Help needed - can't run anything

Discussion in 'Malware Help (A Specialist Will Reply)' started by superluckycat, Jul 6, 2005.

  1. superluckycat

    superluckycat Private E-2

    Hi there I'm hoping someone can help me. I'm writing from a different computer such is the extent of my problems!

    A short while ago I picked up some sort of virus that hijacked my desktop and wouldn't let me run IE. I ran all the scans that you guys recommend on this site and a few things were picked up. When I rebooted things got a lot worse. I couldn't run anything - the computer would just freeze whenever I click on anything. Eventually got so bad I could only boot up in safe mode and the only thing I can get running now is the task manager. I can't get hijackthis to run or anything else so I have no idea where to start.

    Any help is greatly appreciated.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the below steps:
    - try using HJT in safe mode
    - if that does not work, try renaming hijackthis.exe to myhjt.com and try running that (preferably in normal boot mode)
    - if you cannot do the above, run Task Manager and provide a list of running processes.
    - always provide your OS in a request for help
     
  3. superluckycat

    superluckycat Private E-2

    Hi Chaslang, thanks.

    I running Windows XP on an HP pavilion m703.

    I can run HJT in safe mode but once i do, it freezes up again so there's no way for me to save it and post it here. Task manager says CPU is running at 100%.
     
  4. tblue

    tblue Corporal

    Hi superluckycat,
    See if you can provide Chas with the above. Good Luck :D
    T.Blue
     
  5. superluckycat

    superluckycat Private E-2

    Processes running:

    taskmgr.exe
    svchost.exe
    svchost.exe
    explorer.exe
    Isaas.exe
    services.exe
    winlogon.exe
    csrss.exe
    smss.exe
    System
    System Idle Process SYSTEM
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is that all the processes? You mean you have no antivirus, no firewall, no spyware blockers running at all.

    I assume this Isaas.exe was a typo and you meant lsass.exe


    Did you try renaming HJT as suggested? How far do you get when trying to run HJT?
     
  7. superluckycat

    superluckycat Private E-2

    I have MS Antispyware and others - spybot s&d, but I guess they're not able to run at the moment.

    In safe mode I can fully run HJT but I can't get it to save anywhere once it has run.

    I think Isass.exe was a typo but looking at it now it doesn't seem to be running anymore.
     
  8. superluckycat

    superluckycat Private E-2

    Got an HJT log...
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://C:\WINDOWS\system32\shdocsv.dll/API32.htm#ID=347;065D
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://shdocsv.dll/asst.htm
    O4 - HKLM\..\Run: [intel32.exe] C:\WINDOWS\System32\intel32.exe
    O4 - HKLM\..\Run: [Fast Start] C:\WINDOWS\system32\svcnt.exe home
    O16 - DPF: {11010101-1001-1111-1000-110112345678} - mk:mad:mSItSTORE:Mhtml:FiLE://C:\html.mHT!http://205.177.122.27/docs/xxx/html.chm::/html.exe

    After clicking Fix, exit HJT.
    Now boot into safe mode (if not already in safe mode) and use Windows Explorer to delete:
    C:\WINDOWS\System32\intel32.exe
    C:\WINDOWS\system32\svcnt.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now try to reboot in normal mode and post a new HJT log (even if you have to get one from safe mode again - post it). And tell us how things are working.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds