Trying to do the READ & RUN ME FIRST

Discussion in 'Malware Help (A Specialist Will Reply)' started by betteboop, Jul 13, 2008.

  1. betteboop

    betteboop Private E-2

    Hi. I started to do the steps in READ & RUN ME FIRST, but when I use msconfig and put into "normal" mode, my wireless adapter won't connect. I keep getting an error that says I don't have an adapter at all.

    I want to go through each step and try to help myself, but if I can't get back online...what do I do??

    Thanks in advance!:confused
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not knowing what items you had in selective startup or what was not selected, I would suggest that you do a system restore and see if you get back. Then skip the msconfig for now and do the rest of the READ & RUN ME FIRST. Malware Removal Guide
    and attach the logs.

    Also please tell us what the issues are that you are having.
     
  3. betteboop

    betteboop Private E-2

    I was able to change to normal startup and have run all the programs in the Read & Run Me First.

    I have CA Security Suite Plus and somehow my system became infected. It started when my screnn went blue and I got something like "your computer has encountered a serious error and has shut down....if this happens again, contact your system admin", then it rebooted.
    When it started up, everything ran very slow, especially IE (6.0). It takes well over 2 min. to load. I contacted CA and they had me uninstall and reinstall all components. Nothing worked.
    I do find that when I click on IE, and then RIGHT click on the taskbar, it will load quicker....but it still is verrrry slow.

    Now after doing all the Read & Run...a few things are changed. First, my time is in military time mode; I am showing two computers with a red X thru them stating "Local Area Connection A network cable is unplugged". This usually shows up when I shut off my firewall. (I am on wireless network and that is working correctly). One more thing I noticed is that MSN Messenger auto starts now, I never use that anyway, so I am not sure why that's happening.

    OK...I don't know if I gave enough or too much info. Please tell me what logs you need to help me get my system working correctly. I'm very new at this, so I apologize ahead of time if I'm not putting this where it should be to get help.
    Thanks in advance, BetteBoop
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The instructions ask you to attach the following logs:
    ComboFix

    SuperAnti-spyware

    MalwareBytes

    MGLogs.zip -> located at C:\MGLogs.zip
     
  5. betteboop

    betteboop Private E-2

    One more thing, should I put my system back out of Normal Startup??
     
  6. betteboop

    betteboop Private E-2

    I'll upload the MGlogs.zip file in a minute. I could only upload the first three.

    I so hope you can help me! I don't want to reformat my hard drive.

    Thanks!
     

    Attached Files:

  7. betteboop

    betteboop Private E-2

    OK...here's the MGLogs.zip as promissed.
    Let me know if you need anything else for me to do or send.
    Thanks,
    BetteBoop
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The logs you attached look good ....however, you gave me the instructions for running ComboFix....not the log. And you did not click on accept to the agreement to run HiJackThis when you ran the MGTools.

    Please re-run ComboFix and also the C:\MGtools\GetLogs.bat file. Then attach both logs.
     
  9. betteboop

    betteboop Private E-2

    Oy Vey! Sorry about that!

    Attached are the logs.
    Thanks,
    BetteBoop
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean ....are you having any other malware issues?
     
  11. betteboop

    betteboop Private E-2

    I assume they are malware issues, because that's what CA Internet Security people told me when I went to them for help after the 'serious error' shutdown.

    The main problem I still have is I have a hard time opening up IE. It takes over 2 min. to load, unless I right click it in the task bar. Then it seems to open 'quicker', but still takes awhile. It will sort of hang for a little while, where I can't click on anything. For instance this site when I tried to click to enter my username.
    Forget trying to open a link when in Outlook Express! That is like fighting with the right click trick.

    Should I just bite the bullet and reformat my hard drive?? Oh how I do NOT want to do that!

    :cry
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No...you should not reformat. Certainly not for this type of issue. I would first suggest that you download FireFox from HERE as an alternative browser ....what version of IE do you have?
     
  13. betteboop

    betteboop Private E-2

    I use Internet Explorer 6.
    This "attack" started the moment I downloaded something I shouldn't have.

    I am not familiar with Firefox.
     
  14. betteboop

    betteboop Private E-2

    Also, should I go back msconfig and get out of "normail mode" yet?
    I believe I'm still running that way??

    And my last reboot, did not allow CA to load and I no longer have windows setting my wireless.

    I am SO confused!!

    :confused
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Firefox is an alternate browser that many people like better than IE.....have you tried downloading IE7?
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I was posting while you were ...:) ...what do you mean you no longer have windows setting your wireless? What exactly is going on?

    CA is a suite ...and these kinds of anti-virus suites can bog down your computer.
     
  17. betteboop

    betteboop Private E-2

    I'm not sure how to explain it other than, I used to have Windows manage my WiFi. Now, it is connecting using my Intel/Pro Wireless. I guess it doesn't matter.

    When I did all the instructions in the Read & Run Me First, I had to go to msconfig and set it to NORMAL STARTUP it was set at SELECTIVE STARTUP. I want to know if I should put it back.

    I don't like IE 7, that's why I still have IE 6.

    I understand that CA Internet Security Suite and other antivirus programs slow down systems. However, I didn't have ANY problems until the second I downloaded whatever it was I shouldn't have.

    When you say my logs looked clean, does that mean you don't see ANY virus, spyware or malware whatsoever on my system?

    Is it possible that somehow IE got corrupted? And that's all that's going on right now??

    BetteBoop
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should let it do this ...not have windows configure it.

    Yes you should set the system back to normal startup ....You may wish to use a Startup Manager

    Yes...I see no traces of malware form your logs.

    More likely that you need to clean out your internet cache :
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Are you still having problems now?
     
  19. betteboop

    betteboop Private E-2

    I did everything you said except Firefox. I've never heard of this browser and quite frankly am a little worried about downloading and using it.

    I know I'm probably really dumb, you said there wasn't any malware, but is malware the same as a virus or spyware?

    I did go to MS Update and it seems there is a service pack 3. Should I download it? Maybe that's what's wrong?

    I am so upset and frustrated with all of this!

    I DO appreciate your help...but besides using Firefox, what else can I try? Again, the only thing not working right is IE, unless I right click it and then wait.

    Thanks again,
    BetteBoop
     
  20. betteboop

    betteboop Private E-2

    Tim,
    I bit the bullet and downloaded Firefox. I clicked and it opened up in less than FIVE SECONDS!!

    I want to thank you very, very much for ALL your help and patience. I guess there was something wrong with IE. I have no idea what, but am just happy to get online in a quick manner.

    I hope I won't have to come back...but if I do...I'll seek you out for help.
    Again, THANK YOU!!!
    BetteBoop
    :-D
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are very welcome! :)

    Perhaps you should post in the software section regarding the issues with IE.

    If you are not having any other malware problems, it is time to do our final steps:

    1 If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)

    * Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (substitute for cf whatever you renamed it)
    * "%userprofile%\Desktop\cf" /u
    o Notes: The space between the cf" and the /u, it must be there.
    o This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    * Delete the C:\cf folder from combofix.
    2 *If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3 *If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    6. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  22. betteboop

    betteboop Private E-2

    Tim,
    I will post, if you think it will help someone else.

    I went to the link at the bottom of your post to help keep malware off my system. The first thing it said to do was Update Windows. OK...it won't let me because I'm not using IE! Does this mean it will not do any automatic updates for me?

    Thanks again..you've been SO helpful!
    BetteBoop
    :wave
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The updates can be had by right clicking my computer / properties / automatic updates / click the box to download updates but notify you before installing....click apply.

    Then when updates are available ...open the update notification icon in the system tray and choose manual install -> that way you can monitor/choose which updates you want to install.

    There is no need to update thru IE.
     
  24. betteboop

    betteboop Private E-2

    Hmmmm, I guess I have to get used to the idea that MS isn't the all & mighty!
    ;)

    I'll set as you recommend,
    BetteBoop
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do post in software .....and you are most welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds