giving me pop-ups (Why you wanted counter spy deleted?). I finally goofed and at the end had the script accidentally quarantined. Thus you will see a second comfix log.txt where I turned off the counter spy and was not so spastic with Norton. This file is combofix.txt. The first log is combofix2.txt. The newfiles, runkeys, and hjt files have the number 1 in front of them since I did not want to lose the older logs just in case.
    Anyway at this point it appears that I have regained control panel and am able to right-click for properties access. Do I need to do anything more???
     

    Attached Files:

  7. gunrunner

    gunrunner Private E-2

    The combofix log text files for the above post.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O20 - AppInit_DLLs: hardlife.ini
    O20 - Winlogon Notify: abrdrv - C:\WINDOWS\system\abrdrv.dll (file missing)
    O20 - Winlogon Notify: dllad - C:\WINDOWS\Fonts\dllad.dll (file missing)
    O20 - Winlogon Notify: mfcurl - C:\WINDOWS\AppPatch\mfcurl.dll (file missing)
    O20 - Winlogon Notify: msvccr - C:\WINDOWS\system\msvccr.dll (file missing)
    O20 - Winlogon Notify: nutps - C:\WINDOWS\Web\nutps.dll (file missing)
    O20 - Winlogon Notify: pswin - C:\WINDOWS\occache\pswin.dll (file missing)

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    No see if you can do the below.

    Uninstall the below software:
    Java 2 Runtime Environment, SE v1.4.2_03
    Sunbelt CounterSpy <-- we are finished with this trial now

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  9. gunrunner

    gunrunner Private E-2

    I have ran all of the applications as you have suggested above. I am attaching the new text files and log. I think everything is for the better at this point but have not been on the unit long enough to determine if all is Okay. In a previous posting you had said something about deleting a file in my application data folder. I cannot find an application data folder on this XP Pro system. I get confused because I use a Win 2000 system at work and the XP at home. One thing that I have been noticing is that for some reason I have been seeing a number of pop ups from my Norton stating "Rules automatically created for symantec live update." Not use to seeing this so often when opearting PC. Anyway, please see requested attached files. NewFiles and GetRunKey Files beginng with a 2. Will send HJT File with follow-on post.

    Thank You so far for all of your assisstance.
     

    Attached Files:

  10. gunrunner

    gunrunner Private E-2

    Please see attached requested HJT Log follow-on, also beginning with a 2. Thank You again for all of your help to date.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That folder is still there and you should delete it. It is this one:

    C:\Documents and Settings\DAD\Application Data\Sunbelt Software

    You must make sure you have done step 2 of the READ ME properly or you will not see this folder.


    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  12. gunrunner

    gunrunner Private E-2

    Sorry, but I have been away from my machine. I just wanted to thank you for all of your assistance with my problem. Just Thank You very much. All seems to be back to normal now.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds