Serious Malware Problem after removal guide

Discussion in 'Malware Help (A Specialist Will Reply)' started by Durfio, Nov 9, 2007.

  1. Durfio

    Durfio Private E-2

    First let me thank all of you guys for having this site online in the first place. I can't tell you how much I appreciate any help at this point.

    I'm using a Dell Inspiron 6000 laptop running Windows XP Media Center Edition Version 2002 SP2.

    Initially my problem was: When I connected to the Internet sometimes another window would open with a completely unrelated site. After running Norton, Windows Defender and a-squared I started looking for help online and found this site.

    I found the malware removal guide and followed all the instructions. However I got a little confused when I was following the instructions and ran the CounterSpy scan before I was suppossed to. Stupid I know but I thought you should know. Other than that I followed all instructions from that point on including running CounterSpy scan when I was supposed to.

    I am attaching all the logs requested.

    At this point I still get the pop-ups and now I'm also getting messages poping up on my taskbar. "Security Alert: Spyware Found" There are a few different messages telling me to click on the baloon to download antispyware. I have not clicked on the baloon. I've got enough problems already. I also notice anti-spyware ads on websites that should not have them so I've also avoided clicking on those ads.

    Again thank you to anyone who helps. I really appreciate it.
     

    Attached Files:

  2. Durfio

    Durfio Private E-2

    Here are the other files.
    I tried to upload Counterspy2.txt which is from my second scan (the one I ran at the correct time) however I keep getting a message upload of counterspy2.txt failed.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    Java 2 Runtime Environment, SE v1.4.2_03
    Viewpoint Media Player

    Reboot and install:
    Java Runtime 6

    You did not attach a HJT log...we need it!

    When you re-ran Counterspy, did you have it remove/quarantine all that it found, as you did not do that on the first run?

    We will try to start without the logs.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Attach new logs for:
    ShowNew
    GetRunKeys
    HJT
    Avenger
     
  4. Durfio

    Durfio Private E-2

    Yes on the 2nd Counter Spy scan I quarantined everything it found as instructed.

    I turned on my machine with the intention of following your directions only to get a message "Windows could not start because the following file is missing or corrupt: <Windows root> \system32\hal.dll.
    Please re-install a copy of the above file."

    I do not have a Windows XP Media Center Edition CD as none shipped with the laptop.

    I do have a Windows XP Professional SP2 CD.

    Infected machine does not have floppy drive.

    Need advice as I don't want to make things worse.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Boot into safe mode and see if you can reboot into "Last good config" ....let me know.
     
  6. Durfio

    Durfio Private E-2

    Tried booting in safe mode but as soon as I select safe mode from the boot menu I get the same message. I tried booting from last known good configuration and got the same message.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You will need a Windows Media cd to effect the repair. Borrow one if you are able.

    You will boot into the cd ...let it copy files and then go to the option to enter the Recovery console. If the prompt is not C: type
    Cd: C enter
    COPY E:\i386\hal.dll C: enter (this is assuming your cd drive is E:)
    then after it is done, type exit to get out and try to reboot.

    Tell me it that works for you.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    To be more specific:
    Boot from your CD and follow the directions below to start Recovery Console.

    Insert the Setup compact disc (CD) and restart the computer. If prompted, select any options required to boot from the CD.
    When the text-based part of Setup begins, follow the prompts; choose the repair or recover option by pressing R.

    When prompted, type the Administrator password. (if you didn't create one try pressing enter).

    At the system prompt, type Recovery Console commands; type help for a list of commands, or help commandname for help on a specific command.

    Most likely you will need to expand the file from the CD. The command would be expand d:\i386\hal.dl_ c:\windows\system32\hal.dll. Substitute d: for the drive letter of your CD. Once you have expanded the file type "exit" to exit the Recovery Console and restart the computer.
     
  9. Durfio

    Durfio Private E-2

    I will ask anyone and everyone I know. If I am unable to find one is there anything I can do with the Win XP Pro CD?

    BTW Thank you so much for your help and patience!

    P.S. Not sure if the idea even makes sense but if I can't get my hands on a Media Center CD Would it be possible to install XP Pro without losing everything?
     
    Last edited: Nov 9, 2007
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can perform an install over Media center (upgrade)...but it would be better to do a clean install ...as in save all of your data and important files and then do a reformat and xp pro install.

    But see if you can get the Media disc ...I'm not sure that you can use the xp pro to do the recovery with ...
     
  11. Durfio

    Durfio Private E-2

    I am trying to locate a Media CD so I can follow your original instructions. I'm checking with friends and asked them to ask friends of friends, gonna go now and check the library etc... Right now I'm waiting for call backs.

    If I do have to resort to trying the Pro CD I just want to make sure I understand correctly.

    First I'd try the recovery and expand the file I need. Then restart the computer.

    If the recover doesn't work I'd have to setup Win XP Pro without formatting the drive which would "upgrade" my install to Pro edition. Then backup all my (likely corrupted) data that I want to save then run a clean install of Windows XP Pro formatting the hard drive.

    I'm imagining at this point I'd have to start over with the Malware removal guide downloading everything again and running the scans again reposting the logs, etc... to see if anything is lingering and then I could have fun installing preventive measures and re-installing everything I have and restoring my data scanning every bit as I go along.....

    Does that sound correct?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes up to the point of having to redo all the malware guides as a clean (reformatted) install of xp pro will be clean ....no malware.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds