Anti Virus Pro 2010 and now dead computer

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ctesias, Oct 2, 2009.

  1. ctesias

    ctesias Private E-2

    Hi

    Not sure where to post this as my computer is totally down and I am stuck. I've put it here as I believe the problem is due to infection with Anti Virus Pro 2010.

    Yesterday my son was duped into downloading this virus - usual thing, a message saying 'PC is infected do you want to run a scan'. I said I'd fix it today and was about to start your READ & RUN ME FIRST process (which I have used to good effect before) and I can't even get the computer to start, in either normal or safe mode. I get as far as the initial Dell startup page and then get the blue screen.

    I have run Dell diagnostics (F12) and it has passed the Express Tests and also the Symptom Tree 'Windows Blue Screen' diagnostic so I am pretty sure the problem is not hardware related.

    The system is a Dell Dimension 5000 and I have a Reinstallation CD for Windows XP incl. Service Pack 2. I don't have an XP Recovery CD.

    Please help!

    Thanks

    Ctesias
     
  2. ctesias

    ctesias Private E-2

    Hi

    I have some further information which will hopefully help you in providing a solution to this serious problem.

    When I try to start the computer and encounter the blue screen the message displayed is "Process1 Initialization Failed".

    I have also used the Dell Recovery Console to try to recover important data, and while the computer boots from the Dell XP OS disk and the Recovery Console runs OK, when I try to change direcory and access the Documents and Settings folder it says "access denied". I don't understand why as there is no administrator password and it does not request a password when I select the account to open with the Recovery Console. That said, I'm not sure if the Recovery Console will allow me to copy data to a CD even if I can access it.

    My son's course work is on this computer along with family photos etc and I am desperate to find a solution - I know we should have backed it up!

    I look forward to hearing from you.

    Thanks in advance.

    Ctesias
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not a symptom of Anti Virus Pro. This sounds more like OS damage. Anti Virus Pro wants you to be able to boot so they can do their dirty work.

    Are you referring to the Windows Recovery Console or are you referring to something from Dell.


    If you are referring to the Windows Recovery Console, there is only a limited amount you can do with it, but it may be possible to fix your problem if you really mean the Windows Recovery Console. I need to know that you are booting up a Windows XP Bootable CD and accessing the Windows Recovery Console.


    You can read about the Windows Recovery Console here: http://support.microsoft.com/kb/314058


    If you can boot to the real Windows Recovery Console, you can change directories at the command prompt to get into the C:\Windows\system32 folder. Then you can use the DOS DIR command to find out the file sizes of the below files

    C:\Windows\System32\eventlog.dll
    C:\Windows\System32\netlogon.dll
    C:\Windows\System32\scecli.dll

    One of the above files is normally the source of the infection and will need to be replaced by a backup which the infection creates. The backups will be the below depending on which file is infected. Notice the play on the original names:

    C:\Windows\System32\logevent.dll
    C:\Windows\System32\ntelogon.dll
    C:\Windows\System32\sceclt.dll

    You will then be able to use the DOS copy command to copy the backup file over the infected file and then you may be able to boot up.

    If you cannot bootup after replacing the infected file, doing the below from the Recovery Console may help restore a working registry:

    http://support.microsoft.com/default.aspx?scid=kb;en-us;307545&sd=tech

     
  4. ctesias

    ctesias Private E-2

    Chas

    Many thanks for the detailed and considered reply - I can see how busy you guys are.

    I'm afraid that the problem went from bad to worse and it got to the point where I didn't even get a blue screen when booting; it just went black and hung.

    So I did the following which may be of help to someone else:

    A little research revealed that the Windows Recovery Console (you were right - Dell just renamed it!) cannot access or copy data files as its essentially an OS recovery utility. So I scouted aroung and found a site which suggested other ways of recovering data - which at that point was my primary concern.

    I managed (after three attempts) to create a bootable CD using something called Bart's Preinstalled Environment (search for Bartpe) and boot up a limited version of the OS. It did a good job in enabling me to get all our data copied to a USB hard drive.

    It was high time to rebuild the OS anyway so I reformatted the hard drive and reloaded XP. As I had a spare copy of Vista Ultimate I then upgraded to Vista, restored the data and all seems well. A somewhat crude approach, I know, but I was getting desperate!

    The only problem left is that my son's favourite game (Championship Manager 4) runs out of memory under Vista and insists on being closed down - any thoughts on how to get round this would be much appreciated.

    Thanks again - keep up the good work.

    Ctesias
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes this is one of many useful tools to have available. You should also check out the below especially UBCD4Win. I never leave home without it. ;)


    Sorry but we don't even have enough time in this forum to deal with all the malware problems. We cannot deal with non-malware issues here. Try the Software Forum or Game Forum.

    Since you have reinstalled, you should work thru the below:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds