Trojan horse Downloader virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by kobiemi, Jan 20, 2008.

  1. kobiemi

    kobiemi Private E-2

    hi,

    i'm not a real technical person so i may need more hand holding than what you're used to. anyway, my niece somehow infected my computer with a virus (this has never happened to me before) and i've been trying w/out success to clean up my computer for the past 2 weeks. here are the steps i've taken so far. updated my norton av program and it detected the virus but it can't get rid of it. i also downloaded and ran spybot, spyware blaster, adaware and then most recently avg 7.5 and the avg program has found a threat called Trojan horse Downloader.Generic6.XAD and the file is called notepad.exe.

    avg keeps finding it and deleting it but it keeps coming back. i've stopped using my ie browser because i kept getting pop up ads like crazy. instead i use mozilla firefox now and whenever i click on a link, a blank ie browser will launch.

    please help! thank you!
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. kobiemi

    kobiemi Private E-2

    thank you very much for your help. it's taken me a while, but i think i completed all the tasks exactly as instructed. but i'm still having problems. i have quit using my i.e. browser and only use the firefox browser but whenever click on a link, a blank i.e. browser launches. i'm afraid i'm still infected. here are the log files i was instructed to save during the cleanup process. please help! thank you!
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Okay now we need to use a new tool.

    * Download and save to RenV.exe from following link to Desktop (
    must be on the Desktop)
    * Now Copy the bold text in the below code box to notepad. Save it as Log.txt to your desktop. (It must be on your Desktop).

    Code:
    C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager .exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy .exe
    C:\Program Files\Common Files\Real\Update_OB\realsched .exe
    C:\Program Files\Common Files\Sonic\Update Manager\sgtray .exe
    C:\Program Files\Common Files\Symantec Shared\ccApp .exe
    C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt .exe
    C:\Program Files\Dell\Media Experience\PCMService .exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd .exe
    C:\Program Files\Intel\Modem Event Monitor\IntelMEM .exe
    C:\Program Files\iTunes\iTunesHelper .exe
    C:\Program Files\Java\jre1.5.0_08\bin\jusched .exe
    C:\Program Files\Logitech\Video\LogiTray .exe
    C:\Program Files\Logitech\Video\ManifestEngine .exe
    C:\Program Files\Messenger\msmsgs .exe
    C:\Program Files\MSN Messenger\msnmsgr .exe
    C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask .exe
    C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray .exe
    C:\Program Files\QuickTime\qttask  .exe
    C:\Program Files\QuickTime\qttask .exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
    C:\Program Files\Yahoo!\Messenger\YahooMessenger        .exe
    C:\Program Files\Yahoo!\Messenger\YahooMessenger       .exe
    C:\Program Files\Yahoo!\Messenger\YahooMessenger      .exe
    C:\Program Files\Yahoo!\Messenger\YahooMessenger     .exe
    C:\Program Files\Yahoo!\Messenger\YahooMessenger    .exe
    C:\Program Files\Yahoo!\Messenger\YahooMessenger   .exe
    C:\Program Files\Yahoo!\Messenger\YahooMessenger  .exe
    C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
    C:\WINDOWS\SYSTEM32\hkcmd .exe
    C:\WINDOWS\SYSTEM32\igfxtray .exe
    C:\WINDOWS\SYSTEM32\LVCOMSX .EXE
    C:\WINDOWS\SYSTEM32\mobjchku .exe
    C:\WINDOWS\SYSTEM32\dla\tfswctrl .exe
    
    * Now using your mouse, drag Log.txt onto RenV.exe
    * When finished, RenV.exe will produce a new log names Log.txt on your Desktop I will ask for this log later.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 8

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: On The Net Search Helper - {4E8F5D76-EF5B-46C8-B35B-C86F8BD6621A} - C:\WINDOWS\system32\memolxsk.dll (file missing)
    O4 - HKLM\..\RunOnce: [SpybotDeletingA3006] command /c del "C:\WINDOWS\SYSTEM32\drivers\core.cache.dsk"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC1950] cmd /c del "C:\WINDOWS\SYSTEM32\drivers\core.cache.dsk"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA6796] command /c del "C:\WINDOWS\SYSTEM32\drivers\core.cache.dsk"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC1627] cmd /c del "C:\WINDOWS\SYSTEM32\drivers\core.cache.dsk"
    O4 - HKCU\..\Run: [mocu] C:\WINDOWS\system32\mobjchku.exe G
    O4 - HKCU\..\RunOnce: [SpybotDeletingB367] command /c del "C:\WINDOWS\SYSTEM32\drivers\core.cache.dsk"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6494] cmd /c del "C:\WINDOWS\SYSTEM32\drivers\core.cache.dsk"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB88] command /c del "C:\WINDOWS\SYSTEM32\drivers\core.cache.dsk"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3811] cmd /c del "C:\WINDOWS\SYSTEM32\drivers\core.cache.dsk"
    O15 - Trusted Zone: *.gomyhit.com
    O15 - Trusted Zone: *.imageservr.com
    O15 - Trusted Zone: *.imagesrvr.com
    O15 - Trusted Zone: *.storageguardsoft.com
    O15 - Trusted Zone: *.gomyhit.com (HKLM)
    O15 - Trusted Zone: *.imageservr.com (HKLM)
    O15 - Trusted Zone: *.imagesrvr.com (HKLM)
    O15 - Trusted Zone: *.storageguardsoft.com (HKLM)

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    Quote:
    Files to delete:
    C:\Temp\tn3
    C:\WINDOWS\system32\drivers\core.cache.dsk
    C:\WINDOWS\SYSTEM32\memouint.exe
    C:\WINDOWS\SYSTEM32\memolxsk.dll
    C:\WINDOWS\SYSTEM32\rushitvz.exe
    C:\WINDOWS\SYSTEM32\bkmoopob.exe
    C:\Temp\liHco0109.exe

    Folders to delete:
    C:\WINDOWS\SYSTEM32\vt8
    C:\WINDOWS\SYSTEM32\nz0
    C:\WINDOWS\SYSTEM32\mp2
    C:\WINDOWS\SYSTEM32\ez4
    C:\WINDOWS\SYSTEM32\che9
    C:\WINDOWS\SYSTEM32\edcA01
    C:\Temp\tn3

    [/quote]

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.
    Then attach the new logs:

    * Log.tx from running RenV
    * c:\avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  5. kobiemi

    kobiemi Private E-2

    hi timW,

    thank you again for taking the time to help me. after doing all the steps as instructed, i opened up the firefox browser and a blank i.e. browser launched again. i don't even dare open up i.e. because the problem is crazier when using that browser.

    i followed the steps in your last message and when i got to the part of selecting the O4 boxes, i couldn't find any of the spybot boxes in the list.

    also, after doing that avenger thing, there seemed to be a problem finding or deleting 2 of the files: C:\WINDOWS\SYSTEM32\memouint.exe and C:\WINDOWS\SYSTEM32\memolxsk.dll

    i really hope we can fix my computer. and i thank you again for all your help!

    should i run spybot and avg again in the meantime?
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you infact take the code that I gave you and drag and dropped it on the RenV.exe ?

    Let's do a few more things:
    Now Copy the bold text in the below code box to notepad. Save it as Log.txt to your desktop. (It must be on your Desktop).

    Code:
    C:\Program Files\Common Files\Symantec Shared\ccApp .exe
    
    * Now using your mouse, drag Log.txt onto RenV.exe
    * When finished, RenV.exe will produce a new log named Log.txt on your Desktop I will ask for this log later.

    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger and the new log from RenV.
     
  7. kobiemi

    kobiemi Private E-2

    yes, i did drag and drop the code as you instructed. here are the next set of files. thanks again for all your help!
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below quote box into it:
    Code:
    File:
    C:\Program Files\Common Files\Symantec Shared\ccApp .exe
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    use your mouse to drag CFscript.txt on top of ComboFix.exe
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt

    Attach the Combo Log and tell me how things are running.
     
  9. kobiemi

    kobiemi Private E-2

    Ok, I followed the instructions exactly...

    After the computer rebooted, I got an error message about msnmsgr not being found. Also, when I opened up firefox to log into this forum, the blank i.e. browser opened up again.

    The log is attached.

    Thanks again for all your help.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    In Firefox...under tools / options...on the general tab..what is set for the home page?
    MSN Messenger is showing in your logs ...so I'm not sure why it is giving you the error message.
    Also, what is this:
    C:\WINDOWS\system32\drivers\ULTRAA.sys --->? Memory stick?

    We still have to remove a few stubborn files:
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.
    Then attach the new logs:
    * c:\avenger.txt
    * C:\MGlogs.zip
     
  11. kobiemi

    kobiemi Private E-2

    1) Home page for Firefox: http://en-US.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official

    The error message reads as follows: msnmsgr.exe - Unable to locate component: The application has failed to start because msidcrl.dll was not found. Re-installing the application may fix this problem.

    2) I'm sorry but I have no idea what this is: C:\WINDOWS\system32\drivers\ULTRAA.sys --->? Memory stick?

    3) After I ran AVenger, I checked my C drive and C:\WINDOWS\system32\drivers\core.cache.dsk is still there. When I tried to delete it, I get the following message: Cannot delete core.cache: It is being used by another person or program. Close any problems that might be using the file and try again.

    I don't of any programs running so I don't know how to fix this.

    Thanks again.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Copy the bold text below to notepad. Save it as Log.txt to your desktop.
    Code:
    C:\Program Files\Common Files\Symantec Shared\ccApp .exe
    
    * Now using your mouse, drag Log.txt onto RenV.exe
    * When finished, RenV.exe will produce a new log. Attach the new Log.txt to your next reply.

    Now go to Bitscan link: agree to the license and then select Scan. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files. Once Bitdefender completes the scan:

    Click-on the Detected Problems tab. Then select Click here to export the scan report

    When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.
     
  13. kobiemi

    kobiemi Private E-2

    Ok, completed the tasks as instructed.

    While I was running Bitscan, a virus alert from Norton AV popped up that said: Virus name: W32.trats!inf Unable to repair this file. Access to this file was denied.

    I had to click the ok button a number of times to get rid of that pop up alert.

    Also, wasn't sure if you wanted me to attach the bdscan.txt but I did anyway.

    Note: I had to use IE to download bitscan and whereas before when using IE a crazy number of browsers with all different kinds of ads would launch, this time, it acted like when i use Firefox -- blank IE browsers would open up whenever i clicked on a link -- so although it's not as crazy as before, it seems to be getting better?

    Thanks.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Bitdefender just removed all the malware in the system restore files and the quarantine folders.

    We still need to remove that last Vundo file.

    Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below quote box into it:
    Code:
    C:\Program Files\Common Files\Symantec Shared\ccApp .exe
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    use your mouse to drag CFscript.txt on top of ComboFix.exe
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    *Attach this log to your next reply.

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  15. kobiemi

    kobiemi Private E-2

    Here's the combofix log. Was I supposed to attach anything else?
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The core.cache.dll is back...so please run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  17. kobiemi

    kobiemi Private E-2

    Thanks. Log files attached.
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, we have the same two to remove.

    But first, run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now Copy the bold text in the below code box to notepad. Save it as Log.txt to your desktop. (It must be on your Desktop).
    Code:
    C:\Program Files\Common Files\Symantec Shared\ccApp .exe
    
    * Now using your mouse, drag Log.txt onto RenV.exe
    * When finished, RenV.exe will produce a new log names Log.txt on your Desktop I will ask for this log later.

    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger and the new REnV log.
     
  19. kobiemi

    kobiemi Private E-2

    Ok, here are the new log files.

    Thanks.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Norton Antivirus is infection and it cannot be repaired. This requires that all of Norton be uninstalled and then this should be run afterwards: Norton Removal Tool (SymNRT)

    Then you should reboot and continue on with the below steps.


    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_03


    Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  21. kobiemi

    kobiemi Private E-2

    Hi,

    I got as far as running avenger and when my computer rebooted, it took a while to do a scan disk. (It has never done this before.) Then I got an error message that is attached. I don't know what to do next.
     

    Attached Files:

    • err.txt
      File size:
      855 bytes
      Views:
      6
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does it give you this error message after you physically power down and then do a reboot?

    Does it give it to you if you try to boot in safe mode?

    Does last known good boot work?

    Do you have your Windows XP bootable CD?
     
  23. kobiemi

    kobiemi Private E-2

    1) Yes. I physically powered down then powered up and the computer goes through a scndsk process (5 stages). Then I get a blue screen that reads:

    A problem has been detected and windows has been shut down to prevent damage to your computer.

    Session5_initialization_failed

    If this is the first time you’ve seen this Stop error screen, restart your computer, if this screen appears again, follow these steps:

    Check to make sure any new hardware or software is properly installed. If this is a new installation, aks your hardware or software manufacturer for any windows updates you might need.

    If problems continue, disable or remove any newly installed hardware or software. Disable BIOS memory options such as caching or shadowing. If you need to use Safe Mode to remove or disable components, restart your computer, press F8 to select Advanced Startup options, and then select safe mode.

    Technical Information:

    *** STOP: 0x00000071 (0x00000000, 0x00000000, 0x00000000, 0x00000000)

    2) After I got this message, I powered down again and tried the last known good boot and got to the same error message.

    3) Then I powered down again and when the machine started, I hit F8 and a black screen with a list of system32 things (I think) appeared and nothing happened so I just turned off the computer and quit.

    4) I have something called Microsoft Windows XP Reinstallation CD.

    Please help.

    Thank you.
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What you are going to need to do is use your recovery cd ...when you boot with the cd in the drive ...then hit enter to boot to the cd ...it "should" give you an option to either do a fresh installation or allow you to do an installation that keeps your settings and data ....let me know if it does.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on all info I can find this probably occurred due to the scan disk (chkdsk) that was run after that reboot when the last Avenger fix was run. The fix with Avenger was not a problem we do this dozens of times per day. Something occurred within your OS to cause a chkdsk to run and some kind of corruption occurred.

    We already tried last know good. And I think we tried safe boot mode but all you said was you pressed F8. Did you ever actually choose safe boot mode or did the PC bypass the Window where options for the type of boot appear?

    Can you give me the names of the last 5 or 6 files you say you saw appearing on the screen from the system32 folder.



    Next step I want you to try doing is the below using your Windows Reinstallation CD.

    Start Recovery Console


    To start Recovery Console, do the following:
    • Start your computer with the Windows Reinstallation CD in the CD drive.
      • Make sure the boot order in your BIOS is set to boot from CD before booting from your hard disk
    • At the Welcome to Setup screen, press R to start the Recovery Console.
    • Select the Windows installation that you want to repair (which should just b C:\Windows), and then press ENTER
    • Type the Administrator password, and then press ENTER. If the administrator password is blank, just press ENTER.
      • Note: The Recovery Console uses the Administrator password that you configured when you installed Windows XP.
    • Once you get to the command prompt window of the Recovery Console enter the below commands ech followed by the enter key.
    cd C:\Wiindows\System32

    ren Ntoskrnl.exe ntoskrnl.new
    cd C:\Windows\$NtUninstallKB931784$
    copy Ntoskrnl.exe C:\Windows\system32\
    Exit

    The exit should cause a reboot. Can you boot now?


    If you wish to have more information about the Recovery Console, see the below:

    http://support.microsoft.com/kb/307654/en-us
     
  26. kobiemi

    kobiemi Private E-2

    Ok, I put the CD in and powered up the computer and it came to the same screen that says:

    We apologize for the inconvenience, but Windows did not start successfully. A recent hardware or software change might have caused this.

    If your computer stopped responding, restarted unexpectedly or was automatically shut down to protect your files and folders, choose Last Known Good Configuration to revert to the most recent settings that worked.

    If a previous startup attempt was interrupted due to a power failure or because the Power or Reset button was pressed, if you aren’t sure what caused the problem, choose Start Windows Normally.

    Safe Mode
    Safe Mode with Networking
    Safe mode with Command Prompt

    Last Known Good Configuration (your most recent settings that worked)

    Start Windows Normally

    Use the up and down arrow keys to move the highlight to your choice.

    --------------
    So I click on Last Known Good Configuration and it goes through the same routine of CHKDSK (5 stages). It says the files are all clean. Then I get the same error message: Session5_Initialization_Failed.

    It's like it doesn't recognize that the cd is in the drive.

    What should I do next? Should I try the Safe Mode?
     
  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please try the steps that Chas posted in the previous post. Let us know if that was helpful.
     
  28. kobiemi

    kobiemi Private E-2

    1) As soon as I power up the computer, I get to the screen where I have to choose how I want to boot up (Safe Mode, Safe Mode with Networking, etc)

    2) If I click on Safe Mode, a black screen with a list: (the last 6 are)

    multi(0)rdisk(0)partition(2)\WINDOWS\System 32\Drivers\drvmcdb.sys
    multi(0)rdisk(0)partition(2)\WINDOWS\System 32\Drivers\PxHelp20.sys
    multi(0)rdisk(0)partition(2)\WINDOWS\System 32\Drivers\KSecDD.sys
    multi(0)rdisk(0)partition(2)\WINDOWS\System 32\Drivers\Ntfs.sys
    multi(0)rdisk(0)partition(2)\WINDOWS\System 32\Drivers\NDIS.sys
    multi(0)rdisk(0)partition(2)\WINDOWS\System 32\Drivers\Mup.sys

    3) Re: Start Recovery Console

    I don't know how to even begin because the first screen I get when I power up the computer is the one noted in my last thread where I have to choose how to boot up.

    I have the CD in the drive.

    I don't know what this means or how to do this:

    "Make sure the boot order in your BIOS is set to boot from CD before booting from your hard disk "

    Please tell me how to proceed.

    Thank you.
     
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    When you first boot up ..there is usually a brief message about hitting a key to get into the bios menu ...could be F2 or F11 ....from there you will go to the (?) 2nd or 3rd tab for the startup order ...you scroll thru to make the first choice the cd drive..then hard drive ...F10 to save the changes and exit ...it should then boot into the cd.
     
  30. kobiemi

    kobiemi Private E-2

    Ok I finally got to that Boot Device Menu by hitting F12 as soon as I powered on.

    Here were the choices:

    1. Normal
    2. Hard-Disk Drive C:
    3. IDE CD-ROM Device

    4. System Setup
    5. IDE Drive Diagnostics
    6. Boot to Utility Partition

    Enter a Choice.

    I chose 3 and hit enter.

    Press any key to boot from CD.

    I hit Enter.

    Blue screen appears: Windows Setup

    On the bottom of the screen: Setup is loading files.

    Another blue screen titled: Windows XP Home Edition Setup

    Welcome to Setup.
    This portion of the Setup program prepares Microsoft Windows XP to run on your computer.

    -To set up Windows XP, now press ENTER.
    -To repair a Windows XP installation using Recovery Console, press R.
    -To quit Setup without installing Windows XP, press F3.


    Per Chas' post below, I press R.

    A black screen appears: Microsoft Windows XP REcovery Console.
    The Recovery Console provides system repair and recovery functionality.
    Type Exit to quit the Recovery Console and restart the computer.

    1: C:\WINDOWS

    Which Windows installation would you like to log onto
    <To cancel, press ENTER>? __

    I type in 1 and hit enter.

    Then I get this:

    C:\WINDOWS>__

    Now what?

    (This is the second time I got this far. The first time I tried to type in all of the things in Chas' post starting with: cd C:\Wiindows\System32 but I'm not sure I did it correctly because when I got to the last step and typed Exit, the computer rebooted and it did a chkdsk again and I got to the same awful blue screen with the Session5_Initialization_Failed message.

    What did I do wrong?
     
  31. kobiemi

    kobiemi Private E-2

    I just tried to redo the last step in Chas' thread:

    cd C:\Wiindows\System32

    ren Ntoskrnl.exe ntoskrnl.new
    cd C:\Windows\$NtUninstallKB931784$
    copy Ntoskrnl.exe C:\Windows\system32\
    Exit

    ------------

    I got a message asking to overwrite Ntoskrnl (Y/N?)
    I hit Y
    And it said: 1 file copied.

    I then typed in Exit and got the black screen: We apologize for the incovenience... message.

    What am I doing wrong?
     
  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have another system that you could slave the drive to?

    Back in the recovery console

    C:\Windows> now type cd =
    C:\Windows>cd --> to get you to:
    C:\> NOw type each command and hit enter after each:
    C:\>ATTRIB -H C:BOOT.INI
    C:\>ATTRIB -R C:BOOT.INI
    C:\>ATTRIB -S C:BOOT.INI

    Then type:
    C:\>DEL BOOT.INI

    C:\>BOOTCFG /REBUILD

    you will now get a system file rebuild at the end of which you will be back to:

    C:\>

    and type:

    C:\>
    CHKDSK /R /F


    Then after that is done:


    C:\>FIXBOOT


    Finally exit and see if you can boot.
     
  33. kobiemi

    kobiemi Private E-2

    it didn't work.

    i tried to follow your steps below but couldn't exactly because i got different prompts along the way. here's what happened:

    After I got to this point: C:\>BOOTCFG /REBUILD

    Here's what happened:

    Scanning all disks for windows installations.
    Please wait, since this may take a while…

    The Windows installation was successful.

    Notes: These results are stored statistically for this session. If the disk configuration changes during the session, in order to get an updated scan, you must first reboot the machine and then rescan the disks.

    Total identified Windows installs: 1

    [1]: C:\Windows
    Add installation to boot list? <Yes/No/All>:

    Entered: Y

    Enter Load Identifier: Microsoft Windows XP Home Edition

    Enter OS Load Options: /fastdetect

    (I got the information for the 2 prior steps from the following site: http://support.microsoft.com/kb/330184)

    C:\>CHKDSK /R/F
    Volume created 09/10/04 12:39 p
    The volume Serial Number is 642e-ee22
    CHKDSK is checking the volume…
    CHKDSK is performing additional checking or recovery…
    CHKDSK is performing additional checking or recovery…
    CHKDSK is performing additional checking or recovery…
    CHKDSK has finished checking the volume.
    74397012 kilobytes total disk space.
    57530684 kilobytes are available.

    4096 bytes in each allocation unit.
    18599253 total allocation units on disk.
    14382671 allocatin units available on disk.

    C:\>FIXBOOT

    The target partition is C:.
    Are you sure you want to write a new bootsector to the partition C: ?

    Entered: Y

    FIXBOOT is writing a new boot sector.

    The new bootsector was successfully written.

    C:\>EXIT

    Please select the operating system to start:

    Microsoft Windows XP Home Edition
    Microsoft Windows XP Home Edition

    Use the up and down arrow keys to move the highlight to your choice.
    Press ENTER to choose.

    For troubleshooting and advanced startup options for Windows, press f8.


    When I selected either one of the XP choices, it does a chkdsk again and when it's done, I'm back to square one:

    Session5_Initialization_Failed.

    What should I do next?
     
  34. kobiemi

    kobiemi Private E-2

    also the answer to your question is no, i don't have another system to save my drive to.

    at this point, i'm just hoping to get my computer up and running again. i mainly use it for email, MS Office apps (word, excel), internet. all my pictures were on it too. i would hate to lose all my documents but if that's the only way to fix it, i guess i have to live with it. i'm not a technical person at all so i hope i'm doing everything correctly.

    thanks again for all your help.
     
  35. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    My only other suggestion is to do a repair install ....so when you boot to the cd ...your first choice is:


    -To set up Windows XP, now press ENTER. ---> Chose this!!
    -To repair a Windows XP installation using Recovery Console, press R.
    -To quit Setup without installing Windows XP, press F3.

    You will go to the agreement page (F8 to agree) ..then it will find the previous install of xp ...that is when you opt for Repair (R) ...let it rip.

    Tell me if this works or you have problems with it.
     
  36. kobiemi

    kobiemi Private E-2

    Does this mean I will lose all my data and my pictures? Is there a way to salvage it? (I know, stupid me, didn't do a backup.)
     
  37. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Repair install ...if it works ...will preserve all your files and data ....and malware.
     
  38. kobiemi

    kobiemi Private E-2

    eeewwww malware.

    well, i've done the repair install and it rebooted and is now doing a chkdsk. it's on stage 5. crossing my fingers. will keep you posted.
     
  39. kobiemi

    kobiemi Private E-2

    After running the chkdsk succesfully, i got to another dreaded blue screen but this time it says:

    STOP: c000021a unknown hard error
    unknown hard error.

    what should i do next?

    thanks.
     
  40. kobiemi

    kobiemi Private E-2

    also, am i supposed to be taking out the windows xp cd whenever the computer reboots?
     
  41. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  42. kobiemi

    kobiemi Private E-2

    Here's what happened after I did the repair install:

    After running the chkdsk succesfully, i got to another dreaded blue screen but this time it says:

    STOP: c000021a unknown hard error
    unknown hard error.

    what should i do next?

    thanks.
     
  43. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  44. kobiemi

    kobiemi Private E-2

    no good news yet.

    i was finally able to copy the seagate to a cd.
    turned on the computer.
    hit F12
    got to the boot device menu.
    selected the ide cd rom device

    then it tells me:

    hit F1 to reboot; F2 for setup utility

    i hit F1 and nothing happens. i get the same message.

    i hit F2 and the setup menu appears.

    so i changed the boot sequence so that the cd rom is first, c drive is second and try again but get the same message:

    hit F1 to reboot; F2 for setup utility.

    am i totally screwed? all this damage from a virus?
     
  45. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are saying that once you select the cd as first boot device ...then hit f10 to save and exit ...it should reboot to the cd ....I suspect you are not saving the changes in the Bios menu.
     
  46. kobiemi

    kobiemi Private E-2

    I did save the changes but then the computer reboots and it goes into that chkdsk again (which takes a while) and then I get that same error message:

    STOP: c000021a unknown hard error
    unknown hard error.

    what should i do next?
     
  47. kobiemi

    kobiemi Private E-2

    Also, why does it run the chkdsk every time i boot up or reboot? is there a way to stop this?
     
  48. kobiemi

    kobiemi Private E-2

    Right now the only thing I can boot to is the Windows CD.
     
  49. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try removing any and all accessories (printers / scanners / etc.) and try rebooting.
    Do you feel capable of opening the box and removing the hard drive so that we can instruct you how to put it into another computer as a slave drive?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds