i think there's a worm in my system

Discussion in 'Malware Help (A Specialist Will Reply)' started by kalavera, Jan 30, 2005.

  1. kalavera

    kalavera Private E-2

    i desperately need help to get rid of the problems i'm having with my windows xp
    system.
    some of the problems i have are:
    *"paste" function is disabled ... i can't paste folders/files, can't paste links in the IE browser address bar
    *I can't drag folders/files
    *I can't restore folders/files that are in the recycle bin
    *Minimizing windows closes them instead of minimizing them
    *I can't open task manager
    *Windows Installer Service does not work
    *I can't view properties of the Services in the Administrative Tools folder
    *I've noticed when shutting down my computer, the floppy drive light goes on for a while
    *I've scanned my computer for viruses and other malwares ... but still the same problems ...
    *I can't download anything from Microsoft Windows Update site, simply because I can't enter it
    *Clicking on the "Go" button in the Symantec Security Check website does not do anything
    *MSN Messenger IM windows do not open when someone sends me an MSN IM message
    *Clicking on some links in some sites do not do anything
    *I can't kill processes running because I don't have the administrative rights ... or something like that ... but, before the problems occurred, this used to work with the not-so-important processes
    *I can't search for files/folders in my computer
    *My Network Connections folder is magically gone
    *Loading Windows and its settings takes a long time (about 3 minutes). Before, it only took around 30 seconds.

    I'm very sure there's a big fat worm/virus or some other malware in the computer that's causing this. It can't be anything else.

    Please help, and thanks in advance.
     
  2. jarcher

    jarcher I can't handle a title

    First, Welcome to MG. . .


    Have you already gone through this sticky? If not please do so. . .
    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal:
    Double check everything and make sure you did do everything
    and all software is up to date
     
  3. kalavera

    kalavera Private E-2

    I've scanned with the latest versions of spybot and ad-aware, scanned with Housecall's online antivrius scanner, enabled all protection with spyware blaster, immunized everything with spybot ... all updated and in safe mode (with networking) ... couldn't access symantec security check scanner, though, and stinger did not detect anything in my computer, system restore is off (actually i don't know if it's on/off cause I can't launch it and the system restore tab is no longer there in the System file of Control Panel, but it was off before my computer got infected)
     
  4. jarcher

    jarcher I can't handle a title

  5. kalavera

    kalavera Private E-2

    I see no system restore tab in the properties of My Computer

    I have the latest version of HijackThis! do I post the log here or what?

    Thanks again
     
  6. jarcher

    jarcher I can't handle a title

    if you followed the links, go ahead and attach one
     
  7. kalavera

    kalavera Private E-2

    ok, here's the log
     

    Attached Files:

  8. jarcher

    jarcher I can't handle a title

    the log looks pretty clean to me
    are you still having problems?

     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually this is a real baddie:

    MessengerPlus! 3

    It should be uninstalled from Add/Remove programs. But if you do not have Admin rights you are going to have problems doing that. Also that log looks like it was from safe mode boot not normal boot.

    Whose PC is this?
     
  10. jarcher

    jarcher I can't handle a title

    as a third party plug-in to MSN Messenger, I thought that was only a user choice thing, my mistake
    thanks, chas.


    alot of the "symptoms" could be due to the admin. rights, right?
     
  11. kalavera

    kalavera Private E-2

    no, i did it in normal mode, not safe mode

    but yeah, even if there was something to kill in the scanned list, I couldn't cause of admin rights. how do i get it back, if possible ...

    the pc is my own

    About Messenger Plus, I know it's a risky program to use, but I've had it way before the the computer got infected

    I think the problems first appeared when I finished downloading a zipped file from Limewire, although I didn't unzip the files in it. I just simply deleted the zipped file, but the symptoms stayed.

    But also, today I remembered that on the day my PC got infected and before downloading the zipped file from Limewire, I actually used a program called Registry Analyst and with it removed all the "invalid" entries that Registry Analyst told me to clean. But I really don't think that's the problem ... I hope not ...
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Messenger Plus installs a load of malware on your PC including a nasty LOP infection. It is crap and must be removed. It was the beginning of your problems. Software like this cannot be trusted to have on your computer even if you carefully read the license agreement and did not install the sponsor stuff.

    Removing registry entries like you did can be dangerous. You should always do a back up first. These kinds of tools point out many "potential" problems but they are not always problems. You must look at them and decide for yourself. Did it do a back up of your registry. If so, restore from it.

    Do not use Limewire? All P2P programs can be dangerous. But check this out for reference purposes: http://www.spywareinfo.com/articles/p2p/

    Can you boot in safe mode as the Administrator?
     
  13. kalavera

    kalavera Private E-2

    ok, i uninstalled MSN plus and limewire, still the problems

    about the registry backups, sad to say but I was too careless to create backups, but still the problems can't be the result of just errors in the registry, my logic says a malware (or more) is causing this, and it happened right after I downloaded the zipped file from Limewire (like I said before)

    Yes, I can boot in safe mode as administrator ... fortunately! but the internet connection there only works for a while ... strange ... but when in safe mode as another user, the internet connection works just fine ... also in safe mode (no matter what user), the same problems appear ...
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Follow the below instructions and get me two HijackThis logs to start. I want one log for the administrator account and one for another user, but I want both of them from safe mode. Note: this is different then normally requested. We normally want logs from normal boot mode. I may ask for that in the next post (depends on the results here). Make sure you put HijackThis where indicated. It will also make it easier for all accounts to find it and run it.

    Note: Registry deletions can cause any kind of problem. The registry controls everything on your PC.


    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  15. kalavera

    kalavera Private E-2

    here they are

    I noticed that with Internet Explorer I don't see the Manage Attachments button, but with Mozilla I can

    anyway, first log is as administrator

    and second as another user

    both in safe mode
     

    Attached Files:

  16. kalavera

    kalavera Private E-2

    here's what Spybot detected ... i did a scan with it just now (in normal mode)
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problems are visible in your logs from safe mode. Please provide a HJT log for a user in normal boot mode.

    Have you disabled WinXP SP2's built in firewall? You need to do that if you not done it already but that is not your problem here.

    Were you tinkering around with enabling or disabling any service on the system?

    Do the following (you may need to do it from the Admin account):
    - click Start, Run, and enter secpol.msc and click OK
    - when this Local Security Settings window comes up click the Action and select Export list and save this to a file where you can find it. Then attach that list back here.

    - Download GetService.zip from here: Getservice.zip

    Extract the file to a folder where you can find it, then go to the folder and double-click on the getservices.bat file. A notepad will open up when it finishes. Please paste the contents of that notepad file as an attachment. Call it service.txt.
     
  18. kalavera

    kalavera Private E-2

    ok, first the HJT log

    also, I want to tell you that when I log into normal mode, I don't get an option to select which user to login as, I automatically login, so I'm not sure if I'm logging in as administrator or a normal user ...
     

    Attached Files:

  19. kalavera

    kalavera Private E-2

    i can't change the firewall (due to ICS (Internet Connection Sharing cannot start) problem)

    I did disable certain services like universal plug n play and shoot messenger or something like that and with bugoff program i disabled the services, but i forget whether that was before or after the problems appeared
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have no Security Policies at all! And I think some of your services that should be running are not?

    I think you are in bad shape here and recovering from this may not be easy if possible at all. You should start looking into backing up what you need from this system and looking into a reinstall!

    I'll do some more checking to see if there are any solutions for this but I'm not sure I would count on it. If System Restore would work, that could be useful.

    I'm not sure but I wonder if a Repair using your Windows XP boot disk would help (do you have a WinXP bootable CD?)
     
    Last edited: Feb 1, 2005
  21. Adrynalyne

    Adrynalyne Guest

    Damn...

    There is not any singular cuase that I can see here, but a whole buttload of little ones.

    Lets see if we can kill off the easy ones first.


    *"paste" function is disabled ... i can't paste folders/files, can't paste links in the IE browser address bar
    --Make a new user account and test.

    *I can't drag folders/files
    --Should fall under new user account

    *I can't restore folders/files that are in the recycle bin

    --Do you have any Norton products installed? A Norton Protected recycle bin can pose problems such as this.

    *Minimizing windows closes them instead of minimizing them
    --I've seen issues like this when the mouse is not working right, or is not accurate. I know, a bit of a long shot there.

    *I can't open task manager
    --Does it work in Safe Mode? Are there any errors?

    *Windows Installer Service does not work
    --What is the error?

    *I can't view properties of the Services in the Administrative Tools folder
    --Is there an error? Is it greyed out?

    *I've noticed when shutting down my computer, the floppy drive light goes on for a while
    --Perfectly normal. Most antivirus applications are configured to scan floppies on shutdown, whether there is a floppy in the drive or not.

    *I've scanned my computer for viruses and other malwares ... but still the same problems ...
    --An effective virus/worm, is the one that can't easily be found, although save for some problems here, I'm not sure it is a virus.

    *I can't download anything from Microsoft Windows Update site, simply because I can't enter it
    --Sounds like a blocked port. Can you get to this site instead? https://www.microsoft.com:443

    *Clicking on the "Go" button in the Symantec Security Check website does not do anything
    --Start, run, regsvr32.exe jscript.dll
    click ok, and make sure it succeeds.

    *MSN Messenger IM windows do not open when someone sends me an MSN IM message
    --Stumped.

    *Clicking on some links in some sites do not do anything

    --the abbove command for jscript.dll may resolve this.

    *I can't kill processes running because I don't have the administrative rights ... or something like that ... but, before the problems occurred, this used to work with the not-so-important processes

    --I thought you couldnt get into task manager??

    *I can't search for files/folders in my computer

    --jscript issue

    *My Network Connections folder is magically gone

    --Make certain the Network Connections Service is running.
    If you can't get to it by services.msc, tthen open regedit.exe, locate this key:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netman
    Set the start type to 3. Then reboot. If that still doesn't start it, go to a cmd.exe prompt, and type:
    net start netman
    press enter

    *Loading Windows and its settings takes a long time (about 3 minutes). Before, it only took around 30 seconds.
    --have you done a repair install lately?
     
    Last edited by a moderator: Feb 1, 2005
  22. Adrynalyne

    Adrynalyne Guest

    Classic symptom of mismatched files. Another reason why i asked above if you have done a repair recently.

    Open msconfig from start, run. Click Launch System Restore and post back with the error message.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks for jumping Adryn!

    Did you notice the abscence of RpcSs? It should look like this in the Service list. It's missing. That can be a major problem!

    SERVICE_NAME: RpcSs
    Provides the endpoint mapper and other miscellaneous RPC services.
    TYPE : 20 WIN32_SHARE_PROCESS
    START_TYPE : 2 AUTO_START
    ERROR_CONTROL : 1 NORMAL
    BINARY_PATH_NAME : C:\WINDOWS\system32\svchost -k rpcss
    LOAD_ORDER_GROUP : COM Infrastructure
    TAG : 0
    DISPLAY_NAME : Remote Procedure Call (RPC)
    DEPENDENCIES :
    SERVICE_START_NAME: LocalSystem
    FAIL_RESET_PERIOD : 0 seconds
    FAILURE_ACTIONS : Reboot DELAY: 60000 seconds
     
  24. Adrynalyne

    Adrynalyne Guest

    I've some ideas about that, but I have to go to bed.

    I'll post more on it later.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ok! Catch later tomorrow/today!
     
  26. kalavera

    kalavera Private E-2

    thanks guys for all the help ... i really appreciate it ... too bad this isn't easy to solve
    well, i can't create a new user account, it seems, cause when I open the user Account in Control Panel, the box appears but it is blank ... only the title bar is is normal with "Back" "Forward" and "Home" buttons which don't work

    I'm sure I don't have Norton utilities installed

    Task Manager doesn't work in Safe mode

    The Windows Installer Ervice error is "The Windows Installer service could not be accessed. This can occur if you are running in safe mode or if the Windows Installer is not correctly installed."

    The Properties of the Services in Administrative Tools isn't greyed out, but when I click on it, no box appears

    About the links, well, I think there's a problem with Internet Explorer, cause with Mozilla I can access any link no problem

    About task manager, true, I can't open it, but I have a program that kills processes

    The jscript thing didn't fix any error, neither the other instructions you told me to do :(

    no repair install lately.

    'System restore is not able to protect you computer. Please restart and your computer and start again' error occurs when i do the Lauch System Restore

    Anyway, I don't mind reformatting, but I just want to make sure if these can be fixed without doing that process ... but since adrynalyn still has some solutions, i'll wait before reformatting

    Thanks again, guys, for the help
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Wait for Adryn to come back. I asked him to jump in here! I sure he will have some great ideas to try before resorting to a format.

    Anyway time for bed! Catch ya later!
     
  28. Adrynalyne

    Adrynalyne Guest

    Missing RPC.

    The RPC service missing from the system fubars most things, too.

    A missing service can be something as simple as it missing a start value, or it missing a type value.
    Check HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcSs via regedit and see if it matches what you see here (keep in mind I have Sp2, which changes some of these values:
     
  29. kalavera

    kalavera Private E-2

    "RpcSs" is missing ... I don't see it
     
  30. kalavera

    kalavera Private E-2

    weird, when yesterday, i couldn't access the system volume folder, now i can

    and it has mountpointmanagerremotedatabase file and tracking.log
     
  31. Adrynalyne

    Adrynalyne Guest

    Here is a copy of the RPC service.

    Unzip it and run it.
     
  32. kalavera

    kalavera Private E-2

    man, you're a genius! Thanks to you and Chaslang, most of the problems got fixed! You guys are wonders!

    Task Manager still doesn't open, but that's probably cause I killed it with x-raypc program. Any ways to get it back?

    System Restore, Minimize windows, copy/paste, drag, startup problems, all solved! And hopefully, the links and other stuff, too

    Thanks again, guys
     
  33. Adrynalyne

    Adrynalyne Guest

    Try start, run, taskmgr.exe

    Does that bring it up?
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I had a feeling RpcSs was a big part of the problem! Good job Adryn!
     
  35. kalavera

    kalavera Private E-2

    it says "file not found"

    but i can live without it, I have a couple of substitute programs for task manager, so it's no big problem

    thanks for the help
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should be able to locate a copy of taskmgr.exe in your i386 folder. It may be c:\i386 or c:\Windows\i386

    Just copy it to your c:\windows\system32 folder.

    If you find taskmgr.ex_ and not taskmgr.exe, it needs to be expanded first.
     
  37. kalavera

    kalavera Private E-2

    Amazing! :D

    Thanks for the help, mate! This is definitely the best computer-related problems forum! I'm gonna recommend this site to my friends!
     
  38. jarcher

    jarcher I can't handle a title

    :) :)
    those guys are good ,ain't they? :cool:
     
    Last edited: Feb 2, 2005
  39. kalavera

    kalavera Private E-2

    They sure are :)
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So I assume that means you have Task Manager working now!

    Yes! Send your friends to MG's!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds