13 year old nephew visited... now everythings a mess.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by audiogirl, Jul 22, 2004.

  1. audiogirl

    audiogirl Private E-2

    Hello, This is a first time post. I'm in a major jam, so I'm looking to you guys for help. We had tons of family in town and I stupidly let my nieces and nephews have free reign with the computer. Well needless to say, after deleting all the porn files I could find that were apparently the product of some secret late-night surfing, I still have big problems. msconfig won't open (flashes and then goes dead), same with Spybot Search & Destroy. Then I downloaded the trial version of Norton Antivirus, and it also will not open. I ran the symantec W32. worm removal tool (which I apparently had), and now my desktop is that white screen and when I click "Restore Active Desktop", it opens the c:\windows\WEB window and won't let me do anything else. I have unistalled Spybot and Norton. Any ideas? Thanks in advance.
     
  2. NeoNemesis

    NeoNemesis Moutharrhea

    porn! wtf...13 year olds??? :eek:
     
  3. audiogirl

    audiogirl Private E-2

    Honestly, stuffing a mag between the mattresses seems nostalgic. BTW still on Win 98
     
  4. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

  5. audiogirl

    audiogirl Private E-2

    Oddlly enough, when I went to the http://housecall... link, the "scan" button is greyed and won't let me click it. And, on the www.pandasoftware link, I click the "scan your pc" button and nothing happens.
     
  6. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Ill assume your Windows Update is current. Please verify that Microsoft Java is removed and Sun installed by going to http://forums.majorgeeks.com/showthread.php?t=36310 and following the steps in that first post.

    Then try to go to those online scanners. I saw you ran a specific virus tool, so heres a thought. Try Mcafee Stinger, but lets do it from safe mode just in case with the internet disconnected. This means to unplug the network cable from your computer or do not dial in depending how you do it. Booting into safe mode without networking support should cover it if your on broadband.

    To boot into safe mode simply reboot and tap the f8 key after the black and white screen (nomally) appears but before the Windows splash screen.
     
  7. audiogirl

    audiogirl Private E-2

    Hi there, Thanks so much for your help. I've run through the tutorial and the good news is I can now run Spybot again. The bad news is I can't run the Housecall or Panda virus scanner, and when I went to Microsoft to make sure I had the updated version of windows, the windows update page was blank! Also, I still can't restore my active desktop. Is all hope lost? Thanks again for any help. :)
     
  8. nickson2

    nickson2 Master Sergeant

    yep believe it or not....they start very young these days :rolleyes:
     
  9. Matacumbie

    Matacumbie Rocky Top

    Audiogirl,

    I noticed you are using Windows 98, when you go to Microsoft Update does the page actually finish loading and is blank, or is the page loading and just hanging there (hourglass).

    Also, are you having trouble accessing links or shortcuts, are there some links you click on and nothing happens?

    Steve
     
  10. audiogirl

    audiogirl Private E-2

    It is just blank and "Done"
     
  11. NeoNemesis

    NeoNemesis Moutharrhea

    make sure your accessing it through IE.
     
  12. audiogirl

    audiogirl Private E-2

    P.S. Shortcuts and links seem to be ok after running through your tutorial. I find it wierd that this is affecting web pages... housecall, panda, and microsoft (and probably more).
     
  13. audiogirl

    audiogirl Private E-2

    Yes, IE is the only installed browser
     
  14. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Did you do the java steps, you might have said you did, I dont see it? Make sure under IE options, programs that Sun Java is checked as well. Im wondering if you should just check default settings in that panel too just to see if you can get these applets to load. Worth a shot.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Start, Run and in the Open box type:

    notepad c:\windows\hosts

    When the notepad window comes up, hit CTRL-A to select everything, then hit CTRL-C to copy everything. Now come back here to a new message and hit CTRL-V. That will paste in you hosts file. I want to see if you are getting redirected.

    Also, in Internet Explorer, click on Tools, Internet Options, Security, and look at what is in your Restricted Sites list. See if any of the links you are having problems with are in the Restricted list.
     
  16. audiogirl

    audiogirl Private E-2

    Hey guys... when I typed in notepad c:\windows\hosts it said file doesn't exist would you like to create one? I unfortunately said yes and so when I typed it in the run box again it just brought up that blank page in notepad. I feel like I'm wasting you guys' time with my XL problem, but if you don't mind I'll explain what happened in the last few hours. Things seemed to be going along fine, then the entire thing crashed and would not reopen at all. The error message was "problem with explorer.exe you must re-install windows". When I somehow got it into safe mode, it wouldn't even recognize the d: drive and there was no internet connection at all. So I got into command prompt and did a system restore to yesterday. I once again can't run spybot, windows update is blank and can't restore active desktop so it looks like I'll have to go through your list again. At least I can get online now! :)

    Sun Java is checked in internet options. Sites aren't on restricted list. I think I'll have to re-install windows. (Should just buy XP but do not have the cash right now and can't make any cash without the computer... you know how it is) If you can spare a few more nuggets of knowledge it is HUGELY appriciated!!!
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Earlier you said "BTW still on Win 98". Windows 98 does not have a system restore. So I'm a little confused by your statement "So I got into command prompt and did a system restore to yesterday."

    Do you really have WinMe?
     
  18. audiogirl

    audiogirl Private E-2

    If you're at the c:/ prompt in msdos mode and type "scanreg /restore" it shows you the last few days and you can restore from there. Definately is Windows 98 SE.
     
  19. Matacumbie

    Matacumbie Rocky Top

    Audiogirl,

    I think you should try the mcrepair tool here, http://download.microsoft.com/download/msninvestor/patch/1.0/win98/en-us/mcrepair.exe

    It is a program that repairs several things in IE, just download and run it, be sure to answer Yes to everything (that is very important) until it is finished, then restart your computer and see if you can access Windows Update or Housecall.

    You can read the Microsoft Article here, http://support.microsoft.com/?kbid=836929 scroll down to Method # 3, Item #3 and it explains the process.

    Hopefully, this will work for you and solve one of your problems.

    Steve
     
  20. audiogirl

    audiogirl Private E-2

    Thank you Steve, I'll try that now!
     
  21. Matacumbie

    Matacumbie Rocky Top

    I thought you had Windows 98. Steve
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! But that is not system restore. Poor choice of words. System Restore has a very specific meaning for WinMe and WinXP systems.
     
  23. audiogirl

    audiogirl Private E-2

    Yes, I do have Windows 98. I ran that mcrepair and also found the "unofficial Windows 98 Service Pack" here on Major Geeks, and those seem to have helped alot on the more bizzare problems (windowsupdate.microsoft.com now opens normally and my active desktop is back to normal) Only trouble still is that none of the spyware or anti-virus programs will open (AVG 6.0, Ad-Aware, Spybot Search & Destroy). The only one that will open is Trojan Remover, which found "I-worm/bagel.n" . It tried to re-name the file (c:windows\system\winupd.exe) but could not, and I could not manually either. I ran it again and checked "prevent this program from running by removing it's reference" and it has asked me to re-boot. I'm going to do that now.
     
  24. audiogirl

    audiogirl Private E-2

    Sorry about that!
     
  25. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Hi,
    Try it from safe mode, it has worked for me. As noted in other threads, your trying to delete a file in use. windows no like that :) So, it might be easier from XP, but for 98 try deleting it from safe mode if thie steps you took did not work.

    Active Desktop? Was that not the old way of getting web content on your desktop in Windows 98 that was considered buggy and huge loophole? Anyone second me on that before I tell her to kill that?
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I second that! Had problems with it myself way back and disabled it never to use again! ;)
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The most likely reason for you applications not running is due to what you did with scanreg.
    You probably lost all the settings for the programs. You will probably have to re-install all of them.
     
  28. Matacumbie

    Matacumbie Rocky Top

    Agree, it can cause problems. Still would like to see if she can run Housecall. Steve
     
  29. audiogirl

    audiogirl Private E-2

    Housecall and Panda still don't run. I tried re-installing ccleaner, and it won't open even after re-install. I'd love to disable Active Desktop... not sure how though. Thanks again guys for spending your time with this.
     
  30. Matacumbie

    Matacumbie Rocky Top

    Right-click somewhere on your desktop and point to Active Desktop, if it's checked, just left-click to return to the normal desktop.
     
  31. audiogirl

    audiogirl Private E-2

    Aha! Thank you. Getting late here on the East Coast and my brain is toast. (sounds like a song lyric). I'll be back at it in the AM! Thanks again
     
  32. Matacumbie

    Matacumbie Rocky Top

    Try getting all your updates in the morning, restart, and try Housecall again. Your making progress. Steve
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download and run these and then retry the online scans:
    CWshredder:http://www.majorgeeks.com/download4086.html
    CoolWWWSearch.SmartKiller: http://www.majorgeeks.com/download4113.html


    And it's no later than here in NJ! :D
     
  34. audiogirl

    audiogirl Private E-2

    Well, here we are the next day and any progress I made seems ot have somehow been wrecked, probably by me trying to fix things at this point. There is no functioning Java and I can't get it to install or unintall or anything, pretty much every program I click says "this has performed an illegal operation and will be shut down" (some are xaupdate, rundll32, run, runonce, scanregw and MORE), message that c:/windows/winaspi.dll is missing and to get it from windows setup on the disk, dblbuff.sys is missing or corrupted and not even a word document will open. I can still get online though! I think I'm giving up. Can I buy and download a version of Windows XP online (nope... would probably need Java for that) and install it over this mess? :\
     
  35. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    If it were me, I never install on OS on top of another, I would backup critical data and do XP clean, especially having pre-exisiting problems. Windows 98 blue screen and illegal errors are VERY tough to diagnose. XP is much easier to recover or repair.
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And what did yo do since yesterday to cause all of this. Or is this still a residual effect of when you did the "scanreg /restore" and you just had not check everything out yet.

    You could try running sfc (system file check) to try to repair some of the system files but that may not be your problem. I'm not sure what you have been doing.

    As Major said, it is not a good idea to upgrade over an existing OS to XP. It is much better to do a clean install. Question though, can the PC you have handle it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds