Re: Windows 2k logon problem

From: Jan Il (abuse_at_localhost.com)
Date: 01/24/05


Date: Sun, 23 Jan 2005 21:16:25 -0500

Hi WayWet :-)

Try the following and see if it helps. Even if you have already run some
programs, run them again according to the instructions in the information
below to thoroughly clean you system. It is best to read through all the
information before you start to know before hand what you need to do and
how. Follow all instructions to letter as much as possible.

WARNING>>>> Backup all documents and files before removing any spyware!!

Dealing with Unwanted Spyware and Parasites:
http://mvps.org/winhelp2002/unwanted.htm

What You Should Know About Spyware
http://www.microsoft.com/athome/security/spyware/devioussoftware.mspx
Be sure to run CWShredder here

http://www.majorgeeks.com/download3019.html

and AdAware and Spybot.
Download the newest version of HiJackThis here:
http://www.bleepingcomputer.com/files/hijackthis.php
and SpyBot Search & Destroy

http://www.majorgeeks.com/download2471.html

Also visit these two sites to test for parasites and help basic cleaning:

On-Line Check

http://aumha.org/a/noads.htm

and

Quick-Fix Protocol.
http://aumha.org/a/quickfix.php

Basically, throw everything here at your "infection".

And be sure to use the HijackThis. Please DO NOT post your log to this
newsgroup, but to the HiJackThis Support Forums below:
http://www.hijackthis.de/forum/forumdisplay.php?f=10&guestlanguageid=4
the Aumha HiJackThis Forum
http://forum.aumha.org/viewforum.php?f=30

or Bleeping Computer Forum

http://www.bleepingcomputer.com/forums/forum22.html

to allow the experts there to evaluate your log and advise you of any
necessary steps to clean your system.

(Note: You will have to Register before posting on these Forums. Please
follow all posting instructions carefully to avoid having your log deleted
or ignored.

Also this program searches for hidden .dlls that recreate the malware.
About Buster:
http://www.majorgeeks.com/download4289.html

CAUTION!!!!! Before you try to remove spyware using any of the programs
below, download a copy of LSPFIX from any of the following sites:
http://www.cexx.org/lspfix.htm
http://www.spychecker.com/program/winsockxpfix.html
(if your OS is Win2k or XP) The process of removing certain malware may kill
your internet connection. If this should occur, this program, LSPFIX, will
enable you to regain your connection.

You should also get a copy of WINSOCKXPFIX available at:
http://www.spychecker.com/program/winsockxpfix.html
and
WinsockXP Fix- WinXP
http://www.spychecker.com/program/winsockxpfix.html
with instructions, at
http://www.iup.edu/house/resnet/winfix.shtm
Also
>From LavaSoft- all versions of Windows-
http://digital-solutions.co.uk/lavasoft/whndnfix.zip
(NOTE: It is reported that in XP SP2, the command netsh winsock reset
will fix this problem without the need for these programs.)

or ........

Winsock Fix Utility
http://www.dfwonline.net/files/WinsockFix.zip

Also.........

Courtesy of Jim Byrd -

Download Sysclean.com, from Trend Micro, here:
http://www.trendmicro.com/download/dcs.asp along with the latest pattern
file, here:
http://www.trendmicro.com/download/pattern.asp
Be sure to read the "How-to" info here:
http://www.trendmicro.com/ftp/products/tsc/readme.txt
You might also want to get Art's updater, SYS-UP.Zip, here for future
updating of these: http://home.epix.net/~artnpeg/.
(If you download and use the updater from the beginning, it will
automatically handle downloading the other files. Place them in a dedicated
folder after appropriate unzipping, and then run. This scan may take a long
time, as Sysclean is VERY extensive and thorough

NOTE: If you can not download these programs from the Internet, if your PC
has CD read capabilities, go to another computer with CD-ROM burning
capabilities. Create a folder on the hard drive of the other computer called
HOLD, download the programs to that folder, then burn that folder to a CD.
Copy the HOLD folder to your HD and then install the programs from there
and run them. After you have IE access again, update all programs where
possible to get the latest definitions and run them again in Safe Mode to be
sure there are no lingering items on the system.

If these steps do not resolve your problem, or you need help with the above,
please post back to this thread with the details and any error messages.

Hope this helps

Jan :)
Smiles are meant to be shared,
that's why they're so contagious.

Replies are posted only to the newsgroup for the benefit or other readers.
How to make a good newsgroup post:
http://www.dts-l.org/goodpost.htm

> My laptop was working fine til suddenly it will not let me use
ctrl-alt-del
> to start logging on.
>
> The keyboard works to have it try to start in the 'safe mode', but once
the
> start up screen is loaded, the keyboard no longer function. Also, there
is
> no mouse cursor.
>
> I have plugged in an external keyboard with the same results, keyboard
works
> until the log on screen appears.
>
>
> Any ideas or work arounds?
>
> Thanks,
>
> Doug
>
>
>



Relevant Pages

  • Re: CWS searchx strain wont go away
    ... > Download: CWShredder ... > Unzip, but do not run it yet, it will be needed later. ... > Navigate to System32 folder. ... I have followed the instructions below and still can't shake ...
    (microsoft.public.security)
  • Re: Some times IE works and sometimes it doesnt
    ... please do so again according to the instructions below. ... Download the newest version of HiJackThis here: ... Create a folder on the hard drive of the other computer called ... > At one point in an attempted reinstall in place attempt I get the message ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: Access Blocked - Virus Warning
    ... Download the newest version of HiJackThis here: ... follow all posting instructions carefully to avoid having your log deleted ... Winsock Fix Utility ... Create a folder on the hard drive of the other computer called ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: IE Home page keeps defaulting to some search engine....
    ... Follow all instructions to letter as much as ... Winsock Fix Utility ... Download Sysclean.com, from Trend Micro, here: ... Create a folder on the hard drive of the other computer called ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: IE has encountered a problem and must close
    ... Follow all instructions to letter as much as ... or Winsock Fix Utility ... Download Sysclean.com, from Trend Micro, here: ... Create a folder on the hard drive of the other computer called ...
    (microsoft.public.windows.inetexplorer.ie6.browser)

Loading