Hello from Tribalpath55

Discussion in 'Malware Help (A Specialist Will Reply)' started by tribalpath55, May 25, 2013.

  1. tribalpath55

    tribalpath55 Private E-2

    I will cut to the chase:
    What's wrong:

    Windows XP Home edition, upgraded to windows 8,
    Automatic updates will not load, tells me I have no operating system
    System restore is gone
    Antivirus is gone
    Firewall is gone
    Services.msc , many integral services not working
    Have Malware bytes, it is not working
    Have Microsoft Security Essentials, it is reporting it is out of date
    I am not able to run anything that you suggest to download, it loads starts to run and then stops with a message, failed to load.
    Start Menu is missing


    What is right:

    Safe mode works,
    attempted to restore at command prompt, Does not "recognize" the command
    Attempted every safe mode option , restore, start last known config, nadda

    I am able to surf the web


    I think , that is it in a nutshell...Ideas?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    All of these problems started when you upgraded to Windows 8? What makes you think it is a malware problem and not a Window upgrade issue?

    Nothing will run in Normal Boot mode at all???

    If you want to start the check for malware, the below can be run in safe boot mode.

    READ & RUN ME FIRST. Malware Removal Guide
     
    Last edited: May 26, 2013
  3. tribalpath55

    tribalpath55 Private E-2

    I have no clue what caused the issue,just making note of the chronology of events. My computer boots in every mode, however, whatever mode I boot in:
    I am unable to run:
    antivirus,
    I am able to download the programs from your read me first list, however they will not run, I get an error message, "vbr did not load" the only program that did run was ccleaner, it will not let me save a file.
     
  4. tribalpath55

    tribalpath55 Private E-2

    I am now in another safe mode, am able to download and run. Will do the steps that are in the read me run first and get back to you. Thanks!
     
  5. tribalpath55

    tribalpath55 Private E-2

    Here are the logs from the run me first scans

    Note:
    mbam would not run, error message," out of date",
    I did attempt to update, it would not download.
     

    Attached Files:

  6. tribalpath55

    tribalpath55 Private E-2

    Footnote:

    My new foster daughter and her friends just told me they snuck on my computer and went to a few porn sites. Isn't that special? She is so grounded.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What about Hitman Pro?

    I'm not really seeing too much in the way of malware on your PC. Yes I do see some junkware/adware, but not much else. What is more troubling is the non-malware stuff I see. It looks like you have had a bunch of antivirus programs installed and pieces of them are still present. Also I see Reimage Repair. Did you just run this??? What did you do with it?

    I also see Tweaking.Com's Windows Repair. What exactly did you do with it?

    I see all of your restore points so they are not gone as you stated.
     
  8. tribalpath55

    tribalpath55 Private E-2

    I had a bunch of antivirus freeware, when they expired i used another one, and so on...

    As to the tweaking and reimage, I ran them today and then removed them when they proved futile.

    I ran, in sequence , the suggestions on your forum, after I did those I attempted the above.

    As for Hitman, it started to run and then stopped, Keep getting messages that VBR is not working.

    My ICES is not working either nor is RPC Services. So, time for another computer or is this fixable? At least three quarter of the "Services in msc" will not turn on, error messages are the same on all of them.

    Have attempted several windows updates, all shut down saying the RPC is not supported.

    I work as a grant writer for a non profit, from home, I am in a huge hurry to get my system working by Tuesday with virus protection, as much of what I research is quite competitive and sensitive. Therefore the desperate measures to get it fixed. I think perhaps I made more of a mess with my lack of patience.

    Any suggestions.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    DId you actually really fix anything with Reimage? I don't like what this program does in replacing Windows files as it can cause many incompatibilities and break things ( i.e., could explain why some programs do not run ). As for Tweaking.com. Please try the below.


    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.



    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!


    Is this the exact word for word message ( no abbreviations ).

    Please do not do anything we do not ask you to do while we are working on your PC. We requested this up front in the READ & RUN ME. It can cause much confusion and more breakage.

    Perhaps. Every problem requires a controlled approach. Sometimes there may not be a clean fix if there is too much damage to Windows. It is still possible that if we can get system restore to run that we may be able to recover from this. As I stated, there are still some restore points. Do you have your Windows XP Boot CD? There is a manual method to try and recover a restore point but it is quite complex and you will need to be able to follow some detailed instructions from Microsoft to do this.
     
  10. tribalpath55

    tribalpath55 Private E-2

    Thanks for your help and patience thus far..

    As for Reimage,( I have to agree with you) it "allegedly" repaired stuff. I did get my start menu back though.

    As for tweaking, as I recall it would not run, started and stopped.

    Since I just bought an old house and have painting to do, that should keep me busy while I run the windows repair. I will stay away from my office while it runs.
    I do have the CD, already tried to reinstall yesterday prior to contacting you, it is scratched and not working. Have a few friends who will mail me a copy. Can't borrow in a hurry as I just moved to NH and don't know anyone, my fam and friends are a few thousand miles away.
    Off to feed my Saint Bernard. Again, thanks for all your help. If you all take bribes, I can offer a free cookbook I just got published, I am also a chef and author.
     
  11. tribalpath55

    tribalpath55 Private E-2

    I get an error message when I attempt to run windows repair,

    attempted to download it three times, each time it would open, I attempted :

    extract all , it worked, but would not open, "Iv_Button_H" version out of date" error message
    attempted to right click, nothing
    attempted normal double click, opened but error message when I get to the tool box picture
     
  12. tribalpath55

    tribalpath55 Private E-2

    I am able to do detailed instructions to repair windows. Let's give that a whirl if your unable to think of another method. I have until Tuesday and all of my time is wide open.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you get it to run in safe boot mode?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But you need the Windows XP boot CD. The procedure I'm referring to is in the below link:

    http://support.microsoft.com/kb/307545

    Basically it is a way to manually copy registry hives from restore points. Mostly it is used when Windows does not boot, but it can be used to perform a manual restore. And then if things run better and if the System Restore service then runs, you can then perform a full system restore. The above procedure is not a full system restore. It is just a partial registry restore of certain registry hives.
     
    Last edited: May 26, 2013
  15. tribalpath55

    tribalpath55 Private E-2

    I can do safe boot, I saved the xp disc snapshot in a folder the last time I installed the program. Will that do or do I need the original cd, which is scratched and unusable?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But my question is "Does Windows Repair run exactly as requested in safe boot mode".

    You will need a Windows XP boot CD so that you can boot to the recovery console.
     
  17. tribalpath55

    tribalpath55 Private E-2

    Foiled again! Now it is not loading in safe mode...if this were not so sad, I would laugh...
    I am so screwed! You have no idea....so how risky to do my research with no anti virus program? It will be at least a week untill I can buy another XP program or get one from friends...never mind a rhetorical question, I know the answer, gonna have to risk it...my job is at stake and a few hundred people who need me to get grants to build affordable housing for them. Thanks, you tried your hardest..I appreciate all your attempts to help me. Have a wonderful weekend...
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. But let's not give up yet. Let's see if we can make any progress by trying a few registry patches. Assuming we can get them to import!

    Copy the bold text below to notepad. Save it as servfix1.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now reboot your pc back into normal boot mode.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
     
  19. tribalpath55

    tribalpath55 Private E-2

    Unable to copy into notepad, word or email now. ??

    Surrender to defeat?
     
  20. tribalpath55

    tribalpath55 Private E-2

    Oh, now AVG has taken over my browser?
     
  21. tribalpath55

    tribalpath55 Private E-2

    And the Angel said unto the Lord, let there be erunt and lo I reinstalled the backup I made from that pro. All systems are working. Am running Micro second essentials now and updating. Will keep you posted. Thanks I learned more here than anywhere.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That was going to be my next message since I had seen the "C:\WINDOWS\ERDNT\" folder with a few backups. I just was not sure it would run since you were having problem running many things. I figured first a few quick registry patches could get a few services started.

    Glad to hear you have it running now.
     
  23. tribalpath55

    tribalpath55 Private E-2

    Again, thanks for all the help, it dawned on me I had that program installed just to do the backup some months ago and wham, it worked like a charm. Fingers crossed, it all seems to be working fine, like it never happened. Ran the virus scan and am all set.

    With Warm Regards,

    Tracy
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Glad to hear all is well.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds