WinAntiVirus-No Safe Mode-Service won't start

Discussion in 'Malware Help (A Specialist Will Reply)' started by stevelasvegas, Sep 10, 2006.

  1. stevelasvegas

    stevelasvegas Private E-2

    I have read and run the procedures described in Read & Run Me.

    1. Browser pages flash and disappear quickly or sometimes an ad page will show up. I do see winantivirus at the beginning of some url's like - http://www.winantivirus.com/pages/s...a98_cc5f0d87+5235d72081a94d118dc18059254fc84b
    2. When I try to go to safe mode, I get logon screen and windows starts. I start to see desktop icons. If I wait, the icons dissappear and the border safe mode text on the perimeter of the screen stay.
    3. When trying to install a program (Memeo) I get the msg "Service Memeo (BMUservice) failed to start. Verify that you have sufficient privileges to start system services."

    After realizing I was having these problems, I used restore points thinking I could get back to something stable. So I have some apps that are not loading. I guess that can be fixed by reinstalling, although, Memeo is one of those apps that was working and after the restore wasn’t working. I tried to reinstall, and the above error is encountered.
    Now I am trying this forum. Thank you for your assistance.



    From Belarc:
    Operating System System Model
    Windows XP Professional Service Pack 2 (build 2600) Enclosure Type: Desktop
    Processor a Main Circuit Board b
    3.27 gigahertz Intel Pentium 4
    16 kilobyte primary memory cache
    1024 kilobyte secondary memory cache Board: http://www.abit.com.tw/ Fatal1ty AA8XE (Intel Alderwood-ICH6R) 1.x
    Bus Clock: 204 megahertz
    BIOS: Phoenix Technologies, LTD 6.00 PG 10/17/2005
    Drives Memory Modules c,d
    448.78 Gigabytes Usable Hard Drive Capacity
    268.12 Gigabytes Hard Drive Free Space

    SONY DVD RW DRU-720A [CD-ROM drive]
    3.5" format removeable media [Floppy drive]

    BELKIN USB 2 HS-CF USB Device [Hard drive] -- drive 2
    BELKIN USB 2 HS-MS USB Device [Hard drive] -- drive 3
    BELKIN USB 2 HS-SD/MMC USB Device [Hard drive] -- drive 5
    BELKIN USB 2 HS-SM/XD USB Device [Hard drive] -- drive 4
    Maxtor 6B300S0 [Hard drive] (300.08 GB) -- drive 1
    Steve's Raid [Hard drive] (148.70 GB) -- drive 0
    USB DISK 20X USB Device (518 MB) -- drive 6 2048 Megabytes Installed Memory

    Slot 'A0' is Empty
    Slot 'A1' has 1024 MB
    Slot 'A2' is Empty
    Slot 'A3' has 1024 MB
     

    Attached Files:

  2. stevelasvegas

    stevelasvegas Private E-2

    This is working now - 3. When trying to install a program (Memeo) I get the msg "Service Memeo (BMUservice) failed to start. Verify that you have sufficient privileges to start system services."

    cli.exe and rss newsreader were not loading (probably due to the system restore point I fell back to). After reinstall ATI drivers, I was able to reinstall Memo and RSS reader just starting working on its own. Problem 1 and 2 are still not corrected.
     
  3. stevelasvegas

    stevelasvegas Private E-2

    Now, after reading the HJT log, I saw the "pmkhe.dll" file listed. I searched MG and found the Vundofix posts. I ran it and had it remove the files it found. Now I can get into safe mode (horray!)

    I will monitor my browser problem to see if that is fixed also.

    I am posting a new HJT log. If someone could look at it please and give me any further advice, I would appreciate it.
    Thanks
     

    Attached Files:

  4. stevelasvegas

    stevelasvegas Private E-2

    By the way, what app would have detected the pmhke.dll vundo problem before it was allowed on my system?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    No applications appear to actually stop it from being installed. That is because in most cases the user (you) do something that allows it to be download and installed.

    Are you still having malware problems? If so, attach the other two logs (GetRunKey and ShowNew) requested in the READ ME and also a new HJT log.
     
  6. stevelasvegas

    stevelasvegas Private E-2

    Thanks for the quick reply. Sorry I am late in getting back to you; preoccupied.

    I am pretty sure the malware issue is gone, but other problems are presenting themselves.

    The main problems I am having now are;
    1. When I run windows update, it wants to install Microsoft Windows Installer 3.1. After performing the installation, I get a message "Updates were unable to be successfully installed".
    and
    2. Services necessary for open file backups will not start.

    I atribute these behaviors, and other behaviors of "missing" or "misconfigured" applications is that when I first recognized the malware issue, I used previous restore points to get back before the malware issue presented itself. Anyway, although my system is packed with apps and such, I am contemplating doing a clean install of Windows XP Pro, and starting over. It seems that over the coarse of a year or two, on an active system like mine, (one which many apps are loaded, evaluated and discarded or kept), some sort of malfunction forces me to start over.
    Given that, I am mentally preparing for the process of a clean install. Do you have any recommendations for me that would be a guide during this process. I am thinking;
    1. Install the operating system.
    2. Install Anti-Virus and malware protection.
    3. Update the operating system.
    4. Reinstall applications.

    I have backups and images of my drives; that is where I will regain my data.

    Should I install an application monitoring app so I can see all of the changes that are made to my system during installation? (Maybe this would help if I have problems with other areas of my system after installation of applications).
    Should I install a software firewall (I have a router)? (I have found them to be sometimes confusing. Like when you have to decide to allow a request access or not).

    Any pointers would be appreciated.

    Thanks for your help.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Before you begin the reinstall:
    • make sure you backup all necessary user data and application configuration settings (like your Favorites etc).
    • make sure you have all the software that you will need to get your system protect BEFORE reconnecting to the internet. Use this link How to Protect yourself from malware! as a guide for things that you should have downloaded and backed up to a CD to reinstall from. It is important to protect your PC BEFORE you reconnect to the internet. I have seen improperly protected/updated PCs get infected in less than 10 seconds of reconnection to the internet.
    • make sure you DO USE a software firewall. The added protection and control that they add is important. They also give more visibility into what is going on.
    • make sure you have current reference file updates for your antivirus & antispyware applications to also reinstall before connecting to the internet.
    • it is best to fdisk (repartition) a PC and then reformat, and reinstall all.
    I don't find them to be that much use and they amount of changes made can be significant and to complex for you to bother trying to track. If you are constantly making changes to PCs and need to periodically go back to a point in time, just doing what you mentioned (having drive images) is something that many people use. A couple of spare hard disk (or a large spare hard disk) to store a few images on is a fast way to get back to a particular point.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds