XP IE8 - Major Issues

Discussion in 'Malware Help (A Specialist Will Reply)' started by capparella, Apr 3, 2011.

  1. capparella

    capparella Private E-2

    I am unable to open IE8, Adaware, AVG, Combo Fix, Malwarebytes, Combo Fix, or CC Cleaner. A dialogue box opens to have me select which program to open it with. When I select a program to open it with, it asks me to run the program and cycles through over and over again. I tried opening up control panel to add and remove programs and it states Application not found. Please let me know what I should try next.
     
  2. capparella

    capparella Private E-2

    I tried to start in safe mode and the blue screen came that a problem has been detected and windows needs to shut down
    stop: 0x0000007B (0xF78D2524,0XC0000034,0X00000000,0X00000000)
     
  3. capparella

    capparella Private E-2

    before I rebooted for the first time, The XP warning flashed up about my firewall not being connected and that it had detected a virus that infected the computer. I quickly ran Ad-aware and it delted some cookies but that was it. Now that I rebooted, I cannot open and .exe files and IE will not open either.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download RogueKiller.exe and save it to your desktop.
    • Now quit all running programs.
    • Double click RogueKiller.exe to run it.
    • When prompted, type 1 and hit Enter.
    • A RKreport.txt should appear on your desktop.
    • Note: If the program is blocked, do not hesitate to try several times. If it really does not work (it could happen), rename it to teal.com
    • Please post the contents of the RKreport.txt in your next Reply.

    Then see if you can start working your way through the below.

    READ & RUN ME FIRST. Malware Removal Guide
     
  5. capparella

    capparella Private E-2

    I am running through the READ & RUN ME FIRST in safe mode now. Up to combo fix. There were no threats from super anti spy , and 3 from Malwarebytes. I attched the logs from RogueKiller after installing it in normal mode.
     

    Attached Files:

  6. capparella

    capparella Private E-2

    I am still unable to do add/remove programs from control panel, and ie8 is still not coming up. It says there are connection problems and when I try to diagnose problems, nothing happens. I attached all of the logs. All of the programs were run in safe mode. When going through combo fix, it kept stating Ad-aware was still detected but I thouroughly uninstalled it from add/remove programs and deleted all of the lavasoft folders in the c: drive.
     

    Attached Files:

  7. capparella

    capparella Private E-2

    should i try and redo all of the scans in normal mode now?
     

    Attached Files:

  8. capparella

    capparella Private E-2

    I re-installed ie8 and I can get that to work but in order for me to get any programs to exectue I have to right click, run as, and then uncheck the protect my computer and data from unauthorized program activity. Any ideas?
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I need my sleep soon but try this and let me know if it makes a difference.

    Run C:\MGtools\FixFA.bat by double clicking on it. The reboot the PC.

    I will review your logs tomorrow. :)
     
  10. capparella

    capparella Private E-2

    I all of the read and run 1st in normal mode and here are the logs. I tried the MGTools\FixFA.bat but I am not sure anything happened. A small black screen popped up and disapeared before I could see anything. I can see the add /remove programs, and all the other programs seem to be functioning. I thought I had fully uninstalled AVG but when I ran Combo Fix it said it was still there but I could not find it anywhere on the computer. Is there anyway to make sure there still isn't anything on this computer?
     

    Attached Files:

  11. capparella

    capparella Private E-2

    i will wait to hear from you before i reinstall ad-aware and avg again
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Important Notice: A new version of SUPERAntiSpyware is available.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later.

    Uninstall the below outdated Java

    • J2SE Runtime Environment 5.0 Update 6
    • Java(TM) 6 Update 16

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    • O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    • O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
    • O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
    • O15 - Trusted Zone: http://*.facebook.com
    • O15 - Trusted Zone: http://www.nickjr.com
    • O15 - Trusted Zone: http://*.pbskids.org

    After clicking Fix exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    c:\windows\system32\CF30856.exe
    c:\windows\system32\CF30493.exe
    C:\Documents and Settings\Jen\Local Settings\Application Data\e6d571031he03p0h7blm0cx
    C:\Documents and Settings\All Users\Application Data\e6d571031he03p0h7blm0cx
    C:\Documents and Settings\Jen\Templates\e6d571031he03p0h7blm0cx
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\NoExplorer]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  13. capparella

    capparella Private E-2

    When I have been running combofix it tells me Ad-aware and AVG are still running, but I fully uninstalled them and don't see a location anywhere to totally delete them from the computer.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just carry on for now we are almost done anyway.
     
  15. capparella

    capparella Private E-2

    Everything went through fine. Combo fix did say something about AVG but I ran it anyway. Everything seems fine. Should I reload Ad-aware and AVG now?
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, those logs look good now.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  17. capparella

    capparella Private E-2

    everything seems fine now, thanks so much for your help!:drool
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem. Safe surfing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds