your read me is not complete...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by apolide, Oct 24, 2004.

  1. apolide

    apolide Private E-2

    Major attitude,
    willing remove an annying "adware.CDT" file that appears in Norton but that NAV can't delete, I found your "read me before posting" on spyware.

    I tried all the various sws (Ad-aware, spywareblaster, etc, etc).

    Then, I decided to follow your intrusctions that happen to be wrong:
    - disabled system restore
    - started in safe mode
    - relaunched the various antivirus, spyware sws

    but now Windows continues rebooting ONLY in safe mode and using F8 to :
    - launch last known configuration or
    - boot in normal mode
    has NO effect and...

    I can't use the properties to restore the system.... becuase I disabled.

    so your solution seems worse than the problem. I can guess why the part of your advice is written in red ("If you have a problem for any reason...) implying that you know there may be some problems but without detailing-anticipating them.

    Now, How can I revert back NORMALLY working PC (even keeping the adware.CDT that until now had no effect) ?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These procedures are used literally thousands of times per week. There is nothing wrong with them. How did you get into safe mode the first time? Did you use msconfig or F8? You may need to run msconfig and check to make sure you are not locked into booting in safe mode.
     
  3. Corporal Punishment

    Corporal Punishment Head of Software Shenanigans Staff Member

    Pointing blame at people trying to help is an interesting tactic. But – lets chalk this up to you’re frustrated.

    Booting in safe mode is a function of the operating system which attempts to load the system with a minimum of supporting files as possible. Booting to it or from it will not effect any operation.

    Something you did either prior to or during the time you were in safe mode, did.

    Whatever you did, if you remember, try to undo it and you should be able to boot. If you can’t you may want to look at Symantec’s manual removal suggestions --- I suspect remnants of your malware problem is the cause.
    http://securityresponse.symantec.com/avcenter/venc/data/adware.cdt.html

    Otherwise you may want to triple scan everything to make sure it is clean and run repair off your cd – but obviously back up your data first.
     
  4. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    As the guys said, it has been used almost 100,000 times and you are the FIRST complaint. Thats a fairly impressive record and thats not a pat on my back, while I wrote the original, Chaslang, Kodo and all the mods here contributed to its fine tuning.

    Please let us know if CP's suggestion does not work and we will get you through it. One sad part about scumware is its ability to take advantage of different Windows features in different ways and your case is simply that.
     
  5. apolide

    apolide Private E-2

    Yes I was frustrated after 4 hours of trials and thoughts on how could it happen.
    I must say I used "safe mode boot" since many years ago (DOS "old times" so this gives you an idea of how old am I). I do know what you mean, it should work and that's why I was mad. It was 2 o clock morning Italian hour. What i didn't like (of your read me) is that, by deactivanting system restore, it's like launching without a parachute...

    I've been using Macs (at home) for many years and had to revert to Win last year for my daughter school needs. This is the first time I tried safe mode back again.

    I did:
    - start safe mode with F8
    - all antivirus sw runs (spywareblaster, spybot, Ad-aware, Norton)
    BTW everything is the same: Norton "sees" the file but can't eliminate, the others don't advice. An it wasn't a big problem since I wasn't receiving any ads. I read around that the file adware.CDT is only a piece, the others are gone so probably it can't work.
    And yes... I read all the Symantec and MS knowledge bases before writing to you...
    - retried F8 (doesn't work with both options: normal mode or last working configuration)
    - tried msconfig with both options: full normal mode or selective by deactivating all with exception of Microsoft and Symantec options.

    always the same, it takes minutes to boot up and is... in safe mode !

    Is there a way to cheat the OS by going low level and switch the right registries telling to boot in normal mode ?

    thanks

    PS: I'm using the old Mac to write this.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  7. apolide

    apolide Private E-2

    Adding more info:
    I tried with msconfig alternating ALL the options of selective boot with no effect.
    It ALWAYS start the same, the changes have NO effect.

    I can see the normal Windows desktop screen launch some applications (adobe reader, adware, etc) but not others (Word starts but doesn't open documents, Hotsync for Palm doesn't work), can't dragndrop, can't copy-paste.
    Almost unusable and strange behavior indeed.

    Re-did virus-adware checks, found nothing (NAV is not working now).

    The system is :
    Intel Pentium 4 at 2.4 Mhz, 224 MB RAM, XP Home SP2 (no problems at all at installation and ever since 3 weeks ago), CDROM and Iomega DVD-writer, ADSL connection, Norton Internet Security.

    Beginning to think a rough reinstall is needed... and it would be the third in one year (2 hardisks gone to hell)... <-(
     
  8. Adrynalyne

    Adrynalyne Guest

    I'm almost willing to bet you have been to msconfig recently.
    Go back to it
    Click on boot.ini tab
    Uncheck ANYTHING checked on this tab.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please post the HJT log I requested below just before you posted.
     
  10. apolide

    apolide Private E-2

    thanks, I'll probably do tomorrow now it's 2 am again... going to bed.
    Probably sending the PC to the shop, I need it fast and this process may take too long.

    BTW we just crossed our messages, read mine that may give you some hint.

    I already tried to read through the Hijackthis log and it seems there's no problem...
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I think maybe you missed my point with using msconfig in message #2. Adrynalyne is pointing this out in a more direct manner. Please double check that you have none of the items on the boot.ini tab checked.
     
  12. apolide

    apolide Private E-2

    Ok, I'll do both (msconfig with only boot.ini and HJT log) this evening (Italian hour) and send to you.
    I'd like to fix within the night (4 hours) otherwise I'll have to bring it to the shop... those young guys are not that experienced or willing to solve they almost always suggest the reisntall of OS from scratch (*§$!)
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re-installation should not be the first thing to try but in some cases it may be necessary.
     
  14. apolide

    apolide Private E-2

    in the BOOT.INI tab there has never anything checked.

    and Ops !
    but the HJT log can't be sent... since I'm without Internet connection.
    I should recopy it by hand on this Mac... with possibility of errors...
    I can't print or can't scan or copy-paste into a floppy...

    anyway I just checked the previous one (before this mess, because the one I see now is much shorter...since some of the services are disabled) and there was nothing to worry. All the items are with known names that I wanted there. It's a quite short (compared to other horrible ones I've seen here around).

    One question: may I try a reinstall from the SP2 CD ?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What services do yo have disabled?

    I'm not sure about the SP2 re-install. SP2 installs have not worked well if there are problems on a PC. However you were already at SP2 so I'm not sure what will happen. I'm not even sure if you can run the install from safe mode boot. I have never tried that.

    Maybe Adrynalyne can shed some light on this if we can get him back here.
     
  16. Adrynalyne

    Adrynalyne Guest

    You can install it from Safe Mode, but you would be wasting your time.

    Open your boot.ini on your C: drive and post the contents here.

    It is a hidden file, so you need to show hidden files and folders.
     
  17. apolide

    apolide Private E-2

    here it is:

    (boot loader)
    timeout=20
    default=multi(0)disk(0)rdisk(0)partition(1)/Windows
    (operating systems)
    multi(0)disk(0)rdisk(0)partition(1)/WINDOWS="Microsoft windows XP Home Edition" /fasdetect /NoExecute=Option

    Note: This is typed by hand on this Mac so the first two slashes are opposite

    I noticed that under Control Panel opening the user the window is... totally blank as if there was no user and there's no Administrator. Is it normal ?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Adryn,

    Is the /NoExecute=Option a problem?
     
  19. Adrynalyne

    Adrynalyne Guest

    Only if Sp2 is not installed on the system.

    Hmmm...how odd.

    Wonder what the event viewer shows?

    For it to boot to SafeMode without errors or prompts, SOMETHING has to be passing a command to Windows during the boot process.

    Is this an AMD64 machine?
     
  20. apolide

    apolide Private E-2

    No it's a Pentium 4, as I wrote.

    Anyway don't bother anymore. I sent it to shop for a scratch reinstall... and will pass this weekend reinstalling and configuring all the applications.... what a joy !

    Still, the big question remains and remained: what kind of command was not taking into consideration ANY of the cahnges I tried with msconfig ????

    For the future I'll be VERY MUCH in doubt about deactivting system recovery.

    Ciao
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what caused your problem but thousands of people are disabling system restore and have no problems doing that every day.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds