SuperAntispyware cannot install

Discussion in 'Malware Help (A Specialist Will Reply)' started by dvtedgar, Aug 26, 2008.

  1. dvtedgar

    dvtedgar Private E-2

    Hello, I am trying to follow your Malware removal instructions but I get a message that "Windows installer not found or running in safe mode" (I'm not).

    I am attaching the other logs. Please let me know what you think.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Why did you run MBAM twice?

    Please attach the log from MGtools that was requested in the READ & RUN ME.

    Also please explain what malware problems you are still having if any.
     
  3. dvtedgar

    dvtedgar Private E-2

    Hi and thanks for replying so quickly! I was alerted to this problem after the fact. My son had downloaded some "You-Tube" video player, this took over our screen background, then gave an alert as the virus "Smitfraud-c". Unfortunately, he did not tell me until the following day, thus the PC was allowed to shut-down and restart. Now we have no internet connection, Windows Explorer is behaving very strangely, keeps returning to the "My Documents" view by itself, making it very hard to check on or open anything. The Windows installer is apparently disabled, and I cannot install Super Anti-spyware or Windows Defender. I am attaching the file you requested, hoping that I don't have to format and start from scratch!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have both AVG8 and Avast antivirus programs installed. As stated in the first instructions in the READ & RUN ME, only one antivirus should be installed. However before doing anything about this, check to see if System Restore works. If so, restore to a point before your problem began and then se how things work. If you do get System Restore to run, then download the current version of MGtools and run it to get a new MGlogs.zip to attach.
     
  5. dvtedgar

    dvtedgar Private E-2

    Hello and thanks for taking the time to work with me.

    First, System Restore was somehow disabled, so there are now no restore points. I will remove Avast from the system (assuming it lets me) as soon as I get home from work. Should I run MGtools again after removing Avast?

    Thanks again for your time. You folks at Major Geeks are amazing!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on things I saw in your log, here is what I suggest that you do.

    • Uninstall Avast and then reboot
    • Uninstall AVG8 and then reboot (necessary due to have Avast installed and because it does not appear to be working properly)
    • now reinstall AVG8
    • Now get the new MGtools log
     
  7. dvtedgar

    dvtedgar Private E-2

    * Uninstall Avast and then reboot
    Done
    * Uninstall AVG8 and then reboot (necessary due to have Avast installed and because it does not appear to be working properly)
    Done
    * now reinstall AVG8
    Done
    * Now get the new MGtools log
    I am attaching this. Please note that I received a 16 bit MS-DOS subsystem error at one point, but continued anyway. I will D/L the resolution patch from work and bring it home. For now, can you use this MGtools log?

    Thanks again for all your time and patience.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First two notes:
    1. You are using MSconfig to control startups. See step 1 of the READ & RUN ME and put your PC into normal startup mode. Do not use anything to control startups while we are working on your PC and never use MSconfig as a long term method of doing this as explained.
    2. You have Spybot's Teatimer running and you need to disable this as requested in the READ & RUN ME. See this: How to disable Spybot's TeaTimer
    You forgot to download the current version of MGtools first! Please do so. Also see the link below from the READ & RUN ME which explains some possible error messages (including the one you received) and the fixes.

    Using MGtools
     
    Last edited: Aug 29, 2008
  9. dvtedgar

    dvtedgar Private E-2

    Thanks for your reply!

    I did try to access MSconfig via the Start/run command, however an error message came up saying "file not found."

    I also anticipate trouble with fixing the registry (to correct the MGtools 16 bit error) because I have also tried accessing the "regedit" command via start/run and get the same "file not found" error.

    I could swear I disabled Tea Timer, but I will try this again when I get home from work.

    If I am unable to access MSconfig and Regedit, can I still accomplish what you need from me? Should I run the (freshly downloaded!) MGtools again anyway?

    Thanks again for your patience and advice!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes!!!! It appears that you are missing some necessary Windows files and folders. I just took a look in your newfiles.txt log which is part of MGtools and you are missing the below folder:

    C:\WINDOWS\PCHealth\HelpCtr\Binaries

    This normally contains MSconfig and a bunch of other required files.

    Perhaps you are missing many more system files too. Do you have your Windows XP bootable CD? It probably is not an SP3 CD so you may need to update later if we have to use this CD.

    Look in the below folder, do you see anything like regedit in it?

    C:\WINDOWS\ServicePackFiles\i386
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way, when did you update to XP SP3 and when did your problems begin?
     
  12. dvtedgar

    dvtedgar Private E-2

    Okay. I've checked and I had already followed the instructions for removing Teatimer.

    I looked in C:\WINDOWS\ServicePackFiles\i386 and you were right, there was a copy of regedit there, so I was able to do the registry fix for running MGtools.

    I d/l and ran the current version of MGtools, and am attaching the log here.

    As to when I updated to SP3, it WAS very close to when my son reported the infection. I cannot say exactly as I was not there at the time.

    You are also correct, I have the XP install CD, but it is SP2.

    Thanks again for all your work on this.
     

    Attached Files:

  13. dvtedgar

    dvtedgar Private E-2

    I just found a copy of MSconfig in the same folder (C:\WINDOWS\ServicePackFiles\i386) so I have returned settings to Normal startup as you suggested.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What I'm really concerned with is whether the upgrade was before or after the infection occurred.


    Click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System Rile Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it.


    Uninstall the below old version of software:
    J2SE Runtime Environment 5.0 Update 12

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {098716A9-0310-4CBE-BD64-B790A9761158} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O21 - SSODL: tsxngabr - {8AAE3604-350B-4636-BA2D-6FA2828BCE07} - C:\WINDOWS\tsxngabr.dll (file missing)
    O23 - Service: PsExec (PSEXESVC) - Unknown owner - C:\WINDOWS\PSEXESVC.EXE (file missing)
    O24 - Desktop Component 0: Privacy Protection - (no file)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  15. dvtedgar

    dvtedgar Private E-2

    What I'm really concerned with is whether the upgrade was before or after the infection occurred.
    I believe it was before, but this is NOT certain.

    I ran sfc /scannow. Seems to have worked, at least I received no error messages.


    Uninstall the below old version of software:
    J2SE Runtime Environment 5.0 Update 12

    There was no uninstall info via Add/Remove programs, so I deleted this manually.

    I successfully added the items you listed to the registry.

    I am attaching the newest MGtools files. So far not much change in performance, but, to be fair, I haven't tried to do much with the "infected" PC.

    Thanks!
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And it will not get any better with anything we have to do. You logs are clean. What you are having problems with now is a broken/corrupted operating system. Your best and most reliable alternative now is to back up necessary data and perform a reinstall. This may be the only way to fix all of your problems. A repair/rebuild type install may work, but I would not trust it right now.
     
  17. dvtedgar

    dvtedgar Private E-2

    Do you have any suggestions for a good guide for a safe reinstall? I asume you mean a full format and fresh Windows install.

    Bummer. That is the worst possible outcome. :(

    Thanks for all of your time and help! I appreciate the effort.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I do not have any guides that I really use however I will post a couple of links for you to look at. You may want to try the Rebuild method first to see if it works for you before going the total reinstall method.

    Check out the below links:

    XP's Little-Known 'Rebuild' Command

    XP's No-Reformat, Nondestructive Total-Rebuild Option


    And the below may be useful if you wind up doing a reinstall:

    http://rcc.bgsu.edu/info/Windows_XP_Installation
     
  19. dvtedgar

    dvtedgar Private E-2

    Sorry for the delayed reply, I was off taking my oldest child to college.

    I did the rebuild per your suggestion. Had a bit of trouble at first, as I have a SATA drive as my main "C" drive, and XP does not recognize that unless you first put in the RAID drivers, which I forgot to do. Now I've fixed that and things seem to be running okay.

    Thank you so much for your advice. Is there more I should do in terms of testing my system, now that Windows has been rebuilt?
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If everything is working OK now then you should work thru the below.

    How to Protect yourself from malware!
     
  21. dvtedgar

    dvtedgar Private E-2

    Once again, I thank you for all of your helpful suggestions and work on this.

    :)
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome now let's do our final cleanup which I almost forgot to post.;)


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link if you have not already done this as suggested in my previous message:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds