Vista and READ & RUN ME FIRST b-4 asking for support

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by gatorman, Jul 4, 2007.

  1. gatorman

    gatorman Private E-2

    Have had e-machine with Vista for 7 weeks and already have a problem with ErrorSafe in its differing forms. Thanks to major geeks I wouldn't have even known it was a problem, nor got my printer to work or been able to get antivirus after my ISP provider told me to get rid of Mcaffee when I started with them because they provided it-for every OS except Vista. Anyway as bewildering as it looks I figure I have to go through READ & RUN ME FIRST to get rid of it. Of course I stumble at knowing whether I have MSConfig Startup Mode. I then go to step 4 and figure I can learn how to download tools needed to folder and not install until told. Then it starts to strike me as I read on that all of these great instructions go for Windows 95,98...up to XP which has been the problem I've had with getting anything done on this darn computer. Can't even print coupons off the net for the grocery store. So do I try and go with the process trying to use the XP info if possible? Is there a form of READ & RUN ME FIRST out there that has the steps for Vista? Do I gladly volunteer to be a test case since my computer has so little baggage on it? I have faith in Major Geeks. Please help.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All of the READ & RUN ME applies to vista with the below exceptions/requirements

    • CCleaner works, but its best to set the Privilege level on this app to Run as Adminstrator, so all areas and registry locations are scanned fully, also helps with removal of junk. Do this via right clicking the shortcut on the Desktop/Start menu choose compatability and tick the privilige Level to "Run as Administrator"
    • to run GetRunKey and ShowNew you must disable UAC
    • the two online scanners (BitDefender and PandaActiveScan) cannot be run on Vista
    • Hijackthis will run but it does not have access to the Hosts file if run normally. UAC will block its scan, to scan, you need to right click the Hijackthis/Analyze exe and Choose "Run as Administrator".
     
  3. gatorman

    gatorman Private E-2

    Have faithfully run the steps and submitted info please contact. Thanks.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Where is the log from CounterSpy? Did it find anything?

    You should have installed HJT as recommended. It does not belong in a folder with anything else.

    However there are no problems showing in any of your logs.

    You can uninstall CounterSpy now since we are really finished with it. You should also update to the current Sun Java version (see step 6 of the READ ME).
     
  5. gatorman

    gatorman Private E-2

    In advance thanks. In answer to no counter spy log, I even went back to counterspy and since it found nothing I did not include the log. It was run in safe mode with hidden files showing.
    HJT confused me because per directions it was supposed to go to c:\program files\hijackthis but did not. I was under the the impression that I had Sun Java 6 and per earlier response from you I cannot run Panda and Bitdefender in Vista. What do you recommend? As an added note after I uploaded the logs the screen went blank and there was a window saying windows internet explorer asking me if I wanted drive cleaner to fix my world.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Perhaps this is something unique to Vista but I don't think so. Did you use the self-extracting file that we asked you to download and install from or did you already have HJT?


    I don't know what you are referring to. I only mentioned Sun Java once in message # 4 when I said you don't have the correct version.

    Vista is not supported by many tools and from what was posted thus far you don't show any malware. Let's try running a full scan with this: SUPERAntiSpyware and save a log from it so you can attach it.

    Did you have UAC already disabled before coming here?
    Or did you disable it just to run GetRunKey and ShowNew? If so, have you reenabled it.

    Nothing posted thus far shows any signs of this infection. Again I would like to know the status of UAC?
     
  7. gatorman

    gatorman Private E-2

    In answer to your ?'s from top to bottom:
    1. I tried to download HJT in step 4 but could not find it anywhere. As I reviewed the instructions I then did it in step 7 which I hope was not a mistake. The 2nd time it went C,users,my name, downloads. I figured this was the default location in Vista and did not mess with it since there was nothing else at that location.
    2. Sorry about Sun Java. I did find & download the current Sun Java from Major Geeks.
    3. I only disabled UAC for GetRunKey and ShowNew. I enabled it after that so, yes, before and after that it was enabled.

    Thank you for your patience and help. If I'm to understand correctly you want me to download and run SUPERAntiSpyware, save a log, attach it and send it to you. Please tell me should I do this with UAC off and Hidden Files showing? Also should I unistall CounterSpy as you said? I thought CounterSpy had me turn Windows Defender off if that is the case should I turn it back on?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below is a direct quote fro the end of step 4
    The link is right there so I'm not sure how you are missing it. You need to download from us so you can follow the directions in step 7. Step 7 actually repeats this link again when you follow the directions that say
    Yes uninstall CounterSpy. Don't re-enable Defender yet. Yes install and run SuperAS. I'm not sure if UAC needs to be off or not. You may be able to use Run As to run it as Administrator.
     
  9. gatorman

    gatorman Private E-2

    Here is the result from the SUPERAntiSpyware.

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 07/09/2007 at 05:50 PM

    Application Version : 3.9.1008

    Core Rules Database Version : 3266
    Trace Rules Database Version: 1277

    Scan type : Complete Scan
    Total Scan Time : 00:38:11

    Memory items scanned : 513
    Memory threats detected : 0
    Registry items scanned : 6403
    Registry threats detected : 0
    File items scanned : 76060
    File threats detected : 2

    Adware.Tracking Cookie
    C:\Users\mark\AppData\Roaming\Microsoft\Windows\Cookies\Low\mark@atdmt[1].txt
    C:\Users\mark\AppData\Roaming\Microsoft\Windows\Cookies\Low\mark@tribalfusion[1].txt
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well I still see no signs of any infections. Exactly what malware problems are you still having?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds