Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.When posting your problem, do not run and post a ComboFix logs. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.
To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.
![]() ![]() |
Dec 3 2007, 09:37 AM
Post
#1
|
|
|
Member ![]() ![]() Group: Members Posts: 18 Joined: 3-December 07 Member No.: 174,207 |
Can anybody tell me how to de-bug this thing and get me back up and running normal?? |
|
|
|
Dec 3 2007, 09:46 AM
Post
#2
|
|
|
Forum Addict ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 3,840 Joined: 14-April 06 Member No.: 64,042 |
It is likely Smitfraud or Vundo.
Use Super Antispyware to identify and remove the malware. Post back with what SAS found and for further instructions. Install Super Antispyware free. Run it in safe mode. Allow it to quarantine whatever it finds. http://www.superantispyware.com/ How to Start Windows in Safe Mode: http://www.bleepingcomputer.com/tutorials/tutorial61.html |
|
|
|
Dec 3 2007, 10:36 AM
Post
#3
|
|
|
Member ![]() ![]() Group: Members Posts: 18 Joined: 3-December 07 Member No.: 174,207 |
buddy215...I downloaded SAS to my desktop. no issues there...but when i get into safe Mode and try to run SAS...I get an alert? that says something about administrator wont allow it.
Help?? |
|
|
|
Dec 3 2007, 11:10 AM
Post
#4
|
|
![]() Bleepin' Janitor ![]() ![]() ![]() ![]() ![]() ![]() Group: Global Moderator Posts: 16,573 Joined: 9-July 05 From: Virginia, USA Member No.: 26,513 |
How to login as Administrator in Windows XP?
How to Use the "Run As" Command to Start a Program as an Administrator. -------------------- "THE BAD GUYS DON'T NEED A SEARCH WARRANT. ARE YOU PROTECTED?"
Microsoft MVP - Windows Security 2007-2009 ![]() Member of UNITE, Unified Network of Instructors and Trusted Eliminators |
|
|
|
Dec 3 2007, 11:10 AM
Post
#5
|
|
|
Forum Addict ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 3,840 Joined: 14-April 06 Member No.: 64,042 |
SAS must be installed before going into safe mode. Not just downloaded. If you HAVE installed and it still want work in safe mode then run in normal mode.
|
|
|
|
Dec 3 2007, 01:20 PM
Post
#6
|
|
|
Member ![]() ![]() Group: Members Posts: 18 Joined: 3-December 07 Member No.: 174,207 |
I got it to work...mistake on my part.
so...I ran it in Safe Mode....found a bunch of issues and deleted them. Re-start computer and......same thing.... black screen.. with warning about Spyware. Any suggestions? |
|
|
|
Dec 3 2007, 01:32 PM
Post
#7
|
|
|
Forum Addict ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 3,840 Joined: 14-April 06 Member No.: 64,042 |
I asked in my first post for you to list what SAS found. Without that info it is only a guess as to whether it is Vundo, Smitfraud or something else.
|
|
|
|
Dec 3 2007, 04:00 PM
Post
#8
|
|
|
Member ![]() ![]() Group: Members Posts: 18 Joined: 3-December 07 Member No.: 174,207 |
Yes you did...I'm sorry. I just ran it again in normal mode and it only found 2 issues...yet i just cleaned it out too. I will run it again to see if anything else pops up again.
Thank You!! |
|
|
|
Dec 3 2007, 04:42 PM
Post
#9
|
|
|
Forum Addict ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 3,840 Joined: 14-April 06 Member No.: 64,042 |
Run the online scan for Bit Defender in normal mode. Allow it to quarantine whatever it finds.
http://www.bitdefender.com/scan8/ie.html Post Bit Defender's log here. |
|
|
|
Dec 4 2007, 02:27 PM
Post
#10
|
|
|
Member ![]() ![]() Group: Members Posts: 18 Joined: 3-December 07 Member No.: 174,207 |
buddy215...I ran Bit Defender and came up with nothing. But I did run SAS again AFTER checking for more updates...which there were several. It did find more junk. Here's the log from it:
SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 12/04/2007 at 12:56 PM Application Version : 3.9.1008 Core Rules Database Version : 3354 Trace Rules Database Version: 1353 Scan type : Custom Scan Total Scan Time : 01:14:35 Memory items scanned : 640 Memory threats detected : 1 Registry items scanned : 5448 Registry threats detected : 1 File items scanned : 49140 File threats detected : 15 Trojan.Unclassified/SLDR C:\WINDOWS\SYSTEM32\LWINUPDATE.EXE C:\WINDOWS\SYSTEM32\LWINUPDATE.EXE Adware.Tracking Cookie C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt C:\Documents and Settings\Administrator\Cookies\administrator@tradedoubler[1].txt C:\Documents and Settings\Administrator\Cookies\administrator@adbrite[2].txt C:\Documents and Settings\Administrator\Cookies\administrator@specificclick[2].txt C:\Documents and Settings\Administrator\Cookies\administrator@2o7[2].txt C:\Documents and Settings\Administrator\Cookies\administrator@ads.adbrite[2].txt C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[2].txt C:\Documents and Settings\Administrator\Cookies\administrator@ads.pointroll[1].txt C:\Documents and Settings\Administrator\Cookies\administrator@zedo[2].txt C:\Documents and Settings\Administrator\Cookies\administrator@ad.yieldmanager[1].txt C:\Documents and Settings\Administrator\Cookies\administrator@adopt.specificclick[2].txt C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wjkocmcpego.stats.esomniture[2].txt C:\Documents and Settings\Administrator\Cookies\administrator@tacoda[1].txt C:\Documents and Settings\Administrator\Cookies\administrator@adultadworld[1].txt Trojan.Media-Codec/V4 HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad#E404Helper [ {6bd36adb-7281-4670-bff3-c029d9d8f2c3} ] |
|
|
|
Dec 4 2007, 02:51 PM
Post
#11
|
|
![]() Bleepin' Janitor ![]() ![]() ![]() ![]() ![]() ![]() Group: Global Moderator Posts: 16,573 Joined: 9-July 05 From: Virginia, USA Member No.: 26,513 |
Mostly "tracking cookies" showing. Cookies are NOT a "threat". As text files they cannot be executed to cause any damage. Cookies do not cause any pop ups nor do they install malware. As long as you surf the Internet, you are going to get cookies and some of your security programs will flag them for removal. However, you can minimize this by reading "Blocking & Managing Unwanted Cookies".
Now go to Start > Run and type: regedit Press "OK" and navigate to: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon In the right pane you should see the default entry for Userinit and the "Value data" should read: C:\WINDOWS\system32\userinit.exe, Let me know what it says but don't make any changes. -------------------- "THE BAD GUYS DON'T NEED A SEARCH WARRANT. ARE YOU PROTECTED?"
Microsoft MVP - Windows Security 2007-2009 ![]() Member of UNITE, Unified Network of Instructors and Trusted Eliminators |
|
|
|
Dec 4 2007, 02:53 PM
Post
#12
|
|
|
Forum Addict ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 3,840 Joined: 14-April 06 Member No.: 64,042 |
Are you still getting the black screen and warnings?
|
|
|
|
Dec 4 2007, 03:24 PM
Post
#13
|
|
|
Member ![]() ![]() Group: Members Posts: 18 Joined: 3-December 07 Member No.: 174,207 |
Mostly "tracking cookies" showing. Cookies are NOT a "threat". As text files they cannot be executed to cause any damage. Cookies do not cause any pop ups nor do they install malware. As long as you surf the Internet, you are going to get cookies and some of your security programs will flag them for removal. However, you can minimize this by reading "Blocking & Managing Unwanted Cookies". Now go to Start > Run and type: regedit Press "OK" and navigate to: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon In the right pane you should see the default entry for Userinit and the "Value data" should read: C:\WINDOWS\system32\userinit.exe, Let me know what it says but don't make any changes. quietman7....Here goes it. C:WINDOWS\system32\winupdate.exe,c:WINDOWS\system32\userinit.exe |
|
|
|
Dec 4 2007, 03:34 PM
Post
#14
|
|
|
Member ![]() ![]() Group: Members Posts: 18 Joined: 3-December 07 Member No.: 174,207 |
Are you still getting the black screen and warnings? Yup. My 'puter is much quicker now...probably the quickest it's ever been. The annoying Windows Security Center alerts have disappeared along with the alert bubbles that appeared in the lower right hand corner. Home page is good now too. No more issues there too. But the black screen w/warning is still over top of my desktop pic. What I have noticed is that when I start my computer...after my log on screen...it used to put up my desktop pic and icons right away when loading. Now (since I ph*cked up this thing),my desktop pic comes up a bit later and stays there while everything is loading. No icons yet though. After a few minutes of loading...it flashes to the black screen w/warning and THEN my icons appear. It stays like that as long as my 'puter is on. |
|
|
|
Dec 4 2007, 03:36 PM
Post
#15
|
|
![]() Bleepin' Janitor ![]() ![]() ![]() ![]() ![]() ![]() Group: Global Moderator Posts: 16,573 Joined: 9-July 05 From: Virginia, USA Member No.: 26,513 |
Please download SDFix by AndyManchesta and save it to your desktop.
alternate download When using this tool, you must use the Administrator's account or an account with "Administrative rights"
Open the SDFix folder and double click RunThis.bat to start the script.
Please go to Start Menu > Run > and copy/paste the following line: %systemdrive%\SDFix\apps\swreg IMPORT %systemdrive%\SDFix\apps\Enable_Command_Prompt.reg Press Ok and then run SDFix again. -- If the Command Prompt window flashes on then off again on XP or Win 2000, please go to Start Menu > Run > and copy/paste the following line: %systemdrive%\SDFix\apps\FixPath.exe /Q Reboot and then run SDFix again. -- If SDFix still does not run, check the %comspec% variable. Right-click My Computer > click Properties > Advanced > Environment Variables and check that the ComSpec variable points to cmd.exe. %SystemRoot%\system32\cmd.exe -------------------- "THE BAD GUYS DON'T NEED A SEARCH WARRANT. ARE YOU PROTECTED?"
Microsoft MVP - Windows Security 2007-2009 ![]() Member of UNITE, Unified Network of Instructors and Trusted Eliminators |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 4th July 2009 - 03:23 PM |