this is bad

Discussion in 'Malware Help (A Specialist Will Reply)' started by nomogoog, Jul 1, 2009.

  1. nomogoog

    nomogoog Private E-2

    this pc was given to me without virus protection, and i am not able to update windows, ie or .net framework. it has sp1 and when the previous owner tried to update to sp2 it would not and she must have screwed something up because there are 31 windows xp hotfix programs in add or remove that will not uninstall or repair .going through the read and run i will list what i was ans was not able to do. could not remove all unwanted programs, uninstalled some malware, there was no java installed and when trying to install newest version it would not install [trying to do so only gives the mouse pointer an hourglass for a few seconds then nothing happens. msconfig will not stay on normal startup mode and in the startup tab there are 2 entries named a bunch of squares with a capital H in between the squares with a location of SOFTWARE\Microsoft\Windows NT\CurrentVersion\windows. however after all the read run and scans finished one of these weird entries was gone. sas.exe would not install either way it was named(got error msg "MSIEXEC is not a valid win32 application") so i could not run it, and that's why there's no log. MB.exe ran without problems. rootrereal stopped with an error msg that i didn't remember to write down and i hit ok and it shut down, tried it again and it seemed to run successfully. mgtools stopped with a .net framework error msg and so i tried the link in the instructions to download the framework but it would not install with error msg "Microsoft .net framework setup failed. if this problem continues, contact product support services". well sorry for the long post and any and all help is greatly appreciated. thanks
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have something running for network protection called PCShield --> can you stop it? If not, we can remove it from your startups.

    You may wish to use one of these:

    Startup Manager

    Startup_CPL

    Go to start / run / and type services.msc ---> then scroll down to MSIServer and stop it, then set it to manual.

    Please use add/remove programs to uninstall:
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Now use windows explorer to find and delete:
    c:\windows\king-uninstall.exe
    c:\windows\kinginstaller.exe

    The lack of RAM is probably why you are having many problems...esp. with SP2:

    Total Physical Memory 256.00 MB
    Available Physical Memory 82.25 MB

    You need 4x that amount to adequately run your system.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  3. nomogoog

    nomogoog Private E-2

    i was unaware that net protect program was running, and regarding the realtime player i am unable to uninstall anything from add or remove programs, and regarding the other instructions i will attempt them and report back. thank you very much for your help and time!
     
  4. nomogoog

    nomogoog Private E-2

    i tried to uninstall realplayer again and it says uninstaller "component missing". and when i try to uninstall anything(including viewpoint) it always freezes so im thinking the lack of ram is the issue, do you mean that i dont have enough ram from factory or that something is eating it all up? also there is no MSIServer in services.msc. ok while typing viewpoint DID uninstall but nothing else will. deleted both:c:\windows\king-uninstall.exe
    c:\windows\kinginstaller.exe
    should i still run the mgtoolsgetbatlog file now?
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I didn't ask you to remove Real Player. And I wouldn't have asked for a new MGLogs if I didn't want it.
     
  6. nomogoog

    nomogoog Private E-2

    i know you didn't ask me to remove realplayer, i informed you so you would know what happens when i try to uninstall anything, and i did tell you that i uninstalled viewpoint. if you don't want to help me and are only going to try to belittle me then just tell me you don't want to help me, on the other hand if you do still want to help me i will still be very thankful. so if you do still want to help me here's my mglogs and do you have any further instructions for me not being able to see MSIServer in services.msc? thanks in advance if you are still going to help me.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    In what way did I belittle you? I only pointed out that you were doing something I hadn't asked you to do, and had not done what I had asked you to do.

    Now let's get on with it.

    Go to start / run / type "services.msc" without quotes and when it opens, scroll down to windows installer - double click it and if it is in auto, stop the service. Then set it to manual.

    Now, not knowing what pcshield is, let's also stop that from running:

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    You have this on your desktop, but it is not in your add/remove program list:
    Does it run?

    Now I want you to go to run again, this time type msconfig --> hit enter. Go to the startup tab and tell me what this is:
    If you do not know, then do the following:

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    And this is still showing in your logs:
    C:\WINDOWS\king-uninstall.exe
    C:\WINDOWS\kinginstaller.exe

    So try double clicking the uninstall.exe and lets see if it will uninstall.

    Now after doing all of the above, let me know what you did and what happened and then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
    Last edited: Jul 7, 2009
  8. nomogoog

    nomogoog Private E-2

    ok, i checked windows installer and it was already set to manual. then i added the txt to the registry and i DID get a notification saying it was successful. no that avg on the desktop is not running as far as i know i was planning on installing avira once i figured out the microsoft updating issues, and this pc doesn't get online while I'm working on it. ok now i can id the stautup your talking about but it only shows squares all across the board and I'm unaware what it it so i added the next txt to the registry successfully. now i did not see C:\WINDOWS\kinginstaller.exe but i did see C:\WINDOWS\king-uninstall.exe and i double clicked on it and it said it uninstalled but the file is still there maybe it will stay untill i reboot i don't know. then i ran C:\MGtools\GetLogs.bat and i got a .NET Framework Initialization Error message saying "C:\WINDOWS\MICROSOFT.net\fRAMEWORK\V1.1.4332\mscorwks.dll could not be loaded so i clicked ok and the scan completed right away so here is the log, and thanks again.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean....as to the Windows installer issue, you could try running this:
    Windows Installer Cleanup.

    But I think you would be better off trying to Download SP2.

    For additional assistance, please post in the software forum.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  10. nomogoog

    nomogoog Private E-2

    great thanks again for your help!
     
  11. nomogoog

    nomogoog Private E-2

    i have to go to work but just wanted to say i tried both links and neither worked, and when i get home i will do the "final steps" then post in software, thanks again for your help and patience!
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Both links work for me. I suggest you clean out your internet temp files and try again.
     
  13. nomogoog

    nomogoog Private E-2

    sorry i worded that wrong, i meant to say that the links worked but the downloads both did not work they would both run but then disappear and nothing happened after that, on both of them, my bad. i should have worded them better.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to post in the software forum to get your windows installer issue worked out.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds