Page 2 of 2 FirstFirst 12
Results 11 to 16 of 16

Thread: please help - xlibgfl254.dll virus

  1. #11
    Security Expert-Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    3,934

    Default

    Hi again, we'll continue

    One or more of the identified infections steal information. If this system is used for online banking or has credit card information on it, all passwords should be changed immediately by using a different computer (not the infected one!) to make the changes. Banking and credit card institutions, if any, should be notified of the possible security breech. I suggest that you read this article too.

    You should print these instructions or save these to a text file. Follow these instructions carefully.

    Download ATF Cleaner by Atribune to your desktop.
    Do NOT run yet.

    Make your hidden files visible:
    • Go to My Computer
    • Select the Tools menu and click Folder Options
    • Click the View tab.
    • Checkmark the "Display the contents of system folders"
    • Under the Hidden files and folders select "Show hidden files and folders"
    • Uncheck "Hide protected operating system files"
    • Click Apply and then the OK and close My Computer.


    ==================
    Backup Your Registry with ERUNT:
    • Download erunt.zip to your Desktop from here:
      http://aumha.org/downloads/erunt.zip
    • Right-click erunt.zip, select Extract All... and follow the prompts to extract ERUNT to a new folder on your Desktop
    • Inside the new folder, double-click ERUNT.exe to start the program
    • OK all the prompts to back up your registry to the default location.
    Note: to restore your registry, go to the backup folder and start ERDNT.exe


    Open Notepad (NOT WORDPAD!) and copy the following lines from the quote box below into a new document, leaving a blank line at the end. (don't forget to copy and paste the word REGEDIT4) :

    REGEDIT4

    [HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders]
    "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

    Make sure there are NO blank lines before REGEDIT4
    Make sure there IS one blank line at the end of the file.

    Save the document to your desktop as Fix.reg and filetype: All Files
    Go to your desktop and double click on the file to run Fix.reg and when it asks you if you want to merge the contents to the registry, click yes/ok.

    Run HijackThis, click Do a system scan only, and check the box next to each of these entries if still present. Close all other windows and press Fix checked. If something isn't there, please continue with the next entry in the list.
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/c...o/bt_side.html
    O4 - HKLM\..\Run: [gwiz] C:\WINDOWS\system32\arpl.exe


    Restart your computer.

    Open "My Computer" and delete the following files (if present):
    C:\WINDOWS\system32\arpl.exe
    C:\23100247.exe
    C:\WINDOWS\system32\i
    C:\WINDOWS\system32\ntsystem.exe

    Use the Windows search BE CAREFUL WITH THE FILENAMES
    • Start
    • Search
    • All files and folders
    • More advanced options
    Checkmark these options:
    • "Search system folders"
    • "Search hidden files and folders"
    • "Search subfolders"
    • Search for this and delete if found: ntoskrnl.dll
    • Search for this and delete if found: xlibgfl254.dll
    • Search for this and delete if found: append.dll


    Run ATF Cleaner
    • Under Main choose: Select All
      Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main menu to close the program.

    Download Dr.Web CureIt to the desktop -> ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe

    Restart your computer to the safe mode:
    • Restart your computer
    • Start tapping the F8 key when the computer restarts.
    • When the start menu opens, choose Safe mode
    • Press Enter. The computer then begins to start in Safe mode.

    Run a scan with Dr.Web CureIt
    • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
    • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
    • Once the short scan has finished, you should now mark the drives that you want to scan.
    • Select all drives. A red dot shows which drives have been chosen.
    • Click the green arrow at the right, and the scan will start.
    • Click 'Yes to all' if it asks if you want to cure/move the file.
    • When the scan has finished, look if you can click next icon next to the files found
    • If so, click it and then click the next icon right below and select Move incurable
    • After the scan, in the menu, click file and choose save report list
    • Save the report to your desktop. The report will be called DrWeb.csv
    • Close Dr.Web Cureit.
    • Reboot the computer in Normal Mode,
    • Post the Cure-it report and a fresh HijackThis log
    Last edited by Mr_JAk3; 2007-09-19 at 18:35.
    MalWare Removal University - You too could train to help others
    UNITE & ASAP member since 2006

  2. #12
    Junior Member
    Join Date
    Sep 2007
    Posts
    11

    Default Me Bad!

    Hi, Thanks so much for all the help so far. However, looks like I screwed it up big time. I followed all the steps till the fix.reg creation. When I tried to merge it with the registry, I got an error message saying - import denied, cant access registry.

    So, I went to regedit, opened the HKEY LOCAL/Security Key and checked the permissions. Everything seemed ok, but I was not being able to add a new key. I restarted the machine and checked the registry again, and this time I could add a new key. So to undo the add, I ran the ERNDT which I had used before to take a registry back up, and this gave many many errors during the restore process. However I completed the restore process.

    This I think completely screwed the user permisions in the registry as I could not see any of the login ids (that I use in this pc) in the list when I opened a key in registry and checked the permissions. I rebooted and now i cant get it up. Everytime I boot it, it give me an error saying lsass.exe not found and reboots, even in safe mode.

    I am totally aghast, is there a way or have I lost it all ?

    Thanks again!

  3. #13
    Security Expert-Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    3,934

    Default

    Hi

    Ok let's see. All hope is not lost.

    Please try to start the pc with the Last Known Good Configuration feature.

    Let me know how it went
    MalWare Removal University - You too could train to help others
    UNITE & ASAP member since 2006

  4. #14
    Junior Member
    Join Date
    Sep 2007
    Posts
    11

    Default

    Yes, I tried that option, it didnt work :(

  5. #15
    Security Expert-Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    3,934

    Default

    Hi

    OK that makes things a bit complicated...

    You have the Windows installation disks, right?

    You could follow these instructions for repairing the registry -> Damaged Registry Repair and Recovery in Windows XP

    Let me know

    Otherwise there is no other choice than do a repair installation...
    MalWare Removal University - You too could train to help others
    UNITE & ASAP member since 2006

  6. #16
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,961

    Default

    This topic has been moved to archives.

    If you need the thread re-opened, please send me a private message (pm) and provide a link.

    Applies only to the original poster, anyone else with similar problems please start your own topic.
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •