private geek needing help sir

Discussion in 'Malware Help (A Specialist Will Reply)' started by radstar, May 8, 2006.

  1. radstar

    radstar Private E-2

    Hi I read the stickies re spyfalcon and hijack this however when I performed the steps in the spyfalcon removal thread I could not rename the .dll file as it was protected/being used by windows.
    I checked the security and found new administrators had been created so I modified and delted them still unable to rename or delete the dll file. all this was done in safe mode.
    I rebooted this morning in normal mode and the anoying little pop up that said I had a virus and click on this to download antimalware was gone (good outcome)
    However I beleive I still have a problem and I wont use IE to surf only mozilla untill I can clear this as it has taken controll of IE and I cannot remove it.
    Q. can I remove IE? (Internet Explorer"
    If so how and how do I install it again?
    So sorry if this is a bit of an old thread but as I am not fully pc literate (dah)
    I would like to beat this this so I can again surf in peace and play games etc.
    Anyhelp is appreciated.
     
  2. radstar

    radstar Private E-2

    just discovered I have the 1024 folder aswell and ofcourse I cannot delete it or rename it.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    If you are following our procedure then you need to attach the smitfiles.txt log for us to review.

    Which file is it that you cannot rename?

    Also run the below procedure and attach the runkeys.txt log.

    Using GetRunKey
     
  4. radstar

    radstar Private E-2

    Ok I have run both getrun key and smitfiles.txt. How do I find the text logs you need me to post? are they in notes or something? Sorry I just dont know where that info wentalso IE wants to go to shdoclc.dll every time I open it (offline ofcourse) found that file but could not delete it.
    I can also see this twain32 folder is this the one you say to delete?
    there is a smitrem folder is this ok?
    can I copy and print a screen cap for you to see? If so how (I cant remember sorry?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The GetRunKeys procedure tells you exactly where to look for the file. C:\runkeys.txt

    The directions for Spyfalcon and others tell you the same thing for the smitfiles.txt log. It should be c:\smitfiles.txt
     
  6. radstar

    radstar Private E-2

    I am hoping this works. Here is the runkeys.txt file if I have been succesful I am still looking for the smitfile.
    Youre help is greatly appreciated this has to be the most valuable website out there.
    Once my pc is cleaned I would like to puchase a tshirt or something in appreciation for your help.
     

    Attached Files:

  7. radstar

    radstar Private E-2

    I found the smitfile. here it is. Hope this stuff helps.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure if you are running the correct procedure and deleting the files as indicated. It looks like you may still be infected based on your logs. Please follow ALL steps in the below procedure from beginning to end (even if you don't find things being mentioned just continue).

    SpywareQuake & SpyFalcon Removal Procedure

    When finished, attach the new smitfiles.txt log that is created. Also tell me which items you found and deleted. Things that I think that may still be there are the below files but running SmitRem again my delete some:
    C:\WINNT\system32\reglogs.dll
    C:\WINNT\system32\1024 <--- the folder
    C:\WINNT\system32\ld****.tmp <--- where **** can be anything
    C:\WINNT\system32\hp***.tmp <--- where **** can be anything
    C:\WINNT\system32\ts.ico
    C:\WINNT\system32\ot.ico

    Now after running the above procedure re-run GetRunKey.bat and attach a new runkeys.txt log.

    Now tell me if you are still having problems.

    Did you purchase this: Ashampoo AntiSpyWare
     
  9. radstar

    radstar Private E-2

    I downloaded ashampoo from download.com only the trial version is this not a good idea? also followed the proceedure again but could not locate the .dll files indicated and also could not run the fixquake program it wouldnt allow it even in safe mode and offline.
     
  10. radstar

    radstar Private E-2

    ran getrunkeys again please find attached. did this change/overwrite the previouse txt file?
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to follow steps in the order given! I said run SpywareQuake & SpyFalcon Removal Procedure first. Then afterwards run GetRunKey.

    The below file still shows in your log:
    C:\WINNT\system32\reglogs.dll

    So you are not following the procedure properly!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What do you mean by fixquake program? Do you mean the fixquake.reg patch for the registry? This is not a program. What happens when you double click on this registry patch?
     
  13. radstar

    radstar Private E-2

    I finally think I got it right. I did delete the reglogs file but could not delete dcomcfg. and when I click yes add to registry for fixquake.reg a pop up says
    "registry error cannot import C:\Documents:Error opening the file there maybe a disk or file system error"
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like you did not save the file properly. Exactly where did you save it? Do you have viewing of hidden files and also EXTENSIONS for known file types enabled? Is the file saved as fixquake.reg? Are you sure you saved the whole quote box to a file?

    Try downloading the attached ZIP file. Extract the fixquake.reg file from it to the root folder of drive c (that is you should have c:\fixquake.reg when you do this). Then from Windows Explorer, locate c:\fixquake.reg and double click on it and allow it to add to the registry. Did this work?

    If it does give you a success message, now get a new runkeys.txt log and post it.

    Also as far as the Ashampoo trial program is concerned, I would suggest uninstalling it. If you want to buy something, buy Spy Sweeper which is one of the best tools out there.
     
    Last edited: May 10, 2006
  15. radstar

    radstar Private E-2

    Ok I know how tired you must get dealing with newbie's like me (thank you for your patience) I finally managed to get fixquake.reg to work here is my new runkeys file
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! So now the infected registry keys and files are finally deleted!

    Are you having any other malware problems?
     
  17. radstar

    radstar Private E-2

    I have one remaining issue I cannot set Internet explorer to use anything other the res://c:\winnt\system32\shdoclc.dll/navcancl.htm as a home page and this is a bad url totally messes with IE.
    I found the shdoclc.dll file but it wont let me rename or delete it I think I tried this even in safe mode but I'm not sure.
    anyway of removing this little bug completely?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You cannot delete shdoclc.dll. It is a file that you need on your system. See: http://www.liutilities.com/products/wintaskspro/dlllibrary/shdoclc/

    Perhaps you had more malware problems on your system than just SpyFalcon! Let's find out.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    1. Click Start > Run.
    2. Type regedit

      Then click OK.
    3. Navigate to the key:

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs
    4. In the right pane, reset the values for the following keys (The values listed here are the defaults. Your system values may have been different):

      "NavigationFailure" = "res://shdoclc.dll/navcancl.htm"
      "NavigationCanceled" = "res://shdoclc.dll/navcancl.htm"
      "OfflineInformation" = "res://shdoclc.dll/offcancl.htm"
      "blank" = "res://mshtml.dll/blank.htm"
      "PostNotCached" = "res://mshtml.dll/repost.htm"
    5. Exit the Registry Editor.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds