AllExperts > Computer Security & Viruses 
Search      
Computer Security & Viruses
Volunteer
Answers to thousands of questions
 Home · More Computer Security & Viruses Questions · Answer Library  · Encyclopedia ·
More Computer Security & Viruses Answers
Question Library

Ask a question about Computer Security & Viruses
Volunteer
Experts of the Month
Expert Login

Awards

About Us
Tell friends
Link to Us
Disclaimer

 
 
 
 
About Brian Benosky
Expertise
I will help you in eradicating malware and all forms of virus/trojans/adware. I can answer all PC-related hardware issues. I can also troubleshoot Windows OS errors (including Vista) and other software problems. HijackThis logs are a MUST for virus related help. If you do not know how to do this, I have posted easy-to-follow instructions on the Ask a Question page. Every computer infection is different, so I will give you personal instructions on how to remove the malware, not a 'pat' answer. You can be assured of a prompt, polite, and knowledgeable response in all regards.

Experience
I have over 25 years experience in using, building, and repairing computers. I have helped over a thousand people here on AllExperts, with consistent Top Feedback Scores. Please look at my answers here: http://en.allexperts.com/q/Computer-Security-Viruses-1737/indexExp_84308.htm I am also a Top Contributer of General Computing answers in Yahoo! Questions.

Education/Credentials
College Educated Self-taught Computer Skills

 
   

You are here:  Experts > Computing/Technology > Internet/Network Security > Computer Security & Viruses > system error

Computer Security & Viruses - system error


Expert: Brian Benosky - 11/16/2007

Question
QUESTION: I am receiving an error as soon as i switch on my computer:
------------------------
RUNDLL
---------------------------
Error loading C:WINDOWSsystem32winsys16_061230.dll

Access is denied.


---------------------------
OK   
---------------------------
The second question :While scaning the objects detected are C:Tally   ally72.exe
   C:Tally   ally72.exe.BAK
I would be glad if you could help me out with this.

ANSWER: Hi Ritika

It looks like you have a worm on your PC.  Please go to the following link and download HijackThis:

http://www.download.com/HijackThis/3000-8022_4-10227353.html

Download to your desktop or other convenient location, and run HJTSetup.exe to install. Once installed open HijackThis by clicking Start -> Program Files -> HijackThis.
1. Click the button labeled Do a system scan and save a logfile.
2. HijackThis will quickly scan your system, and then open two new windows. The results of the HijackThis scan, and hijackthis.log in Notepad. Save hijackthis.log. By default it will be saved to C:\HijackThis, or you can chose “Save As…”, and save to another location.
3. Hijackthis.log contains the info that’s required for analysis. Highlight the entire contents. Copy and paste the contents into a follow-up here. DO NOT fix anything.  I will get back to you with instructions.

---------- FOLLOW-UP ----------

QUESTION: hi, Brian, this is a follow up question with reference to your answer to run Hijack this.Following are the contents:
_______________________________________________________

Logfile of HijackThis v1.99.1
Scan saved at 10:13:26 AM, on 11/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
c:\program files\a-squared free\a2service.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\Grisoft\AVG7\avgw.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
E:\SOFTWARE DOWNLOAD OFF\trade tiger download 2 nov\TradeTiger.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
C:\PROGRA~1\WinZip\winzip32.exe
C:\DOCUME~1\USER\LOCALS~1\Temp\HijackThis.exe

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\USERINIT.EXE,rundll32.exe C:\WINDOWS\system32\winsys16_061230.dll start
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=111707 serial=DR12CUK-5333492-PGW lang=EN
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{01061CD7-2DF7-4581-B96D-F646BF69F32E}: NameServer = 203.187.192.15 203.109.127.23
O17 - HKLM\System\CCS\Services\Tcpip\..\{2E22C57D-66FF-45D8-B47A-765783E49C29}: NameServer = 203.187.192.15,203.187.192.12
O17 - HKLM\System\CS1\Services\Tcpip\..\{01061CD7-2DF7-4581-B96D-F646BF69F32E}: NameServer = 203.187.192.15 203.109.127.23
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - c:\program files\a-squared free\a2service.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Indexing Helps (Indexingbox) - Unknown owner - %WINDIR%\system\svchest.exe (file missing)  

Answer
Hi Ritika

Download ATF Cleaner from here:
http://www.atribune.org/ccount/click.php?id=1
Double-click ATF-Cleaner.exe to run the program.

Under Main choose: 'Select All' (cookies optional)
Click the 'Empty Selected' button.

Next, download ComboFix To Your Desktop from here:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Double click combofix.exe & follow the prompts.
A window will open with a warning.
Type 'Y', press Enter.
When the scan completes it will open a text window.
Caution - do not touch your mouse and keyboard until the scan completes.
The scan temporarily disables your desktop, and if interrupted, it may freeze your desktop. If this occurs, simply reboot.
Combofix will automatically save the log file to C:\combofix.txt

Finally, please download SUPERAntiSpyware Home Edition here:
http://www.superantispyware.com/downloadfile.html?productid=SUPERANTISPYWAREFREE

Install it and double-click the icon on your desktop to run it.
It will ask if you want to update the program definitions, click 'Yes'.
Now reboot your PC to 'Safe Mode':
Click Start and then click Shut Down.

In the drop-down list of the Shut Down Windows dialog box, click Restart, and then click OK.

As your computer restarts but before Windows launches, press F8.  

Use the arrow keys to highlight 'safe mode', and then press ENTER.

Now Click on SUPERAntiSpyware
Under Configuration and Preferences, click 'Preferences'.
Click the Scanning Control tab.
Under Scanner Options make sure the following are checked:

   * Close browsers before scanning
   * Scan for tracking cookies
   * Terminate memory threats before quarantining.
   * Ignore System Restore/Volume Information on ME and XP

Please leave the others unchecked.
Click the Close button to leave the control center screen.

On the main screen, under Scan for Harmful Software click Scan your computer.
On the left check C:\Fixed Drive.
On the right, under Complete Scan, choose Perform Complete Scan.
Click Next to start the scan. Please be patient while it scans your computer.
After the scan is complete a summary box will appear. Click OK.
Make sure everything in the white box has a check next to it, then click Next.
It will quarantine what it found and if it asks if you want to reboot, click Yes.

After reboot, run HijackThis again and save a new log.
Click the SUPERAntispyware icon on your desktop.
   * Click Preferences . Click the Statistics/Logs tab .
   * Under Scanner Logs , double-click SUPERAntiSpyware Scan Log .
   * It will open in your default text editor (such as Notepad/Wordpad).
   * Please highlight everything , then right-click and choose copy.
   * Exit the program.

Paste that Scan log, along with the new HijackThis log, and the ComboFix log into a follow-up here so that I can look it over.

Brian

Add to this Answer    Ask a Question



  Rate this Answer
   Was this answer helpful?
Not at allDefinitely              
   12345  

     
About Us | Advertise on This Site | User Agreement | Privacy Policy | Help
Copyright  © 2008 About, Inc. About and About.com are registered trademarks of About, Inc. The About logo is a trademark of About, Inc. All rights reserved.