Help! Computer will only start in safe mode!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by carlrobison, Mar 31, 2010.

  1. carlrobison

    carlrobison Private E-2

    In the last couple weeks, this computer (running Vista) started doing weird things. Icons in the toolbar started to disappear, it slowed down and the screen resolution would change on its own. A couple days ago I got a blue screen which said something about "windows needs to close down to prevent further damage." Now it will only start in safe mode. I read the post on what to do first. I think I got through everything except when I tried to remove all old instances of Java, I got the message "the windows installer service could not be accessed. This can occur if the installer is not correctly installed. contact your support personal for assistance." My wife mostly uses this computer for word processing and she was still doing that in safe mode putting up with the screen resolution, but now it won't allow her to save documents. When she selects "Save as..." no window pops up. She's using Open Office. Anyway, any help would be greatly appreciated. Thanks!
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there, and welcome. :)

    Then please attach what logs you have.
     
  3. carlrobison

    carlrobison Private E-2

    Thanks for your reply! However, I must be looking at the wrong post, because I'm not seeing where it's asking me to run anything that produces log files. This is what I'm reading

    http://forums.majorgeeks.com/showthread.php?t=35407

    Please let me know where else I should look. And once I DO have logs, am I correct that I don't post them in the reply but send an attachment? Thanks again. I'm kinda new at this!
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Scroll down until you see your operating system, Vista in your case.... THEN follow instructions from there as well. ;)

    Yes, we like attachments here not "inline" logs. :)
     
  5. carlrobison

    carlrobison Private E-2

    Sorry about that. So I downloaded all the progams, turned off UAC and rebooted. When I try to install Superantispyware, I get the message "The windows installer service is not accesible in safe mode....." and it won't let me install. What's my next step? Thanks!
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes.. as stated in the instructions, if one step doesn't work, simply move onto the next, noting down any errors you may receive that you can later report. :)
     
  7. carlrobison

    carlrobison Private E-2

    Thanks so much for your help. Everything seems to be working okay. You're great!!!
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem, but if you wish for us to check for any remaining malware (which is often the case) then you can attach those requested logs.
     
  9. carlrobison

    carlrobison Private E-2

    Okay, so I ran all the programs and they seemed to run okay except rootrepel. It kept saying that AVG was running though I made sure it wasn't. Then it wouldn't finish running. It would give me an error message but the window itself was transparent, I could see the text behind the window but not what the error message was. Anyway, I'm attaching any logs I could find. The computer seems to be running okay but icons from the network icon and volume icon on the task bar keep disappearing. If I go to properties on the task bar, the option to always show these icons is grayed out. Thanks for your help!

    I couldn't find the log from mgtools or super anti spyware. I did a search for both but they were nowhere to be found.

    Thanks!

    Sorry ....somehow didn't send attachments.
     
  10. carlrobison

    carlrobison Private E-2

    here are the attachments
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well those logs showed nothing out of the ordinary.... but the other logs you failed to attach because you said you couldn't find them I will show you where they are. I would like to see them to completely diagnose if you are having a malware issue or not.

    Your SAS log is retrievable here:
    The zipped log from running MGTools.exe is sitting right here (on your c drive):

    Please attach them into your next reply. :)

    Thanks
    Kes13!
     
  12. carlrobison

    carlrobison Private E-2

    Thanks again for your help. Here are the logs
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Important Notice: A new version of SUPERAntiSpyware is available.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later.
     
  14. carlrobison

    carlrobison Private E-2

    Okay. Here's the log. Thanks!
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    This is something you can discuss in the software forum. Let's just do this:



    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix exit HJT.

    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).
    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  16. carlrobison

    carlrobison Private E-2

    Thanks once again!!!! My wife was just telling me her mother got a computer virus (they live in another state) and she had to pay someone $150 to have it removed..... You've been wonderful! I'm going to run all these scans on my other computers!!!!
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome ;) Safe surfing!
     
  18. carlrobison

    carlrobison Private E-2

    New problems. The computer worked fine for a few days. I decided after reading some posts here about AV software and how AVG may slow the computer down, I decided to uninstall it (since we were having speed issues) and try AntiVir. I then started having issues with the computer locking up and going to a black screen with the only way to shut down the computer was to unplug it and take the battery out. I've also started having networking issues which I've never had before (I posted the problem on the Networking forum here but didn't get a response). So I then installed Avast, but had the same issues. Then in the last couple days, I was getting the message there was no antivirus protection installed on the computer even though Avast was installed it seems it wouldn't load for some reason. Now I'm still having the same issue with the computer freezing and going to the black screen so I thought I'd run all the scans again. I'm attaching what I could. Root repeal freezes and comes up with a warning window that I can't read because it's transparent and I can only read the text behind the warning box. Tried this twice with the same results.
    Thank you so much for all your help.
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I would rather you have begun a new thread rather than piggy backing off this one, but no matter, we will proceed. :)

    Whilst I put the kettle on and review your logs please attach the below log from running MBAM:

     
  20. carlrobison

    carlrobison Private E-2

    Thanks again. Here it is.
     

    Attached Files:

  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am not seeing any malware in those logs.

    I presume you eventually uninstalled avast again due to it not working properly? I am seeing no signs of it being installed. After we have made some progress you must install some anti virus again. I will have you run the avg removal tool as well as getting rid of remnants of avast.

    Avg Removal Tool


    Now Run Ccleaner. (Not the registry section)

    Please go to Add/Remove programs and uninstall the following software:

    • Java(TM) 6 Update 19

    Use windows explorer to find and delete the below file. It is not malware, it is just from running combofix.

    Now we need to use ComboFix to be rid of old antivirus remnants.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    RegLock::
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    
    Folder::
    c:\programdata\Alwil Software
    c:\program files\Alwil Software
    c:\programdata\avg9
    c:\program files\AVG
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  22. carlrobison

    carlrobison Private E-2

    Here are the logs
     

    Attached Files:

  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.


    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Also delete all files in the below folder except ones from the current date (Windows will not let you delete the files from the current day).

    Any other issues that remain must be dealt with in the software forum, as once again, these logs are clean, and you can follow the final steps.
     
  24. carlrobison

    carlrobison Private E-2

    Okay, I did get a successful merge. Thank you for your help! If I have any further problems, I'll post in the software forum.
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. :) Safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds