BleepingComputer.com: infected by some type of malware

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
  • 4 Pages +
  • 1
  • 2
  • 3
  • 4
  • You cannot start a new topic
  • This topic is locked

infected by some type of malware no control over mouse/software antivirus usless

#31 User is offline   pensioner 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 30
  • Joined: 09-November 09
  • Gender:Male
  • Location:Nottinghamshire UK

Posted 28 November 2009 - 06:22 PM

tried the command prompt by pasting your instruction but on trying to run it, the error C:\windows\system32\pstores.exe is not recognised as an internal or external command etc.

Then tried to run microsofts fixit, got the message that windows installer service is not accessible in safe mode, use system restore etc.

tried to reboot into normal windows but it will only start in safe mode

Not doing very good am I.

regarding your query re the registry, I have deleted items in the past without any problems so I am confident that with you guiding me averything should be ok

#32 User is offline   m0le 

  • I know the drill!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 29,090
  • Joined: 24-July 08
  • Gender:Male
  • Location:London, UK

Posted 28 November 2009 - 07:27 PM

Alright, this is operation Internet :(

You are backed up with ERUNT. If you get unsure at any stage then post before you try something.

Remember the registry is a dangerous place but it isn't lethal.


To run regedit just click on the start button and then select run.

Then type regedit in to the box and click ok

When you are there we need to navigate through the registry.

Here are the two navigation paths we are going to take.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winsock]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2]


To get to the first one, look for HKEY_LOCAL_MACHINE and click the folder. This will expand to a list of subfolders. Again look for the next entry, this is SYSTEM. When the list expands under that you then look for CurrentControlSet, and so on.

When you reach Winsock you right click and delete it.

You do the same with Winsock2.

When you have done this then restart your PC and then post back.

This post has been edited by m0le: 28 November 2009 - 07:29 PM

If I have helped you fix your PC then please donate. Thanks

Posted Image
m0le is a proud member of UNITE (Unified Network of Instructors and Trusted Eliminators)

#33 User is offline   pensioner 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 30
  • Joined: 09-November 09
  • Gender:Male
  • Location:Nottinghamshire UK

Posted 29 November 2009 - 06:37 AM

winsock and winsock2 deleted and machine restarted

#34 User is offline   m0le 

  • I know the drill!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 29,090
  • Joined: 24-July 08
  • Gender:Male
  • Location:London, UK

Posted 29 November 2009 - 07:48 AM

Good job, now to reset the connection.

1. Right-click the network connection, and then click Properties.
2. Click Install.
3. Click Protocol, and then click Add.
4. Click Have Disk.
5. Type C:\Windows\inf and then click OK.
6. On the list of available protocols, click Internet Protocol (TCP/IP), and then click OK.

Restart the computer and let's see if you can now access the internet.
If I have helped you fix your PC then please donate. Thanks

Posted Image
m0le is a proud member of UNITE (Unified Network of Instructors and Trusted Eliminators)

#35 User is offline   pensioner 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 30
  • Joined: 09-November 09
  • Gender:Male
  • Location:Nottinghamshire UK

Posted 29 November 2009 - 08:56 AM

unless I am misreading your instructions, I have accessed the internet connections icon via control panel and on right clicking I can only open or explore, in open the icon is totally devoid of any information.. in explore it reverts to the control panel menu

#36 User is offline   m0le 

  • I know the drill!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 29,090
  • Joined: 24-July 08
  • Gender:Male
  • Location:London, UK

Posted 29 November 2009 - 11:51 AM

What does the icon look like and what status does it say?

This Microsoft link will make sure you have navigated correctly to the network connections.
If I have helped you fix your PC then please donate. Thanks

Posted Image
m0le is a proud member of UNITE (Unified Network of Instructors and Trusted Eliminators)

#37 User is offline   pensioner 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 30
  • Joined: 09-November 09
  • Gender:Male
  • Location:Nottinghamshire UK

Posted 29 November 2009 - 12:54 PM

yes, same shaped icon but in safe mode it is in classic view,, it is the shape of the world with a connection in it. As I have said. to right click the only options are as Ive described, and to double click it gives the same result, nothing,

I am concious that I am monopolising your valuable time, do we still continue????

#38 User is offline   m0le 

  • I know the drill!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 29,090
  • Joined: 24-July 08
  • Gender:Male
  • Location:London, UK

Posted 29 November 2009 - 01:31 PM

We can continue for a bit longer before we refer to you another forum.

Besides, I hate being beaten :(

The connection is a problem in safe mode so let's attempt to regain your normal mode again.

1. Exit all programs.

2. Click Start > Run.

3. In the Run dialog box, type the following text:

msconfig

4
Click OK.

5
In the System Configuration Utility, on the BOOT.INI tab, check /SAFEBOOT.

6. Click OK.

7. When you are asked to restart the computer, click Restart.

The computer restarts in Safe mode. This can take several minutes.


After you complete the work in Safe mode, use the System Configuration Utility to start Windows XP in Normal mode.

1, Close all programs.

2. Click Start > Run.

3. In Run dialog box, type the following text:

msconfig

4. Click OK.

5. In the System Configuration Utility, on the BOOT.INI tab, uncheck /SAFEBOOT.

6. Click OK.

7. Close all programs, and restart the computer.
If I have helped you fix your PC then please donate. Thanks

Posted Image
m0le is a proud member of UNITE (Unified Network of Instructors and Trusted Eliminators)

#39 User is offline   pensioner 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 30
  • Joined: 09-November 09
  • Gender:Male
  • Location:Nottinghamshire UK

Posted 29 November 2009 - 02:20 PM

YIPEE, windows started normally,
but a message popped up saying that it was in diagnostic or selective startup and on acknowledging that message, the system configuration utility reappeared with 'selective startup' selected and 'use modified BOOT.INI'

Thanks for sticking with me, I have all the time in the world but I am aware that others have not.

#40 User is offline   m0le 

  • I know the drill!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 29,090
  • Joined: 24-July 08
  • Gender:Male
  • Location:London, UK

Posted 29 November 2009 - 03:42 PM

Okay, that's not so bad.

Select a diagnostic startup and restart

When the startup configuration panel comes up after the diagnostic startup you should be able to select normal startup and restart the PC.

My fingers are crossed. :(
If I have helped you fix your PC then please donate. Thanks

Posted Image
m0le is a proud member of UNITE (Unified Network of Instructors and Trusted Eliminators)

#41 User is offline   pensioner 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 30
  • Joined: 09-November 09
  • Gender:Male
  • Location:Nottinghamshire UK

Posted 29 November 2009 - 04:13 PM

Done, started normally, this time in network connections there are two items. one a dial up, which I dont use. the second a LAN which is currently disconnected

#42 User is offline   pensioner 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 30
  • Joined: 09-November 09
  • Gender:Male
  • Location:Nottinghamshire UK

Posted 29 November 2009 - 04:13 PM

Done, started normally, this time in network connections there are two items. one a dial up, which I dont use. the second a LAN which is currently disconnected

Done, started normally, this time in network connections there are two items. one a dial up, which I dont use. the second a LAN which is currently disconnected

#43 User is offline   m0le 

  • I know the drill!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 29,090
  • Joined: 24-July 08
  • Gender:Male
  • Location:London, UK

Posted 29 November 2009 - 04:23 PM

Okay, what exactly does the wording next to the icon say.
If I have helped you fix your PC then please donate. Thanks

Posted Image
m0le is a proud member of UNITE (Unified Network of Instructors and Trusted Eliminators)

#44 User is offline   pensioner 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 30
  • Joined: 09-November 09
  • Gender:Male
  • Location:Nottinghamshire UK

Posted 30 November 2009 - 06:53 AM

Network connections,, accessed via control panel, am I looking at the right conection?

#45 User is offline   m0le 

  • I know the drill!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 29,090
  • Joined: 24-July 08
  • Gender:Male
  • Location:London, UK

Posted 30 November 2009 - 07:48 AM

Quote

the second a LAN which is currently disconnected


You said there were two icons inside of Network Connections, one of them was The LAN icon, does it show "disconnected"?
If I have helped you fix your PC then please donate. Thanks

Posted Image
m0le is a proud member of UNITE (Unified Network of Instructors and Trusted Eliminators)

Share this topic:


  • 4 Pages +
  • 1
  • 2
  • 3
  • 4
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users