1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive Antivirus.net

Discussion in 'Malware and Virus Removal Archive' started by GRAHAM WESTON, 2011/02/09.

  1. 2011/02/11
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Possibly just some leftovers.
    We'll remove them manually.
    Hold on there...
     
  2. 2011/02/11
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    1. Update your Java version here: http://www.java.com/en/download/installed.jsp

    Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

    2. Now, we need to remove old Java version and its remnants...

    Download JavaRa to your desktop and unzip it to its own folder
    • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
    • Accept any prompts.

    ================================================================

    Run OTL
    • Under the [color= "#0000FF"]Custom Scans/Fixes[/color] box at the bottom, paste in the following

      Code:
      :OTL
      MOD - [2011/01/13 18:47:35 | 000,189,728 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\snxhk.dll
      SRV - [2010/03/15 11:50:36 | 001,142,224 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\pctsSvc.exe -- (sdCoreService)
      SRV - [2010/03/11 11:09:22 | 000,366,840 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\pctsAuxs.exe -- (sdAuxService)
      PRC - [2009/02/25 19:18:14 | 000,425,080 | ---- | M] (Emsi Software GmbH) -- C:\Program Files\a-squared Free\a2service.exe
      SRV - [2010/01/22 08:56:24 | 000,112,592 | ---- | M] (Threat Expert Ltd.) [Auto | Running] -- C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe -- (Browser Defender Update Service)
      SRV - [2009/02/25 19:18:14 | 000,425,080 | ---- | M] (Emsi Software GmbH) [Auto | Running] -- C:\Program Files\a-squared Free\a2service.exe -- (a2free)
      DRV - File not found [Kernel | Unknown | Running] -- -- (aswTdi)
      DRV - File not found [Kernel | Unknown | Running] -- -- (aswSP)
      DRV - File not found [Kernel | Unknown | Running] -- -- (aswRdr)
      DRV - File not found [File_System | Unknown | Running] -- -- (aswMon2)
      DRV - File not found [File_System | Unknown | Running] -- -- (aswFsBlk)
      DRV - File not found [Kernel | Unknown | Running] -- -- (Aavmker4)
      DRV - [2010/03/29 10:06:14 | 000,218,592 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\PCTCore.sys -- (PCTCore)
      IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
      IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
      IE - HKU\S-1-5-21-1692841710-2068341944-2074956095-1005\..\URLSearchHook: - Reg Error: Key error. File not found
      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
      O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
      O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
      O3 - HKU\S-1-5-21-1692841710-2068341944-2074956095-1005\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
      O15 - HKU\S-1-5-21-1692841710-2068341944-2074956095-1005\..Trusted Domains: localhost ([]http in Local intranet)
      O15 - HKU\S-1-5-21-1692841710-2068341944-2074956095-1005\..Trusted Ranges: GD ([http] in Local intranet)
      O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} http://download.ebay.com/turbo_lister/AU/install.cab (Reg Error: Key error.)
      O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
      [2011/02/10 01:36:34 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Uvoyihu.bin
      [2011/01/25 10:18:00 | 000,000,272 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\~XXGD2bSitG6N
      [2011/01/25 10:18:00 | 000,000,160 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\~XXGD2bSitG6Nr
      [2011/01/24 21:48:46 | 000,000,336 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\XXGD2bSitG6N
      [2011/01/24 21:23:45 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Inidagoga.dat
      [2010/05/01 11:20:34 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLdu.DAT
      [2010/02/17 23:36:02 | 000,000,000 | -HS- | C] () -- C:\Documents and Settings\Peter\Local Settings\Application Data\j63L22
      @Alternate Data Stream - 204 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
      @Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
      
      :Services
      
      :Reg
      
      :Files
      C:\Program Files\Alwil Software
      C:\Program Files\Spyware Doctor
      C:\Program Files\a-squared Free
      
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [Reboot]
      
    • Then click the [color= "#FF0000"]Run Fix[/color] button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.

    ===============================================================

    Last scans...

    1. Download Security Check from HERE, and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

      NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.


    2. Download Temp File Cleaner (TFC)
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.


    3. Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • IMPORTANT! UN-check Remove found threats
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • NOTE. If Eset won't find any threats, it won't produce any log.
     

  3. to hide this advert.

  4. 2011/02/12
    GRAHAM WESTON

    GRAHAM WESTON Well-Known Member Thread Starter

    Joined:
    2002/07/30
    Messages:
    371
    Likes Received:
    0
    Broni,
    I have run into a problem. I ran OTL with the code pasted as requested, it asked for a reboot when the scan was completed, and thats when the trouble started. When it rebooted, we get an ASUS screen up first, then a Select System screen, ( Windows XP or Recovery Console ), then it attempts to load windows. We get as far as the 1 st little blue square on the loading bar, the screen then flashes blue, with some text on it, then it goes back to the ASUS start up screen again, it's in an endless reboot loop. The blue screen that fllashes up is to quick to read the text that is on it. I think we have a problem. :)
     
  5. 2011/02/12
    GRAHAM WESTON

    GRAHAM WESTON Well-Known Member Thread Starter

    Joined:
    2002/07/30
    Messages:
    371
    Likes Received:
    0
    Broni,
    I recorded the screen with my HD camera at 300 fps, and played it bach to see what the text is. It is the normal text that comes up with a blue screen, problem detected so shutting down unit, run chdsk, the usual speil, and the tech info reads as follows.
    stop : 0x0000007B ( 0xBA4CF524 , 0xC0000034, 0x0000

    I hope this gives u some idea of the problem.

    Cheers
    Graham
     
  6. 2011/02/12
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    OTL created restore point, so try "Last known good configuration ".
     
  7. 2011/02/12
    GRAHAM WESTON

    GRAHAM WESTON Well-Known Member Thread Starter

    Joined:
    2002/07/30
    Messages:
    371
    Likes Received:
    0
    Tried that, still the same. ?
     
  8. 2011/02/12
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Did you try different restore points?
    Do you have Windows XP CD?
     
  9. 2011/02/12
    GRAHAM WESTON

    GRAHAM WESTON Well-Known Member Thread Starter

    Joined:
    2002/07/30
    Messages:
    371
    Likes Received:
    0
    Broni,
    At post, gone f8, last known good config, blue screen , tried all safe modes, starts to load, blue screen. I have an XP cd, but not the original that is on this laptop.

    cheers
    Graham.
     
  10. 2011/02/12
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    What do you mean?
     
  11. 2011/02/12
    GRAHAM WESTON

    GRAHAM WESTON Well-Known Member Thread Starter

    Joined:
    2002/07/30
    Messages:
    371
    Likes Received:
    0
    I have an XP PRO cd of mine here, but I do not have the original CD for the XP PRO that is installed on this laptop.
     
    Last edited: 2011/02/12
  12. 2011/02/12
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I still don't understand.
    As far, as I can see, you have XP Pro installed, so what do you mean by not having XP CD?
     
  13. 2011/02/12
    GRAHAM WESTON

    GRAHAM WESTON Well-Known Member Thread Starter

    Joined:
    2002/07/30
    Messages:
    371
    Likes Received:
    0
    Broni, i have a copy of XP Pro , which is installed on my old laptop. This laptop ( the one we are working on )does not belong to me, it is my friends laptop. I do not have his copy of XP Pro which is installed on this machine. I mentioned this because i do not know if we can use my copy of XP Pro to repair the installation on his laptop. Sorry for all the confusion .

    Graham
     
  14. 2011/02/12
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I see now, what you're saying.
    All XP CDs are equal, as long, as it's full version CD, not some reinstallation CD, which came with your computer.
    What does the CD say?
     
  15. 2011/02/12
    GRAHAM WESTON

    GRAHAM WESTON Well-Known Member Thread Starter

    Joined:
    2002/07/30
    Messages:
    371
    Likes Received:
    0
    Broni,
    I have started the XP repair as described in the web page u supplied, but it has now stalled. We are getting a message up, "File nvenetfd.inf on Nvida network bus installation disk # 1 is needed ", and it will not go any further. The mouse pad is inoperative, so i cannot clear this message. Where to now. ?

    Cheers
    Graham.
     
  16. 2011/02/12
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Arrow keys won't work?
     
  17. 2011/02/13
    GRAHAM WESTON

    GRAHAM WESTON Well-Known Member Thread Starter

    Joined:
    2002/07/30
    Messages:
    371
    Likes Received:
    0
    No, thats the second thing i tried after the mousepad, oh joy. This is being a pain in the Axxx. Should i just shut it down and try again, suggestions please , but be nice !!!

    cheers.
     
  18. 2011/02/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Going to bed, but if you have some time.....

    If you have Windows CD...(if you don't have Windows CD, scroll down)

    1. Insert your Windows XP CD into your CD and assure that your CD-ROM drive is capable of booting the CD.
    2. Once you have booted from CD, do NOT select the option that states: Press F2 to initiate the Automated System Recovery (ASR) tool.
    You’re going to proceed until you see the following screen, at which point you will press the “R” key to enter the recovery console:

    [​IMG]

    3. After you have selected the appropriate option from step two, you will be prompted to select a valid Windows installation (typically number 1).
    Select the installation number, and hit Enter.
    If there is an administrator password for the administrator account, enter it and hit Enter (if asked for the password, and you don't know it, you're out of luck).
    You will be greeted with this screen, which indicates a recovery console at the ready:

    [​IMG]

    4. There are eight commands you must enter in sequence to repair your problem..
    NOTE. Make sure, you press Enter after each command. Make sure, all commands are exact, including "spaces ".
    These commands are as follows:

    CD..
    ATTRIB -H C:\boot.ini
    ATTRIB -S C:\boot.ini
    ATTRIB -R C:\boot.ini
    del boot.ini
    BOOTCFG /Rebuild


    Note about the above command.
    BOOTCFG /REBUILD command which searches for pre-existing installations of Windows XP and rebuilds sundry essential components of the Windows operating system, recompiles the BOOT.INI file and corrects a litany of common Windows errors.
    It is very important that you do one or both of the following two things:
    A.) Every Windows XP owner must use /FASTDETECT as OS Load Option when the rebuild process is finalizing.
    B.) If you are the owner of a CPU featuring Intel’s XD or AMD’s NX buffer overflow protection, you must also use /NOEXECUTE=OPTIN as an OS Load Option.
    For the Enter Load Identifier portion of this command, you should enter the name of the operating system you have installed.
    If, for example, you are using Windows XP Home, you could type Microsoft Windows XP Home Edition for the identifier (it's not crucial, however what the name is, as long, as it's meaningful).
    Here is your computer screen:

    [​IMG]

    5. Following command verifies the integrity of the hard drive containing the Windows XP installation. While this step is not an essential function in our process, it’s still good to be sure that the drive is physically capable of running windows, in that it contains no bad sectors or other corruptions that might be the culprit:

    CHKDSK /R

    6. This last command writes a new boot sector to the hard drive and cleans up all the loose ends we created by rebuilding the BOOT.INI file and the system files. When the Windows Recovery Console asks you if you are Sure you want to write a new bootsector to the partition C: ? just hit “Y”, then Enter to confirm your decision:

    FIXBOOT

    7. It’s time to reboot your PC by typing
    EXIT
    and pressing Enter.

    With any luck, your PC will boot successfully into Windows XP as if your various DLL, Hive, EXE and NTLDR errors never existed.



    If you don't have Windows CD...
    Download Windows Recovery Console: http://www.thecomputerparamedic.com/files/rc.iso
    Download, and install free Imgburn: http://www.imgburn.com/index.php?act=download
    Using Imgburn, burn rc.iso to a CD.
    Boot to the CD...let it finish loading.
    When the "Welcome to Setup" screen appears, press R to start the Recovery Console.
    Then, follow instructions from Step #3 above.
     
  19. 2011/02/13
    GRAHAM WESTON

    GRAHAM WESTON Well-Known Member Thread Starter

    Joined:
    2002/07/30
    Messages:
    371
    Likes Received:
    0
    Ok Broni, have a good night's sleep. Thanks for all ur help. I'll go through what u have sent, and post it here for u tomorrow. Again, many thanks.

    Cheers.
     
  20. 2011/02/13
    GRAHAM WESTON

    GRAHAM WESTON Well-Known Member Thread Starter

    Joined:
    2002/07/30
    Messages:
    371
    Likes Received:
    0
    Broni,
    Ran through the above, all went well. Rebooted , and it went straight back to windows setting install, with the message about the missing nvida file. I have advised my mate probabily the best thing to do is remove the hd, fit to a docking station, copy all his required docs and software, wipe the hd, and start again with a clean install and mobo drivers. He is off to Brisbane tomorrow, so he is taking it with him. Many thanks for all your help here Broni, but i think this one got the better of me, and i just couldn't afford to spend anymore time on it, as i have paying customers work to do. You can only do so much for friends. Again, many thanks for all ur help.

    Cheers
    Graham Weston
     
  21. 2011/02/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I understand.
    It may be the best option. It seems like there are too many issues with that machine.
    I wish, we could have done better :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.