I think I've got a big problem Please help ASAP

Discussion in 'Malware Help (A Specialist Will Reply)' started by roddinron, Jun 12, 2006.

  1. roddinron

    roddinron Corporal

    I have been trying to install a second hard drive, and in doing, found that I was not able to enter safe mode, it's a seagate drive and I was trying to run their disk wizard but it kept freezing in the startup window, that's how I discovered the problem with safe mode, I got around it by restoring my PC to an earlier time using Go Back (I've had problems in the past with system restore, so it's disabled).
    So i've been trying to figure that out and thought I'd run an online virus scan. And none of them will run even in IE. I tried Panda, trend micro, eTrust. and bitdefender, and none will load.I use Avast, zonealarm, adaware se, spybot, spyblaster, crap cleaner, etc. I ran a scan using avast but it found nothing just a few files it couldn't read related to incredimail.

    Also I just ran my curser over the shortcuts in the lower left hand tray, and they all disappeared, but if I hang the curser over the area a box becomes visible and a balloon tells what it is.
    Please answer quick, since I don't want to shut down now since I'm afraid it won't restart, and I can't get into safe mode.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure this is malware.


    Please try to follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments. If you cannot run the online scanners in step 6, please explain exactly what happens when you try to run them.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  3. roddinron

    roddinron Corporal

    thanks, ok what does it mean DO not post logs directly in line with your message?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Basically what you are reading right now is inline text. So if you just paste your logs directly into a message, they are inline. Logs must be attachments. In several spots in the READ ME there are even links to HOW TO: Attach Items To Your Post
     
  5. roddinron

    roddinron Corporal

    I should have mentioned that I belong to a Yahoo group that seems to be infested by a worm in the form of an email calling itself "new Graphics", but the admin says it's this---JS.Yamanner@m---could that be my problem, and shouldn't avast have caught it? I didn't open any attachments that I know of. If it is is there a removal tool?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't know! I have never heard of this. At least not yet.
     
  7. roddinron

    roddinron Corporal

    I'm following the directions, but still can't run the online virus scans. I tried bitdefender and get "could not load the online scanner", it may be that I need to restart the computer after installing latest Java, but I'm a little afraid to try that the way this thing is acting, I mean, if it fails to start, I don't have safe mode.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what your logic is. Are you saying if you reboot your PC it will not come up? Or Are you saying it will not reboot into safe mode (we already know that)? Sooner or later you are going to have to reboot.

    We are not getting anywhere like this. Run the READ ME! At least run all steps that you can run. Attach any logs that you can get.
     
  9. roddinron

    roddinron Corporal

    If I reboot, it starts as usuall, but I can't make it go into safe mode.
    I'm trying to follow the "read and run me first" directions, but as stated earlier, I can't enter safe mode as instructed to in "read and run". Also, I still can't run the online virus scans, bitdefender says "could not load" and trend micro says an "error sending info" message. And yes I updated java first.
    I've tried following directions at microsoft help but no good. It says to boot using startup disk, and run scanreg /restore but I keep getting "bad command or file name". I move the jumper on my cmos to set it to defaults, but no good.
    The main point here is that "read and run" reguires safe mode, and I don't have it.
    As I get older, I get a little dumber, and this is starting to wear me out now.
     
  10. roddinron

    roddinron Corporal

    another hijack this log

    I could not get my pc into safe mode, so I did everything in normal mode. I tried to follow the "read and run" directions, but I am not able to run any online virus scans.
    bitdefender -couldn't load online scanning
    Panda -error downloading Active scan
    I am also not able to run scanreg /restore when booting from startup disk
    Hope you can help, I want to copy this to my new hard drive but don't want to do it till I have everything clean, and working correctly
     

    Attached Files:

  11. roddinron

    roddinron Corporal

    I could not get my pc into safe mode, so I did everything in normal mode. I tried to follow the "read and run" directions, but I am not able to run any online virus scans.
    bitdefender -couldn't load online scanning
    Panda -error downloading Active scan
    I am also not able to run scanreg /restore when booting from startup disk
    Hope you can help, I want to copy this to my new hard drive but don't want to do it till I have everything clean, and working correctly.
    I screwed up and posted the logs in a new thread titled "another hijack this thread" instead of posting it here, now can't add them to this thread, sorry, just getting tired I guess.
     
    Last edited: Jun 14, 2006
  12. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    It happens especially when faced with the stresses that being infected with malware bring and tiredness, so dont worry as I have merged the two threads, albiet the logs are in Post 10

    you will however need to follow the HijackThis guide again and install HJT where the guide advises as you have it in one of the exact places not to install it in C:\WINDOWS\DESKTOP\TOOLS\SPYWARE AND POP UPS\HIJACKTHIS.EXE
     
  13. roddinron

    roddinron Corporal

    sorry about installing HJT wrong, I'll try again. I'm trying to handle a whole lot of other problems right now (non computer related) and it's getting to a point where the stress of it all is taking a toll on me. I'll try again. Thanks for your help.
     
  14. roddinron

    roddinron Corporal

    Here's the new scan, I hope I did it right this time. Again, this was done in regular mode since I can't enter safe mode.
     

    Attached Files:

  15. roddinron

    roddinron Corporal

    well, I've been sitting here trying everything and found an old win me boot cd that I burned a long time ago, don't know what it is or where I got it, but it did let me enter safe mode, so here is another hijack this done in safe mode.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We do not ask you to run TrendMicro. We ask for Bitdefender and PandaActiveScan.

    The READ ME does tell you if you cannot run in safe mode to run everything in normal boot mode. Yes, safe mode is better but anymode is better than no mode. ;)


    We do not requeste HijackThis logs from safe mode. They are not typically of any use unless you cannot boot into normal mode.

    You logs show now real malware problems. You can have HJT fix the two below lines but they are only minor things:

    O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1435/ftp.coupons.com/v3123/cpbrkpie.cab
    O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab

    Are you actually having any malware problems?

    Not being able to boot into safe mode is not normally a malware issue? At this point, may be better off asking a specific question in the Software Forum. But if you are simply trying to install a new harddisk and you are having strange problems with your current install of WinMe, you may be better off just doing a clean install onto the new hard disk. WinME gets flaky over a period of time anyway (so did Win98) so a reinstall my be a good idea. Then you can just slave the old hard disk drive and copy what you need from it.

    The only other thing you could try is to make use of Goback (which you have installed) to go back in time to a date where you had no problems. But this (just like using System Restore) does revert you back completely to that point in time as far as the registry is concerned. So you basically loose anything that has been installed since that date.
     
    Last edited: Jun 16, 2006
  17. roddinron

    roddinron Corporal

    thanks very much for your help, my main concern was that I can't run scanreg, can't boot into safe mode, and can't run any online virus scans. I know I wasn't suppose to run trend micro, and didn't during the "read and run" phase, I tried to run it at an earlier time and just thought I'd let you know that it doesn't run either.
    You said in your post "You logs show now real malware problems. You can have HJT fix the two below lines but they are only minor things:"
    I take it you mean NO real malwear problems, meaning I don't have any virus present, and that's a relief. I would do a clean install on the new disk, but I don't know how to do that since i never got a ME disk with my pc, there's a disk image (DISE_backup) on partition drive D but that's all I ever got with this thing.
    Thanks again, I really appreciate the help that you people offer.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that was a typo and should have been "no".

    I'm not sure what is on this other partition you are referring too. Is it a full backup of your system as it was shipped? If so perhaps you can use it some how but don't forget to backup things you need from your current active partition first. People in the Software Forum can help you with all of this.
     
  19. roddinron

    roddinron Corporal

    ok, the machine seems to be working well now, aside from still not being able to run any online scans or run scanreg/restore, so I think I'm ok. I just wanted to be sure that there is no malware. Thanks again
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds