Malware and Virus RemovalProblems removing malware/viruses? Get help from our Malware removal experts.
Mission Statement
WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.
Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.
[Resolved] Infected with trojan/virus and windows will not boot anymore
hi and thank you to anyone who is willing to help
I am currently running windows xp pro edition service pack 3 and it was up to date by about the 15th of December.
So i would say about a couple of weeks ago i got hit with the vundo virus and i think some other virus / Trojans. I also noticed that i had tinyproxy.exe installed.
I had been trying to remove the virus / trojans myself which i hope wasn't a mistake.
i was using avg8 free edition with no firewall except the windows one.(i now know that this was a really bad mistake)
so when i first got infected with the virus avg told me about it and said that my pc was infected.i tried to clean it up with a combination of anti-virus tools
i tried ccleaner , windows defender, hijackthis, cleansweep, and i may have used one other but i can not remember it at this time. so long story short nothing was working.i eventually got some help from a friend using a remote assistance program called webex.com and we tried to clean up as much of it as we could by going through the registry. Nothing was working so after countless hours i told him to stop trying and gave it another try on my own.
so i downloaded vundofix and that told me that it did not decect any sign of vundo.i then also tried vundobegone it helped a bit most of the trojan was gone but i was still geting files rewritten when i rebooted like tinyproxy.exe
i had installed maleware bytes and ran it multiple times and still could not completely remove the infections.i also tried to download a firewall/anti virus program called pc tools internet security 2009. I think this program helped stop more of the virus when i was connected to the internet since it kept blocking an ie.tmp program from accessing the internet.
i also had run a symantec security check to at least see what files where still left on my pc but the scan could never be completed and would always crash. the last thing that was happening when i was running the maleware bytes program was that it was telling me that some startup program was infected and that it wanted to delete it after reboot.
Also one thing that i may have jumped ahead on was that i had cleared my system restore points by unchecking and rechecking the box labeled turn off system restore .
I have gotten these errors when trying to boot up:
windows - registry recovery
one of the files contaning the systems registry data had to be recovered by the use of a log or alternate copy.the recovery was successful.
pctsTray.exe application error
the application failed to initialize properly (0xc0000142).click on OK to terminate the application
So the main problem i am having now is that i cant seem to get windows to boot up in either safe mode or in regular mode, what happens in either boot cycle is that it gets to the windows screen loads all the way up to the part when i click to log on as administrator and then goes black for a sec and then says logging off and saving settings.
when i log in in safe mode i can get to the screen where it shows safe mode in the corners and its say what service pack and build i am using but then hangs for a bit and goes back to the login screen .
So i am using a secondary pc to write all my posts and i am willing to reformat my pc if necessary but i would like to see if i can recovery some files on the pc.So if we can not get windows to work properly then i was wondering if i could connect my hard drive to this pc and recovery the files,but i am concerned about getting this pc infected due to the fact that it is not mine .so i do not know what files are safe and if there is a way to prescan them but lets see what we can do with getting windows to start first.
Didn't find the information you thought to find? Check out these Similar Threads
Insert a blank cd into your cd/dvd burner. Browse to C:\Program Files\Microsoft Diagnostics and Recovery Toolset and right click erd50.iso, then select Copy image to CD. Follow the instructions in the following link to finish creating the bootable cd.
Once finished, restart the PC with the cd in the drive and boot to the cd to verify it works properly. If successful, restart the computer but remove the cd upon startup and boot back into normal mode, then post back here to let me know it was successful. I'll post instructions on how to proceed from there.
I just fixed a Gateway for a friend. He had Xp with sp2 and it would get to the screen with the icons and the taskbar, then lock up completely. I ran the installation disk (Gateway disk) for windows and it gave two choices- a clean install or a clean install with backup. I did the latter and backed up the documents and settings to the c drive. After the install I ran McAfee and Spybot on the system and again on the backup. He had over 30 infections. Spybot is free and I think it does a good job.
If you do this don't forget to run windows update, to get security patches and your service packs.
I haven't used a windows disk to reinstall a system in a long time, but its got to be close to the gateway disk.
I'd like to get my hands on one of those Gateway disks, because after quite a number of re-installs with a retail Operating System disc and several OEM discs, I have never seen an option to backup.
I know, windows usually gives the two options, one being repair, but I haven't done a clean install since windows 98.
If you want to follow it further, it was Model: GT 4016, SER: GCM64 110 51252.
Gateway made some changes in June, 2005 on how they provided their system and recovery disks. I don't know how much it would cost, but it should be available.
Boot with the cd and when prompted, connect to the operating system (should show C:\windows).
Once logged on, Click Start>System Tools>System Restore
The System Restore interface should open where you can select to restore the system to an earlier time.
There should be at least one available restore point (one made when you turned System Restore back on).
Select it and restart when prompted, removing the cd upon reboot.
If startup is successful, post back here (before doing anything else) and we'll see about cleaning it up.
If unsuccessful, post back here as well and we'll try some other options.
yay
so the restore worked i used the farthest one back.I will be leaving the infected pc running so that there is hopefully no chance of it not booting up again and i am leaving it off line from the internet until further advised.I would like to mention that when we do get it hooked up to the internet i would like to download a firewall of your choice right away since i do remember that tinyproxy and other programs were sending out connections and i know that windows firewall is only good to stop incoming connections.
Please include the contents of both logs in your next reply. The scan will instruct you to post the attach log as an attachment. No need for that though ..... just post it as you would any other log.
DDS (Ver_09-01-07.01) - NTFSx86
Run by ryan at 1:55:41.20 on Sun 01/11/2009
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_07
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.292 [GMT -5:00]
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-01-07.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 10/17/2004 11:51:29 PM
System Uptime: 1/11/2009 1:32:19 AM (0 hours ago)
A: is Removable
C: is FIXED (NTFS) - 128 GiB total, 16.947 GiB free.
D: is CDROM ()
E: is Removable
F: is Removable
G: is Removable
H: is CDROM ()
I: is CDROM ()
J: is Removable
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP1058: 12/22/2008 5:54:46 PM - System Checkpoint
RP1059: 12/23/2008 5:58:21 PM - System Checkpoint
RP1060: 12/24/2008 2:35:03 AM - Removed Ad-Aware
RP1061: 12/27/2008 11:12:21 AM - Software Distribution Service 3.0
RP1062: 12/27/2008 11:16:41 AM - Windows Defender Checkpoint
RP1063: 12/27/2008 12:29:15 PM - Software Distribution Service 3.0
==== Installed Programs ======================
Ad-Aware
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Reader 7.0.9
Apple Software Update
ArcSoft PhotoImpression
ArcSoft VideoImpression 1.6
Azureus
BitComet 1.06
BitTorrent 3.4.2
Bonjour
C-Media WDM Audio Driver
CCleaner (remove only)
D-Link CIF Webcam
Direct Show Ogg Vorbis Filter (remove only)
DVD Solution
EncFlac 1.1.2
EncVorbis 1.1
FinePixViewer Ver.4.3
FUJIFILM USB Driver
GetDiz 3.0
Half-Life
HijackThis 1.99.1
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
InCD
InFlac 1.1.1
InterActual Player
iTunes
J2SE Runtime Environment 5.0 Update 1
J2SE Runtime Environment 5.0 Update 6
J2SE Runtime Environment 5.0 Update 9
Java 2 Runtime Environment Standard Edition v1.3.1_04
Java(TM) 6 Update 3
Java(TM) 6 Update 5
Java(TM) 6 Update 7
Java(TM) SE Runtime Environment 6 Update 1
Macromedia Shockwave Player
Malwarebytes' Anti-Malware
Matroska Pack (remove only)
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
mIRC
Mozilla Firefox (3.0.4)
Multimedia Launcher
Nero OEM
Net MD Simple Burner
NVIDIA Drivers
Panda ActiveScan
PowerDVD
PowerProducer
QuickTime
RealPlayer
Scorched3D 40.1d
Security Update for CAPICOM (KB931906)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Sierra Utilities
Skype™ 3.8
Steam
TeamSpeak 2 RC2
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Ventrilo Client
VideoLAN VLC media player 0.8.4a
VobSub v2.23 (Remove Only)
WebEx
WebFldrs XP
Winamp (remove only)
Windows Defender
Windows Defender Signatures
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Live installer
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WinRamTurbo Free 2.6
WinRAR archiver
Yahoo! Address AutoComplete
Yahoo! Internet Mail
Yahoo! Messenger
==== Event Viewer Messages From Past Week ========
1/8/2009 5:49:14 PM, error: Service Control Manager [7026] - The following boot-start or
system-start driver(s) failed to load: SAVRTPEL
1/8/2009 5:49:07 PM, error: Service Control Manager [7028] - The 994D46E4DC061202
Registry key denied access to SYSTEM account programs so the Service Control Manager took
ownership of the Registry key.
1/8/2009 5:49:07 PM, error: Service Control Manager [7028] - The Cfg Registry key denied
access to SYSTEM account programs so the Service Control Manager took ownership of the
Registry key.
1/8/2009 5:45:44 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the
service EventSystem with arguments "" in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}
1/8/2009 5:41:29 PM, error: Service Control Manager [7000] - The PC Tools Security Service
service failed to start due to the following error: The service did not respond to the start or control
request in a timely fashion.
1/8/2009 5:41:29 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds)
waiting for the PC Tools Security Service service to connect.
1/8/2009 5:39:30 PM, error: Service Control Manager [7026] - The following boot-start or
system-start driver(s) failed to load: AmdK7 eeCtrl Fips SAVRTPEL
1/8/2009 5:29:14 PM, error: Service Control Manager [7034] - The PC Tools Security Service
service terminated unexpectedly. It has done this 1 time(s).
1/8/2009 5:29:14 PM, error: Service Control Manager [7022] - The PC Tools Security Service
service hung on starting.
1/8/2009 5:23:06 PM, error: Ntfs [55] - The file system structure on the disk is corrupt and
unusable. Please run the chkdsk utility on the volume C:.
1/8/2009 5:13:36 PM, error: Service Control Manager [7022] - The Windows Image Acquisition
(WIA) service hung on starting.
1/11/2009 1:32:46 AM, error: WinDefend [2004] - Windows Defender has encountered an error
trying to load signatures and will attempt reverting back to a known-good set of signatures.
Signatures Attempted: Current Error Code: 0x8050a001 Error description: The
program can't find definition files that help detect unwanted software. Check for updates to the
definition files, and then try again. For information on installing updates, see Help and Support.
Download ComboFix by sUBs from here, saving the file to your desktop.
Disable realtime protection applications as they sometimes interfere with the tool. Check this link for your applicable programs.
Close all open programs and windows
Double click ComboFix.exe and follow the prompts.
It may reboot your computer and resume running when you logon. Wait for it to complete. When finished, it will open a log for you. Post that log in your next reply.
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
**NOTE - I recommend you allow the Recovery Console to be downloaded and installed if or when prompted.
ComboFix 09-01-10.02 - ryan 2009-01-11 2:47:47.2 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.368 [GMT -5:00]
Running from: c:\documents and settings\ryan\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_TDSSSERV.SYS
-------\Legacy_TDSSSERV.SYS
-------\Service_MSQPDXSERV.SYS
-------\Legacy_LOGICAL_DISK_MANAGER_(DMSERVER)_
-------\Legacy_PLUG_AND_PLAY_(PLUGPLAY)_
-------\Service_Logical Disk Manager (dmserver)
-------\Service_Plug and Play (PlugPlay)
((((((((((((((((((((((((( Files Created from 2008-12-11 to 2009-01-11 )))))))))))))))))))))))))))))))
.