Virus/Malware SAS/MBam won't instal even in Safemode

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by carmello2003, Oct 10, 2012.

  1. carmello2003

    carmello2003 Private First Class

    Can not access the internet (Safemode or otherwise) Can not access Control Panel, Network Connection.
    When connecting to the internet IExplorer just Flashes.
    I got somethings back after running Combofix.
    I get a error when trying to instal SAS (in safemode)that says "Failed to create shortcut, Aborting"
    I get an error when trying to install MBam (in safemode)that says "CoCreateInstance Failed; Code 0x80040154"

    I googled it and I ran A couple "RKills" till one worked.

    ComboFix installed a recovery that did not work.
    Got as fas as asking what I wanted to restore. The only choice was
    1. C:windows but I typed in 1 and hit enter and just got a command prompt C:_ blinking
    Please Help
    Its a friends computer and she has lots of kids it looks like they have been on IMesh and Bearshare.
     

    Attached Files:

  2. carmello2003

    carmello2003 Private First Class

    Thought I should mention I am running

    XP Pro SP3
    Version 2003
    1Gb Ram

    Computer is a HP Pavillion
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to finish running the below

    READ & RUN ME FIRST. Malware Removal Guide


    And then attach the rest of the logs we requested. You only attached 2 of the 5 logs we requested and require in order to help you.

    Also what lead you to believe there were malware problems on this PC to begin with? Was it just the lack of internet access?
     
  4. carmello2003

    carmello2003 Private First Class

    Sorry about that I thouggt I had the others.
    Like I said Malwarebytes wouldn't open and I tried to download it to flash drive and it wouldn't install. This happened in Safemode.
    I get an error when trying to install MBam (Malwarebytes) (in safemode)that says "CoCreateInstance Failed; Code 0x80040154"


    I assumed it was malware because no internet, Disabled anti virus, access to control panel and Restore disabled.
    Thank You For Your Time.
     

    Attached Files:

  5. carmello2003

    carmello2003 Private First Class

    Also,
    I couldn't even open (and still can't) CCleaner from desktop. Only from Program files.
    If I make a (fresh) shortcut to the desktop from program files it still will not open up from desktop.
    I tried to open Malwayebytes from Prog File but it did not work.
    While trying to reinstall Malwarebytes it Uninsteall the old version.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Just as easily caused by broken protection software.

    Also note that according to your MGtools log, it accessed the internet just fine. See the nwktst.txt log in the MGlogs.zip file which shows it could ping by IP address as well as by URL. The log shows full network connectivity.

    I'm not sure all your issues are due to malware but I do see a bunch of junkware that needs to be removed.

    Let's start though by uninstall Avast since there is a good chance it is broken anyway. Do this now and then continue with the below.

    Also uninstall the below now:
    CWA Reminder by We-Care.com v4.1.18.3
    J2SE Runtime Environment 5.0 Update 6
    NetAssistant
    Produtools Manuals 2.1 Toolbar
    Yontoo 1.10.02



    Please download OTM by Old Timer and save it to your Desktop.
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Documents and Settings\Kristie\Local Settings\Application Data\Smilebox
    C:\Documents and Settings\Kristie\Local Settings\Application Data\visi_coupon
    C:\Documents and Settings\All Users\Application Data\Tarma Installer
    C:\Documents and Settings\All Users\Application Data\WeCareReminder        
    C:\Documents and Settings\Kristie\My Documents\My Smilebox 
    C:\Documents and Settings\Kristie\Start Menu\Programs\NetAssistant
    C:\Documents and Settings\Kristie\Start Menu\Programs\Smilebox.lnk 
    C:\Program Files\Free Offers from Freeze.com
    C:\Program Files\Freeze.com
    C:\Program Files\Yontoo
    C:\Documents and Settings\Kristie\Application Data\DefaultTab
    C:\Documents and Settings\Kristie\Application Data\Smilebox
    c:\Program Files\BearShare Applications
    
    :Reg
    [HKEY_USERS\S-1-5-21-1229272821-1303643608-682003330-1003\Software\Microsoft\Windows\CurrentVersion\run]
    "ctfmon.exe"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DATAMNGR]
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\Program Files\\BearShare Applications\\MediaBar\\Datamngr\\ToolBar\\dtUser.exe"=-
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{8CB95106-6966-4E97-B9C1-7A4916937B06}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. carmello2003

    carmello2003 Private First Class

    UNINSTALL CWA REMINDER---->
    The windows installer could not be accessed. This can occur if you are running in safe mode (which I am not) or the windows installer is not correctly installed

    UNSTALL AVAST-----> Complete

    Uninstall J2SE----> The windows installer could not be accessed. This can occur if you are...............

    UnInstall Produtools Manuals-----> Complete

    Uninstall Yonto-----> Complete
    After Uninstalling Yontoo IExploter opened up but would not connect.
    Now if I Try to open it myself it opens but freezes. It wouldn't opewn at all before.

    Restarting and going to use OTM then trying again.
     
  8. carmello2003

    carmello2003 Private First Class

    As soon as it (OTM) tries to start I get message......
    OTM has encountered a problem and needs to close.
    INFO-----> Appname: OTM.exe AppVer; 3.1.21.0 Modname; Kernel32dll
    Modver; 5.12600.5781 Offset: 00012afb
     
  9. carmello2003

    carmello2003 Private First Class

    Tried again to re-install Malwarebytes and I got .....> CoCreateInstance failed; Code 0x80040154.
    Class not registered
     
  10. carmello2003

    carmello2003 Private First Class

    I have to go to work. Will check back later.
     
  11. carmello2003

    carmello2003 Private First Class

    Went to Control Panel thru RUN:
    tried to uninstall programs....... Same msg's
     
  12. carmello2003

    carmello2003 Private First Class

    I DO have a generic XP CD here. Can I change the C.O.A. after installing legally?
    I downloaded XPPID.exe
    Thought I would ask first.
    I am doing a scf /scannow first.
    I DO want to thank you for your time. Most of my computer knowledge and experience has come you MagorGeeks!
    (A little google also)
    Where there is a will there is a way!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should not be doing anything that I do not ask you to. This includes trying to install MBAM, running sfc, and other things you are doing. We know you are trying to fix your PC but it is much better that you only do what we ask and nothing else. Don't even keep trying to uninstall things that did not uninstal. We will come back to this later.

    Please boot into safe mode, and attempt to follow the instructions with OTM. Whether it works or not, boot into normal mode to do the C:\MGtools\GetLogs.bat instructions and attach a new MGlogs.zip file.
     
  14. carmello2003

    carmello2003 Private First Class

    OK will do ONLY as you request.
    OTM would not run in safemode or otherwise. "Program an encountered an error and needs to close..........."

    Here is the MGlogs.
    It was almost finished when I got an "ProcessDll.exe Application Error"

    The SFC /Scannow.exe did nothing
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This new log seems much different than the first log you posted. Now MGtools shows no connection to the Internet.

    Can you boot this PC in normal boot mode? If yes, please run everything in normal boot mode from now on. Your last MGlog.zip was from safe mode and I specifically stated to boot into normal mode to get this log.

    Back in message # 7, you said nothing about having any problems with uninstall NetAssitant that I asked you to uninstall. Please uninstall this now. If you have a problem uninstalling it then use the below program to try and uninstall everything that you could not uninstall from my list.

    Revo Uninstaller

    Then continue on with the below.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now download The Avenger by Swandog46, and save it to your Desktop.



    See the download links under this icon [​IMG]
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Be patient while doing the below. The fixes can take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.



    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Now run MGtools.exe ( Note: If using Vista or Win7 make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )




    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Oct 14, 2012

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds