Please help me

Discussion in 'Malware Help (A Specialist Will Reply)' started by jamie140, May 9, 2006.

  1. jamie140

    jamie140 Private E-2

    I've done all the stuff in the do this first thread.

    I'm including the attachments. I'm about to take a baseball bat to this thing.

    TIA. Jamie.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run the steps in the below link and attach the requested smitfiles.txt log:

    SpywareQuake & SpyFalcon Removal Procedure

    Then double check and delete all of the below if they still exist:
    C:\WINDOWS\System32\hp73A4.tmp
    C:\WINDOWS\System32\dcomcfg.exe
    c:\windows\system32\ld119E.tmp
    c:\windows\system32\msblank.html
    c:\windows\system32\ot.ico
    c:\documents and settings\all users\favorites\Download Free Spyware Remover.url
    c:\windows\system32\1024 <--- the wholde folder
    c:\windows\smdat32m.sys
    c:\windows\warnhp.html

    Note: you skipped step 3 of the READ ME. You have Kaspersky and Symantec running. Uninstall one of them.

    Please follow the directions given in step 7 of the READ ME and install HijackThis as instructed. You have it here:
    C:\Documents and Settings\jamie\Local Settings\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe

    Which means you are running it from the ZIP file. This is exactly what the directions say not to do. Please fix this now. Then attach a new HJT log.


    What version of Morpheus are you running? Older versions of this contain malware.

    How are things running now?
     
    Last edited: May 9, 2006
  3. jamie140

    jamie140 Private E-2

    The Norton file is corrupt is unuseable. I have tried to delete it using control panel, but it won't allow it. Should i still delete kas.?

    Morpheus 4.8.1.

    Sorry about the HJT, I spent an hour trying to do it exactly pursuant to the instructions and couldn't get it right. The folder I thought was correct had a warning that it was protected.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No do not uninstal; Kaspersky. You need to uninstall Norton if it is not working. But is that what you meant by Control Panel? Did you mean you could not use Add/Remove programs to uninstall it? Try using the below procedure:


    Using the Norton uninstall tool

    This version contains malware. See: http://www.spywareinfo.com/articles/p2p/

    You have not extracted it from the ZIP file. What you are doing is opening the ZIP and then running the hijackthis.exe file that is inside the ZIP. You must follow the instructions in the link given in step 7 to install it properly. The C:\Program Files folder is not protected. You need to creat a subfolder in C:\Program Files and name the subfolder HJT then extract the hijackthis.exe file from the HijackThis.zip file you downloaded into the C:\Program Files\HJT folder.
     
  5. jamie140

    jamie140 Private E-2

    I'm in safe mode. I did the registry update. I've found system 32, but don't see any of those files?
     
  6. jamie140

    jamie140 Private E-2

    sorry, found some files that look like that...
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please be specific. What did you find and what didn't you find? Do not delete anything unless it is an exact match for what was given!
     
  8. jamie140

    jamie140 Private E-2

    Can't find any of the listed files.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which listed files? The ones in the SpywareQuake procedure or the one listed in message # 2 of this thread.
     
  10. jamie140

    jamie140 Private E-2

    In spyware quake:

    %System32%\dxmpp.dll
    %System32%\ginuerep.dll
    %System32%\stickrep.dll
    %System32%\__delete_on_reboot__stickrep.dll
    %System32%\suprox.dll
    %System32%\xenadot.dll
    %System32%\sivudro.dll
    %System32%\twain32.dll
    %System32%\dvdcap.dll
    %System32%\reglogs.dll
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you using the PC with the problem to post messages here right now while running the procedure?
     
  12. jamie140

    jamie140 Private E-2

    No..........

    I ran the smitrem and I'm now rebooting.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Tha't not what I meant! I mean while you were posting all these messages you implied you were in safe mode and could not find the files. Which PC where you posting messages from?
     
  14. jamie140

    jamie140 Private E-2

    I understood. I'm using another computer to post.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! So why were you reporting that those files could not be found. The procedure begins with the below note.
     
  16. jamie140

    jamie140 Private E-2

    Yup, continuuing...Although it doesn't seem to want to boot into normal mode
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What happens? You must provide more descriptive comments.

    If you still cannot boot into normal boot mode, power the PC down for a minute. Then turn the power back on and see if you can boot in normal mode.
     
  18. jamie140

    jamie140 Private E-2

    Ok, it's booting now after repeated attempts. I'll continue with the steps.
     
  19. jamie140

    jamie140 Private E-2

    Now it keeps locking and re-booting. I'm done with this. Thanks for trying to help!
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nothing that was given in the SpywareQuake procedure would cause any problems like this. As long as only what was given in the procedure was run and no files except what were given there were deleted, it would have no impact on your ability to boot into normal mode. In message number 6 you said:
    What exactly did you find and delete? Perhaps you delete things you should not have deleted. You should only delete exact matches not "things that look like that".

    Two things I would suggest after booting in safe mode.

    1) Get the smitfiles.txt log from running SmitRem over to your other PC and attach it here.

    2) While in safe mode look to see if the C:\Windows\system32\wininet.dll file exists.
     
  21. jamie140

    jamie140 Private E-2

    Didn't find or delete anything. Just did the registry edit procedure in safe mode and then tried reboot into normal mode. Now it keeps trying to boot, locks up then reboots.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What about the rest of what I said in my last message?
     
  23. jamie140

    jamie140 Private E-2

    I'm taking a break from it so I don't destroy it. I took it to work and I'll play around with it tomorrow. I'll try that and give you an update.

    Thanks. Jamie.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Something else you can try if you have other user accounts, is to try logging into a different user account in normal boot mode. Does that work?

    You could also create a new user account while in safe mode. Then try booting into normal mode and using the new user account.

    Question: Do you boot to the welcome screen and require user login or are you set to directly boot into a particular account immediately. This second option is normally an admin account and it is not a very secure things to do if that is how you were setup.
     
  25. jamie140

    jamie140 Private E-2

    When I boot, it goes to a user account with my name, then I enter my password and it boots. When I was in safe mode last night, I noticed there were two accounts as you mentioned: Jamie and administrator.

    I'll be sure to update you tomorrow relative to my progress.

    --Jamie
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I thought you said it did not boot! Or did you mean after you enter your password you have a problem?
     
  27. jamie140

    jamie140 Private E-2

    What I was describing was the procedure prior to the problems.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just do what is in message # 20 and get me the log and tell me about wininet.dll.

    You should also login to the Administrator account and see if it boots okay.
    Also you should create a new user account and then see if you can boot into this new account without a problem.
     
  29. jamie140

    jamie140 Private E-2

    Ok, I'm working on it now...
     
  30. jamie140

    jamie140 Private E-2

    Found .....system32 file called WININET.DLL. Having some trouble connect to the internet so I can send that smitfiles.txt over....
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you get it to your other PC and send it from there?

    Which mode are you booted in (normal or safe)?
    Which user account are you logged into? Use the Administrator account.

    What kind of connection to the internet do you have (dial-up, cable, DSL)?
     
  32. jamie140

    jamie140 Private E-2

    ....
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't have a floppy drive, a flashdrive, CD burner etc????

    Are your PCs connected to a network (a router etc)?
     
  34. jamie140

    jamie140 Private E-2

    I'll try to use a disc. The infected one is not on the network.
     
  35. jamie140

    jamie140 Private E-2

    I've tried to burn it, but when i try to attach it here from the disc, it says it says not accessible, the when I explore it, it says the disc must be formatted?
     
  36. jamie140

    jamie140 Private E-2

    I think it's dead. I keep getting a message: read error, alt+crt+del to restart which of course doesn't work.
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your PC is giving you this message when you try to boot it now??

    A little while ago you said you could boot into safe mode. What did you do that has changed this?
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What kind of disc? Floppy or CD?

    Floppies must be formatted before you write to them to begin with.
    CD must be burned using CD burning software and you would need it to be a data disk.
     
  39. jamie140

    jamie140 Private E-2

    When I couldn't access the internet from safe mode, I tried start>restart to boot again into regular mode and that's when this message began. Tried a number of times to get back into safe mode, but the same error message keeps coming up.
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't understand why your symptoms keep changing. They should not be changing so radically unless you are changing things on the PC.

    If you can not longer boot your PC after a power down, I would suggest you put in your WinXP CD and do a repair.
     
  41. jamie140

    jamie140 Private E-2

    I'm pretty sure it's dead.
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  43. jamie140

    jamie140 Private E-2

    Thanks for all your help. I'll give this a shot tomorrow.

    --jamie
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Keep me posted. If you have any problems trying to work thru a repair, guys over in the Software Forum can help you with this.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds