Trying to repair after a worm attack.

  1. #1
    Noel PW is offline Full Member

    Trying to repair after a worm attack.

    Hi, i've been a long time user of this site and it's helped me a lot over the years. But I can't find any solution to what is happening now. It started with a notice from our internet provider telling us we were sending high volumes of spam from our address. After scanning our system I was able to remove a 'couple' nasty things. I knew there were more issues when I could no longer update windows and we seem to be getting missing dll messages. I backed-up and did a windows repair, it's worse now. I can't update, my antivirus will not start and for some reason I'm unable to turn off web pages. It seems to 'freeze up on the screen.

    I'm running XP, on a Dell Dimension 4600, pentium 4.

    I downloaded and have a hijackthis scan ready to go but I don't know if I should post it here.

    I spent about two to three weeks on this already, obviously it is beyond my skills. Thanks in advance for any direction you can give me.
    Noel


  2. #2
    Ztruker is offline Technical Guest
    Post your HJT log in the Spyware, Adware, Viruses and HijackThis Logs forum.
    Last edited by Ztruker; 21-11-2009 at 12:31 AM.

  3. #3
    Noel PW is offline Full Member
    Thanks Ztruker for the quick response. It's over there.

  4. #4
    Noel PW is offline Full Member
    Hi, after cleaning up my system with a lot of help on the Hijackthis forum I'm having problems getting any Explorer related commands to respond. Shortcuts, favorites, links are not responding. Start menu links also are not responding. It was working fine until I restarted after windows updates. But right now I am unable to get on the internet at home.
    Thanks to everyone for any help.
    Last edited by Noel PW; 24-11-2009 at 01:26 PM. Reason: spell

  5. #5
    Dan Penny is offline Techie7 Staff
    You can try to run a file check on the O/S.

    If you have an XP CD:
    Click START, RUN, type in:

    sfc /purgecache

    (This ensures that system files are copied from your Windows installation media, and files which may be infected/damaged with malware, or are corrupted, are not copied from your drive. Some of the files which are restored/replaced may need MS Updates applied. If sfc replaces any such files, you will have to reinstall updates for those files. (If you have Automatic Updates active, this will happen automatically.))

    Then type in:

    sfc /scannow

    Have your XP CD handy.


    If you do not have an XP CD:
    Click START, RUN, type in:

    sfc /scannow


    ** OR **

    If you have System Restore enabled, have you tried restoring to a point before the "problem(s) started?

    If this brings no relieve, a repair install might be in order.

    How to Perform a Windows XP Repair Install (Just below the first bold red bar on the page. Please read the entire page first though.)

    BEFORE running this, go to C:\WINDOWS\system32 and copy the;

    wpa.bak
    wpa.dbl


    files to a safe location. After the repair install, if asked to VALIDATE WINDOWS, try copying these two files BACK INTO the C:\WINDOWS\system32 folder and do a restart. (You may not have to revalidate Windows.)
    Last edited by Dan Penny; 24-11-2009 at 07:54 PM.

  6. #6
    Noel PW is offline Full Member
    Thanks Dan, I'll start on this when I get home after work tonight. Yes, I do have the xp disc. For each of those run commands I press 'ok'? Or do I use both in the same run command?
    The system restore won't be an option, I wiped it clean yesterday as the final move to wipe out any traces of the infection. Automatic updates are working, well yesterday, I didn't see any response this morning.

  7. #7
    Dan Penny is offline Techie7 Staff
    ",,, I wiped it clean yesterday ,,,"

    Oh, well that changes thing a little. I didn't realize the "installation" was so fresh. If it was mentioned, I missed it.

    Did you remove, then re-create, the C: partition for the fresh install?

    If not, then I would start again and do so. That will make your other questions a moot point.

    Let us know.................

  8. #8
    Noel PW is offline Full Member
    Hi Dan, I may have confused you by what I wrote. I only wiped clean the system restore points prior to yestreday afternoon. After doing a lot of windows updates yesterday and all night I could not get on the internet at all. I could receive and send messages through outlook but it was like explorer was gone.

    I took your advice and did a system restore to yesterday before SP3 was installed. Everything is working now. Should I try the updates again?
    Thanks for all your advice.

  9. #9
    Dan Penny is offline Techie7 Staff
    I wouldn't. (Typical MicroSlop.) I run SP2 only, and only ONE Windows Updates. Time Zone update. Never had a problem.

  10. #10
    Noel PW is offline Full Member
    The pc was running great last night. I had one 'script error' that shut down IE. I couldn't write down what it was before it disappeared. When I shut down automatic updates started. When I tried this morning no internet. Same thing, I can get messages but I can not get online. This time I'm getting 'send error report messages'.

    Do you think I should do a 'restore' and shut off automatic updates? I could download them manually, I think it may be IE7 causing the problem. How do I shut off autoupdate properly?
    Thanks for your help.

+ Reply to Thread
Page 1 of 2 1 2 LastLast