Went thru READ and RUN me FIRST, logs attached. HELP PLZ

Discussion in 'Malware Help (A Specialist Will Reply)' started by pennywisezzz, Feb 13, 2010.

  1. pennywisezzz

    pennywisezzz Private E-2

    I had a post over on the software board but since this seems to be a malware problem I started a thread over here. This was my original post:
    http://forums.majorgeeks.com/showthread.php?p=1453487#post1453487

    I read and READ & RUN ME FIRST and followed the directions.

    * Could not install SuperAntiSpyware at all. Wouldn't in regular or safe mode. In regular mode it gave me this error "Error 1904. Module c:\Program Files\SuperAntiSpyware\SASSEH.DLL failed to register. HRESULT -2147024891 Contact your support personnel." Got the same error after renaming it to SAS.exe When I tried to install it in Safe Mode it said "The system administrator has set policies to prevent this installation."

    * Could not run Malware Bytes or ComboFix in regular mode - gave me this message on both "Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item." Switched to Safe Mode and then they worked.

    * MGTools wouldn't run in regular mode, so had to run it in Safe Mode.

    TIA
     

    Attached Files:

    Last edited: Feb 13, 2010
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, pennywisezzz

    I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Our queue is working the oldest threads first.

    Thanks for your patience.
    dr.m
     
  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    The below fixes and advice are specific to this member's problem and should be used for issue(s) on this machine only.

    Hello, pennnywisezzz

    NOTE: I would suggest that you use a better anti-virus than Clam AntiVirus (ClamAV) which is integrated with Spyware Terminator.

    Remove this file from your desktop to the proper "Downloads" folder directory:
    "C:\Documents and Settings\Compaq_Administrator\Desktop\setup-spybotsd162.exe"

    Step 1:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and continue on.
    Step 2:
    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Step 3:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 4:
    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" . Once you have saved it double click it and allow it to merge with the registry.
    Please make sure that you tell me if receive a success message about adding the above to the registry - if you didn't, it definitely did not work.

    Step 5:
    Delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    Step 6:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 7:
    Now install the latest Sun Java Runtime Environment

    * Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
  4. pennywisezzz

    pennywisezzz Private E-2

    I don't have my regular antivirus/malware programs loaded on this computer because it won't let me. My friend removed the ones that were on the computer and when I try to install them I get error messages.

    Still cannot install the latest Java. Gets hung while trying to install and gives me the message "Error 25099. Unzipping core files failed." Went to the Java site and tried to do what it suggested but the directory it wanted me to delete from did not exist (something like jre6).

    I got a success message about adding to the registry.

    I don't see the vibrant media links/popups I was noticing on this site before (didn't mention them before because I thought maybe you guys were using them, but after following your instructions the link/popups disappeared).

    But, still cannot run certain programs without being in safe mode. Still getting the same messages. Microsoft Works Word Processor also gives me the message about some files being renamed, deleted, or moved - yet it works fine in safe mode. Other programs give the repeated message about "Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item." Yet, those same programs work in safe mode as well.

    So frustrating. Guess a complete reinstall is in order - which means I'll have to buy a disk as this computer didn't come with one. Argh!

    Thanks for your help and let me know if you have any further suggestions as I probably won't purchase another disk for a few weeks.
     
  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hi, pennywisezzz

    Step 1:
    Uninstall Spyware Terminator

    Step 2:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 3:
    Then - click Start, Run and enter sfc /scannow and click OK. This may ask you for your Windows XP CD so have it ready.

    Step 4:
    Please download and run Win32kDiag per the below instructions:
    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK.

      C:\win32kdiag.exe -f -r
    • When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log.

    Step 5:
    Now download Junction,zip to your Windows folder
    • Please download Junction.zip and save it to your Windows folder (i.e, C:\Windows\Junction.zip This assumes C:\ is your Windows boot drive.)
    • Now unzip it and put junction.exe into the Windows folder (i.e., C:\Windows\junction.exe)
    • Do not try to run it right now. We will run something that uses it later.

    Step 6:
    Now we need to reset the permissions altered by the malware on some files.
    • Download and save inherit.exe to your Desktop: Inherit.exe
    • It must be in your Desktop or the below fix will not work!
    Now run the C:\MGtools\FixPerm.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).
    • A command prompt window opens and also a license agreement from SysInternals will appear for Junction.
    • Accept the license agreement and the scan will begin.
    • Wait until it finishes we can take a while to run since it scans your whole harddisk. e patient and don't do anything else while it is scanning.
    • The command prompt window should close when it finishes.
    • While this is running, you will get several/many popups that have a title Finish and say OK. Just click the OK button each time. This is an indication that it has found a file and has attempted to fix permissions. Depending on how many files that need to be fixed, you could get only a few or many of these popups.

    Step 6:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Please attach these files to your next reply.
    • Win32kDiag.txt log
    • C:\MGlogs.zip

    * Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
  6. pennywisezzz

    pennywisezzz Private E-2

    Thanks - will try either tonight or tomorrow night. I kind of got disgusted and quit fooling with that other computer, lol. But one good computer and 2 computer-holics in one house is not always a good thing. ;) My 7 year old daughter can get some pretty mean computer withdrawal symptoms... so can her momma... :-D

    TIA
     
  7. pennywisezzz

    pennywisezzz Private E-2

    Thanks again for helping out. I was able to do these steps in safe mode except for Step 3 as I do not have an XP CD for this computer. I don't remember if it came with one and if it did it is well lost by now because I can't find it (mind you I have moved 3 times in the last 3 years).

    The files are attached!
     

    Attached Files:

  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Can you borrow a XP SP3 CD from a friend, while I confer with my colleagues?

    dr.m
     
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Please uninstall your protection software and re-run the steps in post # 5. *Your issues are not appearing to be malware related.

    dr.m
     
  10. pennywisezzz

    pennywisezzz Private E-2

    I'll ask around if any of them have a CD I could borrow. Not sure what programs are on it so I will have to look. My friend who borrowed the computer said she removed them and when I got the computer back I tried to install some back on but ran into problems where those stupid pop ups were giving me the message that I didn't have the right permissions or whatever. Can't remember off the top of my head what programs it allowed me to install and which it wouldn't. When I get home I'll look. TIA
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds