1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Active 0x7c91b21a - told it might be an infection

Discussion in 'Malware and Virus Removal Archive' started by etanpinsky, 2010/01/10.

  1. 2010/01/10
    etanpinsky

    etanpinsky Inactive Thread Starter

    Joined:
    2010/01/10
    Messages:
    22
    Likes Received:
    0
    [Active] 0x7c91b21a - told it might be an infection

    When I turn on my computer and arrive at the windows XP "pick user" screen, I receive this message:

    Iaantmon.exe - Application error.
    The instruction at "0x7c91b21a" referenced memory at "0x00000010 ". The memory could not be "written ".

    OK to terminate
    CANCEL to debug

    Pushing OK doesn't do anything. Pushing CANCEL leads to another identical message except it only gives the "OK" option. Pushing OK again leads to the same original message, only the title is different: this time it's: VsTskMgr.exe. Pushing again leads to the same message with: alg.exe for the title.

    After that I push the user icon and enter Windows, the background appears with no icons or toolbars, and the message appears yet once more - this time with userinit.exe for the title.

    After pushing Cancel here, no more messages appear but all you see is the empty background picture and there is nothing to work with. Alt-Ctrl-Del does nothing.

    I know others have posted this problem but they were able to get into the computer and run virus applications and the like. I can't do anything (even not in safe mode).

    since I have no access to the computer I can't use the DDS either.
    I was told in that it might be an infection.


    Is there anything I can do?

    Many thanks,
    Etan
     
  2. 2010/01/10
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Yoiu were asked to ....

    Please read this as indicated at the head of the forum and post the logs requested in this thread.

    Please post the logs requested.
     

  3. to hide this advert.

  4. 2010/01/10
    etanpinsky

    etanpinsky Inactive Thread Starter

    Joined:
    2010/01/10
    Messages:
    22
    Likes Received:
    0
    I did read the post at the head of the forum - but as I wrote, I can not access my computer so that I can't run the DDS and post the logs. (I'm writing from a different computer).

    Is there no way to deal with the problem without them?

    Sorry for the complication,
    Etan
     
  5. 2010/01/10
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
  6. 2010/01/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Try Avira AntiVir Rescue System

    Using another working computer...
    1. Download the Avira AntiVir Rescue System: http://www.free-av.com/en/tools/12/avira_antivir_rescue_system.html
    2. Place a blank CD in your burner and double-click on the downloaded file.
    3. The program will automatically burn the CD for you.
    4. Place the burned CD into the affected computer and start the computer with the CD in the CD tray.
    5. On the bottom left side of the screen there are 2 flags. Using your mouse click on the British flag to use English.
    6. Click on the Configuration button.

    - Select Scan all files
    - Select Try to repair infected files and Rename files, if they cannot be removed
    - Select Scan for dialers
    - Select Scan for joke programs (Jokes)
    - Select Scan for games
    - Select Scan for spyware (SPR)

    7. Click on Virus scanner
    8. Click on Start scanner at the bottom of the screen.

    9. Let Avira finish it's scan and then remove any threats found and then exit out of the scanner.
    10. Take the CD out of the CD/DVD tray and then restart the computer.

    If needed see this Tutorial for the Avira Rescue CD: http://forum.avira.com/wbb/index.php?page=Thread&threadID=82163
     
  7. 2010/01/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I assume, you'd take Pete's advice as well. We can't be certain here.
     
  8. 2010/01/12
    etanpinsky

    etanpinsky Inactive Thread Starter

    Joined:
    2010/01/10
    Messages:
    22
    Likes Received:
    0
    Thank you for the advice.

    Broni - I downloaded the Avira rescue system and placed the cd in the infected computer but the computer won't open it. I read the tutorial and moved up the disk's boot priority as said - but it didn't help. I tried the disk on a working computer and it doesn't open either - even when moving up it's priority.
     
  9. 2010/01/12
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Are you booting from the CD?
    Put the CD in, restart computer.
    At some point, you should see this:
    Press any key to boot from CD
    Do you see the above message?
     
  10. 2010/01/12
    etanpinsky

    etanpinsky Inactive Thread Starter

    Joined:
    2010/01/10
    Messages:
    22
    Likes Received:
    0
    Wow, that was a quick reply!

    No, I don't see that message - it goes straight into Windows.
     
  11. 2010/01/12
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    That means, you have to enter BIOS and change boot order, so the CD drive is listed first.
     
  12. 2010/01/12
    etanpinsky

    etanpinsky Inactive Thread Starter

    Joined:
    2010/01/10
    Messages:
    22
    Likes Received:
    0
    I did, it is first!
     
  13. 2010/01/12
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
  14. 2010/01/12
    etanpinsky

    etanpinsky Inactive Thread Starter

    Joined:
    2010/01/10
    Messages:
    22
    Likes Received:
    0
    Yes!
    it gives 3 options:

    to set up Windows XP now

    To repair a Windows XP installation using Recovery Console

    To quit Setup without installing Windows XP

    what should I pick?
     
  15. 2010/01/12
    etanpinsky

    etanpinsky Inactive Thread Starter

    Joined:
    2010/01/10
    Messages:
    22
    Likes Received:
    0
    I just realized - those 3 options are in the Windows XP setup window.
     
  16. 2010/01/12
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    No, do nothing. This was only for testing purposes.

    It looks like Avira CD wasn't created correctly for whatever reason.
    Try to make new one.
    If it still doesn't work....

    1. Download [ftp=ftp://ftp.drweb.com/pub/drweb/livecd/minDrWebLiveCD-5.0.1.iso]Dr.Web LiveCD[/ftp].
    2. Download, and install free Imgburn: http://www.imgburn.com/index.php?act=download
    3. Using Imgburn, burn minDrWebLiveCD-5.0.1.iso to a CD.
    4. Make sure that the CD/DVD drive is set as the first-boot device. Adjust corresponding BIOS settings, if necessary.
    5. Insert Dr.Web LiveCD into the drive and restart computer.
    6. As loading starts, a dialogue window will pop up:

    [​IMG]

    7. Press Enter to continue with DrWeb-LiveCD (Default) mode.
    8. The operating system will detect all available disk drives automatically. It will also try to connect to the local network, if available.
    9. Check the disks or folders you want to scan, and click on Start.

    Dr.Web LiveCD user manual: ftp://ftp.drweb.com/pub/drweb/livecd/LiveCD-ru.pdf
     
  17. 2010/01/12
    etanpinsky

    etanpinsky Inactive Thread Starter

    Joined:
    2010/01/10
    Messages:
    22
    Likes Received:
    0
    I created another Avira CD and it worked. The scan renamed 23 files but didn't find anything else. I restarted the computer - and the same problem still exists. Nothing changed.
     
  18. 2010/01/12
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Have you checked out the hard drive?
     
  19. 2010/01/12
    etanpinsky

    etanpinsky Inactive Thread Starter

    Joined:
    2010/01/10
    Messages:
    22
    Likes Received:
    0
    No, I don't know exactly how to do that. I have a dell CD called:
    Drivers and utilities already installed on your computer.
    contents:
    -device drivers
    -diagnostics and utilities

    Do I use that? how?

    I appreciate your help very much.
     
  20. 2010/01/12
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    I posted the download URL's for disk diagnostic software above, repeated below.....

    Disk Diagnostic Software ....

    ExcelStore

    Hitachi/IBM

    Samsung

    Seagate, Maxtor, Quantum

    Western Digital

    Determine the make & Model no. of your hard drive - SIW (Hardware > Storage Devices) will give you the info.

    Then go to the manufacturer's website indicated above and download the DOS version of their diagnostic software to create a bootable CD, create the CD and boot from it. There will be instructions on the site.

    If you are unsure post the make & model no. of the drive here.
     
  21. 2010/01/12
    etanpinsky

    etanpinsky Inactive Thread Starter

    Joined:
    2010/01/10
    Messages:
    22
    Likes Received:
    0
    I don't know how to determine the make and model no of the drive - because, if I understand correctly - SIW has to be used on the computer it's checking - and I can't access my computer.
    Is there another way to know?
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.