T-Spy.html.Smitfraud progress [RESOLVED]
#31
Posted 08 June 2005 - 11:04 PM
#32
Posted 08 June 2005 - 11:06 PM
Yes, please run ActiveScan now
#33
Posted 08 June 2005 - 11:11 PM
Also, I have a different system that's down right now; It's a P4, 925XE, 1GB DDR2 running XP SVC Pack2. I never put it online because it's for digital recording and I never wanted to have any problems like the one I HAD (Thanks 2U) with this one. Well...I went online to check an email really quickly and got right off. When I started back up, I got the "NTLDR is missing" during the boot and the hard reset command. What do you think?
Edited by peacemaker05, 08 June 2005 - 11:23 PM.
#34
Posted 08 June 2005 - 11:19 PM
What kind of vxd and dll errors are you receiving?
Edited by bananafanafo, 08 June 2005 - 11:20 PM.
#35
Posted 08 June 2005 - 11:52 PM
The other errors were connected to the setup.exe for IE6, now that it's installed I don't think it to be an issue any longer. It was the Run Time error I mentioned in post #12. Be back with the active scan results. You're an angel, thanks again!!!
Edited by peacemaker05, 08 June 2005 - 11:55 PM.
#36
Posted 09 June 2005 - 12:07 AM
#37
Posted 09 June 2005 - 01:50 AM
On startup after the main boot sequence just before Windows opens up I get the following DOS error message: Cannot find the device file that may be needed to run Windows or a Windows application. SYSTEM.INI reffers to this device file but the device no longer exists HLDDRV.VXD
Here's the Active Scan result log...
Incident Status Location
Adware:Adware/Adsmart No disinfected C:\WINDOWS\sys???.exe
Adware:Adware/IGuard No disinfected Windows Registry
Virus:Application/Eblaster No disinfected Windows Registry
Adware:Adware/BlueScreenWarningNo disinfected Windows Registry
Virus:Application/Eblaster No disinfected C:\WINDOWS\SYSTEM\wmsemod.dll
Adware:Adware/Adsmart No disinfected C:\WINDOWS\SYSMON.EXE
Edited by peacemaker05, 09 June 2005 - 01:54 AM.
#38
Posted 09 June 2005 - 02:05 AM
msconfig
Click on the System.ini tab
Click the plus signs and see if you can find that HLDDRV.VXD in there, let me know what it's under, but don't do anything with it.
I need you to delete these files:
C:\WINDOWS\SYSTEM\wmsemod.dll
C:\WINDOWS\SYSMON.EXE
Look and see if you can find this one, if there isn't one with actual ??? in it, give me the of any files that start with sys followed by 3 letters.exe
C:\WINDOWS\sys???.exe
Edited by bananafanafo, 09 June 2005 - 02:05 AM.
#39
Posted 09 June 2005 - 02:38 AM
I clicked on the System.ini tab and searched all the processes by clicking on the expander icons (the +'s) but I did not find that DLDDRV.DXV device component.
I found and "deleted" sent to the (recycle bin) the following malicious entries:
1) SYSMON.EXE
2) wmsemod.dll
Now, on the sys???.exe issue...the only two files I saw with a suffix following sys-but preceeding .exe were found in the WINDOWS\SYSTEM folder and they are
1) Sysedit.exe
2) Systray.exe
I did not see anything remotely close in the WINDOWS folder, and did nothing to these devices.
Edited by peacemaker05, 09 June 2005 - 02:38 AM.
#40
Posted 09 June 2005 - 02:47 AM
The HLDDRV.VXD has to be in system.ini because system.ini is trying to load it...
#41
Posted 09 June 2005 - 02:53 AM
system.ini
Click OK
Copy and paste what's in the notepad here (I think this will work on a 98...)
#42
Posted 09 June 2005 - 02:56 AM
[boot]
oemfonts.fon=vgaoem.fon
shell=Explorer.exe
system.drv=system.drv
drivers=mmsystem.dll power.drv
user.exe=user.exe
gdi.exe=gdi.exe
sound.drv=mmsound.drv
dibeng.drv=dibeng.dll
comm.drv=comm.drv
mouse.drv=mouse.drv
keyboard.drv=keyboard.drv
*DisplayFallback=0
fonts.fon=vgasys.fon
fixedfon.fon=vgafix.fon
386Grabber=vgafull.3gr
display.drv=pnpdrvr.drv
[keyboard]
keyboard.dll=
oemansi.bin=
subtype=
type=4
#43
Posted 09 June 2005 - 03:00 AM
Go to Start > Run type
regedit
click to highlight "My Computer" on the left-side. Go up to "Edit > Find" and put this in there:
HLDDRV.VXD
Let me know the location where it's found.
Edited by bananafanafo, 09 June 2005 - 03:03 AM.
#44
Posted 09 June 2005 - 03:02 AM
[windows]
load=
run=
NullPort=None
device=hp officejet v series,hpodj907,DOT4_001
[Desktop]
Wallpaper=C:\WP.BMP
TileWallpaper=0
WallpaperStyle=0
Pattern=(None)
[intl]
iCountry=1
ICurrDigits=2
iCurrency=0
iDate=0
iDigits=2
iLZero=1
iMeasure=1
iNegCurr=0
iTime=0
iTLZero=0
#45
Posted 09 June 2005 - 03:04 AM
regedit
click to highlight "My Computer" on the left-side. Go up to "Edit > Find" and put this in there:
HLDDRV.VXD
Let me know the location where it's found.
Similar Topics
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users