I can't post with my other Username. (in connection with my other w/ my other thread

Discussion in 'Malware Help (A Specialist Will Reply)' started by Lester86, Aug 29, 2005.

  1. Lester86

    Lester86 Private E-2

    I'm LTL, and I can't reply with this Username either. I had made a thread which is here http://forum.majorgeeks.com/showthread.php?t=70997 .

    That's the log from ewido. Here are the new logs, I ran the smitrem after hijack cause I thought I was suppose to just zip it. Some pops up are still here and everytime I go to a website the browser bring me quickly to another one, and my computer shut off by itself twice. Please help.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why did you make a new user account? What are the problems with using the other account?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way HJT logs must always be from normal boot mode unless otherwise requested.
     
  4. Lester86

    Lester86 Private E-2

    Re: I can't post with my other Username. (in connection with my other w/ my other thr

    I couldn't post, I couldn't reply, and I couldn't even edit my account. It happened right when I changed my email which is a valid one.
     
  5. Lester86

    Lester86 Private E-2

    Re: I can't post with my other Username. (in connection with my other w/ my other thr

    Hmmm... I ran it in safe mode. I don't remember. but thanks for the information.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: I can't post with my other Username. (in connection with my other w/ my other thr

    What do you mean you changed your email? Where are you talking about?
     
  7. Lester86

    Lester86 Private E-2

    Re: I can't post with my other Username. (in connection with my other w/ my other thr

    I changed my email in the User Control Panel because my old one isn't working.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: I can't post with my other Username. (in connection with my other w/ my other thr

    And you are saying that you can now no longer user the LTL account after changing your email? Are you sure the password was not changed?
     
  9. Lester86

    Lester86 Private E-2

    Re: I can't post with my other Username. (in connection with my other w/ my other thr

    I'm still able to log in, but I can't do anything.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: I can't post with my other Username. (in connection with my other w/ my other thr

    What did you try to do in your previous thread? Did you try adding a new message or was it uploading of files you had a problem with? Or was it both?
     
  11. Lester86

    Lester86 Private E-2

    Re: I can't post with my other Username. (in connection with my other w/ my other thr

    I tried replying to it with this username but couldn't.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: I can't post with my other Username. (in connection with my other w/ my other thr

    You cannot reply to the thread unless you use the account that you originally created the thread with which was LTL.

    You will not be able to reply to this current thread (the one you are reading right now) which is owned by Lester86 with your previous login either.

    Let's try to work your problem here for now. You will need to post a HJT log from normal boot mode but before doing that I noticed something suspicious in your log. So do the below steps before posting a new log.

    Download the following tool and save it where you will be able to find it.

    L2MeFix Tool

    Please print out these instructions now or save locally so that you can operate with All Browser Windows CLOSED.

    Exit Browsers now before continuing

    Please move the L2MeFix Tool to your Desktop and DoubleClick l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix Folder on your Desktop. DoubleClick l2mfix.bat and Type 1 and ENTER to select Option #1 for Run Find Log . Allow it as much time as it needs to run until NotePad opens with a log.

    NOTE: Please do not run any other options or files in the l2mfix Folder!

    Now reconnect and come back here and post as an attachment the l2mfix log. Also now make sure you are in normal boot mode (with no browsers running) and get a new HJT log. Then post the HJT log too.
     
    Last edited: Aug 29, 2005
  13. Lester86

    Lester86 Private E-2

    Re: I can't post with my other Username. (in connection with my other w/ my other thr

    Here are the log files
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: I can't post with my other Username. (in connection with my other w/ my other thr

    Print or save these instructions locally now because you will have to be disconnected with no browsers open in the next step.

    Please make sure ALL Browser Windows are Closed and also you should physically disconnect from the Internet by unplugging your cable.

    Go to the L2MFix Folder on your Desktop and DoubleClick l2mfix.bat and type 2 and ENTER to select option #2 for Run Fix. Then, press any key to Reboot your machine.
    Your computer will go bazonkers (now there's a great technical term!) for a bit, but just let it run. It should eventually spit out another log in Notepad. Please attach that log when you come back.

    Again, don't run any other files in the L2MFix folder.

    After reboot run Windows Explorer and make sure viewing of hidden and system files is still enabled per the tutorial. Then look for the below files in your c:\windows\system32 folder (note the sizes of the files). Be careful of the question marks in the names. They could translate into anything. Make sure you only delete the files matching those sizes in bytes:

    Directory of C:\WINDOWS\System32
    08/08/2005 06:26 AM 401,408 ??erinit.exe
    08/08/2005 06:23 AM 401,408 ??plorer.exe


    Let me know how things look now.

    Also attach a new HJT log.
     
  15. Lester86

    Lester86 Private E-2

    Re: I can't post with my other Username. (in connection with my other w/ my other thr

    I still get some Red Nova Pop ups, will the scanners fix that? Here are the logs.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: I can't post with my other Username. (in connection with my other w/ my other thr

    Okay have HJT fix the below two lines:
    O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
    O20 - Winlogon Notify: Applets - C:\WINDOWS\system32\wncsapi.dll


    Then boot into safe mode and make sure your can find and delete:

    C:\WINDOWS\system32\wncsapi.dl


    Then reboot in normal mode. Post a new HJT log and tell me your status now.
     
  17. Lester86

    Lester86 Private E-2

    Re: I can't post with my other Username. (in connection with my other w/ my other thr

    hmm... well everything seems cool now. I went from have so many pop up at once that my computer would shut it self down and restart to a cleaner computer that i enjoy going on now, no pops ups have came since i restarted. thanks guys, much appreciated. here's the log.
     

    Attached Files:

  18. Lester86

    Lester86 Private E-2

    Re: I can't post with my other Username. (in connection with my other w/ my other thr

    Oh yeah what was so supicious about the log?
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: I can't post with my other Username. (in connection with my other w/ my other thr

    I'm not sure exactly what you are asking me?


    You current HJT log is now clean and it is time to look at the below tips to help keep you that way:

    How to Protect yourself from malware!
     
  20. Lester86

    Lester86 Private E-2

    Re: I can't post with my other Username. (in connection with my other w/ my other thr

    You said you saw something suspicious, but i just got a pop up but maybe i just need some malware protection.

     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: I can't post with my other Username. (in connection with my other w/ my other thr

    What I was referring to was the below line that we just finished fixing. It point to additional other problems (Look2Me VX2 infection):

    O20 - Winlogon Notify: SharedDLLs - C:\WINDOWS\system32\wncsapi.dll


    What popup? What did it say? What URLs? What site or sites were you connected to when the popup occurred?
     
  22. Lester86

    Lester86 Private E-2

    Re: I can't post with my other Username. (in connection with my other w/ my other thr

    I can't barely remember which site it was but i Had some winfixer ads. but ever since I went in the Protect yourself from maleware and download the programs i havent i don't remember getting any pop ups. Thanks for the support there and here. My computer feels fine, unless there something you know?
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: I can't post with my other Username. (in connection with my other w/ my other thr

    As long as everything is okay now, I will assume we have nothing to worry about since your last log was clean. If anything else comes up, just let us know.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds