Worked through the cleaning process, still problems.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Sisu, May 19, 2009.

  1. Sisu

    Sisu Private E-2

    Hi

    I started having problems the day before yesterday. I got bluescreens with the message:
    DRIVER_IRQL_NOT_LESS_OR_EQUAL
    *nvatabus.sys - address .. ... .

    Yesterday when i fired up my computer Everything was screwed. I got this message at start up saying (translated from Swedish) "One of the files in the register was restored with help from a log or an alternative version". My startmeny was gone. And i could hardly do anything.

    A friend of mine recommended to try superantispyware. When trying to install I got the message "The system administrator has set policies to prevent this installation". I googled it and that's how I ended up here.

    I've now completed (kind of) your cleaning guide with the help of my other computer as this is the first time I even can access firefox.
    I did have some problems on the way though.

    Superantispyware was not installed due to the above mentioned reason. I also tried the guide to enable windows installer, but that folder didn't exist. I tried to enable windowsinstaller from msconfig, but after restart it was stopped again.

    Malwarebytes was also unsuccessful. I got some error message of probably old version. Downloaded the newest version, installed it with no errors BUT the installation folder was empty.

    Combofix, now this is when things started to happen. Combofix passed with no errors (except that system restore was not detected, but successfully installed). After this I actually got my startmeny back and was able to open copy paste and such (haven't done anything else).

    MGtools passed successfully.

    Now here I am. Still getting this registry message when logging to windows.

    Ps: Don't know what caused this. Was like this after my girl had been here (easy to blame her :p).

    Anyway I'd appreciate any help and i look forward for your replies.

    Regards

    Sisu
     
  2. Sisu

    Sisu Private E-2

    logs...
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    It looks like some of your Windows system files could be infected. Or the Swedish version of Windows has different file sizes for some programs. I would not know this for sure since I don't have a Swedish version of Windows. Do you have a bootable copy of your Windows XP SP3 CD? If not and SP3 CD, how about an SP2 CD?

    Note: You must put ComboFix.exe on your Destkop as requested in the instructions otherwise you will not be able to follow steps we will be giving later.

    Some of you problems are probably not malware related especially if your Windows system files are found to be clean.

    Please try running this: Resetting Registry and File Permissions and reboot where requested.

    After running the above, see if you can run SUPEAntiSpyware and Malwarebytes. Attach the logs if you can run them.
     
    Last edited: May 21, 2009
  4. Sisu

    Sisu Private E-2

    Hi, thanks for your reply. I've been busy the last days and haven't had the chance to try solving this until now.

    I do have a bootable XP CD with SP2, somewhere...

    I followed the steps you mentioned.

    After resetting the registry I got rid of the message that kept popping up every time I logged in to windows.

    I successfully installed SuperAntiSpyware, but it seems to have trouble finishing the scan on C:. It Scans my other drives with no infections found. But when i include C: it kind of freezes while scanning some (different ones every time) files. I can move the mouse but that's about it. And only thing that helps is a restart using the reset button.
    *After these restarts it can take ages for windows to load if it loads at all.*

    I installed Malwarebytes and scanned successfully with no infections. See attached log.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Okay then find it since you may need it while doing the below.

    Click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System Rile Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it.

    It still is not looking like you have malware problems but I'm still concerned about the file size that do not look correct. But again, this could be just due to the Swedish version of Windows.
     
  6. Sisu

    Sisu Private E-2

    Was just about to try this last thing you suggested. But windows wont start.

    When i try safe mode i get the following message:

    multi<0>disk<0>rdisk<0>partition<0>WINDOWS\system32\ntoskrn1.exe

    ......

    Btw what files are larger than usual? I can check the size of them on another computer with swedish xp.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What exactly happens when you try to boot in normal mode? Do you have your Windows bootable CD?

    In safe boot mode, does it also report any files to be missing? Like possibly hal.dll ? Did it say ntoskrnl.exe was missing (note it is a lower case L not the number one at the end of the file name)?



    The below are a couple I quickly noticed. There are thousands of files though and I obviously have not compared each one.

    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\dllcache\explorer.exe
    C:\WINDOWS\system32\kernel32.dll
    C:\WINDOWS\system32\dllcache\kernel32.dll

    Please run just MGtools on your other PC and attach the log from it. Is it running the same version of Windows and the same service pack level? The log will tell me this anyway.
     
  8. Sisu

    Sisu Private E-2

    After the part where it chooses wich OS it will run the screen just goes black and nothing happens from there. At the moment There's 2 options in that list.
    microsoft windows recovery console
    microsoft windows xp

    I've found my bootable cd.

    Now when i try to boot in safe mode same thing happens as when i try to boot in normal mode.

    Maybe i should move my raid0 setup to my other comp and try to save some files, and after that do a new install....

    BTW I've also tried accessing the installation by using the recoveryconsole via the xp install wizard. But the system hangs after i enter my password for the login.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This would be the safest and most reliable thing to do. DO NOT BACKUP anything that is an executable program (EXE, ZIP, MSI, ....etc) because they may well be infected and if you reinstall them, you will just spread the infection again.
     
  10. Sisu

    Sisu Private E-2

    I managed to backup everything necessary. And I'm also done with the fresh install.

    I'd like to thank you chaslang for you efforts. Guess there wasn't much left to do when the computer stopped booting up!

    Thanks again and good luck with future problem solving! I will certainly be more careful in the future and I hope this is the last time you see me! :)

    Regards

    Sisu
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    So do we. ;) And to help with that, it would be a good idea for you to work thru the below:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds