Help with Windows Start Up Error and Vundo

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by judalee, Sep 24, 2007.

  1. judalee

    judalee Private E-2

    I have been experiencing some issues with my computer and I was hoping that you guys could help me. A little background, this is regarding a Dell Inspiron 6000, running windows xp (pro), sp2. Over the past few months my computer has been running slow and I had attributed it to installing IE 7.0. (I have minimal memory) I downloaded Firefox and began using that instead; at the same time, I thought I would clean up the system and remove some old programs and also clean up my directories and files. I also thought I would remove some items from start up using msconfig. (I’ve just read that majorgeeks does not recommend that way and would like to ask about other options especially with stubborn items like Realplayer, first things first though), after making changes I received an access denied error. (The changes took affect, but I still received the error.) I read about it and was lead to start in safe mode and log in as administrator and then try…same error. Anyway, after asking advice I was told to change the attribs in the windir and/or windows/system32 directories, which I did, but this did not solve the issue either, so I tried to change them back. The next time I restarted my system after deleting programs and working with the attributes, I received a

    “We are sorry for the inconvenience, but Windows was unable to start normally error.”

    I accepted the start normally option and my system seems fine. The error remained so, I tried to start from last known configuration, and I then did a system restore to an earlier point, but that did not clear the error either. I was told it may be a registry problem so I tried restoring the registry backup from CCleaner. I was then told I would need to reinstall Windows XP to resolve the issue. I could not find my install of XP home, so I upgraded to XP pro using the CD supplied with my spouse’s computer. This did not clear the issue either. I sought out information at Microsoft and ran a One Care Safety Scan, it found one item (I am sorry but I do not know how to access a report) and deleted it; it also rescanned and cleaned the registry. The problem still exsists. I then found your site as I was searching for answers to fix the Start up error. I found a thread that was having the same type error message and discovered that she had a virus. As I was reading the READ AND RUN section I followed all the steps and they are as follows: I use the latest version of McAfee and was unable to find a way to delete the log files, but while I was there I noticed that at the end of august it detected and removed an Exploit MS06-014 (virus) from a script that was running and then on 9/23 it discovered and removed a Vundo (Trojan).

    I ran CCleaner in both Admin and User login’s to clean out files. -- I ran Spybot and used the immunize feature. -- I ran Counterspy – it found a few negligible items, the options were to ignore or remove – I removed. (will attach in follow up) -- I ran BitDefender (in normal mode) but was unable to find an option to save a file so I viewed it and cut and pasted – it was clean. (will attach in follow up) -- I ran Panda – again I couldn’t find an option to save, only buy or scan again? It was also clean. -- I rebooted in normal mode – ran both getrunkey and shownew (attached) -- Followed instructions for Hijack This – (log attached) (also, I was confused about the System Restore so all scans were run with it on, but it was off for the hijack this scan, and is currently off?

    I thank you for taking the time to read this and offer support.

    Judi
     

    Attached Files:

    Last edited: Sep 24, 2007
  2. judalee

    judalee Private E-2

    two more attachments
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks Judi!

    I will begin by adding comments to things you posted.

    That is correct. MSconfig was designed to be used a debugging tool for temporary use only. There are many programs that you can use as a Startup Manager. See this link: http://www.majorgeeks.com/downloads40.html One often recommended is Startup CPL


    What were you accessing when you received this and note that this is not a topic for the malware forum too.

    Again I'm not sure what changes you are referring too.

    I still have the same question! What is it that you are trying to do/change? Are you trying to delete files? What files? The system32 folder is not someplace you should be touching on your own unless you are an expert. What did you delete or change?

    What error, the Windows was unable to start normally error? I confuse because you just stated it seems fine.

    Doing a System Restore would have already repaired a registry problem so using CCleaner was not necessary and was not a good idea since you now may have restored a registry backup that does not make sense to your system after already having done a System Restore to a different version of your registry.

    Not really legal nor is it a good idea to try and upgrade a computer that is currently having problems no matter whether they are malware or Windows OS problems.

    Which issue? The Windows failed to start normally issue?


    What thread? A message about Windows failed to start normally would not usually be addressed in the Malware Forum.

    It was not supposed to be turned off until you were given a clean bill of health. Turning it off removes all restore points.


    I don't really see any malware issues in your logs (which is what I expected based on your problem description). You should uninstall CounterSpy now since it will slow your PC down and we are finished using it to look for malware.

    You also missed uninstall Viewpoint Media Player in step 0 of the READ ME so you can uninstall it now.
     
  4. judalee

    judalee Private E-2

    Thank you for addressing each statement. Since I seem not to have malware, should I continue? I will answer your questions, just in case? (1) I was in msconfig to stop items in startup.ini, ie. real, powerdvd, etc. after unchecking those items and applying, I recieved the access denied error, even though the changes take place. this error is still there. (2) I understand that I shouldn't have been in system32, lord knows I am no expert. I didn't delete anything, just changed the attributes to +r, +h, but then tried to change them back, when it did not fix the access denied error. which is what I was trying to do (bad advice, huh?) (3) Yes, I still get the "windows didn't start normally error at start up," but when I select start normally my system seems fine - as in, still running, still slow. (4) Gotcha, CCleaner, System Restore, Upgrade...bad...How Bad? (5) The thread I refered to ...I only mentioned it because of the system restore, and because she had viruses, viri?..not really relevant.

    I think that is it. I will go back and remove the viewpoint and counterspy.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Continue with what?

    What else was included in etc? Did you undo these changes?

    First of all using +r and +h was the exact opposite of what you should be doing if you were having a problem deleting or finding a file. What you did was set whatever file you were dealing with to be READ-ONLY and also hidden. And you did not tell me which files or did you do this to the whole folder. This alone could be causing problems.

    Yes very bad advice especially if they said +r, +h and did they also say +s?


    Unknown because I cannot tell you what the differences between what System Restore had and what Ccleaner had.

    Not relevant at all.
     
  6. judalee

    judalee Private E-2

    (1) continue with this thread on the malware forum.
    (2) they were just items from programs running, nothing system wise, and yes I undid the changes and msconfig is now starting in normal start up.
    (3) yes, I forgot +s, Im sorry, but I may have unprotected them first -r, -h, -s, then when that didn't work, reapplied and I did it to the whole folder.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you say reapplied you mean you applied +r +h +s to the whole c:\windows\system32 folder???? Very bad idea. Undo it now. While some files should have protection on them, not all files in this folder should be. Since there is no easy way to to fix what you did, the best thing to do is to use -r -h -s on the whole folder. This may or may not help fix your startup error. If it does not, I suggest you post in the Software Forum to continue repairing what you may have done to your Windows Operating System.
     
  8. judalee

    judalee Private E-2

    Thank you, I will repost in the software forum.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your welcome. Did you undo the +r, +h and +s yet? If not, do this first and see if you still have problems before staring a new thread.
     
  10. judalee

    judalee Private E-2

    I did, straight away - and the error went away. Is there no way to reset the attribs to their default state? I feel so stupid for doing this? Am I more vulnerable for having done it? Thanks.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! And there are tons of files in the system32 folder and subfolders you would have to deal with.

    I would not worry about it too much since most files in there do not have those attributes set anyway. Yes there are some, but I don't think it is worth worrying about.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds