Help request, please

Discussion in 'Malware Help (A Specialist Will Reply)' started by pauliwood, Jul 29, 2007.

  1. pauliwood

    pauliwood Private First Class

    Good day all,

    Requesting help at your convenience please.

    I did run through steps 1-6, however, the PC would not allow me to install CounterSpy. Goes through the setup process, but fails to install. Should I run AVG-Anti Spy in it's place on a Windows XP Home Edition Pc?

    Symptoms that brought me here. PC fails to load any web pages, also not able to view files and folder inside windows file explorer. Booting into Safe Mode allows me to do both.

    Ok to post all my log files, or is there anything additional you'd like me to try first? Thank you very much in advance.

    Paul,
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that is what the READ ME indicates you should do.


    Run AVG Antispyware first and fix all that it finds. Save a log.

    Then get new logs from the below if you had already run them:
    • GetRunKey - make sure you have the current version from the READ ME
    • ShowNew - make sure you have the current version from the READ ME
    • HJT
    Attach all 6 logs requested:
    • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
    • Bitdefender - from step 6
    • Panda Scan - from step 6
    • runkeys.txt
    • newfiles.txt
    • HijackThis
     
  3. pauliwood

    pauliwood Private First Class

    Thanks Chaslang, running AVG Anti-Spyware now. Will then re-run the logs for GetRunKey, ShowNew and HJY.

    Also, was not able to run Panda, as it would not fully go into scan mode in Safe Mode, and I cannot connect to the internet in Normal Boot mode.

    Anything you would like me to run in place of that? Thanks again, will post logs shortly.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not right now. When I see your logs I will know better what to run next.
     
  5. pauliwood

    pauliwood Private First Class

    Chaslang,

    Installed and ran AVG Antispyware as instructed in the help file. I followed the instructions on how to set it up and generate reports, however when the scan was finished and I clicked on the reports tab, it said no reports to generate. It did find two things, which I selected Apply all actions for, and quarrantined:

    trackingcookie.netflame
    trackingcookie.tribalfusion
    both medium threats

    Attached:
    bitdefender log
    runkeys.tst
    newfiles.txt
     

    Attached Files:

  6. pauliwood

    pauliwood Private First Class

    attached HJT log
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please complete the instruction in steps 2 & 3 of the READ ME and then attach new logs from ShowNew, GetRunKey and HJT.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also uninstall Viewpoint Media Player as requested in step 0 of the READ ME.


    Also uninstall the below old versions of Sun Java as requested in step 6 of the READ ME
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 5

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
     
  9. pauliwood

    pauliwood Private First Class

    Sorry, nephew's Pc, wasn't sure if the Norton that came with PC was firewall only or firewall plus anti-vir. In any case, I uninstalled MacAfee as instructed and attached new logs.

    Cannot uninstall Java, running in safe mode, I get the error message:

    The windows installer service could not be accessed. This can occur if you are running Windows in safe mode, or if the Windows Installer is not correctly installed. Contact your support personnel for assistace.

    Same message when trying to uninstall from normal boot mode.
     

    Attached Files:

    Last edited: Jul 29, 2007
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You HJT log was from safe boot mode and we they must be from normal boot mode. However before attaching a new one. Let's fix a few things which include so left overs from McAfee that did not get removed.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to McAfee Application Installer Cleanup (0159931185765296)
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below two Services (if you do not find them or get any errors, just continue):
      • McAfee Real-time Scanner
      • McAfee SystemGuards
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste 0159931185765296mcinstcleanup into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below two Services (if you do not find them or get any errors, just continue):
      • McShield
      • McSysmon
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - Global Startup: $McRebootA5E6DEAA56$.lnk = C:\WINDOWS\system32\cmd.exe
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) -

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now reboot your PC.

    And delete the below folder if found:
    C:\Program Files\McAfee

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
    Last edited: Jul 31, 2007
  11. pauliwood

    pauliwood Private First Class

    in the services.msc step
    McAfee Application Installer Cleanup - did not find
    McAfee Real-time Scanner - when trying to change startup type from automatic to disabled, received error message: Unable to open service McShield for writing on Local Computer. Error 5: Access is denied (tried both in safe mode and normal mode) Service shows as being stopped though.
    McAfee SystemGuards - was able to change to disabled.

    Copy/paste 0159931185765296mcinstcleanup into the box that opens, and press OK

    received messages: service '0159931185765296mcinstcleanup' was not found in the registry. Make sure you entered the short name of the service., vbExclamation

    McShield - The service 'McShield' is enabled and/or running. Disable it first, using HijackThis itself (from the scan results) or the Services.msc window

    Attached are the new log files you requested.

    Things improving, I can now access the web, however I can goto yahoo.com yet I cannot access my e-mail and also cannot open windows file explorer and view my files yet.

    Thanks for your help.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do this one again and as I said before, Ignore error messages and continue. Even though it is stopped, try disabling it again and then move on to the next part with HJT to Delete the Service. If it still fails to rmove the below O23 line from your HJT log:

    O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe (file missing)


    Then try running this: McAfee Consumer Product Removal Tool


    Attach a new HJT log afterwards.


    What do you mean Windows Explorer does not work? Explain exactly what happens. Your remaining problems (actually even your starting problems too) may not be due to malware.

    Can you uninstall the old Java versions now?
     
  13. pauliwood

    pauliwood Private First Class

    Chaslang,

    The McAfee Consumer Product Removal Tool seems to have worked. Attached is a new HJT Log.

    Still not able to uninstall the previous versions of Java, is there a removal tool for that also?

    Windows Explorer. If I bring up Windows Explorer, and click on 'My Computer' I get a flashlight that just sits there trying to view the files. If I click on the root drive C: I am able to browse through the hard drive. Also, when navigating the manage attachment, when trying to click on the drop down box, to select a folder, the pc freezes up.

    I want to protect this Pc so my newphew's son doesnt download and install a game that will infect this Pc again. My plan is to remove Norton, install AVG Anti Virus and the PC Tools Firewall, or Sygate if that is still available. Then goto MS and do any critical updates he may need and ensure automatic critical updates is turned on.

    Any other suggestions?

    Thanks as always for your help/
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not really and your problem with uninstalling may be a Windows OS issue. You could try the below but it may not work:

    Your Uninstaller! 2006

    This also indicates possible problems in the Windows OS.


    I recommend that you uninstall all Symantec/Norton software right now while we are working on this PC. It could even be part of your problems. MAKE SURE it all uninstalls by looking at your HJT log and a new ShowNew log afterwards. Verify that all signs of Symantec/Norton and Live Update are gone. Removing Norton can be as difficult as removing malware. You may need to run the below tool.

    Norton Removal Tool (SymNRT)

    Do not try to install any other antivirus application until you get all of Norton removed. You saw how bad things were with both McAfee and Norton installed to begin with.
     
  15. pauliwood

    pauliwood Private First Class

    Was able to remove Java using the Your Uninstaller 2006 program. Used the Norton Tool to uninstall Norton. Was not able to install the latest version of Java. I did download the file from the Help Log, have the .exe, possibly connected to my problem trying to install the auto updates tool from Microsoft, see below.

    Not able to load the Microsoft Update tool, did some searching, appears this Pc may have some corrupted DLLs. I think I may have found the recovery disc on this pc, just need to burn it to CD and see if I can run a windows XP repair to fix these DLLs, manual repair did not seem to work.


    Attached are the two logs, the shownew and HJT.

    Thanks again.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Use Your Uninstaller to uninstall Viewpoint Media Player

    A recovery disk may not be very useful other than to put you back into the same state the PC was delivered in. You need a real Windows XP CD. That way you could run sfc /scannow from a command prompt and have it replace any missing or corrupted system files. You could try running that anyway, but if it asks for the Windows XP CD, it means it found problems and needs the CD to fix them.
     
    Last edited: Jul 31, 2007
  17. pauliwood

    pauliwood Private First Class

    Thanks, will give that a shot later today when I return from work!
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You could also try the below to see if it helps with Windows Update but beyond this you will have to work this problem in the Software Forum.

    Copy the contents of the below Quote Box into Notepad. Then click File and then Save As. Change the Save as Type to All Files. In the File Name field enter C:\WinUpFix.cmd and then click save. This will create the WinUpFix.cmd file in the root folder of drive C.
    Now while you can directly run the WinUpFix.cmd file by double clicking on it, that will not allow you to see any errors if any do occur. So a better method is to run it from a command prompt window. Click Start, Run, and enter cmd and click OK. This opens the command prompt window. In the command prompt window type the following lines each followed by the enter key:
    cd c:\
    WinUpFix.cmd

    Write down any error messages if you get any, and post them back in your next message in your original thread. Post the exact word for word message. You do not need to write down the success messages which will be output as the script runs. Only note any failures.

    If you do not get any error messages, check to see if Windows Update works now.
     
  19. pauliwood

    pauliwood Private First Class

    Thanks Chaslang, I did try both suggestions, and neither seemed to resolve the issue of getting Windows Updates to work. I do not want to take away from your valuable time for a software issue, so is it safe to say this PC is Spyware free at this time? and ok to re-install Antivirus and Firewall protection?


    Just as an Fyi:

    I tried this and received no request for the installation CD

    I did as you said, I also did this manually last night manually for each, according to the online help file from Microsoft, still not letting me install the Express Updates feature. Giving me the error:

    Files required to use Windows Update are no longer registered or installed on your computer. To continue:


    Register or reinstall the files for me now (Recommended)
    Let me read about more steps that might be required to solve the problem

    I will post my current issue in the software forum, thanks again!
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not have any malware since your first message. Nothing we were doing was related to malware removal. So yes you should now get your PC properly protected by following the steps in the below link:

    How to Protect yourself from malware!



    One other thing I have seen people say resolved the same problem is installing the below. I don't know if it will fix your issue or not.

    http://www.microsoft.com/downloads/details...&DisplayLang=en

    If that does not help, you could also check the below out:

    http://wiki.castlecops.com/Windows_Update_Fix

    They include an WUFix.zipfile which attempts to fix it automatically.
     
  21. pauliwood

    pauliwood Private First Class

    Thanks again Chaslang, no luck on the two other tips, so I left a post in the Software forum as you suggested.

    If you have time to answer, if not Spyware that caused this pc not being able to connect to the internet other than in Safe Mode, what could it have been? Both Norton and McAfee were installed simultaneously for some time now.

    Also, when I ran through the Spyware tutorial before posting, S&D did find WildTangent which it appears it removed.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes and that is very bad thing to do. It causes immediately problems with inability to properly provide system security and in the long run, it can cause many other issues. More than likely it even caused your problem with getting connected since they were fighting against each other. Step 3 in the READ ME exists because having multiple AV's installed does the opposite of providing more security.

    WildTangent is not a major issue but you really don't want it. Some people refuse to remove it because they play all of those games from WT. That is a bad idea but some people just don't want to listen. Like all the poker addicts who allow all those online poker sites to put all kinds of garbage (including malware) on their PCs, and this really goes contrary to keep you financial info secure.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds