Unable to complete initial steps!

Discussion in 'Malware Help (A Specialist Will Reply)' started by chuckm51, Nov 26, 2008.

  1. chuckm51

    chuckm51 Private E-2

    My Dell Dimension 2400 (xp home) was running ok more or less. I was trying to update my Norton Internet Security 2007, which had expired 2 weeks previously, with Internet Security 2009, using the CD. The old Norton products were removed (no longer appear on "all programs"), but the new version would not install. Suddenly, decktop icons changed appearance, desktop buttons trigger error messages. Spoke to Norton several times without success.
    I can't run my other antivirus programs, e.g. Spybot, Adaware se, Iobit advanced windows care. For example, when I try to open Spybot, I get a message asking if I want to open or save the file "Spybot-Search Destroy.lnk"
    When I click open, the same message reappears. When I try to open add/remove programs, I get a message "windows cannot open the file" which it calls "rundll32.exe. When I click to "use the Web service to find the appropriate program" to find what program created the file, I get a new window called "Windows File Association" which says Windows does not recognize the file type.
    I did run the Microsoft Onecare scanner. It found several items including a trojan called JS/No Close.R, and a browser modifier called win32/search enhancement.
    I ran the Norton malware scanner. It detected nothing.
    I am unable to open msconfig, add/remove programs, and most other files. I can access IE and websites. But the computer seems to not want to implement anything from the cd drive or let me copy .jpgs to a cd.
    So I'm stuck. I can start the computer in the safe mode, but cannot revert to a former date.
    Can you help? Norton put me with their upper level techs, who say they can clean me up for $100, but I'm cheap and sceptical
    Thanks.
    I am another first time user with a problem. But I sure appreciate your service to the public.
    I could be called an enthusiastic amateur, with more daring to experiment than knowledge.
    Thank you in advance.
    Chuck Monroe
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Some (or many) of your problems may not be malware. First you should check your C:\windows\system32 folder to see if the rundll32.exe file exists. If it does not, you need to get a copy back into this folder. The below will help you do this but you may need your Windows CD so hopefully you have one.

    Click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System Rile Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it.

    After running sfc, reboot your PC and see if there is any change to your problems.
     
  3. chuckm51

    chuckm51 Private E-2

    Hi Chaslang,

    Thanks for taking the time to look at my problem.
    I checked the windows/system32 folder, and the rundll32.3x3 file is there.
    I tried to run the sfc /scannow utility, but I get the same error message that "windows cannot open this file: sfx.exe
    If I click "OK" to use the web service to find the appropriate program to open the file, I get the Windows File Association file screen saying the file type is unknown.
    Really the same problem as all along.
    Any further ideas will be greatly appreciated.
    Thanks
    Chuck Monroe
     
  4. chuckm51

    chuckm51 Private E-2

    Hi again Chaslang,
    Subsequent to writing my last post, I went online with the infected computer and connected to Dell live chat. They took control of the computer but were unable to make any progress. The Rep said I had spyware causing the problem, not a virus. Whether that is tru or not, I don't know. He said he could not determine exactly what the infection was, as my new Norton Internet Security 2009 removed all the old Norton products first, before it tried to install the new version.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure about this message. The file name is sfc.exe not sfx.exe


    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    READ & RUN ME FIRST. Malware Removal Guide
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  6. chuckm51

    chuckm51 Private E-2

    Hi Chaslang,
    Thanks again for sticking with me. I tried to run sfc /scannow again, with the same result. The error message does call it sfc.exe. I think I just typed it wrong in my message here.
    I'll follow your instructions and report the results here.

    chuck
     
  7. chuckm51

    chuckm51 Private E-2

    Hi Chaslang,
    I undertook to follow the steps described in your Read and Run Me first post, with varying results.
    Since I cannot acces the "run" application, any steps requiring this do not work. Thus, I cannot look at possible malware in the add/remove program list. I cannot determine if Normal Startup mode exists. I cannot do anything about the Sun Java applications.
    I can't access my quarantine folders. I did empty the windows recycle bin.
    I was able to download/safe the ccleaner program. However, when I try to open it, I get the usual "Do you want to open or save this file" security warning. Clicking "open" makes it cycle and reappear.
    I was able to enable viewing of hidden files and folders.
    I downloaded all the stated files into the C:// root folder, except combofix.exe which is on the desktop.
    I tried to open superantispyware without success. I get the windows notice "Windows cannot open the file:"
    I haven't tried to open any of the other files; I thought I'd report in first.
    Thanks for staying with me.

    chuck monroe
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • Press CTRL-SHIFT-ESC to see if you can bring up Task Manager.
    • If Task Manager opens. See if you can click File, New Task (Run...) and enter regedit.exe into the box and click OK.
    • If regedit.exe runs, the Windows Registry Editor will open. If you get this far let me know.
    • If regedit.exe will not run, try renaming it or copying it into a file named regedit.com and see if it will run after renaming it.
     
    Last edited: Dec 1, 2008

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds