Can't run any install programs to solve problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by bnp123456, Feb 18, 2005.

  1. bnp123456

    bnp123456 Private E-2

    I have tried to do the "Do these first" items before contacting. My malody won't allow any new files to be opened and installed. Files before problem seem to run fine. I tried updating my adaware, and it wouldn't do that so I downloaded the udate zip and unzipped it and installed it manually. it found 4 "minor" tracking cookies, but the program locks when I try to delete them with Adaware. Also AVGFree doesn't find anything when I run it. Both are latest versions with latest updates. Also when I reboot the system, a green circle icon pops up very briefly in the icon tray while the system shuts down. I've tried to download the recommended spyware utilities, can download the file, but they just lock up when I try to run the install for them, even in safe mode. I've also tried online scans, but I can't download any activeZ controls, system locks up. I believe I got this by trying to download various image "grabber programs" (all on first search page) found using MSN seach for the same. Not for porn use, but for manufacture vendor sites. No Porn sites visited. Any ideas would be appreciated, if all else fails, may by new hard drive and install operating system and recommended software and then put infected drive in as slave and see if I can clean it.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HijackThis does not require an install. (Neither does CWShredder for that matter.)

    Make sure you have HijackThis 1.99.1 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    Also try running CWShredder and select Fix!
     
  3. bnp123456

    bnp123456 Private E-2

    Ok turned off pc for 24 hours was able to finally get in and do some stuff. Reason unknown. Can only do things in Safe Mode with Networking. Hijack This and many of the other software recommended to use when trying to download and install, or run in normal mode pops up with invalid image when clicking on the icon to run it, or locks up when trying to run it, no active x at all will download, no spyware killer programs will install after download in normal. Programs not in any way associated with viruses, spyware, etc. load and run fine. Following are exceptions: Adaware runs and comes up clean, both in safe and normal mode(Had to manually install updated definitions). Spybot runs and comes up clean, both in safe and normal mode. AVGFree runs and comes up clean, both in safe and normal mode. Trend and Symatec Avert Stinger did not find anything. Here is a copy of Hijack this I just ran in safe mode. It will not run in normal mode. Thanks for taking the time to help with this. Much Appreciated.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Were you running Internet Explorer when you scanned with HJT? The below was in your log:
    C:\Program Files\Internet Explorer\iexplore.exe

    If so, always shut down IE before using HJT. If not, make sure you tell me.

    Also, you have a broken LSP chain. Download LSPFix (http://www.majorgeeks.com/download4180.html) and run it.
    Check the "I know what I am doing" box Click on connwsp.dll on the left window and click on the
    arrow pointing to the right. Click Finish and follow the prompts.
    Run HijackThis and with all browsers closed select the following and click Fix!
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm

    I do not see any major problems that could indicated your problem! Boot into normal mode but physically have your cable from your PC to the internet unplugged. Then try to run HijackThis in normal boot mode and tell me EXACTLY what happens. If you receive any error messages tell me what they are exactly. If it runs, post the log.


    Generate a StartupList log using HijackThis
    (Do this either from normal or safe mode - just tell me which one. I prefer normal boot if possible.)
    Run HJT and on the first screen, click the button that says "Open the Misc Tools section". In the next window first select "List also minor sections (full)" and then click the button that says "Generate StartupList log". CLick Yes to the Do you want to continue prompt. Now a notepad window will come up with the Startuplist.txt file. It is already saved in the the directory HJT is running from. So just come back here and upload the file as an attachment to your next message.
     
  5. bnp123456

    bnp123456 Private E-2

    Ran the LSPFix. Ran the fix recommended on HJT. Rebooted in Normal mode. Still will not work in normal mode. Comes up with a little window popup approx 150 x 150 with a red circle and white x in it and says in a plain font INVALID PICTURE. Came back to safe mode and ran HJT again. IE was not running, nothing but HJT was running and internet unplugged when I did the HJT log. On the startup log, I forgot I had the HJT log open still.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I cannot determine anything is wrong from those logs.

    When are you getting this popup window with the red circle in it?

    Are you able to boot in normal mode at all?
    Can you get logged in?

    It sounds like maybe you have a bad or corrupted BMP file trying to load a Desktop image.
    Try changing you settings to not use any wallpaper or images.

    How much RAM do you have in your PC?
     
  7. bnp123456

    bnp123456 Private E-2

    I get the message when i try to download a new program and run it. If it was previously installed, (before any problems) is works fine. I started to notice a little icon pop up as windows was closed and became suspicous that someone had placed some sort of data/password stealer on my machine. About 6 months ago some had stole my aol password somehow. I went to majorgeeks and proceeded to download all recommended items, but they wouldn't install in normal mode. just in safe mode. So I became very suspicious. The error message pops up whenever I click on any of the newly installed items in normal mode. They worked fine in safe mode, but give the image error whenever clicked on in normal mode. All other programs work fine in normal mode and will load when icons clicked on. I have 384M of RAM. Will try to disable images and see what happens.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I repeat HijackThis does not require and installation. You just extract it from the ZIP file and run it.

    Please explain why it cannot be run in normal boot mode. What happens when you double click on Hijackthis.exe?
     
  9. bnp123456

    bnp123456 Private E-2

    Ok wrong wording. I unzipped it and tried to run it. If you click on hijackthis.exe. it brings up the invalid picture warning again. I removed it and tried to download and unzip it again. but still does the same thing. You know now that I think about it a friend recommended a few weeks back to download and run WINner Tweak and registry cleaner XP. To clean up any loose registry entries. I did, but it didn't seem to do anything. So I moved on and forgot about it. I thought I got it off MajorGeeks, but just checked and a link is not there. Just checked it now and it won't run again, or uninstall. Maybe it removed some stuff it wasn't supposed to when I tried to run it the first time. I can't install OR run any program in Normal Mode (I can in safe mode) that wasn't on the machine prior to the WINner Tweak. Is there a fixer for the registry that you recommend. I'm feelin now that is the problem and not a spyware bug of some sorts. But haven't been able to run HJT in normal mode either. I also tried to unzip it and run it on another harddrive to, but still get invalid picture error.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All registry fixing tools come with danger. They are not really that fool proof. They find lots of things and not all are really problems. However it does not matter anyway if you cannot install anything and get them to run....does it. And before doing any kind of registry repair you really should do a registry backup first.

    Try renaming hijackthis.exe to hijackthis.com Now run it in normal boot mode. What happens?


    What happens if you run CWShredder.exe?
     
  11. bnp123456

    bnp123456 Private E-2

    I can run programs in safe mode, in normal I can't. Changing HJT to .com didn't have any affect. CWShredder runs fine in safe, same problem as HJT in normal mode.
     
  12. bnp123456

    bnp123456 Private E-2

    I just went and looked and sure enough it did make a backup of the registry dated 1/24/05. I tried to reinstall the backup, but said that it couldn't because some entries were in use and/or missing. I opened the backup with Notepad. I could post the notepad file if you want to see what it says.
    Here is something that caught my eye when going through it. I have no idea what this is, but i've never used the media player that I know of. My machine is mainly a work machine. [HKEY_USERS\S-1-5-18\Software\Microsoft\MediaPlayer\Battery\Presets\Nerds Are Cool] There are several entries where the are "Nerds are Cool" is replaced with what sounds like song titles. Here are some examples of whats there. khemicalnova, kaleidoscope, ISeeTheTruth, Lotus, illuminator, GrooveSwirl, Geeks Kick ASCII. Is there a secure way to get this to you if you wanted it? The list is very detailed. I'm going to try reinstalling the Winner Tweak and Registry cleaner in safe mode and try restoring the backup. It is download3560 by the way.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry but actually no I don't want to look at a back up of a registry. That would be rather large and time consuming.

    Does Task Manager run in normal boot mode? Can you provide a list of processes that are running? I'm not sure that anything that is running is causing the problem though. It could be as you are thinking registry corruption.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds