Unable to run programs in win 7

Discussion in 'Malware Help (A Specialist Will Reply)' started by jcrubio2001, Jan 19, 2011.

  1. jcrubio2001

    jcrubio2001 Private E-2

    Hi, thank you for the help before hand.
    the pc was been failing before, crashing sometimes, but not often,
    then 2 days ago, i was using photoshop and wow a the same time, the pc crash bsod , but after that i couldn't use it anymore, windows shows up but i can't run anything, i click on them, they seem are going to open up, but nothing, sometimes when a program opens, it fails to and close.
    i ran the test mostly in safe mode.
    after doing the tests that i am attaching i also open the pc and took off the memory cards, and try them in pairs to see if it was a memory problem, but it didn't improve nor got worse.
    i ran 2 more programs after : tdsskiller, windlg, i tried to run mtinst but i am no sure if i have the necessary tools to create a cd. (no sure how to do it)

    thanks for your help
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    As I review your other logs, can you attach the log from TDSSKiller?
     
  3. jcrubio2001

    jcrubio2001 Private E-2

    Hi :) i am using my wife pc to send this info just in case.
    I noticed that in safe mode, programs like real player or firefox work.
    The first day that it happened it showed messages like files are corrupted when i tried to open programs.
    thanks
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am not seeing any malware in those logs. I am going to suggest that you post in the software forum regarding the BSOD's and the fact that some programs will not run. We can finish off here with some miscellaneous clean up:

    Java(TM) 6 Update 22 <--- Uninstall outdated Java.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    SecCenter::
    {BF5CEBDC-F2D3-7540-343C-F0CE11FD6E66}
    {043D0A38-D4E9-7ACE-0E8C-CBBC6A7A24DB}
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    I would like to ask though, can you at least run C:\MGTools.exe in normal mode and attach the C:\MGlogs.zip?
     
  5. jcrubio2001

    jcrubio2001 Private E-2

    Hi, I did the part for Combofix, but i can't uninstall the old java or install the new java, it doesn't allow me in safe mode, and in normal mode, i can open the add/remove programs but once a select the old java and click uninstall, it acts like it is going to do something like preparing to uninstall (a small windows says that is gathering the files needed) but nothing happens (like 20 min, doing nothing).
    When I double click the new java, it doesn't open. (normal mode)

    i tried to run C:\MGTools.exe in normal mode but the same situation with other program, nothing happens. :(

    ty for the help :), i will post in software, I don't have restore point, I trying to get this fix wihtout doing a fresh installation.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try this first

    Run the C:\MGtools\FixFA.bat by double clicking on it.

    Has this done anything to help opening programs? :confused
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we wrap up here just run this:

    GMER - running with a random name and also try and run the below:

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.

    And also

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some data on it
    • Right click on the screen and select > Select All
    • Press Control+C
    • Open a notepad and press Control+V
    • now please ATTACH that report to this thread
     
  8. jcrubio2001

    jcrubio2001 Private E-2

    hi, gmer showed a message at the end saying it didn't find anything, i pressed saved, but i checked the log before sending and it was empty, i ran it twice.
    ty
     

    Attached Files:

  9. jcrubio2001

    jcrubio2001 Private E-2

    Hi :), good news! after trying different things, i noticed that ThreatFire service was always on, even if I uncheck it manually on msconfig, I was trying to see the difference between safe mode and selective startup with all the services and startup disable, just the microsoft services enable (i thought that one of the microsoft services is damage or something )

    I uninstalled the program in safe mode (get error message in normal mode), and the pc worked! i haven't done a lot of tests yet, but programs open, i can access internet , etc

    I don't know why that program failed, (no sure if the real reason, a malware or something is attacking that specific program, i never had a problem before , and i have used it in other pcs).

    Kestrel, thank you for the help, thanks to you, i was able to look to other things in the pc, otherwise i will be thinking is a virus or malware, etc.

    I'll do some more tests today, I noticed i have programs or services on, i don't think i use, i will try to find something here to help clean the pc from software or services, ty again!
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Very glad you are making good progress! :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  11. jcrubio2001

    jcrubio2001 Private E-2

    Hi, I did what u told me to do in the last post, but i lost my internet connection, i remember reading something about it, and how to repair it, but i can't find it, besides that , the pc is working very well
    ty
     
  12. jcrubio2001

    jcrubio2001 Private E-2

    i wanted to update or edit previous post , but i couldn't , i am sorry if this is like bumping.

    i was reading other post in the forum

    i did netsh winsock reset, didn't work
    also i tried SAS to repair network connection, didn't work
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Most welcome. Any outstanding issues can hopefully be resolved in the software forum. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds