pc has gone loopy

Discussion in 'Malware Help (A Specialist Will Reply)' started by ohmissjones, Sep 20, 2006.

  1. ohmissjones

    ohmissjones Private E-2

    I don't know what has happened to my pc. :eek: i have windows xp and had both ZoneAlarm & AntiVir (which has disappeared and i cannot install it again) running fine until a few months ago. now i can't seem to get the .exe file for any anti-virus software to install and when i try and run applications such as CCleaner they won't even open, or they will appear in my "Processes" as running but won't actually run (as far as i can tell). I don't even know where to start! HELP! (It may be useful to know that i am having problems with certain Microsoft pieces of software too, such as Internet Explorer & Messenger, neither of which will open, Firefox seems to work fine, as do other messenger programmes such as Yahoo & AIM).
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please see how much of the below you can run. The more you can do the better. Get us as many logs as possible from this procedure. Just remember that the logs are the only way we can see what is going on so we can give you help. Without them we are blind and cannot do very much but make wild guesses.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. ohmissjones

    ohmissjones Private E-2

    followed the steps as suggested. it seemed that the scans i was able to perform removed quite a few bits of malware but i still cannot open microsoft programmes.

    CCleaner ran fine in safe mode (i have not been able to get it to work on normal mode)

    getrunkey downloaded & ran fine
    shownew downloaded & ran fine
    Have posted logs for both of these

    spybot ran fine and deleted some spyware from my machine

    Windows defender & malicious software remover both ran fine

    hit my first problem when trying to run the online scans. internet explorer REFUSES to open ( i even downloaded a new version) it just keeps turning around and then i get a "not responding" message ( i also have not been able to open Microsoft messenger for some time, which makes me think that the is something microsoft virus related?). Therefore could not run BitDefender OR
    Panda Active Scan.

    HijackThis also ran fine (have attached log for this also)

    Don't know where to go next. Any ideas?
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {BA25708B-154D-4D40-8607-67AA5190C395} - C:\PROGRA~1\INTELL~1\ISengine.dll (file missing)
    O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
    O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
    O4 - HKLM\..\Run: [SvcHost32] C:\WINDOWS\svchost32.exe
    O4 - HKLM\..\Run: [1on1] C:\WINDOWS\1on1.exe -n

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\svchost32.exe
    C:\WINDOWS\1on1.exe -n

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Annika\Local Settings\Temp

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  5. ohmissjones

    ohmissjones Private E-2

    ran HJT and deleted lines. however when i re-booted into safe mode the two .exe files you mentioned were not found. deleted all the other files you mentioned with no problems. ran hijack this and have attached log.

    NB. i have tried to open internet explorer and it still won't open after these procedures. Also, I can run Ccleaner fine in Safe Mode but it won't open in Normal Mode.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure you are not blocking IE from accessing the internet in your firewall (ZoneAlarm)? Try shutting down ZoneAlarm.

    Did your problems begin around the time frame you upgraded to IE7? Maybe you should uninstall it.

    Uninstall CCleaner, reboot, delete the folder for it in C:\Program Files
    Now download the current version given in the READ ME and reinstall it. Does it work now?
     
  7. ohmissjones

    ohmissjones Private E-2

    i shut down zonealarm but it has not made any difference, internet explorer will still not open correctly. I only just upgraded to IE7 a few days ago in the hope that it would fix my IE problem so this has been an issue for quite a few months now not because of a new download.

    followed your instructions re. CCleaner, it still won't open. when i open windows task manager it shows CCleaner in my application list but its status is "Not Responding", and i cannot see any evidence of it running apart from in the task manager.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Upgrading to IE7 while infected and having problems may have made things worse and these issues may not be malware related.

    Click on Start, then Run and type services.msc into the box that opens up, and click 'OK'. On the page that opens, scroll down to Automatic Updates and right click on it and select Properties and click Stop Service. When it shows that it is stopped, please set the Start-up Type to Disabled. Press 'OK' until you get back to Windows.

    Now reboot and let me know if there is any change to your status. If not, go back and set the service to Started and Automatic.

    Have you run a sfc /scannow command from a command prompt windows? You may need a Windows CD for this to complete if it finds missing or corrupted files. Also if your CD does not match your current version of Windows (which is WinXP SP2), it will revert back to the version on your CD.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds