Cant run or install programs.....

Discussion in 'Malware Help (A Specialist Will Reply)' started by the_BALD_guy, Nov 23, 2008.

  1. the_BALD_guy

    the_BALD_guy Private E-2

    While working my way through the "READ AND RUN ME FIRST" instructions I ran into the following problems.

    Windows XP cleaning procedure:

    Step 2:

    I got SUPERAntiSpyware installed and ran a scan.
    I got Spybot S&D Installed but when I try to run it I get the hourglass for 2 seconds but it never loads.
    I got MalWarebytes installed but it is the same as Spybot , wont run.
    When I click on the ComboFix.exe it does absolutely nothing...cant even install.
    I did run the MGTools and have a zip of the logs.

    This is a laptop of a friend from work and she knows zero about computers and I dont know much more than that so any help would be deeply appreciated.

    Thank you.

    G
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Attach the logs from SUPERAntiSpyware and MGtools.

    Did you try renaming the MBAM and Spybot executable files as suggested?
     
  3. the_BALD_guy

    the_BALD_guy Private E-2

    The logs are attached.

    Thanks you.

    Yes I did change the names of the exe files.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below is where you put combofix!
    C:\Documents and Settings\All Users\Documents\Security (EXE)\ComboFix.exe

    This is not where the READ & RUN ME instructions specified. It must be put on your Desktop. That is you should have

    C:\Documents and Settings\andy ryle\Desktop\ComboFix.exe

    Please put it where requested and try running it again later by just double clicking on. But do this after doing the below.

    Now you must disable Spybot's Teatimer as we requested in the READ & RUN ME. See this: How to disable Spybot's TeaTimer

    Now uninstall Viewpoint Media Player as requested in step 1 of the READ & RUN ME.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKCU\..\Run: [88016554115418438706262628376319] C:\Program Files\Antivirus 2009\av2009.exe

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\temp\
    C:\Documents and Settings\andy ryle\Local Settings\Temp\

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. the_BALD_guy

    the_BALD_guy Private E-2

    OK brother, first thanks for your help on this.

    I put combofix on my desktop and tried to run it but it still does nothing when I click on it.....arghhhh

    Spybot has some weird stuff going on with it. Since I can run it (still wont load when I click on it) I cant disable the tea timer. So I uninstalled it completely and reinstalled (without the tea timer) and rebooted. When I reboot the tea timer comes on and I still cant run the main program (what the hell?)

    Malwarebytes still wont run either.

    Just so you know this computer is jacked. I am corresponding with you on a different computer because when I open a browser it allows the search pages (google - yahoo) to come up, but when you search something and click on a link it redirects. If I try to type an address (majorgeeks.com etc) it says page cannot be displayed.

    Also I tried to install the recovery console. I put my windows XP cd in and typed:

    X:\i386\winnt32.exe /cmdcons

    in the OPEN: field and hit OK i got a flash of a dos screen and nothing happened.

    What should I do?
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then uninstall Spybot and leave it uninstall for now.

    What happens? Any error messages? Have you tried running it in safe boot mode? Can you run it after logging into a different user account.

    The logs.zip file you posted is not a new copy of MGlogs.zip. You did not run the GetLogs.bat file to create a new set of logs as requested. However, now I want you to download and run the new version of MGtools from MGtools.exe Then attach the new MGlogs.zip file. You should not need to ever rename the file when the logs are new. The file you attach should always be MGlogs.zip.
     
    Last edited: Nov 28, 2008
  7. the_BALD_guy

    the_BALD_guy Private E-2

    Here are the new logs.

    Malwarebytes does nothing when I click on it (same as spybot) no errors or anything it just doesnt start (even in safe mode)

    thanks,

    G
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
    Now run this: Using SDFix I will ask for the log at the end of this message.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now reboot!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below log
    • the SDFix log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Nov 28, 2008
  9. the_BALD_guy

    the_BALD_guy Private E-2

    I did everything in your post except the SDFix which wont install (of course).

    I did get a confirmation that the fixme.reg worked.

    I dont understand why I cant install/run certain programs.

    Spybot SD, Malewarebytes, and now SDFix.......arghhh

    I attached the new MGlogs.

    Thanks for your help..!

    G
     

    Attached Files:

  10. the_BALD_guy

    the_BALD_guy Private E-2

    OK brother I finally got the SDFix and Spybot to work today. Dont really know what changed or why they worked today but Spybot fixed 6 hijacks and now everything works good now. Thank you for your help on this.
    G
     
    Last edited: Dec 2, 2008
  11. the_BALD_guy

    the_BALD_guy Private E-2

    These are the most current logs.

    I think all is well now.

    Thanks,

    G
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do the below.

    Click Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices.
    • Scroll down to “Non-plug and Play Drivers” and click the plus icon to open those drivers.
    • Then search for TDSSserv.sys
    • Let me know if you find this or not.
    • If you do find it, right click on it, and select Disable. Do not try to uninstall it.
    • Also if this is found and you disable it, then reboot and see if you can run the other scans that would not run.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds