Computer reduced to safe mode without networking... cannot complete READ&RUN

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by powerpuppies, Jan 8, 2009.

  1. powerpuppies

    powerpuppies Private E-2

    I am posting from my laptop because my desktop cannot access the internet; it can only boot into safe mode, not safe mode with networking.

    I had a malware infection around Thanksgiving that I successfully resolved with HJT. My browser was being hijacked and some networking applications did not work. That was the extent of the infection.

    Two days ago I began to see more evidence of browser hijacking. I used HJT, deleted everything that seemed bad, and rebooted. I never made it back into windows proper. Eventually I made it into safe mode. Thinking i had deleted something worthwhile, I restored everything I deleted. Still no boot.

    So I came here. Tried to work through 'read and run me first', but in safe mode I was unable to uninstall Java (I have Java 5). I moved all the downloads reccomended from the laptop to the desktop using a flash drive, but SuperAntiSpyware won't install. It gives me the normal Windows "has encountered a problem and needs to close" message. I did not attempt to install or run any other scanners from the read&run.

    Haaaaalp!
     
  2. powerpuppies

    powerpuppies Private E-2

    Found that TDSserv.sys Driver or whatever and disabled it. Now I am out of safe mode, but I still get the "has encountered an error and needs to close" when I double-click the SuperantiSpyware.exe.
     
  3. powerpuppies

    powerpuppies Private E-2

    The other .exes I downloaded from the Read&Run won't run, even when re-named.
     
  4. powerpuppies

    powerpuppies Private E-2

    Got everything running. Following the Read & Run guide removed a lot of stuff and the symptoms are gone. Can you guys give me a clean bill of health?
     

    Attached Files:

  5. powerpuppies

    powerpuppies Private E-2

    Aaaand the last two logs.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry for the delay, we are just swamped.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds