RUcrzy trojan wont stay removed

Discussion in 'Malware Help (A Specialist Will Reply)' started by runlittlejimmy, Apr 28, 2007.

  1. runlittlejimmy

    runlittlejimmy Private E-2

    When i run my superantispyware scan it finds only two virus Trojan.Downloader-MSNETAX (C:\Windows\System32\o.dll) and Trojan.Spam-RUCrzy (C:\CP1041.nls) and everytime i click to remove them with in minutes of restarting my computers they come back again.
    Its causing my interent explorer only to work certain times like when i first restart my computer for the first 5-10 minutes. I have already removed the O.dll Using LSP-fix.

    Below is my hijack this scan log Please HELP

    Edit: removed inline HJT log for guide to be actioned
     
    Last edited by a moderator: Apr 28, 2007
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.




    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. runlittlejimmy

    runlittlejimmy Private E-2

    Oh im sorry about that, Here are the two anti-virus scanner results
     

    Attached Files:

  4. runlittlejimmy

    runlittlejimmy Private E-2

    here are the two online scanners
     

    Attached Files:

  5. runlittlejimmy

    runlittlejimmy Private E-2

    and lastly the runkeys, newfiles, and hijack this results
     

    Attached Files:

    Last edited: Apr 30, 2007
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you been working on this problem at another malware removal forum? If so, why are you now coming here in the middle of working with someone else?

    I see the below which would indicate that you have been working elsewhere:


    C:\_OTMoveIt\MovedFiles\cp1041.nls

    I also see the Pocket Killbox was being used!

    Did they also have you download LSP-fix? It looks like it based on your logs!


    Are you using any programs to control startups? I see many things disable with MSConfig but MSconfig appears to be in Normal Startup mode.


    Follow the steps below in the order written!!


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the osfupiqlk.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move osfupiqlk.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.
    If it is already in the Remove section, just click Finish.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [RealTray] "C:\Program Files\Real\RealPlayer\RealPlay.exe" SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    After clicking Fix, exit HJT.



    Download the attached LJFix.zip file to your Desktop and extract the LJFix.bat file from it to your Desktop. Then double click on irishFix.bat to run it. This will create a log file named c:\FixND.txt

    NOTE: After running this you will not be able to shutdown or restart your PC in the normal fashion. You will have to hold in the power button on your PC until it powers down.

    • Now close ALL open windows now!!!!!
    • Power down your PC now. Wait about 15 seconds and then power back up.
    • After reboot Attach the c:\FixND.txt file here. Then continue on to the below instructions!

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Now also uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 2
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.1_06
    Java 2 Runtime Environment, SE v1.4.1_07
    Java 2 Runtime Environment, SE v1.4.2_03
    Java 2 Runtime Environment, SE v1.4.2_05
    Java 2 SDK, SE v1.4.1_07E

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment



    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\ntos.exe
    C:\WINDOWS\SYSTEM32\osfupiqlk.dll
    C:\WINDOWS\n_cnzxzg.txt
    C:\_OTMoveIt\MovedFiles\cp1041.nls
    C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But if you do get this message, please let me know!)

    If Killbox does not reboot just reboot your PC yourself.

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     

    Attached Files:

    Last edited: May 1, 2007
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see you just logged in while I have been working this.

    If you have not noticed, I have been editing and adding to the procedure in message # 6 so please refresh your page and re-read before continuing.
     
  8. runlittlejimmy

    runlittlejimmy Private E-2

    Hey i would just like to thank you in advance, and yes I have tried multiple things already to fix my problem but none of them fixed the problem, sorry about this. Well heres the FixND log. And also i was wondering i installed counterspy and well every time I restart the computer this yellow bog will appear in bottom right of corner saying "a program not recognized by couterspy, sample LSP installer (totour.exe), is changing a system startup location in the registry. Should i quarantine, Allow, or Block.
     

    Attached Files:

  9. runlittlejimmy

    runlittlejimmy Private E-2

    Hey everything went very smooth, nice communication. Heres the logs, i still have to restart my computer to see how things run.
     

    Attached Files:

  10. runlittlejimmy

    runlittlejimmy Private E-2

    I'll reply back tommarow though, I'm going to hit the sack now. thanks for your help.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It did not work as desired. I'm attaching a new version of LJFix.zip. Extract it like the last time overwriting the previous file. However this time, make sure you boot into safe mode first, and then run the LJFix.bat file. After running it POWER DOWN like before, and then reboot and attach the FixND.txt log here.

    That's part of this malware and I was wondering why it was not showing yet. Quarantine it and if it gives you an option to delete the file, delete it.

    Please keep your PC in Normal Startup mode!! You now appear to be using MSconfig to control starups (i.e. a form or Selective Startup mode). Run MSconfig and select Normal Startup.


    Now attach new logs from GetRunKey and ShowNew.
     

    Attached Files:

  12. runlittlejimmy

    runlittlejimmy Private E-2

    Ok heres the new fixND, GetRunKey, and ShowNew logs. and theres a problem my local area connection doesnt work anymore, i restarted my computer and my local area connection was disabeled so I clicked to enabel it; at first a popup box says "Enabling" for like a sec but then the text changes to "connection failed!", is this normal.
    But one good thing i see is that cp1041 is no longer in explore.exe threads.
     

    Attached Files:

  13. runlittlejimmy

    runlittlejimmy Private E-2

    I'm just wondering if i should now delate C:\cp1041, hmmm.
     
    Last edited: May 1, 2007
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No this is not normal but the file we were trying to replace (ndis.sys) was infected and was part of your problem. It was also why you could not get rid of the cp1041.nls file. If ndis.sys had not been replace properly (and it looks like it was), you would lose connectivity.

    Please attach a current HijackThis log.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When did this happen?
    Does it happen all the time?
    If it is at boot up, try booting in safe mode and tell me what happens.
     
  16. runlittlejimmy

    runlittlejimmy Private E-2

    I cant seem to get it to happen in safe mode at all, but in normal it happens when kaspersky labs internet security 6.0 starts to load in the buttom right tray after i start up the computer.
     
  17. runlittlejimmy

    runlittlejimmy Private E-2

    Well i just uninstalled kaspersky lab and i can aleast start up windows in normal mode for more than 2 minutes. heres the log
     

    Attached Files:

  18. runlittlejimmy

    runlittlejimmy Private E-2

    But I instead get a popup box that says "The system has recoverd form a serious error.
    A log of this error has been created."

    and two Buttons "Send Error Report" or "Don't Send"

    Well i gotta go right now and milk cows, but ill be back in like 2 hours or so, thanks for your help.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are you installing something new right in the middle of our clean up efforts and also that I did not ask you to install?

    Yes you do need an antivirus and a firewall (not a security suite) but I did not ask you to do this.

    Is that HJT log from normal boot mode or safe boot mode?


    Goto Add/Remove programs and uninstall the below:
    Internet Explorer Default Page
    Symantec Network Drivers Update



    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
    O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll (file missing)
    O16 - DPF: {CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_06) -
    O16 - DPF: {CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_07) -

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete

    C:\$RJ$.DAT
    C:\cp1041.nls
    C:\delete.bat
    C:\WINDOWS\SYSTEM32\lrw.dll
    C:\WINDOWS\SYSTEM32\tamnjql.dll
    C:\WINDOWS\SYSTEM32\zpbqupo.dll

    Now run Ccleaner

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
    Last edited: May 1, 2007
  20. runlittlejimmy

    runlittlejimmy Private E-2

    Hey im sorry about installing the program, i didn't know it would affect anything and i just wanted to see if i still had pesky virues. NEVER AGAIN!
    I didn't find neither of the two programs in add or remove programs is this alright? and i just got done removing things from hijackthis.
     
  21. runlittlejimmy

    runlittlejimmy Private E-2

    Here are the logs, the viruses look to be gone but i am still unable to enable my local area connection.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you remembering to click Fix Checked with HijackThis? Something is blocking some of out fixes. Let's approach this a little differently.

    First uninstall SuperAntiSpyware and Trojan Hunter since they could possibly causing us a problem.



    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    After reboot if you are still having problems with your getting a connection to the internet, please run the LSP-fix and tell me the names of all files you see in both the Keep column and if any are in the Remove column give me those names too.


    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's look for some more details so we can manually remove them.

    Run this: Getting Uninstall Programs List From The Registry and attach the requested log.
     
  24. runlittlejimmy

    runlittlejimmy Private E-2

    GetUnKeys.txt is attached below

    dang, i'm still unable to enable Local Area connection.

    LSP-Fix by cexx.org - v1.1

    No Problems found

    KEEP

    mswsock.dll Tcpip
    winrnr.dll NTDS
    nwprovau.dll NWLink IPX/SPX/NetBIOS Compatible Transport Protocol
    rsvpsp.dll (Protocol handler)

    Remove
     

    Attached Files:

    Last edited: May 1, 2007
  25. runlittlejimmy

    runlittlejimmy Private E-2

    oh no, when you click on search the only the dog is sitting threre, theres no text or textboxes, :cry my computer is getting worst then it already was. Jeeze my life is just great, we get the files off and to stay off but now are getting punished :(
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nothing I have had you do has anything to do with this. However installing Kaspersky Security Suite in the middle of all of this and then uninstalling may have caused issues. But I cannot say that for certain.

    I'm still waiting for you to complete ALL of the instructions in message # 22.
     
  27. runlittlejimmy

    runlittlejimmy Private E-2

    Dude I'm not blaming it on you, hell your working hard to try and help me, your awsome:cool Heres the logs your requested sorry there late.
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below will remove those two items I asked you to uninstall but you could not find!

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not follow instructions or you had an error! SuperAntispyware still shows!


    Did you click Fix checked with HijackThis?

    Did you remember to close ALL browsers before clicking Fix checked?

    Did you run the Reset of web settings step?
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you obtained you HijackThis log why were the below running?
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ntvdm.exe
    C:\WINDOWS\system32\notepad.exe
     
  31. runlittlejimmy

    runlittlejimmy Private E-2

    well thats weird, I uninstalled it from add and remove programs, i even just checked the list again its not there but i looked and its still in program files should i just delate it then
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I will give you steps but first did you do message number 28.

    You did not answer my questions in message # 29.

    Also did you see message # 30?


    Is the connection you are having a problem with a wireless connection? If so, do you have a wired connection you can try?
     
  33. runlittlejimmy

    runlittlejimmy Private E-2

    ok i just delated superspything and i guess i do the 3 scans again. I thought u said not to have a browser up as in a web browser and i didn't.
     
  34. runlittlejimmy

    runlittlejimmy Private E-2

    oh my gosh im bad and slow, so sorry. OK i did what u said in message 28 and in reply to message 29 yes i did click fix and yes i did have open notebook and cmd because i just got done running the newfiles scan.
     
  35. runlittlejimmy

    runlittlejimmy Private E-2

    gosh im probely the worst guy you ever helped, im so sorry. Heres the logs

    and i did notice that

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    keep coming back after i check and fix them and this time i had all windows closed
     

    Attached Files:

  36. runlittlejimmy

    runlittlejimmy Private E-2

    And in reply of question post 32. It is a wired connection and i also found out im not the only one with this network problem
    http://www.techwarelabs.com/community/showthread.php?p=64369

    do u think installing new driver would help or not, heck your probely not even helping me anymore, gosh im a dumb#*$
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They should all be closed before you run HijackThis!
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It may or may not help! In the link you referenced, the person deleted ndis.sys which will definite cause a problem with connectivity. We did not delete the file, we made backup of the malware file and then replaced the bad file with a good copy from another folder on your PC.

    Give the below a run first to see what happens:

    XP TCP/IP Repair
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not yet! ;)


    Okay! I needed to know that you were running the fix properly. This probably means that your registry keys have been blank out.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  40. runlittlejimmy

    runlittlejimmy Private E-2

    :D ok i ran the tcp/ip reset and then restarted but still no luck. I have a question why under network adapters in the device manager do i have four deffernt adapters, i should really only have one right, there are

    Broadcom 440x 10/100 Integrated Controller working fine

    Broadcom 440x 10/100 Integrated Controller -
    Packet Scheduler Miniport not working

    WAN miniport (IP) - Packet Scheduler Miniport not working

    WAN miniport (PPTP) not working
     
  41. runlittlejimmy

    runlittlejimmy Private E-2

    and heres the logs if you want them after i completed all your steps, but i have to go to bed at the moment, thanks again.
     

    Attached Files:

  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not necessarily. These may all be part of your hardware. For example on the PC that I'm on right now, I have only one 10/100/1000 BT interface but three items show under Network Adapter. One is the Gigabit interface and the other two are for two firewire ports.

    Do you have the drivers for your hardware so that they could be reinstalled?
     
    Last edited: May 3, 2007
  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's fix a few other things! These will not fix your network connection issue but they need to be done.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    After clicking Fix, exit HJT.

    Now reboot in normal mode
    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now locate the below folders and delete it if found:
    C:\Documents and Settings\Deb\Application Data\SUPERAntiSpyware.com
    C:\Documents and Settings\Deb\Application Data\TrojanHunter
    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
    C:\Program Files\Kaspersky Lab
    C:\Program Files\SUPERAntiSpyware

    Is the below folder also related to Kaspersky? If so, delete it too.
    C:\KAV

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT
     
  44. runlittlejimmy

    runlittlejimmy Private E-2

    Exactly what drivers are you talking about, I have a driver cd that came with dell, or are you talking about windows xp driver cd, because i dont have that. Im going to do what you said in your last post right now.
     
  45. runlittlejimmy

    runlittlejimmy Private E-2

    Ok here what you asked for. and i also found out for some reason control panel - user Accounts just comes up with a white screen. Am i missing some of Windows files and if so why and how do i get them back, i dont have a windows xp cd. I do have a windows xp laptop would it be possible to use these.
     

    Attached Files:

    Last edited: May 2, 2007
  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like you have a lot more wrong with your PC than just the malware. You could be better off backing up all of your personal data and reinstalling. One other thing that may be of use, is trying to do a System Restore to a date prior to where the infection occurred.


    According to your May 1st logs, you had already downloaded and installed the below:
    Code:
    "C:\Program Files\"
    BROADCOM      May  1 2007              "Broadcom"
    BROADC~1      May  1 2007              "Broadcom Management Programs"
    I guess that means installing new software/drivers did not help.
     
  47. runlittlejimmy

    runlittlejimmy Private E-2

    noop no luck with replacing the drivers for the network. So could i just copy the files from my laptop to this computer replacing them
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What files are you referring too?
     
  49. runlittlejimmy

    runlittlejimmy Private E-2

    as in some of system32 files, some of the main ones. I checked the versions by typing in winver in the run prompt and there indentical. I dont know files like ntdll.dll and maybe kernel32.dll
     
  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which ones? And why do you want to overwrite them if the already exist?

    You only need to restore files that are missing or corrupted and that is the reason for sfc and also why you require a CD that matches your installed version of Windows.

    What is the file size and date of the below file on your laptop

    C:\WINDOWS\SYSTEM32\DRIVERS\ndis.sys

    Don't tell me the size in Kbytes. Tell me the size in bytes.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds