Ohhhh Crap

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by prost55cvy, Dec 1, 2004.

  1. prost55cvy

    prost55cvy Private E-2

    Hi guys,

    I need help bad. I have a problem with the about:blank hijack. I went to the FAQ sticky and was following the instructions there and I think I FUBARed my laptop.

    I went in and disabled my system restore like you said. It gave me the box to click but it didnt ask to restart the comp so I didnt.

    I went to step 2 to disable the "remote procedure call" service however there was no option to disable it. it was on automatic but it didn't give me the stop function box or any box on that screen, so like an idiot I went to the (log)? tab and disabled the box where it said to disable for "profile 1". Pretty much went to crap from there. :rolleyes:

    I tried to go in and undo what I just mentioned and now all the files that were under the extended tab when I ran services.msc are GONE. I also cant go in and re enable system restore because the WHOLE TAB under my computer properties is gone.

    Whatever I did screwed up a lot of things. I need help bad. Please help with any ideas.
     
  2. prost55cvy

    prost55cvy Private E-2

    Anyone?
     
  3. PhilliePhan

    PhilliePhan Guest

    Hi Prost55cvy,

    Please hang in there until Chaslang or Kodo get a chance to take a look at your thread.

    PP :)
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First, Step 2 is only for systems having about:blank and/or HSA hijack problems. Were you having problems with those hijackers?

    Second, Step 2 states to look for the below services:
    • Network Security Service
    • Workstation Netlogon Service
    • Remote Procedure Call (RPC) Helper
    Notice it states Remote Procedure Call (RPC) Helper . This is not the same thing as Remote Procedure Call (RPC) or Remote Procedure Call (RPC) Locator.

    Okay that being said, can you get to the service from the Standard tab (to the right of the Extended tab)? How about trying in safe mode?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the below to see if you can get it back:

    Open a command prompt by clicking, Start, Run, and enter cmd in the box and click OK.

    In the command prompt window enter the following command and hit enter:

    svchost -k rpcss

    Now see if you can find the service again with services.msc and make sure it is set to Auomatic and make sure it is re-enable for Profile1
     
  6. prost55cvy

    prost55cvy Private E-2

    Chaslang,

    Yes I had the about:blank problem. I guess I missed the "helper" at the end of the RPC.

    I can see all of the services under the standard tab after tying in services.msc but it will not allow me to get into the properties in those ones. When I right click properties it doesnt do anything.

    I also tried the cmd and typed in what you said and that didnt seem to do anything. svchost<sp>-k<sp>rpcss where the <sp> indicates a space right?

    I am hoping that being able to get to the services under the standard tab is a good thing. Any other steps I should try? Thanks for your help.
     
  7. prost55cvy

    prost55cvy Private E-2

    I also tried to do the same things in safe mode with networking but that had the same results. :(

    Would restarting using the last known good option in safe mode work?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After running that command, did you actually check service.msc to see if it changed anything?

    You could also try just running rpcss.exe from the command prompt and see if that works.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What OS do you have? If you have WinXP, a system restore point may work.

    You could try last known good, but since you are actually booting, that may be the same as what you get each time.
     
    Last edited: Aug 28, 2007
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have another idea to get that service running properly using the registry but I need your OS first.
     
  11. prost55cvy

    prost55cvy Private E-2

    Chaslang,

    Yeah, when i checked services.msc after the command it didnt change anything on the extended tab.

    I am running windows XP, however since I disabled my system restore in step one, I can't use that. When I try to access it from the my computer properties screen, the tab to unclick the disable system restore is GONE.

    When I try to get to system restore through control panel, it says that I can't access it because it has been disabled. :(
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you run regedit? If so, navigate your way down to:

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RpcSs

    and click on it. On the right side you should see under the Name column a parameter called Start what is the data value to its right.

    Also get the same info for ControlSet003 and for ControlSet
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    While waiting for me to come back download the file I am attaching here. RPCfix.zip It contains 3 files that are for merging into the registry. Don't do anything with them yet accept get the extracted from the ZIP file and on to your PC in a directory where you can find them later.
     

    Attached Files:

  14. prost55cvy

    prost55cvy Private E-2

    chaslang,

    Under controlset001 under start: type is reg_dword and the data is 0x00000002(2)

    There is no controlset003 or controlset.

    There is a controlset002 that has the same values as controlset001 = 0x00000002(2)

    There is also a file that says currentcontrolset which has the same start values as the other two.

    I will download the zip files and as you requested.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay it is suppose to be currentcontrolset , that was a typo on my part. But I not sure about why you do not have ControlSet003. Each PC I look at has the ones I listed. At anyrate the date value seems correct. For all three control sets, check the next parameter below Start called Type and see if it has a value reg_dword and the data is 0x00000020 (32)
     
  16. Adrynalyne

    Adrynalyne Guest

    Starting from the beginning

    Go to C:\windows\inf and right click, install sr.inf.
    You will need the CD.
    If you have Sp2, point it to C:\windows\servicepackfiles\i386


    the inf directory is hidden, you will need to show it, or access it from start, run.

    This should bring back the System Restore tab.
     
  17. Adrynalyne

    Adrynalyne Guest

    Next issue. Using XP Home or Pro?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks for jumping in Adryn! I appreciate the help on this one.
     
  19. prost55cvy

    prost55cvy Private E-2

    Hi guys,

    The info under the "type" tab is correct at 0x00000020(32) on all control sets.

    The version of windows that I am using is windows XP home. It came pre installed on the laptop so I don't have them XP disk. :(

    I do have an XP home CD for a different computer that I built but it is just an upgrade version. Would that work?
     
  20. Adrynalyne

    Adrynalyne Guest

    If its preinstalled, you will generally find the contents of the XP installation (i386) under C:\windows.

    Anyway, report back on the system restore issue.

    Also, in services.msc, does it show RPC running?
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    On some systems, you may find that the i386 is in the root of drive c (c:\i386 ).
     
  22. prost55cvy

    prost55cvy Private E-2

    Hi Guys,

    I found the I386 folder, I have Service Pack 1. Under the i386 folder I dont see a sr.inf file. there is a sr.in_ and there is also an install.in_ file, are these correct?

    Also under services.msn, all the files are in there under the standard tab but none are in the extended tab.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You misunderstood Adryn's comments.

    sr.inf is in c:\windows\inf which is a read only and hidden folder so you must make sure viewing of hidden files/system files is enabled. This is the file you want to run. The one in i386 is still compress (henced the sr.in_).

    His comment about i386 was related to the fact that you said you do not have an XP CD. So when you run the sr.inf file you need to point it to your i386 folder on you hard disk.
     
  24. prost55cvy

    prost55cvy Private E-2

    Ok, found the sr.inf and hit install, pointed it to c:/i386 and the pop up box says

    Source: c:\i386\sr.sy_.

    Target: c:\windows\system32\drivers\sr.sys.

    The target file exists and is newer than the source.

    Overwrite the newer file?

    Should I click yes, no, or no to all?

    Sorry I'm a dork but I dont want to screw anything up worse.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are running C:\Windows\Inf\sr.inf right? If so, yes! Let it run! Tell us if that fixes System Restore.

    You will be prompted for the location of the supporting files. Since you do not have the CD, just point to the i386 on your C drive.
     
    Last edited: Dec 8, 2004
  26. prost55cvy

    prost55cvy Private E-2

    Ok I let it run and it overwrote several files, however I still have no system restore tab, there are still no programs under the extended tab on services.msc, and there doesnt seem to be anything different on what we looked at with regedit.

    :(
     
  27. greinke

    greinke Private E-2

    I did the same stupid thing yesterday & I am stuck too. Its amazing how many issues are caused by RPC. Any new thoughts?
     
  28. greinke

    greinke Private E-2

    Adrynalyne

    Under msconfig the RPC's are shown as stopped. Under services.msc it is not shown as running.

    Also, what do you make of it no services being listed under the 'Extended' tab in services.msc?
     
  29. IrOnMaN

    IrOnMaN Specialist

    do you thing that could possibly be ad-aware finding his homepage set to about:blank in IE ?
     
  30. greinke

    greinke Private E-2

    I dont think either problem is from a specific hijack but from both us follishly disabling RPC.
     
  31. prost55cvy

    prost55cvy Private E-2

    TTT please
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I want you to use regedit to get me exports of those three registry keys we discussed before:

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RpcSs
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RpcSs
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcSs

    Just navigate (one at a time) to select that key. Th bottom of the regedit window must show exactly what I show above. Then in the top menu, click File and select Export. Now in the Filename field use the below filenames to represent the above 3 keys as you save them one at a time:

    - CS1-rpcss.reg
    - CS2-rpcss.reg
    - CCS-rpcss.reg

    Make sure you save them were you can find them. Then I need you to put all three of those exported .reg files into a ZIP file and upload it here. Hopefully you have and know how to use WinZip to do this. Let me know if you need help to do that.
     
  33. prost55cvy

    prost55cvy Private E-2

    Ok let me see if I can get this attachment done.

    edit: guess not, is there supposed to be an attachment link?
     
  34. prost55cvy

    prost55cvy Private E-2

    I don't have the browse button for attachments :(
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Once you have the .ZIP file all you need to do is start a message reply and click Go Advanced then scroll down and you will see the Manage Attachments button. Click it. The in the window that comes up, click the browse button and locate your file and select it. Then click the Upload button. After it uploads close the Manage Attachments window. And then click Submit Reply as you normally do.
     
  36. prost55cvy

    prost55cvy Private E-2

    Is it supposed to be under additional options because I dont see it. Do I need to have my options setup a certain way?
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm referring to Majorgeeks message board. What are you referring too?
     
  38. prost55cvy

    prost55cvy Private E-2

    Yes the message board. On the screen where you type your reply I am not seeing a manage attachments button. Is it supposed to be under the additional options section?

    There is a section called misc options with 2 check boxes, then there is something called attach files which is where I would assume this box should be but it isnt. Then there is thread subscription.
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should have these 3 options:​
    Miscellaneous Options​
    Attach Files​
    Valid file extensions: bmp doc gif jpe jpeg jpg log pdf png psd txt zip

    '); //--> Manage Attachments
    Thread Subscriptions​
     
  40. prost55cvy

    prost55cvy Private E-2

    Ok shit, I was trying to use the laptop that is screwed to post the reply. On the laptop there is no manage attachments button. When I get on my desktop and post a reply it is there. I'm going to have to xfer my zip file to my desktop to post it. Will do in a sec.
     
  41. prost55cvy

    prost55cvy Private E-2

    Here we go. I think my laptop is really FUBAR
     

    Attached Files:

  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Attached is a ZIP file with some modified version of the registry keys. Unzip them to a folder. And then locate them with Windows Explorer and double click on each of them (one at a time) to merge them into your registry. Click OK (or yes) when prompted if you want to merge the file in.

    After merging in the 3 items,reboot. Let me know if RPC is running properly now?
     

    Attached Files:

  43. prost55cvy

    prost55cvy Private E-2

    chaslang,

    I saved the zip file to a folder, unzipped it, double clicked on fixcss-rpcss.reg and had it update, did the same for the other two files (fixcs1 and fixcs2).

    Then rebooted computer.

    What am I looking for now? There is still nothing under the extended tab in services.msc. Am I supposed to be checking something in regedit?
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmm! Are you saying there are no services at all listed under the Extended tab? Or do you mean Remote Procedure Call (RPC) does not show?

    What's under the Standard tab?
     
  45. prost55cvy

    prost55cvy Private E-2

    Correct, under the extended tab there is NOTHING at all just the blue/white background with the gear thing. Under the standard tab everything seems to be there starting with the alerter all the way down to workstation.
     
  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So if you go to the Standard tab, is RPC running. If not, set it to Started and Automatic.

    Then reboot!
     
  47. prost55cvy

    prost55cvy Private E-2

    Under the standard tab there is nothing under the status column for RPC. It is setup for automatic. I can't seem to get into the properties to change the status using right click/properties or anything else. If I try and start it with a right click/start is gives an error

    --------------------------------------------------------------------------
    ! Could not start the Remote Procedure Call(RPC) service on Local Computer.

    Error 1058: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    --------------------------------------------------------------------------

    This is what happened originally when I disabled this thinking it was the RPC helper instead of just RPC. However when I did it the first time it was under the extended tab. I don't know how to enable this thing if I cant get into properties. I thought if it was set to automatic then it should come on during startup?
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's try a few things:

    - Let's try running msconfig. Click Start, Run, and enter msconfig and hit OK.
    Now choose the Services tab. See if you can find Remote Procedure Call (RPC) in there and put a check on it. Then click Apply.


    - If that does not work, check this out: http://support.microsoft.com/default.aspx?scid=kb;en-us;241584


    - And if that does not work, try the below:
    extract the files from the attachment and double click to merge them into your registry. Click yes or ok to the prompt. After this, reboot and let me know what the results.
     
    Last edited: Dec 13, 2004
  49. prost55cvy

    prost55cvy Private E-2

    YES YES YES!!!!!!! AHAAAAAA

    OK the l tried the things in your last post with no success, but I happened to come across this thing on the support page

    http://support.microsoft.com/default.aspx?scid=kb;en-us;838428

    and IT WORKED!!!!! YAAAAYYYYYYY

    I have all my services back on in the extended tab now and RPC is showing started and my system restore is back online.

    Now the only problem is that I still have the damn about blank problem that is directing me to xyzsearch.biz for my homepage.

    Chaslang you rock dude thanks for all your help.
     
  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Okay! Please don't do that again to RPC :)

    Now let's cut to the chase! I know you probably never complete the READ ME FIRST but do the below now:

    Read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Please do not delete or fix anything on your own.

    Now post a HijackThis log file as an attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    Make sure you have HJT version 1.98.2 and follow the guidelines on where to install it and how to post a log as an attachment.
     
    Last edited: Dec 14, 2004

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds