WinAV2008 with stop error

Discussion in 'Malware Help (A Specialist Will Reply)' started by cjon, Dec 3, 2008.

  1. cjon

    cjon Private E-2

    I have a laptop that boots with a critical stop error: 0xC000021A. I searched that error on the MS site and found it to be most often a Winlogon error.

    I can boot this machine in the safe mode only. When I do, I see a WinAntivirus2008 icon on the desktop.

    I tried to install and run your standard group of cleaners. Malwarebytes installed, but wouldn't update. it found quite a few bad files. Spybot S&D installed and updated. It also found several items. SuperAntispy and Adaware refused to install, even when renamed because the "Administrator has set policies to prevent this installation." googling that phrase got me several ideas, none of which worked. This is XP Home, SP2, and there are no group policie settings listed in the registry.

    I was able to install and run combofix and MGtools, and my logs are attached. I appreciate your help.

    CJon
     

    Attached Files:

  2. cjon

    cjon Private E-2

    one more log
     

    Attached Files:

    Last edited: Dec 3, 2008
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is this the same PC you just recently posted about and had cleaned?

    Uninstall the below software:
    Java 2 Runtime Environment, SE v1.4.2_05
    Spybot - Search & Destroy 1.4
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    What is the below file on your Desktop?
    Code:
    "C:\Documents and Settings\Administrator\Desktop\"
    wwa.exe       Jun  7 2008    19153264  "wwa.exe"
    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    You are way out of date with Malwarebytes. Please run Malwarebytes and select the Update tab and then click the Check for Updates button to update it to the current version and database. Then perform a full scan of your system (not a quick scan). Fix what it finds and attach the new log.

    Now look for the below file and delete it if found:
    c:\windows\system32\ffln.dll

    Now download and run the current version of MGtools from here: MGtools.exe Attach the new C:\MGlogs.zip file.
     
    Last edited: Dec 6, 2008
  4. cjon

    cjon Private E-2

    This is a different machine than last week.
    As noted before, I was unable to boot this machine except in the safe mode, and had a number of things disabled. One of those was add-remove programs.

    I have remedied that, and have now removed the items you noted:
    Java 2 Runtime Environment, SE v1.4.2_05
    Spybot - Search & Destroy 1.4
    Viewpoint Media Player

    I was able to successfully run the registry edit.

    WWA.exe was the installation exe for Adaware, which I had renamed in an (unsuccessful) effort to get it to install.

    I got mbam to install, but it wouldn't update. Spybot did install and update. Between them, they removed enough that I was able to get Avast AV to install and run. It found 5 infected system files: explorer.exe, lsass.exe, services.exe, spoolsv.exe and svchost.exe. I was able to boot the Recovery Console from an XP Home installation disk and replace those files. That let Windows boot normally.

    I installed and updated clean copies of MBAM, SAS, Adaware, Spybot and Combofix. I ran those scans and re-ran MGtools and the results are attached. (logs from Avast, SAS, MBAM and Spybot are in the Otherlogs zipfile).
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have both AVG7.5 and Avast antivirus programs installed. As requested in the first instructions of the READ & RUN ME, you must uninstall one of these immediately.


    Since you had a few infected system files, it would be good idea to do the below to possibly fix others that may be corrupted.

    Click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System Rile Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it.

    Your logs are clean otherwise. Is everything working okay now?
     
  6. cjon

    cjon Private E-2

    Thanks, Glad to hear it reads clean.
    The AVG was disabled (by the bug, I assumed) It has since been uninstalled. I will run SFC and see if it finds anything else.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  8. cjon

    cjon Private E-2

    Oddly, the SAS seems to be running in the protective mode, at least the icon appears in the systray and it shows up in the process list of task manager. I think I'll leave it for now, unless you think it is something else masked as SAS.

    Thanks for the help on this one. I suspect I'll be back soon. My wife brought a machine home from work Friday. I haven't started on it, but it sounds like another WinAV2008 plus Vundo.

    Thanks for everything. CJon
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No that does not mean you are protected. It just means the tray icon to start the program is loaded and that is all. You will notice that if you right click on the tray icon and select exit to terminate SAS, and then re-ren SAS from All Programs or from your Desktop icon that the program does not actually open up on your Desktop to do a scan. It just loads the tray icon and then you have to double click it to get a scan to run. This is a feature designed into the program to try and stop malware from preventing the loading of SAS. They feel if it is already running, that malware will be less likely to stop it from running.

    You're welcome. Surf safely!
     
  10. cjon

    cjon Private E-2

    Thanks for your help.

    CJon
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem! ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds