chkdsk won't run!... mal-ware??

Discussion in 'Malware Help (A Specialist Will Reply)' started by P1of4, Apr 17, 2008.

  1. P1of4

    P1of4 Private E-2

    I'm a new user. I posted a new thread under 'Software' but now I think I should have created a new thread here under 'Mal-ware'.

    Because I am new and don't know how to go about asking for help and where to post my new threads...I am going to post a new thread here under 'Mal-ware' with the same problem I posted under 'Software'.

    OK.
    I have Windows XP home edition on my computer.

    I have 4 user profiles: administrator, mom, child1, child2.

    User profile 'child2' had an error message on the desktop which said:

    "Inbox Microsoft Outlook: OUTLOOK.EXE - Corrupt file. The file or directory C:\WINDOWS\system32\nvwimg.dll is corrupt & unreadable. Please run the chkdsk utility."

    I close that error message window.
    I proceed to logoff 'child1' user profile.

    Next, I get the 'end program' window which said:
    "Adobe Photodownloader Boot"
    I have to hit the "end now" button which seems to end it.
    I am logged off of 'child 1' user profile.

    I switch to the 'mom' user profile, which is already logged on.
    I see this error message in a window:

    "Windows - Corrupt file. The file or directory C:\WINDOWS\system32\nwiz.exe corrupt & unreadable. Please run the chkdsk utility."

    I close this window.

    Another error message in a window shows up:

    "CSE Validator Lite v8.04 : cselite80.exe - Corrupt file. The file or directory C:\Documents and Settings\Mom is corrupt & unreadable. Please run the chkdsk utility."

    I close this window.

    I attempt to close my Microsoft Outlook e-mail window, I get this error:

    "OakHollow - Microsoft Outlook: OUTLOOK.EXE - Corrupt File. The file or directory C:\Documents and Settings\Mom is corrupt & unreadable. Please run the chkdsk utility."

    I close this window.

    I proceed to log off of this user profile 'mom' and get the end program window:

    "End Program - NVIDIA Twinview Window"
    I hit the "end now" button and it closes the window.

    I get "End program - Adobe Photodownloader Boot".
    I hit the "end now" button and close the window.

    I proceed to log off this user 'mom'.

    I switch to the administrator user profile.
    I see this error message:

    "YMPTRAY: ymetray.exe - Corrupt file. The file or directory WINDOWS\system32\nvwimg.dll is corrupt & unreadable. Please run the chkdsk utility."

    I close that window.

    I close my Microsoft Outlook e-mail window.
    I get this error message:

    "Inbox - Microsoft Outlook: OUTLOOK.EXE - corrupt file. The file or directory WINDOWS\system32\nvwimg.dll is corrupt & unreadable. Please run the chkdsk utility."

    I close that window.

    Now I have nothing running, just my desktop shows.

    I proceed to run chkdsk.
    I click on "Start", then "Run..." and enter "chkdsk volume:/r".
    It gives me an error that it cannot run chkdsk.

    I try to run one of my anti-spyware software I downloaded from Geeks.com and it just hangs.

    I am afraid to shut-down my computer. I am hoping I can get help with this because I am concerned it might by mal-ware I've gotten from visiting a web site.

    HELP!!!
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I've answered your post in the software section and would prefer you stay there until that thread is resolved. :)
     
  3. P1of4

    P1of4 Private E-2

    I am lost...

    I have received e-mails concerning my two posts (1 post under Software and 1 post under Malware).

    The e-mails contained a link titled: "This thread is located at:"
    and a link follows.

    The link takes me to a MajorGeek web page that says:
    "vBulletin Message
    No Thread specified. If you followed a valid link, please notify the administrator."

    How do I get to my original postings and what does the above "vBulletin Message" mean?
     
  4. P1of4

    P1of4 Private E-2

    I sumitted one reply to this message already, but I realized I needed to add the following:

    My memory is fading, but I thought I replied to my mal-ware posting already with three attachments. I thought I'd be able to find that posting with the 3 files attached. I cannot seem to find it.

    I am really confused on how to use these forums!

    I have a new question I'd like to post but now I am unsure how to proceed.

    Adivse is most appreciated.
     
  5. P1of4

    P1of4 Private E-2

    I cannot find my way around these forums!

    I cannot find your reply under 'Software' forum. I am replying here to inform you that I did follow your steps recommended. I received an e-mail telling me your response.
    I ran 'Error checking' and it ran to completion with NO errors.

    I also followed the "Read and Run Me First" Malware guide steps in order. The Malwarebytes Anti-Malware found a "Trojan Fake Alert". My original problem where lots of error messages stating I had a "Corrupt File..." is gone.

    After downloading all those softwares, all free, recommended in the "Read and Run Me First" Malware guide, I now get this new error message, which pops up here and there, saying:

    "OUTLOOK.EXE - Bad Image. The application or DLL C:\WINDOWS\system32\sensapi.dll is not a valid Windows image. Please check this against your installation diskette."

    Your help on this new error window is apprecaited...
    What does it mean?
    How do I fix it?

    Thank you.
     
  6. abri

    abri MajorGeek

    Hi P1of4,

    The only thread which shows up when doing a search of your name for Any Date is this one. If there was a thread in the Software Forum, it no longer shows up as being there. You probably did post your logs correctly. They may have been removed. This issue needs to be resolved by the Administration. Sorry for the problems.

    abri
     
  7. P1of4

    P1of4 Private E-2

    abri,

    Thanks for your response.

    It is unclear to me how to contact the administrator. Is there an e-mail availble?

    I'll wait for your answer before deciding on posting a new problem.

    thanks.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't know who or when your thread in software got deleted ...however...you can now attach the requested logs from the read and run first instructions now...here. We at least need to remove the:C:\WINDOWS\system32\sensapi.dll

    And there may be more.
     
  9. P1of4

    P1of4 Private E-2


    I have attached 3 log files:

    1. MGLogs.zip
    2. Combofix.txt
    3. MBAMlog.txt

    Are you indicating that the C:\WINDOWS\system32.sensapi.dll is caused by mal-ware?

    thanks.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No I am not....it is your system event notification ..which sounds like it is corrupt...so give me a chance to look at your logs..in the meantime go to start / run / and type "sfc /scannow" without quotes and have your xp cd handy..run it twice.

    The go to windows explorer and see if C:\WINDOWS\system32\sensapi.dll is there.
     
  11. P1of4

    P1of4 Private E-2

    Tim,

    I did the: start / run: "sfc /scannow".

    A window popped up titled: "Windows File Protection"

    It said: "Files that are required for windows to run properly must be copied to the DLL cache. Insert your Windows XP Professional CD2 now. "

    I am confused by that message because I thought I have XP Home Edition.

    I have a Gateway PC, bought in 2005. I called them up to make sure I have the operating disk they say I should have. I was also confused about the operating disk I have because it is labelled:

    "Gateway
    Microsoft Windows XP Media Center Edition 2005
    Operating System Disc"


    It has "XP Media Center Edition" but I was expecting a label with "XP Home Edition" on it instead.

    Gateway assured me I have the correct operating system disk. I only have that one operating system disk and no other driver disks, etc to accompany it, per Gateway.

    So, I popped in my XP operating system disk in response to the Windows File Protection window prompt. It gave the following error window:

    "The CD you provided is the wrong CD. Please insert the Windows XP Professional CD2 into your CD-ROM drive."

    I will wait for further advice...

    thanks.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well..it is not a malware issue.....so I am unsure as to what has happened. Have you tried doing a repair install to the computer?
     
  13. P1of4

    P1of4 Private E-2

    I am such a novice...

    how do I do a repair install?

    and

    what is that suppose to do?
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The repair install will do exactly what it says ...repair the system ....to do so:

    Reboot with your xp cd in the drive ...you will get a black screen (hopefully) that will just say: to boot from cd hit enter ...do so ...it will load files, then you will get an option to install new or repair - this repair takes you to the recovery console which we don't want, so choose install ...you will get the license screen to hit f8 to agree ...then when it finds your previous install...choose "R" to repair .....let it rip.
     
  15. P1of4

    P1of4 Private E-2


    Sounds straight forward.
    Several questions though:

    1. Do I need to back-up anything on my hard drive first?

    2. Should I be worried/prepared for anything getting destroyed, lost, stuck, etc. to where I might not have a working computer after this process?

    3. Have my logs already been reviewed and the conclusion is there is no mal-ware problem at this point?

    I am both a novice AND a worry-wart.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No
    No
    Yes
     
  17. P1of4

    P1of4 Private E-2

    Tim,

    My 2005 computer came with a disk labelled:

    Microsoft Windows XP Media Center Edition 2005
    OPerating System Disc"

    That is the only 'xp cd' I have. So I put that in my drive, clicked "turn off computer" and "re-start".

    My screen went black and some text appeared, instructions that stayed up only a few seconds before I could really read what it said. If I did not hit any keys, XP came up.

    So I did this "re-start" several times and was finally able to see what the instructions were:

    ""R" to to see Gateway recovery options...."

    ""F11" to start recovery"

    So I hit 'R' to see the options.

    The next screen offered me only one clickable option. The screen said:

    "System Restore"
    "System Restore environment is incomplete!
    System Restore re-installs the environment."
    [OK]


    So I clicked "OK", not knowing how to 'back out' of this screen.

    The next window appeared:

    "Completing recovery partition..."

    and files started copying, I guess from my xp cd to my hard drive...

    "From I386 to I36" ...
    "Preload to Preload" ...

    Then it finished, I had a window indicating I could either:

    do a complete wipe out of my hard drive...

    or do a backup of my hard drive to a directory 1st, then wipe out my hard drive.

    Luckily, there was a "QUIT" button which I clicked.

    Then Windows came up as normal.


    I have no idea where the option was to "boot from cd" or to "install new" per your instructions.

    I would like to try and fix some problems I seem to still be having...

    should I start a new post under "Software forum" since there is no more indication of mal-ware?
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes...please start a thread in software....they can get you straightened out with the repair install.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds