There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
 
Tag Cloud
access audio avg avg 8 bios blue screen boot bsod computer connection cpu crash css dell desktop dma driver drivers dvd email error excel explorer firefox firefox 3 freeze gimp graphics hard drive hardware hijackthis hjt install internet internet explorer itunes keyboard laptop macro malware monitor motherboard network networking outlook outlook 2003 outlook 2007 outlook express pio problem problems router seo server slow sound sp3 spyware trojan usb video virtumonde virus vista vundo windows windows vista windows xp winxp wireless
Malware Removal & HijackThis Logs
Search
Search in:
 
Advanced Search
Tech Support Guy Forums > Security & Malware Removal > Malware Removal & HijackThis Logs >
Wanna help out another n00b? :)


HELLO AND WELCOME! Before you can post your question, you'll have to register -- it's completely free! Click here to join today! We highly recommend that you print a copy of our Guide for New Members. Enjoy!

 
Thread Tools
Desperat's Avatar
Junior Member with 6 posts.
 
Join Date: Jun 2008
24-Jun-2008, 01:37 PM #1
Wanna help out another n00b? :)
Hi... Okay, so I am REALLY desperate right now! (Hence my username.. Lol.) My PC has just been hijacked. Completely. Taken over by worms, trojans, viruses and I dunno what, really... I'm a total n00b when it comes to this kind of stuff, unfortunately. But I've done some research, and tried to figure out what the problem consists of...

See, the thing is that I am currently unable to log into my own, administrative windows-account. I write the password, click enter, and everything appears to be allright, except but the fact that it is not. My computer TRIES to log in. And my desktop-background appears. Then it ultimately FREEZES, just like that. No icons appear. The start-menu is not available. And I end up having to switch off the machine by using the main switch, because it gets ALL frozen up... Btw, I always get the same error-message, telling me that it cannot start because of some problem with something called 0xc0000005.

So, what I do now, is, I have managed to log into my GUEST-account. The one that is without a password. And that one, strangely enough, never freezes. But it has no administrative rights, and I dunno what to do, because it won't let me install any anti-virus-programs. Or anything else, for that matter.

As I've said, I have already done some research. And I figured out that the 0xc0000005 probably appears BECAUSE of all the malware that is destroying my PC. I searched some other page, and it told me that certain types of malware are able to rename computer-files, making them impossible for the computer to read. And when something is impossible to read, that is when the 0xc0000005 appears. Because it is unaccessable. So... Now the whole friggin' WINDOWS is unaccessable for me, thanks to whoever made this %&#?F!!! virus... (Btw, the 0cx0000005-command I get when trying to log in comes from something called userinit.exe. If you wondered. :-D)

I also read that ONE way to get rid of the whole thing is to put in the xp-cd, reboot(?) the whole system and rethrive a former cache(?) from something called the Recovery Console. There is only ONE problem: I have lost those CDs, I think. And anyways, I most definitely cannot remember the password. My dad was the one who rigged up this PC for me way back in the days.. I have had it for more than 3 years now. (Btw, sorry if I use the wrong terms anywhere in this paragraph. I put in some (?)s just in case. English is, after all, not my first language...)

Okay, with me so far?
1. Unable to login, thanks to 0xc0000005
2. 0xc0000005 probably caused by malware
3. Unable to remove malware
4. Unable to get into my administrative account
5. Therefore also unable to install/uninstall stuff in order to help me get rid of the malware.
6. I recieve, like, close to a thousand pop-ups. And they are ALL about fake anti-virus programs. Like Vista Antivirus 2008, for instance. I close them, but they just keep popping back up anyway. At least once per minute.
7. My PC is SLOW. I mean really slow. And it has crashed 5 times now. In 2 hours. Each time that happens, I have to restart. I think it is mostly because of the malware, but maybe also because I only have 125 MB of space left on this whole thing.. :-O And I cannot delete/uninstall anything, because I cannot get into the administrative account. As I've said earlier.
8. Did I mention that I am TERRIFIED of having to lose all the files on that account?! ;-(

If you're wondering which types of malware my PC in infected with... I am currently doing an online virus-scan by some program called Kaspersky. I will post them whenever it gets done.

Oh, and I have Windows XP.

Last edited by Desperat : 24-Jun-2008 01:52 PM.
Desperat's Avatar
Junior Member with 6 posts.
 
Join Date: Jun 2008
24-Jun-2008, 01:46 PM #2
C:\WINDOWS\system32\iftuyszv.exe//PE_Patch.UPX//UPX/C:\WINDOWS\system32\iftuyszv.exe//PE_Patch.UPX//UPXInfected: not-virus:Hoax.Win32.Renos.daw1C:\WINDOWS\aG1zIGFrZXJzaHVz\asappsrv.dll//UPX/C:\WINDOWS\aG1zIGFrZXJzaHVz\asappsrv.dll//UPXInfected: not-a-virus:AdWare.Win32.CommAd.a12svchost.exe\svchost.exe/svchost.exe\svchost.exeInfected: Trojan-Downloader.Win32.VB.dck1C:\WINDOWS\Fonts\svchost.exe/C:\WINDOWS\Fonts\svchost.exeInfected: Trojan-Downloader.Win32.VB.dck1C:\WINDOWS\mrofinu1000106.exe//PE_Patch.Upolyx//PE_Patch.UPX//UPX/C:\WINDOWS\mrofinu1000106.exe//PE_Patch.Upolyx//PE_Patch.UPX//UPXInfected: Trojan-Downloader.Win32.Homles.br1
Desperat's Avatar
Junior Member with 6 posts.
 
Join Date: Jun 2008
24-Jun-2008, 02:20 PM #3
Bump!!
Desperat's Avatar
Junior Member with 6 posts.
 
Join Date: Jun 2008
24-Jun-2008, 04:10 PM #4
...And absolutely nobody cared?
Desperat's Avatar
Junior Member with 6 posts.
 
Join Date: Jun 2008
27-Jun-2008, 06:06 PM #5
You people ****ing suck.
sjpritch25's Avatar
Computer Specs
Distinguished Member with 6,794 posts.
 
Join Date: Sep 2005
Location: Florida
Experience: Advanced
28-Jun-2008, 08:37 AM #6
Sorry for the delay, but your language is inexcusable. The forums here are extremely busy and everyone here is a volunteer. None of us get paid, so you need to show a little patience. Do you still require help? If so let me know.
Desperat's Avatar
Junior Member with 6 posts.
 
Join Date: Jun 2008
01-Jul-2008, 04:50 PM #7
Yeah, I still need help, if you would be so kind.
Sorry about my earlier post. I do realize people on this forum don't get paid or anything. But my thread seemed to be the only one to be COMPLETELY ignored. Whereas the other ones got dozens of answers.. :-S

So I got kinda impatient, but I'm not a bad person or anything. Trust me on that. I'm just... On the verge of going insane right now. 'Cause this situation bloody sucks! (I'm allowed to say THAT, right? ). And because I am such a friggin' n00b, I dunno what to do about it.. *Sigh*.

Thank you for being nice and offering to help me out, though. I really appreciate it. You still there? Haven't checked this thread in a few days, so...

*Hugs and rainbow-flavoured cupcakes for everyone*. XD

Last edited by Desperat : 01-Jul-2008 04:57 PM.
sjpritch25's Avatar
Computer Specs
Distinguished Member with 6,794 posts.
 
Join Date: Sep 2005
Location: Florida
Experience: Advanced
02-Jul-2008, 12:22 AM #8
The reason people get skipped is because they don't read the sticky's on the front page.
http://forums.techguy.org/malware-re...ead-first.html


Anyways.


Please click Here to download HijackThis to your desktop.

Click the Download button. When the Trend Micro HJT install box appears, double click on the HJTInstall.exe. Click on Install.

It will be installed by default here: C:\Program Files\Trend Micro\HijackThis

A shortcut to the application will also be placed on your Desktop.

The program will open automatically after installation.

You can double-click the icon that was placed on the Desktop to run subsequent HijackThis scans or you can use the icon inside the folder. The folder HijackThis is where you will find the HJT logs that you save. When you use the application to remove anything, you will also find the backup copies made by HJT inside this folder.

Close all other windows except HijackThis.

Click on "Do a system scan and save logfile" When the log pops up in Notepad, copy and paste that file back here.

Do NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required.
__________________
My Blog
Microsoft Valuable Professional Consumer--Security 2007-2009
If i have helped you, please make a donation to keep the site running. All proceeds go directly to the site!!! Donate Here
Concerned about Browser Security!!! Consider Mozilla Firefox 3.0 and NoScript
Operating System Ubuntu Hardy Heron 8.04
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are Off
Refbacks are Off

You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 03:22 AM.
Copyright © 1996 - 2008 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Powered by Cermak Technologies, Inc.