Serious Problems getting worse

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by smssoleimani, Jun 12, 2007.

  1. smssoleimani

    smssoleimani Private First Class

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome and good luck. You may find that just editing the path text in a notepad window to remove the dupes and then copy and pasting back to the Path box will work.
     
  3. smssoleimani

    smssoleimani Private First Class

    Yeah, but I don't want to mess anything up, and cause a problem.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Either way you are still going to be the one editing the path and making the changes. ;) Just paste it into notepad, you can easily see the duplicates.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'll even do you the favor since I have a few minutes right now before I sign off! ;) The below is what you need to overwrite the current path with.

    c:\windows\system32;c:\windows;c:\windows\system32\wbem;c:\opensa\apache2\bin;c:\program files\pinnacle\shared files;c:\program files\pinnacle\shared files\filter;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Common Files\Ahead\Lib\;c:\perl\bin\;

    If you still don't know how. Try the below.

    Now Copy the bold text below to notepad. Save it as fixPath.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  6. smssoleimani

    smssoleimani Private First Class

    OK, I did it, now what, how do I know if it worked?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Look in a new log from ShowNew at the Path environment variable and compare it to an older log. The path variable is around line 49.
     
  8. smssoleimani

    smssoleimani Private First Class

    If I got the right thing, this is what it is:

    I think it might have changed.

    I uninstalled "C:\Documents and Settings\Owner\Desktop\LimeWire\stuff\Software, Programs, Games\My Programs\Circumventor\ActivePerl\bin\" or well at least the program ActivePerl, a little while back, along with the "opensa and apache2" that is weird. I see a lot of repitition of those, there prob shouldn't even be 1 of them because the program was uninstalled. Most of those entries were from these two programs: "ActivePerl 5.8.3 Build 809" and "OpenSA web server 2", but I uninstalled them. And what is this "Pinnacle" I don't even think I have that program anymore, or if I do I dont use it.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If that is still showing in a new log, you did not get the path variable changed. You should edit it yourself manually.

    Pinnacle may be an external harddisk or a backup drive of some sort.
     
  10. smssoleimani

    smssoleimani Private First Class

    I really don't know how...

    I checked the old and the new one. Only change is the last line of the old one is gone ";C:\Program Files\Common Files\Ahead\Lib\;C:\Program Files\Common Files\Ahead\Lib\" meaning the new one has everything the same form the old one, except the last line(ish) has been removed.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run the Registry Patch I gave you?
    Did it merge in successfully?

    Did you reboot after running the patch? If not, please reboot. I forgot to tell you that.
     
  12. smssoleimani

    smssoleimani Private First Class

    I believe it did work, I didn't reboot though. Can it hurt to do it again, then reboot, then redo a new scan to see if anything changed?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Apply the fixPath.reg patch again and then reboot. After reboot attach a NEW log from ShowNew.
     
  14. smssoleimani

    smssoleimani Private First Class

    OK, here it is.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way are you sure you don't need the Perl and Apache items. You still show and Apache service loading. Is anything for that still installed.

    Also I don't think you ever remove the Freenet and GNUnet stuff either.

    Just to be clear, none of the above nor the issue with your PATH is malware related.
     
  16. smssoleimani

    smssoleimani Private First Class

    Positive! How should I stop the service?

    How should I? Didn't see anything in Add/Remove. I have to sign off now, its 2 am lol. I will be on tomorrow (later today) to follow up. Thanks!
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    While doing the below Services steps, ignore any error messages and complete all steps.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Freenet 0.7 darknet-8888
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below two Services (if you do not find them or get any errors, just continue):
      • Apache2
      • GNUnet
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste freenet-darknet-8888 into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below two Services (if you do not find them or get any errors, just continue):
      • Apache2
      • GNUnet
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after another registry patch.
    Note the path change did not work. Let's try another patch and also I will remove the other items you say you don't need from Apache and Perl.


    Now Copy the bold text below to notepad. Save it as fixPath.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now reboot!

    Delete the below folders if they exist:
    C:\Program Files\Freenet
    C:\Program Files\GNU
    C:\OpenSA\Apache2

    Now attach new logs from ShowNew and HJT.
     
  18. smssoleimani

    smssoleimani Private First Class

    OK, all done with no errors. Freenet folder was full of stuff but deleted anyway. GNU was empty and deleted. I did not find "C:\OpenSA\Apache2". Logs are attached.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay your HJT log is fine but your path is still messed up. Try doing the below.


    To Fix the PATH Environment variable
    1. Right-click My Computer and select Properties.
    2. Select the Advanced tab.
    3. Click the Environment Variables button.
    4. In the System variables area (the bottom part of the form), locate the PATH variable, select PATH (by clicking on it) and click the Edit button! In the next popup window you need to edit the Variable value: so that it looks like the below (you can copy and paste the below string into it but you must backspace/delete over what is there already)
      c:\windows\system32;c:\windows;c:\windows\system32\wbem;c:\program files\pinnacle\shared files;c:\program files\pinnacle\shared files\filter;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Common Files\Ahead\Lib\;
    5. Then click OK.
    6. Then click OK again to close the Environment Variable window
    7. Then click OK to close the System Properties window
    8. Now Reboot your PC for the change to take effect.
    After reboot, attach a new ShowNew log and tell me if you had any problems doing the above!
     
  20. smssoleimani

    smssoleimani Private First Class

    No problems while doing it. Log attached.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's better but you still have 3 duplicate items. You must make sure that you delete all aspects of what is in the path variable box first before pasting in the new path.

    You now have this:
    c:\windows\system32;c:\windows;c:\windows\system32\wbem;c:\program files\pinnacle\shared files;c:\program files\pinnacle\shared files\filter;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Common Files\Ahead\Lib\;C:\Program Files\Pinnacle\Shared Files;C:\Program Files\Pinnacle\Shared Files\Filter;C:\Program Files\Common Files\Ahead\Lib\

    And you should have this:
    c:\windows\system32;c:\windows;c:\windows\system32\wbem;c:\program files\pinnacle\shared files;c:\program files\pinnacle\shared files\filter;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Common Files\Ahead\Lib\;

    The below is a duplicate set which you have added to the end somehow:
    C:\Program Files\Pinnacle\Shared Files;C:\Program Files\Pinnacle\Shared Files\Filter;C:\Program Files\Common Files\Ahead\Lib\

    You need to strip these dups off of the end.
     
    Last edited: Jun 21, 2007
  22. smssoleimani

    smssoleimani Private First Class

    So I just go in there and delete

    or deleted everything in the "variable value" field and replace it with

    And I should be good after that. Or will it come back?
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have to delete that string from the end. Don't forget it is appearing twice. You don't need the second one (I don't even know if you need the first since I'm not really sure what you use on the PC). No it should not come back unless something you are running is adding it back.
     
  24. smssoleimani

    smssoleimani Private First Class

    So delete that string, and reboot. Thats it? Can or should I get rid of both. I don't know what it is, or even use the program "Pinnacle" and I believe Ahead is from Nero.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes edit and reboot.

    The rest is up to you to decide. If you don't need the Pinnacle item in your path then remove it. It you find out you need it later, you can just add it back in the same way you are editing the path right now.
     
  26. smssoleimani

    smssoleimani Private First Class

    I didn't do it yet. I was about to, but I think its fixed. Take a look at what it is now (before I did anything, as it is right now):

    I don't see any duplicates. There is:

    c:\program files\pinnacle\shared files;

    and

    c:\program files\pinnacle\shared files\filter;

    doesn't the "\filter;" make it not a duplicate?

    And I think I might just delete the stupid "c:\program files\pinnacle\shared files\filter;"
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That path is fine unless you decided you want to remove anything else (like Pinnacle)
     
  28. smssoleimani

    smssoleimani Private First Class

    So can it cause a problem if I get rid of the Pinnacle?
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Depends on your definition of problem. You said you don't even know what it is for which sounds to me like you therefore should not need it unless you don't know what hardware and software you use on your PC. Even if you remove it and then find you have a problem with something, you can always add it back.
     
  30. smssoleimani

    smssoleimani Private First Class

    OK ill get rid of it now. I'll also show a before and after. But which one do I get rid of?

    c:\program files\pinnacle\shared files;

    or

    c:\program files\pinnacle\shared files\filter;

    or both
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you don't need Pinnacle then you don't need any of Pinnacle. Rather a simple decision.
     
  32. smssoleimani

    smssoleimani Private First Class

    Problem:

    The Windows Environment Variables says its this:

    But, the ShowNew log says its this:

    What gives?

    I have a quick question. Why are some files on my computer, like the name is in light blue font, and other files are normal black font? I didn't do anything to them. I realized it when I went into a music folder of mine, and some are black font some are light blue.
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't know. ShowNew is only giving you the info that Windows is providing from a DOS prompt. You can see this yourself by simply typing set at the command prompt.

    Compressed files will show in blue.
     
  34. smssoleimani

    smssoleimani Private First Class

    I went to the command prompt and typed in set. Went down to the area where it shows the "path" and it came up with this:

    When I fixed it...I don't know which one is correct now, or what to do about it. The one in the properties of "My Computer" are:

    So the one that the command prompt gave me isn't very good at all. But the one "My Computer" gave me is good.
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I wouldn't bother wasting anymore time on it now. It is alot better than it was. If you wish to continue with it for any reason, you will have to continue in the Software Forum thread you started.
     
  36. smssoleimani

    smssoleimani Private First Class

    Why does my computer always have some type of problem. Get this. As I restarted my computer, a message shows up saying:

    "invalid boot.ini loading from c:\windows"

    Whats is this. OMG. Always something wrong.
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I cannot answer your question but it is more than likely due to something you are doing.

    If you still have problems with your boot.ini file, post in the Software Forum for help. You may need to rebuild your boot.ini file.

    You can also see info about your error message here: http://rselby.net/boot.htm#wxpibih
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds