Malware Chinese Characters

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Bluesbreaker, Feb 2, 2016.

  1. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi Blues,

    We're hoping this will now solve the start up error....

    Open up Autoruns, make sure you are on the 'everything' tab. Scroll down until you see this entry: (I have attached screenshot too of it)

    • BVTConsumer File not found: KernCap.vbs

    Right click it and delete it. Reboot the machine, do you still get the error, yes or no?
     

    Attached Files:

  2. Bluesbreaker

    Bluesbreaker Corporal

    Hi - ok I will be trying this tonight, with baited breath!

    is the fact that the start button (for things such as pulling up the programs, shut down, etc) doesn't work tied to the same whole vbs issue? I guess we'll know tonight.

    thanks again Kestrel13!...
     
    Kestrel13! likes this.
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I had no idea you had issues with the start menu. Again, one thing at a time. Not promising deleting that entry will fix start menu.
     
  4. Bluesbreaker

    Bluesbreaker Corporal

    ok sorry to overwhelm, thought these faults were part and parcel. Will revert back shortly.
    thanks again
     
  5. Bluesbreaker

    Bluesbreaker Corporal

    hi - I still get the error unfortunately....
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I'm consulting with Chaslang about this, hang in there.
     
  7. Bluesbreaker

    Bluesbreaker Corporal

    Thanks Kestrel13!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So please tell me what issues still remain and provide exact details. I know you just said there is a problem with the Start button but I'm not clear on exactly what the problem is (doesn't work is not sufficient). It does not sound like a malware problem though. Also exactly when did the each problem begin.
     
  9. Bluesbreaker

    Bluesbreaker Corporal

    Hi Chaslang. So here's the situation I have now.
    1) When I log into Windows, I get the following error message: Windows Script Error, Cannot find script file "c:\windows\run.vbs". This started a few pages back when we tried running some fixes and I believe this got deleted by mistake. This also may have come up when I logged into safe mode via msconfig versus the other ways you can log into safe mode via windows 10.
    2) when I launch firefox, I get the following error:http://www.%snf%.com/ which I don't know what is.
    3) when I try and launch some picture files, I get c:\users\lil-nick\pictures\blackberry-b30e\camera\img.jpg the app didn't start. this seems to have happened between getting the junkware and now. I used to be able to access these pics without issue, they were uploaded from blackberry
    4) when I click on the window icon on the desktop, the popup screen with applications, weather, pictures, documents, all apps, etc does not come up
    5) I still am unable to access the desktop without hitting ctrl-shift-escape and running explorer, notepad, etc. from task manager. these manifested themselves around the same time as 1) above.
     
  10. Bluesbreaker

    Bluesbreaker Corporal

    It think we used roguekiller to wipe this file C:\Windows\run.vbs and then certain remnants of the junkware such as Baidu or whatever were preventing me from installing the necessary scripts....
     
  11. Bluesbreaker

    Bluesbreaker Corporal

    also, is it safe for me to install Acrobat updates so that I may run flash, etc or should I hang back for now?

    thanks again for all your help, as well as Kestrel13!
     
  12. Bluesbreaker

    Bluesbreaker Corporal

    Now I'm thinking if I'm all clear, maybe reinstall Windows 10?
     
  13. Bluesbreaker

    Bluesbreaker Corporal

    Hey there just wondering what next steps are for me? Thanks again
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry for the delay. Real work and issues at home have kept me super busy this week and I had little time to be here. I have a some more steps that I wanted to take. One was to see if I could help with the startup issue you have related to run.vbs. I will be posting something in a little while. I want to look over a few things in your previous logs first.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay first please run MSconfig and make sure that your PC is set for Normal Startup mode. Then continue with the below.

    Download the attached fixlist.txt file found at the bottom of this message and save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • Fixlog.txt
    • C:\MGlogs.zip
    Please attach the above two log first before you continue with the below.

    Also at this point, I want to double check the status of your PC by having you run another scan with FRST like you have done previously. Please also attach the new FRST.txt.
     

    Attached Files:

    Kestrel13! likes this.
  16. Bluesbreaker

    Bluesbreaker Corporal

    Thanks Chaslang hopefully everything is outside this forum. One thing I should say, I ran this Regedit file to get rid of the cannot find script file c:\windows\run.vbs. From winhelponline.com, I ran this:

    Start Registry Editor (Regedit.exe) and go to:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
    Double-click Userinit value and change the value data from:

    wscript C:\WINDOWS\run.vbs,
    to the following:

    C:\Windows\system32\userinit.exe,

    and that fixed the initial error I get at login.

    the startup still does not work. is it safe for me to proceed with your fix above given what I did? Also, is it safe to go normal from MSCONFIG or should I use the other method that Kestrel13! had provided?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't understand your last message. You said you fix the run.vbs issue but that fix was already given Kestrel13! quite awhile ago.
    However now even though you said you fixed this, you are still saying startup does not work. So I'm not clear on exactly what you problem is. Could you tell me exactly what you mean?

    Don't run anything from my previous fix now!!!! Please just do the below instead so that we can get a new status set of logs from a NEW version of MGtools.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista, Win7, Win8, or Win10, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below logs:

    • C:\MGlogs.zip
     
  18. Bluesbreaker

    Bluesbreaker Corporal

    Ok to clarify, and sorry for any confusion b/c there has been a lot going on here, the windows script error (at login) Run.vbs didn't get fixed. Post 159. I was still having issues up until running that Regedit thing yesterday.

    Start menu still doesn't work, correct. Still cannot open any jpgs.
     
  19. Bluesbreaker

    Bluesbreaker Corporal

    I am running MG Tools as per post 167 above
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But Kestrel13! had you fix this with a registry patch back on Feb 6th in Post # 44.
     
  21. Bluesbreaker

    Bluesbreaker Corporal

    and here is the MGlogs file...
     

    Attached Files:

  22. Bluesbreaker

    Bluesbreaker Corporal

    we did try and fix it with the regedit files but never got rid of the login script error. in any event its gone now.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now run MSconfig and select Normal Startup Mode. You don't have to be concerned about the kind of warning Kestrel13! gave you for using MSconfig to enter Safe Boot Mode. Normal Startup is the mode you should always be running in unless you are debugging problems. Reboot your PC after selecting normal startup mode. Then let's get a new log from AutoRuns ( same as you did previously - zip it and attach it ).
     
  24. Bluesbreaker

    Bluesbreaker Corporal

    here is the autoruns file...
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now run AutonRuns again and look for anything related to Tencent or Baidu and select them one at a time and right click on it and select delete.
    I saw the below in your last log. It may be the only one left:
    Code:
    SRepairDrv   Tencent SRepairDrv(电脑管家修复模块)    Tencent c:\windows\gjfix\srepairdrv 12/11/2015 2:08 AM 
    Do you still have a problem at startup now after putting your PC into normal startup mode?
     
  26. Bluesbreaker

    Bluesbreaker Corporal

    THanks Chaslang - I will run this later today. One thing, am I running this autoruns/deletes in Normal Mode?

    Also, when you ask about problems at startup, do you mean at Login? Because I am ok now as it pertains to logging in and gettings the windows vbs script error, that's all resolved now.
     
  27. Bluesbreaker

    Bluesbreaker Corporal

    ok! deleted the file related to tencent, searched for baidu (nothing) and have rebooted. so the startup menu still doesn't work...
     
  28. Bluesbreaker

    Bluesbreaker Corporal

    and there were no other files related to tencent or baidu just fyi
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So when you boot up your PC, you go thru a login prompt? And then after login, you get a black screen ( Is it totally empty with no icons )? That is like explorer.exe is not running automatically ?
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please answer my questions from my last message and then also do the below.

    See the below link and open up an elevated permissions command prompt window.

    http://www.tenforums.com/tutorials/2790-elevated-command-prompt-open-windows-10-a.html#option1
    • Now in the command prompt window type the below and click OK. Note: There is a space after the sfc.
      • sfc /scannow
    • This runs System File Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it.
    • When it finishes, you should just see the command line prompt return.
    • Reboot your PC after this has finished running.
    • Any change?
     
  31. Bluesbreaker

    Bluesbreaker Corporal

    no - that part was fixed. originally, I would log in, get the windows script vbs error and go black. that part was fixed per post 166 above.

    what is not fixed is the windows start icon (on the bottom left of the screen facing us). to do anything, I need to right click and select (shut down, run, etc)
     
  32. Bluesbreaker

    Bluesbreaker Corporal

    I'm going to reboot now but am attached the log from scannow just in case.

    Thanks for your help Chaslang.
     

    Attached Files:

    • CBS.zip
      File size:
      552 KB
      Views:
      2
  33. Bluesbreaker

    Bluesbreaker Corporal

    Ok rebooted and still no go with the Windows Start menu.

    Also, still getting the error message when I go to open jpegs.
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm still not getting a clear idea of your problem.
    • After you login to Windows 10, does you Desktop appear with all your icons on it?
    • Is the Start Button missing?
    • Or is the Start Button there but does not work when you click on it? As in nothing happens?
    • Or do you mean the Start Button is there button when you open it there are no other icons showing in it?
    • What happens when you press the Windows Logo Key on your keyboard? Normally this pops up the Start Menu.
    • Is the Taskbar present? If yes, are there other icons on it?
    • Was this problem present when you first came here to work on your malware problems or did it start later?
    Start button issues seem to be rather widespread in Windows 10.
     
    Last edited: Mar 1, 2016
    Kestrel13! likes this.
  35. Bluesbreaker

    Bluesbreaker Corporal

    Ok (excuse the all caps) :
    • After you login to Windows 10, does you Desktop appear with all your icons on it? YES
    • Is the Start Button missing? NO
    • Or is the Start Button there but does not work when you click on it? As in nothing happens? START BUTTON IS THERE, NOTHING HAPPENS WHEN YOU CLICK ON IT. OR IN THE SEARCH BAR TO THE RIGHT OF IT.
    • Or do you mean the Start Button is there button when you open it there are no other icons showing in it? START IS THERE, DOES NOTHING
    • What happens when you press the Windows Logo Key on your keyboard? Normally this pops up the Start Menu. NOTHING POPS UP
    • Is the Taskbar present? If yes, are there other icons on it? YES and YES
    • Was this problem present when you first came here to work on your malware problems or did it start later? STARTED AFTER
    I mean, I heard these issues were widespread but they appeared to have hit during the time I was working throught the fix. In fact, around the time that I started getting the windows vbs script error and the black screen. Coincidence? I don't know.
     
  36. Bluesbreaker

    Bluesbreaker Corporal

    theres also the error from the jpgs. for some reason I can't upload a pic....message is: "Cannot import C:\Users\lil-nicky\Desktop\fixME.reg: The specified file is not a registry script. You can only import binary registry files from within the registry editor."
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please try creating a new user account on your PC. Then logout of your original user account ( or reboot ) and then login into your new account and see if the Start Button works in this new account. If it does then reboot your PC and login to your original user account and see if the Start Button now works.
     
    Last edited: Mar 2, 2016
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't understand what you mean about an error with jpgs. Do you mean that your problem is that you cannot upload JPG files here to the forum? Or do you mean that you cannot open them for viewing on your PC?
     
    Kestrel13! likes this.
  39. Bluesbreaker

    Bluesbreaker Corporal

    Ok thanks Chaslang I will try and set up a new user.

    as for the subsequent post, when I try and open a picture, I get that error message, as in windows viewer doesn't work. It even happens when I try and run a movie apparenlty, unless I specifiy an application, like winamp. If I double click on the file, error message. All errors that weren't there prior to me coming here.

    but as Kestrel13! used to say, one thing at a time!
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    fixme.reg is not a JPG. It is a registry patch file. And it has nothing to do with trying to open a JPG. It seems you have your file associations messed up, and you will have to fix them by associating them with the correct applications.

    You can try running the Windows Repair program that you ran way back in message # 22 on Feb 5th, but only select the below option.

    23 - Repair File Associations (12 )

    Then reboot and see if it helped.
     
  41. Bluesbreaker

    Bluesbreaker Corporal

    you're right. sorry for the confusion. that was another error message I'd received. the JPG error message was C\users\lil-nicky\pictures\blackberry-b30E\camera\img_whatever.jpp the app didn't start. however, when I right clicked on the picture, and opened with, say windows photoviewer, no problem, I can see the photo.

    I did create another user, the desktop is there, the toolbar, etc. but the windows start button does not work.

    i will try and run the windows repair option tonight and report back in the am...thanks again for the help, sorry for the bother...
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Had you completely logged out of your original user account before you logged into the new user account?
     
  43. Bluesbreaker

    Bluesbreaker Corporal

    I did sign out and then sign in with the new account. Now in the new profile, on the toolbar, was Store and Edge. I clicked on Store, said there was a problem with store, contact your administrator. Edge tried to open then shut down.

    In fact, when I created the new user, I had to go through ctrl-shift-escape and:
    • Type control userpasswords2 and click OK

    • Click on add under users tab
    and added the user like that. The control panel, user accounts, etc method did not work. It tried to work, the blue wheel spun and then it went back to +add user. no success. but the above way got me there. I will try the repair now...
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is really starting to sound like Windows 10 is very broken. Try going to downloading the below FixWin for Windows 10 tool and see if some of these Microsoft fixes will work for you. There are fixes in there for a damage Store and also for Start Menu problems.

    http://www.majorgeeks.com/files/details/fixwin_for_windows_10.html

    Since I already had you run the System File Checker the other day, you can just skip this recommended step.
     
  45. Bluesbreaker

    Bluesbreaker Corporal

    ok will do. I will try this tomorrow. Incidentally, I ran the fix in 190 above...no go. still the same. I will come back. thanks again.
     
  46. Bluesbreaker

    Bluesbreaker Corporal

    ok so ran the fixwin and tried to fix the store and the start menu...still nada... :(
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well we are quickly approach a point where you may have to do a reinstall of Windows 10 or a repair to the install to see if that can help. Before doing that I want to try restoring a few items from Quarantine folders just to see if it will help. Am not very confident that it will change anything because based on all previous logs, I cannot see anything that removed that could cause all these problems. It seems more like something has broken your Windows installation.

    To that end, I will work up a script to run with FRST and will post it as soon as I can.
     
  48. Bluesbreaker

    Bluesbreaker Corporal

    ok thanks Chaslang...sorry to put you all through this...should I be concurrently searching another fix, take a load off?
     
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Well the only other fixed may be a repair install ( which trys to preserve your current files and just fixes problems ) or a complete reinstall which would wipe everything and start over. Neither of which would be topics for the Malware Forum. One link that contains some info on a repair install is https://neosmart.net/wiki/windows-10-repair-installation/ See the section named Windows 10 repair installation

    Also similar/additional info can be read here: http://www.tenforums.com/tutorials/16397-repair-install-windows-10-place-upgrade.html


    But let's try the below first.

    Download the attached fixlist.txt file found at the bottom of this message and save fixlist.txt on your Desktop. Make sure you save it as a txt file.

    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • Fixlog.txt
    • C:\MGlogs.zip
    Any change to your Start Button problem?
     

    Attached Files:

    Last edited: Mar 5, 2016
  50. Bluesbreaker

    Bluesbreaker Corporal

    Hi - no change!
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds