cannot proceed with read and run me first

Discussion in 'Malware Help (A Specialist Will Reply)' started by hrdwoodpro, Feb 3, 2006.

  1. hrdwoodpro

    hrdwoodpro Private E-2

    I am trying to run throught the read and run me first instructions but my computer will not boot in safe mode. I get the safe mode corners but no desktop options. So i decided to run in normal mode but when i try to run ad aware i get a fatal error message please help what do i do?
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Have you tried Safe Mode w/ Networking? If you still can't get into Safe Mode just skip this for now and procede.
     
  3. hrdwoodpro

    hrdwoodpro Private E-2

    i have successfully started in safe mode with network support but i still cannot complete the ad aware step without a fatal error massage and restart
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Just skip the Ad-Aware scan and procede with the rest.
     
  5. hrdwoodpro

    hrdwoodpro Private E-2

    here are the log files without running adaware
     
  6. hrdwoodpro

    hrdwoodpro Private E-2

    every time i try to post my attachments the screen turns green and freezes up making me leave the internet and start over when i get back to majorgeeks i try to upload again and it says the last uploads are in progress what do i do
     
  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Just post them inline and I will convert them for you.
     
  8. hrdwoodpro

    hrdwoodpro Private E-2

    i am not familiar with inline and i do not want to assume you are asking me to copy and paste please clarify.
     
  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Yes, if you can't attach then copy and paste it inline and I will attach it for you.
     
  10. hrdwoodpro

    hrdwoodpro Private E-2

    ill have to do 1 at a time this is active scan

    Inline logs attached!
     

    Attached Files:

    Last edited by a moderator: Feb 3, 2006
  11. hrdwoodpro

    hrdwoodpro Private E-2

    Inline log attached to post #10
     
    Last edited by a moderator: Feb 3, 2006
  12. hrdwoodpro

    hrdwoodpro Private E-2

    Inline log attached to post #10
     
    Last edited by a moderator: Feb 3, 2006
  13. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  14. hrdwoodpro

    hrdwoodpro Private E-2

    her are the log files you requested after running vundofix
     

    Attached Files:

  15. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  16. hrdwoodpro

    hrdwoodpro Private E-2

    here are the attachments you asked for
     
  17. hrdwoodpro

    hrdwoodpro Private E-2

    her they are
     

    Attached Files:

  18. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please look in Add/Remove Programs for the following and uninstall them if found:

    Ewido

    Spy Sweeper


    Now scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.co m/search/ie.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.co m
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://v4.windowsupdate.microsoft.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yaho o.com/ext/search/search.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.co m

    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)

    O4 - HKLM\..\Run: [MyWebSearch Email Plugin]

    O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
    O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)

    Again, make sure ALL browser windows are closed when you click FIX.

    Next, run CCleaner to clean up cookies and temp files.

    Run full scans with Ad-Aware SE & Spybot S&D and have both programs fix what they find.

    Note: Remember to get all updates before doing the scans.


    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    • Temporary Files
    • Temporary Internet Files
    • Recycle Bin
    And Click OK.


    After you complete the above, REBOOT and proceed with the rest of this fix...

    Finally, I would like you to flush your System Restore points. Please follow the instructions in the below:


    • Disable and Re-enable System Restore

    • Turn OFF System Restore to flush any bad Restore Points.

    • Then, follow the instructions at the bottom of the linked page to Re-enable the Restore Utility which will create a fresh restore point.
    After you complete the above reboot once more and then scan with HijackThis and attach the new log.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  19. hrdwoodpro

    hrdwoodpro Private E-2

    the computer is running very well now but when i restart i get a dell folder system 32 folder and free desktop weather installer pop-up this is the computer at my fathers house with share happy high school kids using it so the history is unknown to me. hjt log attached thank you very much
     

    Attached Files:

  20. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Have HJT fix the below entries:

    O4 - HKLM\..\Run: [MyWebSearch Email Plugin]
    O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"

    Next, please download RegSrch.zip

    Unzip the archive to your desktop and double click on the VBS file.
    (If your AntiVirus alerts, allow the script to run.

    Now enter MyWebSearch and post back with the results in this thread (call it regsrch.txt).
     
  21. hrdwoodpro

    hrdwoodpro Private E-2

    here is the txt you asked for
     

    Attached Files:

  22. hrdwoodpro

    hrdwoodpro Private E-2

    i should at least be an e-3 after the hours ive put in today :)
     
  23. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fix.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fix.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    After you complete the above, reboot and let me know how things are running.
     
    Last edited: Feb 4, 2006
  24. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    LOL!!!

    You will be a "Private First Class" when you reach post 30. ;)
     
  25. hrdwoodpro

    hrdwoodpro Private E-2

    everything is good except the weather popup is still there and the dell window still pops up the weather thing asks if i want to complete installation after clicking the x , the dell window has four folders in it but really seems like something i can take care of in startup manager its too late for me to think for myself at this point i am sorry.
     
  26. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Can you take a snapshot of the Dell popup your talking about?

    Do you use the Weather thing your talking about? If not, just uninstall it via Add/Remove Programs.
     
  27. hrdwoodpro

    hrdwoodpro Private E-2

    It was not in add or remove programs but i found a folder in program files called desktop weather and deleted it. i restarted and it is gone the folders ill restart and get the snapshot
     
  28. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Okay, I just want to confirm it's what I think it is before I take action.
     
  29. hrdwoodpro

    hrdwoodpro Private E-2

    here it is attached
     
  30. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    It didn't attach?
     
  31. hrdwoodpro

    hrdwoodpro Private E-2

    here it is i forgot to compress it
     

    Attached Files:

  32. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Have HJT fix the below entry, afterwards reboot and see if it still comes up.

    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
     
  33. hrdwoodpro

    hrdwoodpro Private E-2

    it still comes up but i noticed right before the os loading screen after reboot there is a black screen with a blue bar at the top that says dell.com it only flashes for a split second. it has done this all night it did not just start after the last hjt fix.
     
  34. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I'm not sure exactly what is causing this to popup. Doesn't appear to be starting from the registry per your HJT log.

    You can try Start > Run > msconfig and see if you can find it here.

    If you don't use it, you can always uninstall.
     
  35. hrdwoodpro

    hrdwoodpro Private E-2

    I went into the ms config startup menu and disabled everything. it is fine now. this computer is at my fathers house and they can decide what they want to startup the computer runs great and i appreciate all of your hard work and patience. Ill probably be back when the kids here get back to their free music addictions again. Thanks again
    :cool:
     
  36. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds