I Think I'm going under

Discussion in 'Malware Help (A Specialist Will Reply)' started by geoff_king_99, Oct 10, 2006.

  1. geoff_king_99

    geoff_king_99 Private E-2

    A few days ago my daughter clicked a 'view picture' link which popped up when chatting to friends using Microsoft messenger. We got hit with a lot of spyware and viruses. I went through the suggested steps and these seemed to clear the problem up for a while, but they are back. When I went through the steps again, there was even more stuff reported than before. I am also continually getting Windows Defender telling me that I have Look2Me and do I want to remove it, and that it needs to reboot to protect my PC. I am also getting regular BSDs with a MULTIPLE_IRP_REQUEST subject. I am way out of my depth here. Help! (please).
    I have attached bitdefender, panda activescan and hijackthis logs.
     

    Attached Files:

  2. geoff_king_99

    geoff_king_99 Private E-2

    And here are the runkeys and newfiles logs...
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please run this Look2Me VX2 Removal and attach the requested log.

    Now goto Add/Remove Programs and uninstall the below three items:
    J2SE Runtime Environment 5.0 Update 3
    J2SE Runtime Environment 5.0 Update 6
    Search Bar

    Now install the current version of Sun Java from: Sun Java Runtime Environment


    Now attach new logs from ShowNew and HijackThis.
     
  4. geoff_king_99

    geoff_king_99 Private E-2

    Thank you for your quick reply.

    I have run the Look2Me-Destroyer program. It all run like you described.

    I've got the output from the destroyer program attached.

    However, in the middle of uninstalling the Java stuff I got a BSOD with the subject "MULTIPLE_IRP_COMPLETE_REQUESTS" and the machine rebooted. All it does now is start, perform a disk check (or I can skip it), then give the BSOD and reboots again....

    I have tried booting in safe mode, but it gets to loading the device Mup.sys and just sits there.
    When (if?) I get a stable boot I'll try to complete the process...
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Were you trying to install the Java updates directly from the online connection or did you download the file to your PC and then try to install the file from your PC.

    Do you have a Windows XP CD-ROM so that you can boot into the recovery console and replace the mup.sys file? It belongs in this folder: C:\WINDOWS\SYSTEM32\DRIVERS
     
  6. geoff_king_99

    geoff_king_99 Private E-2

    OK Done that. Now I can boot into safe mode and the system doesn't crash, but if I try to start normally, after a couple of minutes I get the BSOD (MULTIPLE_IRP_..) and it reboots...

    I had downloaded the file and was going to install it from the hard drive, but I hadn't got that far. I had uninstalled one of the Javas and had requested the uninstall of the other (the unistall was running) when the first BSOD appeared.

    I have two computers at home, so I am in the process of copying as much of our data as I can while in safe mode from the fubar'd laptop to the desktop (using a 2GB SD card)

    Once I get as much as I can backed up, would it be worthwhile trying to track down the problem, or just wipe the HD and start all over?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's up to you! What you are experiencing is probably not related to malware itself. But you did have a load of malware problems so anything is possible. But it sounds more like system files were deleted or corrupted.

    You could try running sfc /scannow from a command prompt window to see if it needs to repair/replace any other files.
     
  8. geoff_king_99

    geoff_king_99 Private E-2

    sfc under Safe Mode wants RPC Server to be running. I looked in Services and everything related to RPC in there is either already running, or says it can't be started in Safe Mode.

    I can boot to normal mode, but I only get about 60 seconds before the BSOD appears, so the sfc barely gets started.

    I've backed everything I can up, so I'm going to bite the bullet and try a Repair installation and, failing that, I'll wipe and restart.

    Thank You very much for your help.

    I now at least have a set of tools if I need them, and, if I follow the advice in the 'How to protect yourself from malware' document, I hopefully won't need to use them.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  10. geoff_king_99

    geoff_king_99 Private E-2

    Thanks,

    The only XP CD I had was for XP Home with SP1. The laptop came with a Ghost image of XP Home SP2. Rebuilding with an SP1 disc just caused XP to get very confused as to which updates it did/did not need to install (and, I think, how to go about it) and things just got murkier and murkier.

    I have ended up just backing up our data to drive D: and using the manufacturers discs to wipe and re-ghost drive C:, then re-install updates and software and data.

    I have installed ZoneAlarms Firewall and disabled Windows firewall, and installed Firefox. Also have Spybot S&D and Windows Defender.

    We appear to be clean at present. (Hopefully we'll stay that way)

    Again, Thanks for your help, much appreciated.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds