Can't run any programs in Windows 7

Discussion in 'Malware Help (A Specialist Will Reply)' started by tds, Dec 29, 2012.

  1. tds

    tds Private E-2

    I am pretty sure my computer is infected. Yesterday I couldn't access Gmail as there was a cookie error. I tried the suggested fixes but it didn't work. So I ran malwarebytes (Quick Scan) and it found a trojan and something else which it quaranteened. So, I decided to run a full scan. Six minutes into that scan, the computer rebooted and since then, I can't run load .exe program at all. I booted into safe mode and I still could not run any programs (cursor would show busy for a few seconds but nothing would load). So I can't load explore, Malwarebytes, etc. I was able to restore the computer to a point about a week ago, but same problem after restore. I have tried other restore points but now restore won't even complete successfully. I did try running FixNCR.reg (which was able to run) to see if would then allow me to run programs but there was no difference. My operating system is Win 7 home premium.

    Before this started I was getting random redirects from search engines, but I don't know if that is related or not. Any help is greatly appreciated!
     
  2. tds

    tds Private E-2

    I also tried running Rkill in safe mode with networking under several different names. I would load, but would display a blank screen and then terminate after about 10 seconds.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please do the below so that we can boot to System Recovery Options to run a scan.

    For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  4. tds

    tds Private E-2

    Thanks! Log file attached.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below is not a complete fix. It is an attempt to get started. You will really need to be able to run other tools in order to fully get this infection removed.


    Download this >> View attachment fixlist.txt


    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows if possible and continue with the below.

    Run this TDSSkiller - How to run


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • Fixlog.txt
    • the TDSSKiller log
    • C:\MGlogs.zip
     
  6. tds

    tds Private E-2

    Thanks. I have attached fixlog.txt
    After that, I was able to boot into windows normally, but explorer/chrome still doesn't run so I couldn't download TDSSkiller onto the desktop. I had TDSSkiller on flash drive but it wouldn't run from that either. Do I need to copy it to desktop first or run it in safe mode?
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes copy it to the main PC hard disk anyway you can and run it from there. Try running in normal boot mode. If that does not work then also try running it in safe boot mode.


    Also please run mentioned GetLogs.bat program from normal boot mode if possible.
     
  8. tds

    tds Private E-2

    I really appreciate the help. I copied TDSSkiller to the main PC hard disk and tried running it in normal and in safe mode. Neither approach would allow me to run the program. Like everything else, when I click on it, cursor shows busy for 5-10 seconds, then nothing happens.

    I also copied MGtools.exe to the main C:\ directory and disabled UAC. When I try to run as adminstrator, it won't run either in normal boot mode or in safe mode (same problem - cursor shows busy but nothing loads). So, I still appear to be stuck, since I can't run getlogs.bat until MGtools.exe itself has extracted all the files.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  10. tds

    tds Private E-2

    OK - I created Kaspersky CD and it was able to run it just fine. I was then able to run each step in the full cleaning procedure. Everything seem to run with no problem now.

    Computer seems to be working just fine at this point! You are absolutely amazing!! Should I attach any of the logs from the full cleaning procedure or stop since everything appears to be working now? :)
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should attach all 5 of the requested logs so that we can verify that there are no other problems.
     
  12. tds

    tds Private E-2

    Logs attached!
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks pretty good now. Just a few minor tweaks and then final instructions.

    Uninstall the below old versions of software:
    Java(TM) 6 Update 25

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now if you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds