Help..major problem after running Ccleaner

Discussion in 'Malware Help (A Specialist Will Reply)' started by BMCI, Dec 14, 2007.

  1. BMCI

    BMCI Private E-2

    I am an admitted novice in need of help. I was going through the procedures in preparation of running Hijack this on my daughter's notebook and posting a log. Original problem was the "Antispy storm" virus. In going through the steps and in error, I unchecked the hidden files first and then ran the CCleaner afterward. Shortly thereafter, I could not access the internet-the homepage would appear for a second or two and then vanish, although everything else seemed to be ok. I wrestled with that for awhile and then elected to simply use the sytem restore in hopes that I could undo whatever I did. After rebooting, I get to the welcome screen and when I click either her account or the administrator, the screen goes black and I get this message " application has failed to start because WININET.dll was not found. Reinstalling may fix the problem" Making matters worse is the fact that we could not locate the reinstall cd that came with the computer. What and how much damage have I done here? Thanks for any input.
     
  2. abri

    abri MajorGeek

    Hi BMCI

    Welcome to Major Geeks!

    Whether you set your hidden files to be visible before or after running CCleaner will have no effect on what CCleaner does. The only thing which could affect what CCleaner deletes is if you did not leave CCleaner's settings in the default position when you ran it.

    Are you able to get into Safe Mode by pressing the F8 key repeatedly during the bootup sequence?

    abri
     
  3. BMCI

    BMCI Private E-2

    Abri...thanks for checking in. I did leave the settings in the CCleaner in the default position. And yes, I am able to get into Safe Mode but the same thing happens. I even tried to utilize the last known good configuration option and had the same result. This is troubling...
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What happens in safe mode? You get the message, but can you do a control+alt+delete and get a task manager?

    If you can get into safe mode: Search for Wininet.dll by clicking the Start button, Find (or Search), and Files Or Folders. In the dialog that appears, type wininet.dll in the name field and click Find (or Search) Now. If Windows finds the file in a folder other than the System32 folder, copy the file to this folder. If Windows can’t find the file or you think that you may in fact have an older version, download it at WinDrivers.com (www.windrivers.com).
     
  5. BMCI

    BMCI Private E-2

    Hi Tim... I tried to bring up the task manager and got a message that the taskmanager was locked by the administrator even though I am the administrator. There is nothing on the screen except for the wording that I am in safe mode or when one of these massages pop up. It is otherwise black. There is nothing on the desktop, no shortcuts, no start button, no task bar (?)... any additional thought. Help is very much appreciated.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to find your reinstall cd! If you know your installation key ..then you can borrow a cd from someone ( as long as it is the exact same version - home/pro/oem, etc.).
    Did you have a restore partition on the drive? That should show when you boot up ...possible a prompt to hit F11.

    If you can borrow one ...you can do a repair install to at least get you back up and hopefully run the tools.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    One other thing to try .....see if you can bring the start menu up by hitting the "windows" key ( the one with the wavy flag).
     
  8. BMCI

    BMCI Private E-2

    Tim..thanks...I saw no signs of the restore partition and F11 was not an option. I tried pushing the windows button but the start menu did not appear. I am not optimistic about finding that reinstall cd in my daughter's junk but the search is ongoing. After leaving the computer alone for awhile, I returned and a had a popup on the screen (which was part of my original problem) telling me I could optimize my pc etc, etc... that was strange...now I have the cursor and the hourglass(which is flickering) and that is all... thank you for your ongoing interest and support.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you boot into Safe Mode with Command Prompt ? Use the account named administrator to login. Do not use your account.

    And I assume you have access to another PC?

    If the answer to both of the above is yes, then try the below.


    • Download smitRem.exe written by noahdfear and save the file to the Desktop of your other PC.
    • Double click smitrem.exe to extract the files. It will create a smitrem folder on the Desktop.
    • Please copy the smitrem folder onto a removable device (USB drive, CD...etc).
    • Insert the removable device into the problem computer.
    • Boot in safe mode with command prompt, and exit/close the command prompt window.
    • Then press CTRL+ALT+DEL to bring up the task manager.
    • Click File > New Task (Run...).
    • Use the Browse button to get to My Computer and then to the removable device you copied the smitrem folder to.
    • Locate the RunThis.bat and select it to run it. Follow the prompts on screen. Wait for the tool to complete and disk cleanup to finish.
    • SmitRem will create a log named smitfiles.txt in the root folder of your Windows boot drive. (Normally this is Local Disk C and the file would be C:\smitfiles.txt )
    • Hopefully you may be able to boot into normal mode now if smitrem was able to find a local copy of your wininet.dll file and restore it.
    • See if you can get this smitfiles.txt log posted here.
     
    Last edited: Dec 14, 2007
  10. BMCI

    BMCI Private E-2

    Chaslang:

    Thank you for your assistance. Here is a misery update: I was able to boot in safe mode with command prompt and input a cd as advised. This brought up a box to log into windows. ( I hadn't had that prior) Unfortunately, once it began logging me in I received the same, original message and was unable to continue.
    And while I remain grateful for the continued assistance, I am growing weary that this mess will be resolved. Cheers.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What version of Windows are you running?

    Do you have a bootable CD for it? If not, can you borrow one from someone? It would be best if it was the same Service Pack level that you are running.
     
  12. BMCI

    BMCI Private E-2

    I do have a CD from a separate computer that is approx 2-3 years older than the one with the problem. The problem notebook is approx 2 years old. The CD is marked "Reinstallation CD Microsoft Windows XP Home Edition" which is the same version on the one with the problem.

    As always, your help is much appreciated.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Look on the CD and see if there is a folder named i386

    If so look inside the i386 folder. Do you see wininet.dll or is it wininet.dl_
     
  14. BMCI

    BMCI Private E-2

    Thanks...it looks like it is wininet.dl :(
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you mean wininet.dl_

    The underscore is significant!!
     
  16. BMCI

    BMCI Private E-2

    Sorry...it is wininet.dl_
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now read thru the below to familiarize yourself with it and print it so you can refer to it while offline since you will not be able to browser once starting the below.
    1. Put the Windows XP CD into the CD ROM tray and close the tray. You may get a popup window asking about installing Windows XP. If you do, just close that window.
    2. Then restart your computer
    3. This should cause your computer to boot from the CD instead of the hard drive..(if not your you'll need to enter the BIOS and set the boot order so the CD ROM is first in the list.)
    4. You should get a "Press any key to boot from CD" message! Press a key to do that otherwise it will by pass the CD boot.
    5. After it boots up, you will see it load a bunch of files (be patient it can take a little while) and eventually you will see a menu where you can select the "Recovery Console" by pressing R It is normally the middle item in the list. Press R
    6. You will see a list of possible Windows partitions with numbers next to them. Select your Windows Installation (which is C:\Windows) by typing the number next to it (which should be 1) and press enter.
    7. It will ask you for the Administrator password is next (so make sure you know it). It you never gave it a password it is probably blank. If it is blank, just press enter. If you have set one then type it in and hit enter. It will tell you if you enter the wrong password.
    8. When you enter the correct password you will get a prompt that looks like this: C:\WINDOWS>
    Now from this command prompt window, here are some things I want you to do. Enter the below commands (the commands are in bold black) in the order given. I will add comments in purple.

    cd system32 <-- the prompt should change to C:\WINDOWS\SYSTEM32>

    expand D:\i386\wininet.dl_ c:\windows\system32\wininet.dll

    There are spaces after the word expand and after the .dl_
    The above should uncompress the compress file from your CD drive and put a copy onto your hard disk in the C:\windows\system32 folder. If your CD drive is not drive D, then substitute in the correct drive letter above.

    If the above works without giving any errors, enter the below command:

    exit <--- this will exit the Recovery Console and boot to Windows


    Does your PC bootup properly now?
     
  18. BMCI

    BMCI Private E-2

    Hi..I did as advised and received a message "unable to create file wininet.dll" ...admittedly I am not positive what the letter for the drive is for the cd. It is a laptop with only one place to insert a disk,...Dell Inspiron 6000 if that matters. Thanks for hanging in there with me.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I assume you still have the Recovery Console opened??

    If so, type D:\ and then hit the enter key.

    Does that get you to the CD drive? If so, now type each of the below

    CD i386
    dir wininet.dl_

    do you see a listing for the wininet.dl_ file?
     
  20. BMCI

    BMCI Private E-2

    Recovery console is open, and I typed as advised. Unfortunately, I could not get to the CD drive.
     
  21. abri

    abri MajorGeek

    Did you try several other possible drive letters besides D? While D is common, it could be pretty much any letter from D on, but generally something between D and L
     
  22. BMCI

    BMCI Private E-2

    Abri..thanks...I will try each letter this afternoon and report back...I am also trying to find a borrow a better reinstallation cd...
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Be careful. You don't want a reinstallation CD. You want a Windows XP bootable CD that is on par with your SP level. As long as you are getting to the Recovery Console on the CD, it is definitely a bootable Windows XP CD. Which SP level is the question. A reinstallation CD would more than likely be a CD that brings you back to the state your PC was shipped. You don't want that and they will not be bootable CDs with the recovery console.
     
  24. BMCI

    BMCI Private E-2

    Now i'm totally confused. The CD is clearly marked "reinstallation" but I did find the i386 file and got to the Recovery Console. ( I think) It sounds like I may be spinning my wheels.... Admittedly, I am unclear as to exactly the XP bootable CD is that I need...i.e. should I have this already like I had the reinstallation cd ? Sorry... still I very much appreciate the help..certainly I am not intending to waste your time...
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry for the confusion. It sounds like it is just a matter of what your PC vendor lableled the CD. I was thinking of a "Recovery CD". A reinstallation CD apparently has what you need to reinstall your OS from scratch to the same vintage of the OS that was installed on the PC when you got it. If it boots up and let's you get to the recovery console as I had given instructions for, then it is a bootable CD.

    Don't worry about what the CD is right now. You were able to get to the Recovery Console which is all that is important. You now need to be able to copy a file off of the CD and onto your hard disk. And the file (wininet.dl_) needs to also be uncompressed which is what the expand command was trying to do. You need to determine what your CD drive letter is so that you can run the commands given.
     
  26. BMCI

    BMCI Private E-2

    Thanks..I tried each letter from D to Z to no avail...when I use "D" I get the message "unable to create file wininet.dl_ 0 file(s) expanded. If I put "E" in, the message is "The system cannot find the file or directory specified". All other letters give me the message " The path or file specified is not valid." Also, for what its worth, the cd I have indicates service pack 1 while the desktop indicates the problem laptop has Service Pack2. Any additional thoughts would be welcome. At this point I am more than willing to either make a purchase for anything that can rectify this mess or maybe turn it over to a pro (although the local computer repair guy is a well known pirate). Anyways, thanks for all of your help, thoughts and efforts.
     
  27. abri

    abri MajorGeek

    ... put in my two-cents worth again ...

    Is your bios set to boot from CD?
     
  28. BMCI

    BMCI Private E-2

    Hello again Abri...I hit F12 "boot menu" and scrolled down to cd and hit enter... I figured that was ok...
     
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Assuming that you are in the recovery console ...at the prompt type:
    fixboot

    see if that works.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not the problem. If the Recovery Console is booting up then the CD is obviously running.

    BMCI, One of my previous instructions said this
    Code:
    If so, type[B] [COLOR=darkred]D:\[/COLOR] [/B]and then hit the enter key.
    
    Does that get you to the CD drive? If so, now type each of the below
    
    [B]CD i386[/B]
    [B]dir wininet.dl_[/B]
    
    do you see a listing for the wininet.dl_ file?
    You need to determine which drive is your CD drive just by doing the D:\ or E:\ or F:\ until you find out which drive is your CD drive. The just do the CD i386 and the dir wininet.dl_ as requested. Do not keep trying to do the expand command? We are tyring to find out why you are not able to expand/copy the file so the first thing we need to do is make sure you are accessing the CD drive properly.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This has nothing to do with restoring the wininet.dll file. It is for writing a new partition boot sector to the system partition. The problem is not the boot partition. See message # 1:
     
  32. BMCI

    BMCI Private E-2

    Chaslang..thanks...so I am clear..at what prompt do I need to type this?
     
  33. BMCI

    BMCI Private E-2

    I tried this where I could and went through every letter to no avail. Each time it tells me the command was not recognized... it did give me a list of commands..
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I believe the problem is that Windows will not allow you to do the D:\ from the Recovery Console. Sorry about that! I forgot about this since I have not needed to boot to it for quite some time.

    Skip the D:\ and just use the below at the Recovery Console command line prompt (the C:\Windows> is your prompt)

    dir D:\i386\wininet.dl_


    If D is not your CD drive, then try another drive letter but it is probably D.

    If the above command shows you information about the wininet.dl_ file then next run the below command.

    copy d:\i386\wininet.dl_

    Do you get confirmation that 1 file was copied? If yes, continue with the below.

    copy wininet.dl_ system32\wininet.dll

    Note there is a space after copy and a space before system32

    Did you get a successful copy? Do the below command, to verify

    dir system32\wininet.dll

    Does it show you file information on the system32\wininet.dll file? If yes, remove your XP CD from the drive and type exit to reboot your PC.

    Can you boot up now? Do you stil get the same error message about wininet.dll missing?
     
    Last edited: Dec 20, 2007
  35. BMCI

    BMCI Private E-2

    I was able to copy that file as directed. However, now the computer will start but only in safe mode. I get a message telling me that windows is running in safe mode and check yes to continue, no for restore. I check yes and all is well for about 5 seconds, when the desktop icons disappear and the same message comes back about being in safe mode. If I keep checking yes, everything eventually freezes...task manager remains disabled. I did check no for restore to see what would happen and all that did was the same message came up again about being in safe mode. If I try to start windows normally, I will get to the old desktop background, no start button, no icons....
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but if you do start in normal mode, can Task Manager be brought up now? Or are you having the problem that Task Manager is disabled in Normal Boot mode?
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Oh and one more question jus in case Task Manager does not work in normal boot mode.

    Can you now get logged in when you boot in safe mode with command prompt or are there problems there too? If so, please describe them.
     
  38. BMCI

    BMCI Private E-2

    I continue to get that message in normal mode. "Task manager has been disabled by your administrator."
     
  39. BMCI

    BMCI Private E-2

    If I boot in safe mode with command prompt....I get to a point with a box "cmd.exe" inside of which reads C:\Documents and Settings\Administrator>
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then try the below.

    Enter the below command exactly as given. Take your time to make sure you enter it correctly. Note the space after REG, after add, after System, after /v, after TaskMgr, after /t, after DWORD, after /d, and after 0

    REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 0 /f

    After you type the above hit the enter key and tell me what happens.
     
  41. BMCI

    BMCI Private E-2

    Chaslang..thanks ...I got a message saying the "operation completed successfully"
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay see if Task Manager will open.
     
  43. BMCI

    BMCI Private E-2

    I went in normal mode...a box popped up "System Configuration Utility"..this wasnt happenning before.. I am not sure if I need to do anything here....I did hit the tools tab, scrolled down to Task Manager and hit the launch button, but got the same message that it was disabled... although I havent proceeded past the system configuration box because I am simply unsure what to do...do I want to be in "Selective Startup" ? Sorry..I'm sure this is elementary but I am uncertain exactly what I need to be doing ..(I hope this makes sense)
     
  44. BMCI

    BMCI Private E-2

    Chaslang...also..the circle is checked for "use Modified BOOT.INI"...is that ok? Thanks
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Leave it on selective startup for now just so we can see if you can boot up. If you can boot up. Just run the steps in the below and nothing else.

    Using MGtools

    Attach the requested C:\MGlogs.zip file if you could do the above.
     
  46. BMCI

    BMCI Private E-2

    I clicked ok for the selective startup and restarted. Basically there is no change from before except for a brief moment the start button appeared but then disappeared. The old background pic is there and the little hourglass..task manager is still disabled
     
  47. BMCI

    BMCI Private E-2

    Chas ... I now get the start button but can't click on it...only get the hourglass when I move the pointer over the start or any part of that bar for that matter ..I did boot into safe mode and was able to get to the Task manager finally...for what that is worth...if anything
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    From safe boot mode see if you can manage to complete the Using MGtools instructions and get me that C:\MGlogs.zip file.
     
  49. BMCI

    BMCI Private E-2

    Chaslang...I wanted to just let you know that I was able to boot normally this a.m.... I just have no internet access until later today...it does appear that all is operating as it had (right down to the spyware issues) prior to having these problems which in my case, is very welcomed news. I cant thank you enough..will get you the additional info
     
  50. BMCI

    BMCI Private E-2

    actually...booted with selective startup ..but not in safemode
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds