Can't access msconfig, device manager and more!

Discussion in 'Malware Help (A Specialist Will Reply)' started by LtTG, May 7, 2010.

  1. LtTG

    LtTG Private E-2

    Hello, the logs attached are from a Toshiba Satellite A55-S306 laptop that belongs to a friend. According to my friend the laptop had a virus that he thinks it got thru a peer to peer program. The computer was taken to a local computer shop for repair but there seems to be several problems remaining. I can't access the device manager, msconfig, ipconfig, system restore, and there have been several svchost.exe app errors. The one most common is
    "The instruction at 0xffbadd11 referenced memory at 0xffbadd11 the memory could not be read". This occurs everytime the computer is started or rebooted. When trying to open msconfig I get "The system configuration utility has encountered a problem and needs to close".
    One thing that seems strange to me is that there is a wireless icon in the taskbar that says Wireless network connection 11(Peer-to-Peer) that is connecting to the internet but it won't allow me to disable it.
    I removed the AVG Free antivirus because it was outdated and then tried to install Antivir, which failed with a read error, then tried Microsoft Security Essentials, which failed with an error also. So, I have been downloading the scanners onto my desktop and transferring them to the laptop for scanning. Not sure what good this does since it seems to connect wirelessly whenever it is on. Not sure if all of this is caused by malware or other problems.
    It looks like ComboFix found something and Rootrepeal as well. There was a Rootrepeal error during install - "Invalid PE image found". Thanks for any help you can give.
     

    Attached Files:

  2. LtTG

    LtTG Private E-2

    Here is MGlogs.zip
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. I suggest you post in the software forum for further assistance.

    You first step should be to go to start / run / and type:
    sfc /scannow ---> have your XP disc handy.

    Other things to consider:
    Do you have this problem in safe mode?
    Can you run things using Task Manager?
    Have you checked your RAM?

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.

    [*]After doing the above, you should work thru the below link:


    [/LIST]
     
  4. LtTG

    LtTG Private E-2

    Thankyou TimW, will post in software forum.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    As a start, disable your AV and AS software and copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Is msconfig now back?
     
  6. LtTG

    LtTG Private E-2

    Hi TimW,
    Tried the fixME.reg and received a success message but still can't open msconfig. Tried sfc /scannow and it didnt ask for cd. Unfortunately the DVD-RW doesn't work anyway.

    In regards to other things to consider in your first post,

    Safe Mode - The same problems exist.

    Task Manager - I can run other programs like notepad or Hijackthis but not the ones I listed in first post.

    RAM - The only check I have done on the RAM is to remove it and try each stick on its own. It has 2X256, and really it seems to boot just as well with one stick as it does with both but the errors and problems are still there. Either way its very slow to boot.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you open a command prompt? If you open task manager, hit new task and type in msconfig.exe does that work?
     
  8. LtTG

    LtTG Private E-2

    Hi TimW,
    Yes, I can open a command prompt but when I enter ipconfig /all a window pops up - ipconfig.exe - Application Error and the message is; The application failed to initialize properly (0xc0000006). Click on OK to terminate the application.

    In task manager entering mscong.exe brings up a window - System Configuration Utility has encountered a problem and needs to close.
    Error signature - EventType : InPageError P1 : c000009c P2 : 00000003

    The technical info about the error is as follows,

    C:\DOCUME~1\customer\LOCALS~1\Temp\WER4e5b.dir00\msconfig.exe.mdmp
    C:\DOCUME~1\customer\LOCALS~1\Temp\WER4e5b.dir00\appcompat.txt
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    At this point, it would be best for you to post in the software forum. You may need to try doing a repair installation. :(
     
  10. LtTG

    LtTG Private E-2

    Hello TimW,

    Thanks for your help, I do have a little good news. I was able to get Chkdsk to run last night, it wouldn't run when I ticked only Automatically fix file system errors but when I ticked both boxes it ran and replaced or repaired several clusters. The computer boots faster now and I'm able to access msconfig and system restore but still can't get to device manager or ipconfig. I now have continuous wuauclt.exe error popups happening and Windows update doesn't work right either although I dont' think that was working prior to the chkdsk scan.

    Thanks again, LtTG
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    wuauclt.exe is your windows update program. Have you checked your system restore folder to see how far back you can restore to? Perhaps you can restore to a point before this all happened?
     
  12. LtTG

    LtTG Private E-2

    Hi TimW,

    When I tried to look in System Volume Info folder I got a message saying that the folder is inaccessible - Access is Denied. However I was able to open the system restore program and restore back to Nov. 2 of 2009 but there is really no improvement. Still getting numerous wuauclt errors and there are no connections listed under Network Connections although when I connect the cable wire I can get on the internet. Still can't access Device Manager either.

    I think it needs the repair install you mentioned. Question is with the DVD-RW not working, and I'm pretty sure he doesn't have the Windows CD, will that be possible?

    Thanks, LtTG
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What exactly does this mean?
    • Does it mean that Device Manager does not open?
    • Does it mean you get an error message?
    • Does it mean it opens, but the window is blank?
    • ......etc
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  15. LtTG

    LtTG Private E-2

    Hi Chaslang,

    The Device Manager does not open and then a window opens and says Microsoft Management Console has encountered a problem and needs to close. I have tried to open it by right clicking on My Computer then Manage then Device Manager and its the same error. Also getting wscntfy.exe errors.

    Ran Resetting Registry and File Permissions procedure but I don't see any change afterward. A window popped up during the run and it was a wscntfy.exe error.

    Thanks, LtTG
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then as Tim previously advised, you would be better off posting in the Software Forum since it is not just a simple permissions issue that was causing problems. A reinstall could be in your future.
     
  17. LtTG

    LtTG Private E-2

    Hi chaslang,

    Will post in Software forum as soon as I can, thanks to you and Tim for your efforts.

    LtTG
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Good luck and surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds