SoftwareTipsandTricks Forum

Go Back   SoftwareTipsandTricks Forum > Operating Systems > Windows XP
User Name
Password


Blaster virus help request - thanks!

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes

  #1  
Old 11-02-2003, 10:39 PM
owenhbrown's Avatar
owenhbrown Offline
Registered User
 
Join Date: Nov 2003
Posts: 4
Send a message via ICQ to owenhbrown
Angry Blaster virus help request - thanks!

Blaster Dilemma

Hello fellow XP users,

My name is Owen Brown, I am 23 from Sydney

I asked how I could back up several gigabytes of data for a reformat of an XP Pro system which is displaying signs of a worm infection. Several people have been quick to try and help so I won’t give up on removing the problems just yet.

I’ll explain the problem form the start…

At about 12:00 pm yesterday I received an RPC call restart message and immediately cursed turning off the firewall that is on the network I have at home here. I restarted windows and tried to run Norton AV only to find that a) My subscription had ended and b) the “virus” wouldn’t allow a Norton scan to run.

I used the Symantec online scanner and found that my computer had NO viruses.

I wasn’t convinced because Norton Anti Virus still wouldn’t run and AVG (grisoft) anti virus wouldn’t install. Like a confident Neo entering the Matrix I looked at my System32 folder and found two newly modified files scvhost.exe and winhlpp32.exe, both 57kb and both looking VERY shifty. Scvhost.exe could NOT be deleted because it could not be removed from the processes list, winhlpp32.exe could be deleted.

I did a forum search and they all recommended downloading and running a Microsoft security patch, I could only do this in safe mode (It wouldn’t work normally) and when I did it didn’t appear to do much except leave who strange looking blue folders in my WINDOWS folder. Then they recommended removing msblast.exe from my processes list, but this process wasn’t there, it isn’t on my system at all

I headed over to Symantec and found that the virus most resembling the one I seemed to have was this:

http://www.symantec.com/avcenter/ven...gaobot.ao.html

I tried to use this to solve my problem, however, Symantec, after acknowledging that the virus disables AV software, recommend a full system scan, which is annoying. The help page said that scvhost.exe and winhlpp32.exe were the screwy files so I knew I was on the right track. However, I opened up the registry in safe mode (because it wouldn’t work in normal mode thanks to the bug) and found that of the values suggested by the help page to be removed from the registry locations;

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\
RunServices

Those being:

• "Registry Loader"="regloadr.exe"
• "Configuration Loader" = "dosrun32.exe"
• "Windows Explorer" = "lsas.exe"
• "Registry Loader"="winhlpp32.exe"
• "Config Loader" = "scvhost.exe"

NONE were there, as far as I could tell, my registry was totally clean…

Symantec also recommends removing Regloadr.exe, Dosrun32.exe, or Lsas.exe from the processes list, they’re not there, and it’s just not my virus!

I downloaded the blast fix program from Symantec and a few other programs offered by AV sites and they all came up with the same answer: No blaster worm was on my system. So why the hell were none of my programs working and why the hell couldn’t I get rid of this damn scvhost.exe process?

What about system restore? I ran it to no avail…

It a fit of rage like Neo against Agent Smith I dived into my processes list and decided to delete scvhost.exe for all it was worth….

Silly me, I deleted four SVCHOST.exe processes… I think I may have even deleted it from the system folder. The SCVHOST.exe file remains and cannot be removed form the system32 folder or the processes list.

So what happened? Well, Networking is screwed, the sound card has vanished, so has the modem and the saviour of all saviours, the beloved reformat is not possible because the one program, Neo, I mean Nero, won’t work. Something about a COM/OLE error. I can’t save any of my beloved gigabytes of stuff to CD so I can’t reformat. I am SCREWED!

OK, I checked out, http://www.sophos.com/support/disinf.../blastera.html and discovered this:

--<<<8. Why am I getting errors associated with SVCHOST.EXE even if my computer is not infected with W32/Blaster-A?
If a vulnerable computer is probed by W32/Blaster-A, even if infection is not successful, the svchost service will fail. This will cause a variety of problems with other software.

To recover from these problems install the patch at http://www.microsoft.com/security/se...s/ms03-026.asp and restart the svchost service. >>>---

Now this seems to be what I am experiencing. No virus but all the rubbish that it comes with. It’s possible svchost.exe was just fine and I ruined it by tinkering.

I can’t download a windows update because I cannot connect to the internet. I took the svchost.exe file from the computer I am using now and attempted to copy it to my computers system32 folder (Which involved opening it in notepad and saving it because the bug won’t allow moving or pasting) and set my services to their default configurations, but still nothing seems to work (The bug is greatly efficient at stopping applications from running).

It seems that in my determination to remove the “virus” I have removed a hugely critical file (svchost.exe) and now I can’t get it back. I get the feeling that if I hadn’t removed the svchost.exe services Nero would have at least run and I could have fixed this problem forever.

So there you go, a virus that can’t even be detected has caused me to completely destroy my system with about 10 gigabytes of valuable stuff…

I ask four questions:

1) How can I get a new copy of sVChost.exe running that will restore all my services back to their original setting? Should I delete the one I stole from my sisters PC? Remember, I cannot cut and paste.
2) If I manage to do this, how can I rid myself of this evil and undeletable sCVhost.exe once and for all and get my system back a point where it likes running AV software? (Please do answer this because this computer may be affected)
3) If neither of the above two requests are fixable, can you think of any possible way to save my data elsewhere so that I can safely run a reformat and not lose all my stuff?
4) Lastly, will my XP Pro CD allow me to reformat my system, removing all the silly bugs and programs, WITHOUT touching the stuff in my “My Documents” Folder? I would see for myself, but you guys know already what happens when I experiment!

I really appreciate your time in reading this. I hope I have explained the problem comprehensibly enough for you to want to help me. I cannot describe how thankful I am. I will keep checking the forum but could you please also CC your response (if you think it would help) to obliky@hotmail.com or add me to ICQ: 48666738.

Here are the Hijack scan details for further help:

Deepest thanks,

Owen.

Logfile of HijackThis v1.97.3
Scan saved at 11:44:08 AM, on 3/11/2003
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\scvhost.exe
C:\WINDOWS\System32\imapi.exe
C:\Documents and Settings\Owen Brown\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://forum.theunsentletter.com/
N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.web-entrance.com/main.cgi?ID=215"); (C:\Program Files\Netscape\Users\ohbrown\prefs.js)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: ICQ Pro (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: YExplorer1_8US.CAB - http://photos.groups.yahoo.com/ocx/u...lorer1_8us.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...ctor/swdir.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
Reply With Quote

  #2  
Old 11-03-2003, 07:13 AM
scouse's Avatar
scouse Offline
Registered User
 
Join Date: Aug 2002
Location: UK
Posts: 858
Send a message via MSN to scouse Send a message via Yahoo to scouse
ok if i was you i would do a repair with your Xp disc, set up bios so your cd rom boots first, have the XP disc in the drive reboot your computer then when XP disc loads the same as if you were installing, once you are past the likes of press F8 if you agree, you know you will soon get to the screen asking you do you want to repair XP or Install XP, choose Install XP, the next screen it will offer you the repair option again at this stage choose repair, what will happen it will repair your OS and all your files will still be there when finsihed except your Patches Like SP1 and other critical updates will be gone as the repair set the OS back to the stage of what was only on the disc, but that is least of your worrys as now you will be able to access your OS and retrieve to disc what you need. when you have done the repair do not connect to the internet just save all what you need to disc once that is done then connect to the net and downlaod all critical updates first. you can download sygate personal free firewall from here http://smb.sygate.com/products/spf_standard.htm.

you could also set your drive up as a slave drive in another computer and see if you can access your files that way which would be the easyest thing to to do if you have another computer handy.

maybe someone else can pop on and give better advice than me, good luck and let us know how you got on

Last edited by scouse : 11-03-2003 at 07:15 AM.
Reply With Quote

  #3  
Old 11-03-2003, 08:52 AM
owenhbrown's Avatar
owenhbrown Offline
Registered User
 
Join Date: Nov 2003
Posts: 4
Send a message via ICQ to owenhbrown
bios probs

I don't know if this is an unrelated problem or a direct result of virus issues...

I have my win xp pro boot disk and edited bios to load from cd-rom, but upon restarting it went straight into windows start up. I made it boot from atapi... same result. Tried all three drives and no luck there either...

Do you have any suggestions as to how I can force my bios to boot from CD? Does it even recognise the CD as a boot cd?

*sigh*

Thanks for your help... please keep helping =)

Owen.

Last edited by owenhbrown : 11-03-2003 at 08:55 AM.
Reply With Quote

  #4  
Old 11-03-2003, 11:27 AM
scouse's Avatar
scouse Offline
Registered User
 
Join Date: Aug 2002
Location: UK
Posts: 858
Send a message via MSN to scouse Send a message via Yahoo to scouse
ok no problem do you ahve a floppy? if so go to microsoft
http://support.microsoft.com/default...;en-us;Q310994 and download these boot floppys for XP you are going to need 6 floppys but you will be able to boot up with them to do your repair. just follow the instructions from the website i have linked you to
Reply With Quote

  #5  
Old 11-03-2003, 07:44 PM
owenhbrown's Avatar
owenhbrown Offline
Registered User
 
Join Date: Nov 2003
Posts: 4
Send a message via ICQ to owenhbrown
thanks

I shall give that a try when I get home...

I certainly hope there isn't a problem with my bios and that I'll be able to boot from A: Drive. When I installed XP I did so from the CD I am using now simply by editing the bios to boot from the CD drive... I wonder why it isn't working for me now. I find it unlikely that an undetectable virus with worm-like symptoms would find it's way into a dual bios.

I'll let you know how I go...

thanks

Owen.
Reply With Quote

  #6  
Old 11-03-2003, 07:57 PM
scouse's Avatar
scouse Offline
Registered User
 
Join Date: Aug 2002
Location: UK
Posts: 858
Send a message via MSN to scouse Send a message via Yahoo to scouse
i doubt it is your Bios at fault Owen, but then as you probably know all hardfware can go faulty , but hopefully i very much doubt it is your motherboard. Let us know how you get on Owen and if you are still haveing difficultys i will ask my friends at majorgeeks what they can do to help with advice or you can always go THERE and post your problem in software i am always there and here.
Reply With Quote

  #7  
Old 04-29-2005, 06:47 PM
memyselfandi Offline
Registered User
 
Join Date: Apr 2005
Posts: 1
I believe that you do probably have a virus. After hearing all that you have tried I would suggest that you boot the machine with Knoppix and run the antivirus from the bootable CD. If this does not fix your problem then you may be doomed to the dreaded format
Reply With Quote

  #8  
Old 04-29-2005, 09:42 PM
ben_P's Avatar
ben_P Offline
Registered User
 
Join Date: Apr 2005
Posts: 10
YEP i think u should back up inportant files and then do a reinstallation of win xp
__________________
ben_p
Reply With Quote

  #9  
Old 04-30-2005, 10:08 PM
owenhbrown's Avatar
owenhbrown Offline
Registered User
 
Join Date: Nov 2003
Posts: 4
Send a message via ICQ to owenhbrown
A reinstallation of the xp system files did the trick for me. It fixed the scvhost.exe file which enables me to run programs like Norton AV and Nero. The problem associated with my CD player not reading boot cd's was remedied by downloading a program from ms which created 6 floppy boot disks which got the cd installation working for me.

thanks for your help, even if it's a belated thanks!

Owen.
Reply With Quote
Reply




Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
virus from hell HELP! Felman Windows XP 3 02-12-2005 05:02 PM
Virus Win32/Hantaner!!! Plz help zile Internet 22 06-19-2003 04:31 AM
Virus detected assif Windows XP 5 05-01-2003 07:20 PM
Virus Help- NAV Isnt Helping antivirus99 Windows XP 3 03-10-2003 06:20 PM
Trillian Pro Virus high6ix Internet 14 02-18-2003 01:32 PM



All times are GMT -5. The time now is 02:34 AM.


Designed by eXtremepixels. Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 2.3.2 © 2005, Crawlability, Inc.