Help - Search - Members - Calendar
Full Version: Programs moving around & trying to uninstall
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
Blackrat
Hi everbody i thought this would be the best place to try and get some help with a very bad situation i,ve encountered so here goes and i really hope yous can help me as i,ve tryed just about everything i can with limitations.

yesterday morning i was surfing the net and then needed to reboot the machine and everything seemed fine, i,m using winxp pro my internet browser is mozilla the latest with all updates i,m using the latest version of NOD32 AV with all the latest updates plus spysweeper full edition with all updates.

so heres whats happening when i got the desktop up i started getting loads and loads of windows being opened and asked was i sure i wanted to unistall spysweeper, i clicked no thinking i,d hit something by accident but nope another box appeared asking the same question with windows opening all over the place.
i cannot click on anything as whatever it is has full control over my system so i thought another reboot would do the trick but it got worse same problem as i,ve explained above only as the windows where opening the started to like float and move all around the screen flooding the box until it shut down.
i can,t do anything as it has taken conyrol of my mouse so i cannot click on anything to help myself or shut the opening boxes down.
i tryed rebooting into safe mode no problem again until i got the desktop window up and the same thing started again while running in safe mode i still no mouse control i can get task manager up but can,t stop anything i have googled this problem but i don,t even know how to put this into words in the search to find anything on this.

seems my biggest problem here is i can,t run any tools like CWSHREDDER or HIJACK THIS.
it has totally destroyed spysweepers installation plus my other programs please guys i would be grateful of any help and your opinions on this as i,m totally lost with this, as i,ve said i can,t run any tools so i can,t post any logs to help you at the moment so i,lle leave this for the experts to give me so ideas thank yous so much for taking time to read this for me. TTYL Blackrat.
Mosaic1
Are you always online? If so, unplug your modem and shut down the computer. Let it sit a few minutes and then restart. Is anything any better?

I can guess at several things but without access to your registry or file system it is not going to be possible to help you.


If unpkugging the moden didn't help then are you able to use your keyboard to access anything?

For example:

CTRL + ATL + DEL

then ALT + F

Then press N

That will get you a file run box. Type cmd.exe
Press enter.

Do you get the command prompt?

Doing this manually would be a very painful, difficult and slow process which I am not sure I would want to attempt.
Blackrat
Mosaic1 i,m really sorry about the late reply and thank you for your response to my problem as i,ve been very busy since this happened to my machine.
but i got the problem sorted it was all down to a FORTRES.DLL that was installed and thats what gave me such a big problem, i just ran the drive as slave and searched for everything under FORTRES, removed the .DLL and ran it again as my master and removed all remnants af it and luckily enough it was the culprit,so once again Mosaic1 sorry about the late reply it was,nt ignorance or anything just busy.Regards:Blackrat.
Mosaic1
Blackrat,

I'm glad you go that sorted. I have no idea how you boiled it down to FORTRES. Isn't that a security program?

Do you want to post a hijackthis log as a double check?

Download and then extract Hijackthis.exe to a new folder. Do not run it from the zip the desktop or a temp folder.

Here's a link:
http://www.merijn.org/files/hijackthis.zip

Do not remove anything using HijackThis. Save the log and then copy and paste the contents into your next reply here in this same topic. It lists many types of entries. Some are good, and others need to be removed. We will help you sort it out.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.