Help Needed

Discussion in 'Malware Help (A Specialist Will Reply)' started by clewis18, Jun 16, 2007.

  1. clewis18

    clewis18 Private E-2

    In need of help i cant access my computer in normal startup only from safe mode, if i try to start up in safe mode i either get a blue screen then it restarts or it loads and i get a message saying system shutdown iniated on NTAuthority, it gives me a countdown then reboots.

    I have done the read me first as best i can i cannot use internet explorer to do the online scans, this causes the blue screen to appear and it to reboot, i can also not install counterspy as windows installer will not work.

    I have done all these scans from safe mode, i hope the logs are still useful this way.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your initial message is unclear ...you can't run in normal mode ...or you can only run in safe mode?

    1. Download this file - ComboFix
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    Now attach new logs for:
    ComboFix
    GetRun
    Shownew
    HJT
     
  3. clewis18

    clewis18 Private E-2

    yea sorry im mean it doesnt run in normal mode, that link for combo fix doesnt work and when searching on google for it loads of websites are saying its been withdrawn for causing damage.

    Is there something else i can use? and shall i still create the notepad file and do the hijack this scan
     
  4. clewis18

    clewis18 Private E-2

    ignore my previous message i dug a little deeper found combo fix and ran it also did the other things here are my results
     

    Attached Files:

  5. clewis18

    clewis18 Private E-2

    and one more
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 6

    Please download and run CWShredder

    Run HijackThis and select the following lines(if they still show) but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now download and run AVGAnti-rootkit.

    Attach new logs for:
    HJT
    ShowNew
    GetRun
     
  7. clewis18

    clewis18 Private E-2

    qqqq
     

    Attached Files:

  8. clewis18

    clewis18 Private E-2

    Hi ive posted them but im now having to type from a different computer because after i uninstalled the Java the keys on my laptop have now gone out they were fine before but now if i type an m i get a 0 and that's the same for lots of other keys i get random characters for letters
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Removing the old java did not cause the problem....you have a pe386 rootkit!
    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    How are things working now?
     
  10. clewis18

    clewis18 Private E-2

    yea seems fine starts up great and no crashes. Thankyou very much youve been brilliant.

    Thanks

    Chris
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Before I give you instructions for the final clean up...
    please attach new logs for:
    HJT
    ShowNew
    GetRun
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds