New MSN Messeger Virus Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by I_Am_The_Best, Aug 11, 2005.

  1. I_Am_The_Best

    I_Am_The_Best Private E-2

    Yesterday my friend sent me a im saying "Hey i just updated my messenger it rocks :D http://www.msgpluszone.com/msnplus-patch"

    So i clicked the link thinking it was an msn plus update but it said file not found then my ip address so i closed it..i just thought they had some form of spyware on their computer and thought nothing of it..when i restarted my computer all .exe files could not be opened regedit cannot be opened msconfig cannot be opened...nothing it is still like this in my task manager i have these weird processes running "lsass.exe, csrss.exe,smss.exe" and idk why but rundll32.exe is in process's... Can anyone PLEASE help me I cannot open anything on my computer.
     
  2. I_Am_The_Best

    I_Am_The_Best Private E-2

    I would run hijack this if i could actually run .exe files :\ i cannot run anything with a .exe extension.
     
  3. I_Am_The_Best

    I_Am_The_Best Private E-2

    I am running Windows XP Media Center Edition and yes it has safe mode with networking..thanks in advance for helping
     
  4. I_Am_The_Best

    I_Am_The_Best Private E-2

  5. I_Am_The_Best

    I_Am_The_Best Private E-2

    bump again can someone help pleaaase this is the most irritating virus everrr
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Bumping your thread will only make it take longer to get an answer. We work from oldest to newest threads requiring answers. So bumping (while it does move you to the first page) pushes you deeper down the queue relative to time.

    D3m3nt3d has not been around today. I'll see if I can help keep you moving until he returns.

    See if you can do the following. Goto this website: http://www.dougknox.com/xp/file_assoc.htm

    and download and install the below registry patch:

    EXE File Association Fix (Restore default association for EXE files)

    Now can you run EXE files?
     
  7. I_Am_The_Best

    I_Am_The_Best Private E-2

    It tried to open reg files in notepad?? so i cannot run it
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like you lost registry file associations too.

    But you were able to open the Zip file you downloaded before so it would seem you can run EXE but only in certain forms.

    Let's try three tests:

    1) Click Start, Run, and enter regedit then click OK. This should open the registry editor.

    2) Click Start, Run, and enter cmd then click OK. This should open a command prompt
    window.

    3) Press CTRL-ALT-ESC simultaneously. This should open Task Manager.


    Just let me know those three tests work.
     
  9. I_Am_The_Best

    I_Am_The_Best Private E-2

    No i get an error that says "Windows cannot open this file 'regedit.exe' and then the use web service to find appropriate program" same for the command prompt..
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What about steps 2 & 3?

    Edit: Sorry! Only question 3!
     
  11. I_Am_The_Best

    I_Am_The_Best Private E-2

    Same for step 2 and on step 3 it just minimizes what ever windows i have open..
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry! I meant use CTRL-SHIFT-ESC for step 3.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way, what OS are you running and what version (Service Pack level)?

    Also, do you have your original bootable CD for the OS?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    One last thing for the night! Have you tried running EXEs from safe mode boot? Also try my 3 steps from safe mode.
     
  15. I_Am_The_Best

    I_Am_The_Best Private E-2

    yes step 3 works now, i am running Windows XP Media Center Edition and the newest service pack...and i will try safe mode right now.
     
  16. I_Am_The_Best

    I_Am_The_Best Private E-2

    ok just got back from the safe mode tests dont work except for step 3...
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please tell me the SP number.

    Also in Task Manager (which you say you can bring up) click File and select New Task (Run...) now click the Browse button. Navigate your way to the c:\windows\system32 folder and look to see if regedit and cmd (fullnames are regedit.exe and cmd.exe) exist.

    You did not answer one of my questions:

     
  18. I_Am_The_Best

    I_Am_The_Best Private E-2

    I have service pack 2. I do have the boot disk that came with the OS but i am not 100% sure as to where it is. And cmd.exe is in the system 32 folder but reg edit is not, however there is a .exe called REGEDT32.EXE.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Regedit.exe is actually supposed to be in c:\windows and the regedt32.exe that you found is correctly located.

    Using Task Manager browse to where you found cmd.exe and right click on it with your mouse in the browse window. Then select rename. Try to rename it to cmd.com. If that works, try to run the file now that it is named cmd.com.

    Is your original CD for Win XP SP2 or did you upgrade to SP2 afterwards?
     
  20. I_Am_The_Best

    I_Am_The_Best Private E-2

    I upgraded with a windows update afterwards..and it now says windows cannot find the program the file "cmd.com.exe is associated with.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! You should rename cmd.com back to cmd.exe just to get it back to normal.

    I doubt the below is going to work since no EXE or COM files will run, but let's try anyway. If this does not work, you may have to run Windows repair from your original CD, so you better find it. I'm not sure that will work either since you CD version will not match your installed OS version. You may be closed to having to do a reinstall.

    Try clicking Start, Run and enter sfc /scannow and click OK. I'll bet it will not work either.

    Provide me a list of all processes seen running in Task Manager.
     
  22. I_Am_The_Best

    I_Am_The_Best Private E-2

    The Following Is The List Of The Running Process's:

    avgw.exe
    SIGserver.exe
    svchost.exe
    MDM.EXE
    KodakCCS.exe
    explorer.exe
    ehsched.exe
    CTSVCCDA.EXE
    avgupsvc.exe
    avgamsvr.exe
    LEXPPS.EXE
    LEXBCES.EXE
    svchost.exe
    svchost.exe
    svchost.exe
    svchost.exe
    svchost.exe
    lsass.exe
    services.exe
    winlogon.exe
    csrss.exe
    taskmgr.exe
    smss.exe
    alg.exe
    firefox.exe
    System
    System Idle Process SYSTEM
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you cannot run EXE programs, how are you getting FireFox.exe to run.

    Did you try the sfc command from my previous message?
     
  24. I_Am_The_Best

    I_Am_The_Best Private E-2

    Yes i tried and it did not work. And idk about firefox it is weird firefox always works and sometimes startup items start randomly like avg and sometimes aol and msn messengers.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have HijackThis on this PC and will it run?
     
  26. I_Am_The_Best

    I_Am_The_Best Private E-2

    No, but I just found a way to get into command prompt so I can open Registry Editor. The way I get in is boot in safe mode with command prompt. Anything you want me to do now, since I can get into the command prompt?
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


    See if you can run regedit and Import the xp_exe_fix.reg patch I had you download in message # 8 (that is assuming you extracted the .reg file from the Zip file you downloaded).
     
  28. I_Am_The_Best

    I_Am_The_Best Private E-2

    I am not sure as how to do that with the cmd prompt?
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You said you could run registry editor so run it and select File, Import. Then locate the xp_exe_fix.reg (if you extracted it, you did not answer that question) and import it into the registry.
     
  30. I_Am_The_Best

    I_Am_The_Best Private E-2

    Yes I extracted it I'll try it right now I'll let you know if it worked..by the way thanks alot for the help.
     
  31. I_Am_The_Best

    I_Am_The_Best Private E-2

    Okay .exe's are now working!! Now I just need to know how to get the .ink files that link to the exe's to work :) . I also left an attachment to my hijack this log.
     

    Attached Files:

  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You mean .lnk not .ink (it's a lower case L for link). You may need to edit them to make sure they point to they correct items.
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to get HijackThis installed properly. You have it here:

    C:\Documents and Settings\Chris Tank\Local Settings\Temp\HijackThis.exe

    This is not a safe location. You could easily loose backups there and it can only be run by you and no other user account names if located there.

    Put it here: c:\Program Files\HJT\HijackThis.exe
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  35. I_Am_The_Best

    I_Am_The_Best Private E-2

    Okay here is the new hijack this log from "C:/program files"...
     

    Attached Files:

  36. I_Am_The_Best

    I_Am_The_Best Private E-2

    Yes everything is working again...now anything in that hijack this file you see i should delete?
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you merge in those other registry patches?

    You have two copies of HJT running:
    C:\Documents and Settings\Chris Tank\Local Settings\Temp\HijackThis.exe <--- delete this one
    C:\Program Files\HijackThis.exe
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You AVG antivirus does not seem to be loading properly. I would uninstall it, reboot and then reinstall and update. Make sure you do this before continuing.

    Also run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

     
  39. I_Am_The_Best

    I_Am_The_Best Private E-2

    Okay, my computer is virus free and faster than ever thanks alot chaslang you helped me so much!
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds