Unable to download/install some programs in READ&RUN

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Cam&Shani, Feb 27, 2006.

  1. Cam&Shani

    Cam&Shani Private E-2

    Hi,

    I'm running OS WinXP Home with SP2 Pentium 4 CPU 2.66GHz 2.67GHz, 504Mb RAM.

    Have been having problem with what I think is the about:blank hijacker and began working through the READ & RUN post, but seem to be unable to download or install a few of the programs on the list.

    I managed to get CCleaner, AdAware, and Spybot, but then was not able to get MS Windows Defender or MS Windows Malicious Software Removal Tool. Got HJT and CWShredder, but was also unable to get Kill2me.

    With both Win Def and Malicious Soft Remov, the process goes through normally as though it is working, but it just doesn't. There is no error messages. I've tried both, opening the files and running them and saving them to the hard drive to try to install from there and neither way was successful.

    Kill2me was different, it was stopped by windows security. When I tried to follow the instructions to unblock it, there was no unblock option. Don't actually know if I need it, was just going to use everything just incase.

    To begin with I thought, maybe the Win Def and Malicious problem was a download problem, (even sent a report error msg just incase *sheepish*) but then when I was reading the "Before You Post Asking For Help, Please Read This" post, I tried to get the program to tell me my system specs and it did the same as what I'd been experiencing with the other two.

    Um, I hope I haven't missed anything I should've included. Thanks for your time,

    Shanna
     
  2. Cam&Shani

    Cam&Shani Private E-2

    Was just reading about download probs in the FAQ section and thought I should mention that I'm also running Norton Internet Security 2006. Firewall is on, but as I said before, there is no error msgs or snything when I'm trying to do these downloads, it all appears to work, the files just don't appear or the install thing doesn't come up. Plus the fact that the first few I downloaded went ok. Could it still be the problem?

    One difference between them though is that for the others, I used one of the Australian download links (not the planetmirror, the other one) but for the two windows files, they both only have an "Author" link? Could be relevant?

    Anyway, hope this helps.
     
  3. Cam&Shani

    Cam&Shani Private E-2

    Hi, don't mean to be impatient, just wondering how long it normally takes for someone to get a chance to help?
    Thanks.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is a free service and we get to you as soon as we can. Your problem is that you kept losing your place in the que each time you posted another message. Oldest unanswered threads get answered first. You kept making yours newer and it looked answered. Be patient and we will always get to you.

    Has your OS been validated by Microsoft to be genuine. If not, you cannot download all updates or tools as you are experiencing.
     
    Last edited: Feb 27, 2006
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Complete the rest of the READ & RUN ME.

    Steps 6 and the two logs must be attached.

    Step 7, make sure HijackThis is installed as indicated or you will just waste more time.
     
  6. Cam&Shani

    Cam&Shani Private E-2

    Oh, woops, sorry bout that.

    Yes, I'm pretty sure I checked that a few days ago before I figured out what the problem was I was having (ie malware). Was making sure that the service packs for IE etc were up to date.
     
  7. Cam&Shani

    Cam&Shani Private E-2

    ok. will do. bbs.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When finished with the steps, attach the three logs to your next message.
     
  9. Cam&Shani

    Cam&Shani Private E-2

    Ok, I'm going to write this as I go along so I don't forget.

    I started from the start again just to make sure I hadn't missed anything.

    When I was going through add/remove programs, I came across Windows Defender! :confused: Weird since I couldn't find it. Anyway, I removed it so that I could try putting it back on again. Also, theres a couple of Casino programs that my husband has on there. When it says Casino client, does it mean, something specifically called that, or any casino thingy?

    Oh, the other thing is that on my start menu it doesn't have an 'explore' option, only 'search'. Do they do the same thing. I did use search to enable viewing of hidden files.

    Ok, both Windows Defender and Windows Malicious Software Removal worked that time - go figure. Dunno how many times I tried it before, was obviously doing something wrong. OMgosh!:eek: I can't believe it, for some reason, Kill2me even downloaded! Don't I feel like a dill.:eek:

    Everything seems to have gone fine. I've attached two BD logs as I actually ran the BD scan yesterday also. Please disregard bdscan1 if you only need the most recent one. The other two logs are also attached.

    Thanks so much for your time. It's amazing that all of you are willing to do this!:)
    Shanna
     

    Attached Files:

  10. Cam&Shani

    Cam&Shani Private E-2

    Well I guess this'll move me to the end of the que again, but I was just reading another thread and you said that they didn't follow the intructions properly to save their bdscan report, but theirs looked the same as the one I included in my last post.

    Thankfully, I also saved the log a different way to specified in the instructions (there's a link that says "export file" or something of the sort, immediately when the scan finishes and shows the report. I clicked on that to make this file) and I've attached that doc this time. I'm guessing that this is the one I should have on here, but if you do what the instructions say "When the window comes up with the report. Click File, Save As.... and then change the Save as type to Text File (*.txt)" then you wait for the second window and get a txt file that looks like the first ones I attached. *shrug* Hopefully one of these is the correct one. Unfortunately I only have the second one from the first scan as I thought the second file was the correct one (going by instructions), hope you don't need that one?

    Anyway, let me kno if I've missed or messed anything.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Empty all file from your Symantec\Norton AntiVirus\Quarantine folder.

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixadt.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixadt.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll (file missing)
    O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\PROGRAM FILES\COMMON FILES\Totem Shared <-- the whole folder

    Additional step to delete f3initialsetup1.0.0.8.inf :
    - Click Start, Run, and enter cmd in the box and click OK. This opens a command prompt windows.
    - Enter the following command lines each followed by the enter key
    cd C:\WINDOWS\Downloaded Program Files\
    attrib -r -h -s f3initialsetup1.0.0.8.inf
    del f3initialsetup1.0.0.8.inf
    exit

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  12. Cam&Shani

    Cam&Shani Private E-2

    Hi again.

    Thank-you so much for your help!! Computer is running much more efficiently now and startup is heaps quicker. Fresh HJT attached. I think it saved backups of those three lines it deleted, was it s'posed to do that?

    I am still having problems using some web pages though - I checked the same ones I'd been having trouble with before. Now I'm wondering if it's a setting problem instead of malware?

    Basically, it seems to be that when a page is supposed to open a new window for a particular function, the new window won't load properly. One site says that it has errors and the error msg is "Class doesn't support automation". The second site is supposed to bring up a log in screen in a new window, but it loads blank and the top bar where the details should be says about:blank (the reason I wondered if I had the about:blank problem). The original window says something about java in the satus bar. The third site opens a new window after you attempt to log in, in which you are supposed to click an "OK" button (agreeing to conditions of use), but the button just doesn't work at all.

    Thanks again.

    PS. Could you please let me kno which was the correct BD file, so I know incase I need to do it again.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes HijackThis makes backups. Your other problem with the automation erro is not malware but give the below a try:

    Did that help?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The one in message # 10.

    You're HJT log is clean now! Anymore malware problems?
     
  15. Cam&Shani

    Cam&Shani Private E-2

    Ok, I did the 3 regsvr things, but I haven't completed the JS extension thing yet because there was one "open" command and one "open with command prompt". Am I still sposed to delete one or are they both supposed to be there?

    OMGosh!!! I just tried the three sites before I posted this and they're all working properly!! You are an absolute legend!! Still do I need to get rid of either of those open commands?

    Thank-you, thank-you, thank-you!!!
    :D :D I so much appreciate your help!!!:D :D
     
  16. Cam&Shani

    Cam&Shani Private E-2

    Nope, seems to be all good, no malware either.

    Just a quick question, if we get rid of Symantec, which program would you recommend to replace it?

    Thank-you again!! I can't say it enough.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Don't do anymore commands if things are working okay!

    Your answer to the Symantec replacement is included in the link given below for your next steps.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  18. Cam&Shani

    Cam&Shani Private E-2

    ok, will do that in a tic.

    um, speaking of Norton,it is suddenly not working anymore. Is that something we did?
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! We did not do anything to impact Norton.
     
  20. Cam&Shani

    Cam&Shani Private E-2

    Right, well it isn't working anymore. The little thing that stays on the taskbar normally is gone and when I try to open it in the start menu, the border of the window opens, but it's empty if you know what I mean. and once it's open I can't easily close it again either.

    Any ideas or is there someone else I should talk to?
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well if you want to keep Norton! Uninstall it, reboot, and then reinstall.

    If you really planned on removing it permanently, now would be a good time to switch to something that is less of a system resource hog and that may work even better (like the ones in the link I gave you).
     
  22. Cam&Shani

    Cam&Shani Private E-2

    Thanks Chas,:)

    Am already in the process of requesting a refund from Symantec (this is actually the second time this has happened - just thought it was related to the other problems last time) and have downloaded AVG free. Everything else seems to be going great and I'm working through the "How to Protect...". Will make a note to do the system restore thing soon.

    Once again, much appreciated. You're a champ!

    Smiles!:D
    Shanna
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Make sure you only have one antivirus installed. So uninstall Norton before, installing anything else.
     
  24. Cam&Shani

    Cam&Shani Private E-2

    Just installed AVG. Had this warning come up


    Local machine: installed successfully
    Installation:
    Warning: Action failed for registry value HKLM\SOFTWARE\Classes\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}:409: creating registry value....
    Access is denied. (5)

    Is that a problem?
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's part ot the IOfficeAntivirus feature of MS Office. See: http://members.chello.be/ws36637/msoav.html

    It could be that all of the Norton/Symantec software had not been uninstalled or has not cleaned up after itself. Thus not allowing AVG to hook into that registry key.

    Attach a new HJT log.
     
  26. Cam&Shani

    Cam&Shani Private E-2

    New HJT attached.

    I have uninstalled Norton & Live Update, but had already downloaded AVG before I read you post to remove Norton first, so that's prob what caused the prob.

    Sorry to be such a pain! :eek:
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have some Symantec stuff running. If their name was not Symantec/Norton, they would be listed in malware due to the fact that they can be impossible to uninstall.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Symantec Core LC ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Symantec Core LC

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
    O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\Common Files\Symantec Shared <--- the whole folder

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)

    Make sure you tell me how things are working now. Are you still getting an error from AVG?

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  28. Cam&Shani

    Cam&Shani Private E-2

    OK, I got as far as trying to delete

    Symantec Core LC

    in HJT, but it said it's system critical and won't allow me to delete it.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It probably deleted it anyway and it is not system critical. Just continue with the rest of the steps.
     
  30. Cam&Shani

    Cam&Shani Private E-2

    Awesome! It's all running sweet - doesn't seem to be any probs with AVG. System restore is re-enabled. Nearly through the "Protect You Comp" thread also.

    Actually, it'd be a pretty safe bet to say our computer is running better today than it was the day we bought it! LOL

    Thanks so much and once again, sorry for being so painful!:D


    PS.I read somewhere that majorgeeks doesn't accept donations...is there any way to support the great work you guys do?
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    Send a message to the owners in appreciation of the help you received.

    Buy some Majorgeeks clothing if desired (link is on the main page).
     
  32. Cam&Shani

    Cam&Shani Private E-2

    Will check the merch out.

    How do I msg the owners?
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  34. Cam&Shani

    Cam&Shani Private E-2

    Thanks again Chas

    and now I will leave you alone.
    :)
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds