can't remove old java in safe mode

Discussion in 'Malware Help (A Specialist Will Reply)' started by ackermann, Sep 18, 2009.

  1. ackermann

    ackermann Private E-2

    Hi,

    I am trying to follow the malware removal guide but cant get old java removed in windows safe mode? Ideas

    Thanks
     
  2. ackermann

    ackermann Private E-2

    I forgot to put the windows message.

    Windows Installer
    The feature you are trying to use is on a network resource that is unavailable.

    Also i tiried to follow this thread with no luck: Problem uninstalling Java 6 Update 2.
     
  3. ackermann

    ackermann Private E-2

    Hi I have taken care of the java issue. Followed the Malware removal guide and now I have two problems. One of which I have a work around for.

    1. Computer hangs after loading of desktop. Mouse curser moves but can't click on or start anything. I found a work around for this. If i set the system date back in safe mode everything boots fine in regular mode next time.

    2. At one time I removed internet explorer and now I can't get it to reinstall.

    Oh bye the way this all started about 10 days ago when I noticed that something had hi-jacked my IE browser and would redirect me when i clicked on a search result. It was do to this that i got rid of IE8. during the cleaning process IE 7 quit working and now I cant find it.

    Thanks for your help.
     

    Attached Files:

  4. ackermann

    ackermann Private E-2

    Here are the last 2 logs.

    Thanks in advance for any and all help
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You appear to have lot of services and processes disabled from loading. I'm not sure what program you are using but it would be best if you undid whatever you did since you have have necessary system services disable and have things trapped in MSconfig registry keys we need to cleanup. But I cannot do this properly while you are controlling all of these startups and services with something (like Windows Defender or Spybot...etc).

    Installation problems with IE belong in the Software Forum. Not sure what you problem is with your mouse. Also don't know what you mean by setting the system date in safe mode? Are you saying that when you just boot your PC normally that your clock (data/time) are incorrect?


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    Viewpoint Media Player <-- should have been uninstalled in step 5 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {1A00A28B-D791-4D35-AFC7-37AD23638B1a} - (no file)
    O2 - BHO: (no name) - {32CE0D1B-3B8E-46C3-B82F-E2AA3D137CBE} - C:\WINDOWS\system32\pmkjj.dll (file missing)
    O2 - BHO: (no name) - {E12BFF69-38A7-406e-A8EF-2738107A7831} - C:\WINDOWS\system32\ayqyqapp.dll (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.



    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.
     
  6. ackermann

    ackermann Private E-2

    Help, I followed your directions but at the combofix something went bad. Now it will boot into safemode only. If I try to boot normally it gets to the log in screen and then just turns off and starts the boot process over again, and again, and again.

    Help
    Thanks
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the requested logs anyway even if from safe mode. If combofix did not create a new log then just attach the new MGlogs.zip file.
     
  8. ackermann

    ackermann Private E-2

    here is the mglog
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well your new MGlogs.zip file shows that you were in normal boot mode when you ran it so I assume that means you can boot in normal mode.

    Also since none of the items that we wanted ComboFix to remove were removed, it means ComboFix did not do anything to cause a problem. Either that, or you ran MGtools.exe out of order and gave me a log that I don't need since it needed to be ran after running ComboFix not before. You need to clarify all of this.

    I will give you another fix using a different tool since you seem to have a problem using ComboFix.

    First remove MGtools.exe from your Desktop since that is not where we asked you to save it.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder this time as previously requested.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. ackermann

    ackermann Private E-2

    Hi Chaslang,

    It will only boot into safe mode. I get a bsod when trying to boot normally. I believe combofix removed everything other than the temp file. In your previous request you asked me to run the HJT file of MGTools first and that is the log you have. than I ran the combofix.

    I ran the HJT in normal mode and than the Combofix also in normal. It did everything up untill showing the log. While it was going through it said something about a dumphive problems and about recovering a driver or something from a log.

    The computer still will only boot in Safe Mode. Do you want me to run the avanger program as previously asked.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I only asked you to run analyse.exe to fix some items with it. I did not say to run MGtools until after ComboFix was run. You still need to get this new log from MGtools and attach it.

    NO! First run MGtools as requested and attach a new log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds