Ok Majorgeeks Steps Are Done, What Next?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by brookesharley, Nov 28, 2004.

  1. brookesharley

    brookesharley Private E-2

    G'day, I did all the Majors steps like a good girl!

    Problems are
    Strange happenings. Startup always gives the list of choices...ie normal or safe mode etc. Also seems like it starts with different configurations. (I dont understand this stuff but am intelligent enough to learn)
    Not working or intermittant and no conflicts or error messages, printer, floppy drive and CD Rom drive. Help doesnt work fully, not all the help pages open. Lots of inconsistencies. Stuff works sometimes and not others. (Can this be due to a virus?)
    I lost my display settings and I made the mistake of re-installing Windows in Safe mode! It took me ages but I finally fixed the display with ATI. Trouble is I dont fully understand how I fixed it. I just feel that something is really strange with my PC.

    Windows 98 4.10.222 A
    Upgrade using Select CD /SrcDir=C:\WIN98/IQ?U:xxxxxxxxxxxxxxxxx
    IE 56.0.2800.1106
    GenuineIntel x86 Family 6 Model 8 Stepping 3 Intel MMX (TM) Technology
    64 MB RAM 49% system resources free
    Windows-managed swap file on drice C (4248MB free)
    Available space on drive C: 4248 of 9756MB (FAT32)
    Dial-up-connection
    I have AVG, Spybot, Ad-Aware

    Before I did your steps
    PCPitstop
    Result
    No problems other than need more memory and more internet protection

    Panda Active Scan
    Result
    Virus trj\Downloader.GK

    MajorGeeks steps

    HouseCall
    Result
    Virus Joke Flipped
    unzipped\badday\Bad_Day.exe

    Symantec
    Result
    Virus Trojan ByteVerify
    windows.jpi.cache\jar\1.0\count.jar-55150581-4c72abc5.zip
    windows.jpi.cache\jar\1.0\ohh.jar-3965ca49-5085ef8f.zip

    In safe mode

    McAffee Stinger
    Result
    WINDOWS\SYSTEM\sci1.dll
    W32\SirCam.dat
    WINDOWS\SYSTEM\scd.dll
    W32\SirCam.dat
    DELETED both

    Ad-aware
    Result
    Fixed 25

    SpyBot
    Result
    Fixed 54

    CWShredder
    Clean

    CCleaner
    Done


    Kill2me
    Done

    TestCPU
    Done

    About Buster
    Done Twice

    Then I repeated

    HouseCall
    No Infections

    Symantec
    Found 2 Trojan ByteVerify again

    Then

    Trojan Scanner
    No Infections

    HijackThis
    Attached
    I tried to read this but it wont let me open it....says it needs Netscape to open.......when i locate Netcape for it it still doesnt open so I hope you can open it.....otherwise i will re-do it with my internet explorer shut and save it in word

    Many thanks
    Carolyn
     

    Attached Files:

  2. brookesharley

    brookesharley Private E-2

    Re: G'day, I did all the Majors steps like a good girl!

    Reply to myself with my log

    EDIT by chaslang: Please do not post inline HJT logs. And we only need the text version not a .doc version. HJT log changed to an attachment.
     

    Attached Files:

    Last edited by a moderator: Nov 28, 2004
  3. brookesharley

    brookesharley Private E-2

    Re: G'day, I did all the Majors steps like a good girl!

    Reply to myself again

    I forgot to say that I did install SpyBlaster as well!

    Carolyn
     
  4. PhilliePhan

    PhilliePhan Guest

    Re: G'day, I did all the Majors steps like a good girl!

    Hi Carolyn,

    So, your machine never boots normally?

    I am not seeing anything jumping out at me from the log you posted, but I only had time for a quick glance and I don't see so many Windows 98 machines these days.
    I am leaving a message for our resident genius, Chaslang, to take a look as I am a bit overextended right now. Hang in there :) One of us WILL get back to you.

    Best :)
    PP
     
  5. brookesharley

    brookesharley Private E-2

    I have done all the MajorGeeks steps see below
    Problems are
    Strange happenings. Startup always gives the list of choices...ie normal or safe mode etc. Also seems like it starts with different configurations. (I dont understand this stuff but am intelligent enough to learn)
    Not working or intermittant and no conflicts or error messages, printer, floppy drive and CD Rom drive. Help doesnt work fully, not all the help pages open. Lots of inconsistencies. Stuff works sometimes and not others. Paths to programs are weird….like sometimes the desktop icons wont open but a window opens with a different program saying it cant find program ie I clicked on icon for shortcut to My Documents and window opened tell my it couldn’t find my dial up window, which I hadnt asked for! (Can all this be due to a virus?)
    I lost my display settings and I made the mistake of re-installing Windows in Safe mode! It took me ages but I finally fixed the display with ATI. Trouble is I dont fully understand how I fixed it. I just feel that something is really strange with my PC.

    Windows 98 4.10.222 A
    Upgrade using Select CD /SrcDir=C:\WIN98/IQ?U:xxxxxxxxxxxxxxxxx
    IE 56.0.2800.1106
    GenuineIntel x86 Family 6 Model 8 Stepping 3 Intel MMX (TM) Technology
    64 MB RAM 49% system resources free
    Windows-managed swap file on drice C (4248MB free)
    Available space on drive C: 4248 of 9756MB (FAT32)
    Dial-up-connection
    I have AVG, Spybot, Ad-Aware

    Before I did your steps I did this

    PCPitstop
    Result
    No problems other than need more memory and more internet protection

    Panda Active Scan
    Result
    Virus trj\Downloader.GK

    MajorGeeks steps

    SpywareBlaster
    Installed

    HouseCall
    Result
    Virus Joke Flipped
    unzipped\badday\Bad_Day.exe

    Symantec
    Result
    Virus Trojan ByteVerify
    windows.jpi.cache\jar\1.0\count.jar-55150581-4c72abc5.zip
    windows.jpi.cache\jar\1.0\ohh.jar-3965ca49-5085ef8f.zip

    In safe mode

    McAffee Stinger
    Result
    WINDOWS\SYSTEM\sci1.dll
    W32\SirCam.dat
    WINDOWS\SYSTEM\scd.dll
    W32\SirCam.dat
    DELETED both

    Ad-aware
    Result
    Fixed 25

    SpyBot
    Result
    Fixed 54

    CWShredder
    Clean

    CCleaner
    Done


    Kill2me
    Done

    TestCPU
    Done

    About Buster
    Done Twice

    Then I repeated

    HouseCall
    No Infections

    Symantec
    Found 2 Trojan ByteVerify again

    Then

    Trojan Scanner
    No Infections

    HijackThis
    Attached as a word document


    Many thanks
    Carolyn
     

    Attached Files:

  6. PhilliePhan

    PhilliePhan Guest

    Hi Carolyn,

    Please be patient as there are only 2 of us who volunteer our time in this forum on a regular basis. :) I will merge your threads together.

    Hang in there :)
    PP
     
    Last edited by a moderator: Nov 28, 2004
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  8. brookesharley

    brookesharley Private E-2

    Ok I did sfc........it said setupx.dll may be corrupted, so I did restore from win 98......i dont have a disk so it did it from my PC.
    You asked
    Are you using msconfig to do a selective Startup or a boot did you Enable boot to Start Menu? Go here and check the options for you Win98 system.
    I dont fully understand this. I am going to start in dos and have a look.


    PhilliePhan and Chaslang
    Sorry I didnt mean to post twice, I thought that the first one didnt work. I do appreciate any help that you guys are able to give people like me. I am ok with computers but I dont understand a lot of how it works. I do seem to have freed my pc of virus's now. I am running system file checker to see what happens. This is the kind of advice I need cos I dont know about these things.

    You are MUCH APPRECIATED

    Carolyn
     
  9. PhilliePhan

    PhilliePhan Guest

    You said, "Startup always gives the list of choices...ie normal or safe mode etc" - That is selective startup. You can find the settings via Start > Run > type msconfig
    No biggie :) There are really only a few of us who respond regularly in this forum, so patience is needed. I know this can be difficult when you have a frustrating problem like this.

    I am not familiar with Windows 98 machines & wouldn't know the proper questions to ask to help you in a timely manner. Chas is far more knowledgeable than I. So, you are in good hands - We both may learn something ;)

    PP
     
  10. brookesharley

    brookesharley Private E-2

    PP Thanks for your words.
    Chaslang
    Ok I have done some investigating today and have come up with some perplexing problems.
    I hope that too much info isnt too much!

    Tried to run misconfig at start run
    Error message said
    Cannot find the file misconfig (or one of its components). Make sure the path and the filename are correct and that the required libraries are available

    So tried to run sfc again
    It ran and told me setupx.dll may be corrupted.
    Then it went through the process of restoring it but an illegal operation for sfc came up.

    I tried to run sfc several times……and in safe mode as well
    Same result

    Then I tried to run misconfig again and it worked.
    It was not set to start in normal.
    It was not set at start in diagnostic.
    t was in selective startup

    I changed misconfig to Normal.
    When it restarted it opened only a black screen with messages that I had
    Duplicate devices in system ini files
    Vmouse,vcd,int13,vkd
    I had to enter after each and then it gave me a blue screen with an error message
    Device BUSTHELP not initialising
    I ok and then it shut down

    It then restarted in safemode
    I changed the misconfig back to selective and restarted
    (I dont really understand the functions in all the tabs in there)


    When it restarted it came up with the display settings all gone and just in 16 colours. The Windows 98 music started and the window came up just like when you first start Windows for the first time.

    I said Oh F***k lol :rolleyes:

    I tried all sorts of stuff to get it to be normal again.

    Then I went into DOS
    I did scanreg/restore and selected yesterdays date
    And thank heavens it worked! Pc came back to working condition

    It wont go back into misconfig again now and it wont run sfc properly

    So maybe the problem lies with these duplicate device files that it finds when it tries to start in normal config. I couldn’t actually find the file names that it said…here they are again

    Duplicate device System ini files

    Vmouse, vcd, int13, vkd
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's msconfig not misconfig.

    Are you sure the message you got said Device BUSTHELP not initialising ?

    Make a note of which items in msconfig, Startup tab have no check marks on them and post it back here.

    Are you still booting up to the menu to select Safe mode or normal mode?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Last edited: Nov 30, 2004
  13. brookesharley

    brookesharley Private E-2

    Chaslang
    The continuing saga or challenge?
    Thanks for helping

    Are you still booting up to the menu to select Safe mode or normal mode?
    Yes I am

    It's msconfig not misconfig.
    Youre right....my typos and nervousness.

    I have attached a screen shot of the system config utility so that you can see what is happening. Hope this helps you.

    Are you sure the message you got said Device BUSTHELP not initialising ?

    Yes. I did a search for the word BUSTHELP in file search and this is what I found in an sfc log
    BustHelp.vxd Added 10/13/200
    Could it be related to an old virus buster?
     

    Attached Files:

  14. brookesharley

    brookesharley Private E-2

    P.S
    Thanks for the link to the reading.
    Carolyn
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Carolyn,

    Let's start with trying to fix the startup menu problem.

    On that same screen of msconfig you posted the snapshot of, click the Advanced button. Then look in the list of options that appear. You will see an option titled "Enable Startup Menu". Make sure you uncheck it. That is most likely the problem. Now reboot and let me know if this problem is resolved.

    Now after reboot. Run msconfig again and click the Startup tab. Post me a snapshot of that.
     
  16. brookesharley

    brookesharley Private E-2

    Yes that is unchecked and has been the whole time. That is weird isnt it.
    Carolyn
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try checking it then. Now reboot. I assume you will get the start menu.
    After reboot, uncheck it. And reboot again. Let me know what happens.

    If this does not work, there could be something in your boot.ini file causing this. I have not look at that file for some time but I think an option in there could do this too.
     
  18. brookesharley

    brookesharley Private E-2

    Ok did that and it worked!
    Carolyn
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so now we no longer have a problem with getting the Start up menu at boot time? Right?

    Are we having other problems still?
     
  20. brookesharley

    brookesharley Private E-2

    Yeah

    Printer
    CDROM
    Floppy Drive

    and still wont start in normal config...only selected.

    But at least we got rid of the virus

    Carolyn lol
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In message #15 I asked:

    "Now after reboot. Run msconfig again and click the Startup tab. Post me a snapshot of that."

    Your Printer, CDROM, and Floppy Drive never work or work sometimes? Tell me which for each.

    Do they work okay in safe mode?
     
  22. brookesharley

    brookesharley Private E-2

    Ok attached is a screen shot of the Start up tab (notice the checked mark on an invisible item near the top?) and also a look at the hardware profile....note there is no printer there.

    I got the cd rom and the floppy working. They were working intermittently but are now working consistently today.

    However the printer is still acting like it is working....no error messages.......says it is printing and there is no printer visible in the device hardware profile. I tried deleting all the software for the printer and went to epson and downloaded the software again and installed the hardware. But still no go.

    Could the fact that it wont startup in normal (only selective) without telling me that I have the duplicate files and to delete them........is this related to the printer problems?

    printer is
    Epson stylus color 600

    Many thanks for your help so far.
    Carolyn
     

    Attached Files:

  23. brookesharley

    brookesharley Private E-2

    Chaslang

    I have moved my enquiry over to the Harware section. Thanks for you help, it is really really appreciated as I know you all do this on you own time. If you think of anything just let me know.

    Carolyn
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try not only uninstalling the printer software but you should delete the printer from your list of printers. The reboot your system and Add the printer back in.

    Your Startup list has a lot of duplicates. This happens when using msconfig to control startups. It is not a good way to do it. A startup manager program should be used. I have to think about this a little to see how we can clean that list up. In the mean time, see if you can get both your win.ini and system.ini files into a ZIP file and upload them here as an attachment.

    I don't like the looks of the c:\windows\welcome.exe file either. Is that really on your PC?

    I forget whether we discussed this or not but have you gone to Windows Update and installed all the updates for your system?
     
  25. brookesharley

    brookesharley Private E-2

    Chaslang

    Yes c:\windows\welcome.exe this is there. I did a search and found it. The whole windows 98 is on my pc not on a disk C:\win98 (as shown in attachment)

    see if you can get both your win.ini and system.ini files into a ZIP file and upload them here as an attachment.

    Can u tell me how to find these files? win.ini system.ini I cant seem to find them anywhere.
    Remember I am a good learner but my knowledge is limited.

    and Yes I have done all the updates for windows.
    Thanks
    Carolyn
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Both win.ini and system.ini should be in your Windows folder. So for you, they should be in c:\win98

    You should located that welcome.exe file using Windows Explorer and right click on it. Select Properties and then click the Version tab (if it has one). Then scroll thru all the item names and get Company, Version, etc info on this file.
     
  27. brookesharley

    brookesharley Private E-2

    Ok now this is weird....I cant find win.ini or system.ini files anywhere........I tried to find them before my last post and when u confirmed that I was looking in the right place I looked again. I also did a start find search but all I got was one of those little certificate icons with the yellow on it.
    I have attached a file with what it looks like in Windows Explorer.
    I am not sure what should be in there maybe you can have a look and see what might be odd.
    Regards
    Carolyn in Australia quite a different timezone
     

    Attached Files:

  28. brookesharley

    brookesharley Private E-2

    Second attachment
    Regards
    Carolyn
     

    Attached Files:

  29. brookesharley

    brookesharley Private E-2

    I was reading that win.ini and sys ini are in here as backups.
    C:\WINDOWS\SYSBCKUP\rb000.cab
    I have taken a screen shot for you. There are those icons i was talking about with the yellow in the other post.
    Carolyn
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I misunderstood you before. The Win98 directory is just a copy of your CD. You need to look for the files in c:\windows (make sure you don't go to c:\windows\system as in your attachment. That's the wrong folder.)
     
  31. brookesharley

    brookesharley Private E-2

    I just cant find them in windows. When I open up windows on windows explorer, should they be in a folder named win.ini and sys.ini or ini cos they arent anywhere. I have opened every single folder and I cant find them. I have it set to show all folders
    What am I doing wrong?
    Carolyn
     
  32. brookesharley

    brookesharley Private E-2

    Check out the attached zip and let me know if this is them?
    Carolyn
     

    Attached Files:

  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well the answer is yes and no. It is system.ini and win.ini but they should not normally have all those commented out line with tshoot on them.

    Where did yo find these?
     
  34. brookesharley

    brookesharley Private E-2

    These were in the Windows folder. I have no idea what is meant to be in there ?
    Carolyn
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds