Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > OS & Software > Security and the Web

Dell Inspiron 9300 - Serious Issue, Malware?

Reply
Bookmark / Share this page
Thread Tools
  #1  
Old 10-14-2008
Newcomer, in training
 
Member since: Oct 2008, 6 posts
Dell Inspiron 9300 - Serious Issue, Malware?

Hi All,

Here is my situation. It would appear that my laptop has become seriously inhibited.
After returning home from work a couple of nights ago, my son informed me that the Laptop was not working right.

Ok here is the run down.


Ok I have followed the above guide to the best of my ability / Failing laptops.

I have not been able to get the latest revisions (updates) for Malwarebytes' Anti-Malware and SuperAntiSpyware as I am unable to connect to the internet. I have now purposely at this stage disabled the connection to the router. The reason for this is every time I have attempted to connect I get the following behaviour.

The desktop will drop-out and I am then forced to CTL-ALT-DEL, to run explorer, the downside of this however is that I get about 10 seconds to try to execute anything. (This is in safe mode and normal boot).

After running through the 8-step guide, (without the opportunity to connect online).

After step 4 - The running of Malwarebytes' Anti-Malware, I am now able to get to the desktop and behaviour of the machine is fine, this is without any connection to the router. If I enable the router the whole situation repeats.

Bearing the above in mind I was unable to undertake step 6 (Update Java Runtime Environment).

I have attached the requested logs.

Please Help.

Many Thanks
Gareth B
Attached Files
File Type: log hijackthis.log (5.3 KB, 1 views)
File Type: txt mbam-log-2008-10-14 (19-13-33).txt (1.7 KB, 1 views)
File Type: log SUPERAntiSpyware Scan Log - 10-14-2008 - 20-24-05.log (465 Bytes, 0 views)
Reply With Quote
  #2  
Old 10-14-2008
kimsland's Avatar
TS Special Forces
 
Member since: Dec 2007, 11,673 posts
Please run HJT again, and tick and fix these two:
Quote:
C:\WINDOWS\system32\qoMedASM.dll
O20 - Winlogon Notify: qoMedASM - C:\WINDOWS\SYSTEM32\qoMedASM.dll
Also go to C:\WINDOWS\system32 and delete qoMedASM.dll
You may need to do this in Safe Mode

Then try connecting and updating, and scanning again
Ideally let us know (say even before you update the Programs) that it is presently working
Reply With Quote
You can remove this banner by registering, join the TS Community for free.
  #3  
Old 10-14-2008
Newcomer, in training
 
Member since: Oct 2008, 6 posts
Firstly thank you.

Ok trtied to delete qoMedASM.dll in both normal mode and safe mode.

In safe mode it give me the message.

Cannot delete qoMedASM: It is being used by another person or program.
Close any program that might be using the file and try again.

On a slightly different note when i boot into safe mode there are to logon option.

Mine and Administrator, is this usually the case?

Cheers
Reply With Quote
  #4  
Old 10-14-2008
kimsland's Avatar
TS Special Forces
 
Member since: Dec 2007, 11,673 posts
Yes that's normal
I should've said log on to Administrator, but forget that now

In HJT there's an option to remove files that cannot be removed normally

Run HJT
(Doh, I haven't got it installed !!!)

Anyway, it's on the first screen, that says misc, tools or something
And in there, is a program to remove files in use (I don't know the label, but can get it if you like)
Reply With Quote
  #5  
Old 10-14-2008
Newcomer, in training
 
Member since: Oct 2008, 6 posts
Hi Again,
It wouldn't let me log on as Administrator, asking for a password and mine did not work. Then logged on in safe mode as me, and tried to delete the file on reboot through the Hijack program, however the file remains?

Not tried to enable my connection just yet.
Reply With Quote
  #6  
Old 10-14-2008
kimsland's Avatar
TS Special Forces
 
Member since: Dec 2007, 11,673 posts
Sorry was away from computer

Please try connecting and let me know the result
We can work out the Admin pass thing a bit later on
Reply With Quote
  #7  
Old 10-14-2008
Newcomer, in training
 
Member since: Oct 2008, 6 posts
It seems to connect but everytime i tried to updates or go online, it states there is no connection. the pc i am using now is connected via the same connection. ?
Reply With Quote
You can remove this banner by registering, join the TS Community for free.
  #8  
Old 10-14-2008
kimsland's Avatar
TS Special Forces
 
Member since: Dec 2007, 11,673 posts
Please do this and then Restart: http://www.techspot.com/vb/post662504-2.html

By the way, it is hard wired using Ethernet (Not USB or wireless) isn't it?
Reply With Quote
  #9  
Old 10-14-2008
Newcomer, in training
 
Member since: Oct 2008, 6 posts
It is wireless yes. And the symptoms have now reverted. !
Reply With Quote
  #10  
Old 10-14-2008
kimsland's Avatar
TS Special Forces
 
Member since: Dec 2007, 11,673 posts
ok it's getting more difficult !

Lets start by removing that Admin Password (it'll probably help a great deal)
Have a look h e r e Go for the Live BootCD and then boot from it

This will take you a little while (download and burn ~ 20 mins & Boot and view password ~ 20 mins or so) So hear back in an hour or so Good Luck

By the way, once you write down (the case sensitive) password(s)
Go back to Safe Mode, and try removing that file again
Reply With Quote
  #11  
Old 10-14-2008
Bobbye's Avatar
TechSpot Guru
 
Location: Clearwater, FL
Member since: Mar 2007, 2,737 posts
Question about this statement:
Quote:
I have now purposely at this stage disabled the connection to the router. The reason for this is every time I have attempted to connect I get the following behaviour.
Can you connect when you bypass the router? If so, you may have a bad router.
Reply With Quote
  #12  
Old 10-14-2008
TechSpot Maniac
 
Location: Chicago-land, IL
Member since: Apr 2007, 1,573 posts
Quote:
It wouldn't let me log on as Administrator, asking for a password and mine did not work.
When i read this i just have to ask to cover all possibilities: Have you ever assigned an Administrator password? From your statement, maybe not. Did you try just hitting Enter? (The default password is no password)
Reply With Quote
  #13  
Old 10-15-2008
Newcomer, in training
 
Member since: Oct 2008, 6 posts
Hi All,

The router is fine i have other hardware working fine through it.
I have never assigned an Admin Password, and as your suggestion tried the default of no password.
Gonna try the Live Boot Cd this morning. Fingers Crossed.

Ok got on as Administrator, but still cannot remove the qoMedASM.dll file?

Just to let you know i havetreid the following:

Logon as Administrator.
Tried to remove the file using Malwarebytes' Anti-Malware. (remove file on Reboot)
Reboot
Look for ther file on reboot it is still there.
Ty to remove thefile using a similar utility in Hijack
Reboot
Look for ther file on reboot it is still there.
I have not attempted to go online per say as yet, as i know the virus will start all over again.

Any other suggestions would be greatly appreciated.

Cheers

Managed to get the file off in the end using and Unlocker program. Ran through the win sock cmd commands, and now have established a connection. It is now time for the * step guide from fresh. I will re-post all relevent logs a little later.

Phweh


Thanks Kimsland - going through the whole routine one last time.
Anything else i should do once i have completed the step by step guide.


Ok New note - What Firewall protection would you reccomend, at the moment I am using the default Firewall supplied with windows.

Last edited by Gareth B; 10-15-2008 at 09:17 AM.
Reply With Quote
  #14  
Old 10-15-2008
kimsland's Avatar
TS Special Forces
 
Member since: Dec 2007, 11,673 posts
I was going to suggest Unlocker, but I knew you couldn't download, so stuck with the normal ones.

Anyway, thanks for the update.
Also instead of replying to yourself (causing excessive emails to everyone just use Edit instead)
Edit: Moderator now combined your posts

Hear back from you later on.
.

Last edited by kimsland; 10-15-2008 at 08:18 AM.
Reply With Quote
Reply
Thread Tools

Forum Jump

Similar Topics
Thread Thread Starter Forum Replies Last Post
Dell Inspiron 9300 Battery question sills18 Other Hardware 5 10-13-2006 12:15 AM
BSOD in Dell Inspiron 9300 ooogyman Windows OS 6 04-23-2006 09:29 PM
Dell Inspiron 9300 1.6ghz, 512mb,40GB,DVD Burner $899 Deal Svengali Hot Deals 0 07-26-2005 03:02 AM


All times are GMT -4. The time now is 12:24 PM.