Restarted computer, Things have changed

Discussion in 'Malware Help (A Specialist Will Reply)' started by whateveryousay, Aug 8, 2007.

  1. whateveryousay

    whateveryousay Private First Class

    I restarted my computer and when I started it back up, Windows reverted back to the original appearence. I lost my wallpaper, I lost certain programs and all of my pictures, video and music is gone. When I open the C: drive, it tells me that my files are hidden. I ran the check dsk at the beginning of startup and still nothing changed. What is going on?


    EDIT: my programs won't run either. When I tried to run CCleaner its reason for shutdown was "Kernel32.exe". When I ran hijack this, I noticed new entries like
    "Protocol Defaults IVT protocol is in my computer zone, should be in Intranet zone"

    There are a string of these.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    System crashes and similar are topics for the Software or Hardware Forum and that may be what the problems you are describing are related to.

    Let me first ask have you tried using System Restore (that I previously had you enable) to go back to a point in time before these problems started. This will not restore any pictures, videos or music if they are really gone but it may fix other problems.

    Other than the above, your alternative is to run the below so we can determine if you are having any malware isssues.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. whateveryousay

    whateveryousay Private First Class

    I actually found my pictures. I right click start, explore all users and they are under my folder name section. Also, how do I use counter spy? Last time you told me to delete it. Can I just reinstall it?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You will need to use AVG Antispyware since your trial period (15 days) for CounterSpy will have already expired since you first installed it.
     
  5. whateveryousay

    whateveryousay Private First Class

    I just tried to download get run keys and show new keys programs but I just found out that I cannot download anything. It won't let me download anything at all.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You will then have to use another PC to do your downloading and then transfer them to this PC somehow. Like a USB flashdrive...etc. The same goes for getting your logs back off of this PC if you cannot upload them from it.

    Did you even think about using System Restore as I suggested already?
     
  7. whateveryousay

    whateveryousay Private First Class

    I disabled it because everytime I restarted it was using up more and more memory.
     
  8. whateveryousay

    whateveryousay Private First Class

    When I went into control panel, and tried to select user accounts or anything of the icons, it said that windows couldn't find run32dll. The only thing that I could post tonight would be the hijack this log.

    EDIT: nm. Can't even do that because it won't find the hijack this logs.
     
  9. whateveryousay

    whateveryousay Private First Class

    when I tried to run panda scan here is the error message that I received:

    Possible causes of this error are:

    Not allowing the application's ActiveX control to be downloaded.

    Problems with the Internet connection.

    The error could be due to a download error or an installation error due to lack of hard disk space, privileges etc.,...
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Very bad idea! It could have saved you from having to fix your PC and possibly formatting it if we cannot fix it. And that maybe the case since I tend to doubt your problems (at least not all of them) are malware. From what I remember last time you were here you still had a variety of Windows OS problems not malware. Perhaps it is time you formatted and reinstalled.

    And as I said to you last time, System Restore does not use memory. It use disk space. And you probably would have plenty of diskspace if you removed pictures, videos and MP3s.

    How large is your hard disk and how much free space is there?
     
  11. whateveryousay

    whateveryousay Private First Class

    my harddisk capacity is 16 GB and I have 1.67 GB left.

    The reason it could possibly be malware is that about 2 days ago, my computer froze and when it restarted my computer detected trojans and asked if I wanted to delete them. I said yes. Then it said that your computer may have lost essential files, insert your windows xp cd. It worked fine after that and then now this happens. I don't know if its connected. I don't have a windows XP cd. I looked all over for it and cannot find.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You really should purchase a larger hard disk especially if you plan to keep storing large amounts of pictures, videos, and MP3s. Do you have a DVD or CD writer installed? If so, backup some or all of these files and get them off your hard disk while you still can. Also these will give you more free disk space and your PC will perform better. You need to have System Restore enabled.

    Your computer did not detect the trojans. A program you have running detected them. Which program detected these trojans and what were they and where were they located.

    If it worked fine after this and now you are having problems again, it still may not be malware.

    Then how did you fix using a CD in the above statement. You need to buy a Windows XP CD. It is very important to have one especially for times like this. Without a CD you cannot fix many problems and you also cannot reinstall (unless you have some system recovery disks that came with your PC, but that puts you back into the state you PC was shipped which is normally very old and full of unncessary junk).


    Do you have the ability to get me logs from GetRunKey, ShowNew and HijackThis?
     
  13. whateveryousay

    whateveryousay Private First Class

    I am able to post hijack this. I cannot download the other programs. So I attatched the hijack log to this post.

    Is there any point in turning on System Restore now given that my computer
    is currently messed up?
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It will not help you now. There are no restore points to restore to since you disable it.

    Do you really need Paltalk? Read the below which is well known about it:

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone
    O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone
    O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone
    O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
    O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone

    After clicking Fix, exit HJT.


    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!


    Can you somehow get the below fixME.reg patch onto your PC and follow the directions given?

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now attach a new HJT log. Any change to your ability to download?
     
  15. whateveryousay

    whateveryousay Private First Class

    I don't think the hijack this log changed at all. When I tried to reset web settings it said that it was unable to do so. I couldn't find internet explorer through control panel so I just tried it with the open browser. Also Fixreg didn't do anything. I am not sure if I am supposed to have a program on my computer for it to work but I saved it, merged it with my computer but I still cannot download anything.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you double clicked on fixME.reg did you get a message at the end that said it was successfully added to the registry?

    Where is the new HJT log?

    You say you cannot download anything but does the PC connect to the internet and can you surf and access this forum with it. In Internet Explore click Tools and select Internet Options. Click the Security tab and then select the Internet zone by clicking on the globe icon. Then at the bottom of the form click the Default Level button and then click Apply. Then at the top of the form select the Advanced tab and then at the bottom of the form click the Restore Defaults button and also click Apply. Then click OK to close the form.

    Now reboot your PC. Any change?
     
  17. whateveryousay

    whateveryousay Private First Class

    This has led me to something interesting. I went to internet zone in the security tab but could not change it to default because it was greylisted and I couldn't click on it. So I clicked on custom. Everything within that is checked to disable. As I said before, my wallpaper was gone and I couldn't download. "Display desktop items" and "save downloads" are both clicked on disabled. When I changed the save download to enabled, I still couldn't download but I am going to restart my computer to see if that works. It is strange though how everything within the internet zone was set to disabled. What do you think?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to answer all of my questions.
     
  19. whateveryousay

    whateveryousay Private First Class

    sorry Chaslang.

    Yes, when I double clicked Fixme.reg it said that it merged with the registry.

    I attatched the new Hijack this log to this post but I don't think anything changed. (When I try to change things, it doesnt seem like the information saves or changes. It just stays the same). Note: A certain program runs. Eyeball chat and a disclaimer poped up that said, "You cannot save any information through this account". It is like I am on a different account that restricts me from doing certain things. When I went under internet options under internet explorer and into the globe icon, under user authentication, Logon, it has me checked as "Annonymous".

    There has been no change after I tried to change the internet settings. I can surf the net. I am on the bad computer right now. I can do everything that I could normally do when using the internet except for downloading and I cannot run certain programs (CCleaner, MSN, etc).
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is your user account name?

    Now see if you can do the below.

    Click Start, Run and enter cmd and click OK. This should open a command prompt window. In the command prompt window enter the below command

    net localgroup Administrators

    tell me what user names are listed down under the word Members
     
  21. whateveryousay

    whateveryousay Private First Class

    Under Members there is just a line going across. Under that line is

    "Administrator"
    "Blakey"
    "The command completed successfully"

    Note: I might want to add that when I typed in "Cmd"
    the line says, "C:documents and settings/TEMP.BLAKE>"


    Usually it is just documents and settings. I don't know where the "Temp.blake" is coming from. I never named my account that. My account is named "blakey".
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like you are logging into the wrong user account to me.
     
  23. whateveryousay

    whateveryousay Private First Class

    but how? In the past I only had blakey. Then one time, my computer freezes and when I restart this happens. I didn't change anything. When I right click start and explorer all users it says the accounts are "TEMP", "TEMPBLAKE" and "Blakey". I never created a "TEMP" or a "TEMPBLAKE".
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I cannot explain how you got like this, but you are not logging into the correct account. And the current account is a restricted user account which is preventing you from doing anything. Logout and log into the correct user account.
     
  25. whateveryousay

    whateveryousay Private First Class

    how? When I get to the main screen, it says, click your username to log on and the only option is "Blakey"
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What happens if you select Log Off and use Switch User?

    Also try booting in safe mode and login to the Administrator account and then make sure your other accounts have administrator priviledges.

    Your problems at this point are not malware related but rather related to something your have done to your operating system. I will have to suggest that you continue in the Software Forum.
     
  27. whateveryousay

    whateveryousay Private First Class

    It sends me back to the logon screen and says "You are logged on as "Blakey", when i try to logoff or switch the user. See, it still has me saying that I am logged in as "Blakey". I don't know where this "TEMPBLAKE" junk came from.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do what I said when logged into the Administrator account which only appears in safe boot mode.

    Do you still have copies of GetRunKey and ShowNew on your PC?
     
  29. whateveryousay

    whateveryousay Private First Class

    Chaslang, I found the lavasoft adware program on my computer and ran it. It detected that I had the "Win 32.backdoor agent and win 32 trojan downloader agent". They were both identified as a virus. Some of the critical objects that showed up were

    "System/currentcontrolset/services/vfilt/"
    "System/currentcontrolset/services/vfilt/start"
    "System/currentcontrolset/services/vfilt/ error control
    "System/currentcontrolset/services/vfilt/ display name

    "System/currentcontrolset/services/vfilt/ group

    "System/currentcontrolset/services/vfilt/ winlogon

    I noticed an

    "win 32.trojandownloader.agent/winlogon/auto admin login"

    I will attatch all that it said. So check that out.
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Vfilt is a service that is used by Outpost firewall. Do you have it installed or did you have it installed at one time.

    Also Ad-ware showed the service named Bits which is also valid and is part of Windows and used by Windows Update. User service just may not be in the correct state but it is not a trojan downloader. It is probably in the wrong state because you are not logged into an account with admin priviledges. Also the AutoAdminLogin entry is probably because you set your system to allow a user to automatically logon at any Windows network computer without giving a password. (not a good idea especially if you set this up this way)

    You still need to do what I requested in my last message and remember to answer questions.
     
  31. whateveryousay

    whateveryousay Private First Class

    I logged in my administrator account on safemode and it looked just like this account.
    I can't find the getnew and shownew programs on my computer. I think you told me to download it to desktop and its not there.

    "Also try booting in safe mode and login to the Administrator account and then make sure your other accounts have administrator priviledges."

    Where do I see what priviledges "blakey" has? Yes I used to have outpost firewall. I tried to get it to work and it never would. I am not sure where it would be on the computer if I still have it.
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    From Control Panel, User Accounts. However you may not be able to run this either. None of these issues are malware issues. You have some how corrupted your registry or at least your user profile (and probably the Administrator profile). I still suggest your best bet is to work thru these issues in the Software Forum since none of this is malware related. If you had not disabled system restore, you more than likely would have been able to use it to fix your problem.


    It does not matter. I just wanted to know since I was telling you that Ad-Aware did not find any valid issues. They left overs from Outpost.
     
  33. whateveryousay

    whateveryousay Private First Class

    okay man. Thanks for the help anyway. I am going to try creating a new user account. How do I do this and does this delete everything from "blakey"?
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Creating a new user account will not remove anything from the other accounts; however I'm beginning to doubt you will be able to do this anyway. Your account seems to have too many restrictions placed on it and you could be missing various system files based on some of the problems you have experienced. You create new accounts from From Control Panel, User Accounts.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds