BleepingComputer.com: BSOD - Corrupt files from infection (clean now)

Jump to content

  • 4 Pages +
  • « First
  • 2
  • 3
  • 4
  • You cannot start a new topic
  • You cannot reply to this topic

BSOD - Corrupt files from infection (clean now) can only boot into safe mode

#46 User is offline   dsk6320 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 96
  • Joined: 08-December 11

Posted 31 January 2012 - 10:36 PM

Strange, when i inserted the link it showed up in the code but didnt on the page once posted as a clickable link so i had to go back and just add the url to the zip.

Also i updated flash yesterday and it shows the old version on that log, but accoring to adobe flash website.. "You have version 11,1,102,55 installed"?

#47 User is offline   dsk6320 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 96
  • Joined: 08-December 11

Posted 07 February 2012 - 11:42 AM

Morning, has been few days.. any new ideas or suggestions?

#48 User is offline   AustrAlien 

  • Inquisitor
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 4,713
  • Joined: 15-July 09
  • Gender:Male
  • Location:Cowra NSW Australia

Posted 08 February 2012 - 06:46 AM

You're quite right: It has been a few days! My sincere apology for the extended delay in responding. It has not been deliberate. Real life sometimes over-rules my best intentions. Having spent time away from the computer, it seems extra difficult getting back into and continuing pre-existing topics!

I will ask that you hold off on trying to solve the Windows Updates issue for the time being. There are a number (many) people with the same problem, and work is underway on many fronts to try and sort out what the malware is doing to create the problem, and how it may be fixed. I will let you know of any progress that in that endeavour.

What is the situation with Avast!/installing an antivirus on the system? I noticed in the Event logs that Avast! was present on the system, and since you hadn't reported having installed it yet, I was wondering if it was left-over from a previous installation of Avast!. Perhaps you did already install it?

Would you please bring me up-to-date with what has happened with the system since we last communicated, and if you have been using it or testing it, let me know how it is running and what problems you have come across ... and refresh my memory!

I know there is one startup entry still there for some malware ... which we will have to remove sometime:
In the msinfo32 report under Startup Programs

Quote

ttool c:\windows\9129837.exe HOMEPC\Donnie HKU\S-1-5-21-1109359870-4165961621-2860427330-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

This post has been edited by AustrAlien: 08 February 2012 - 06:57 AM

AustrAlien
Google is my friend. Make Google your friend too.

Posted Image

#49 User is offline   dsk6320 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 96
  • Joined: 08-December 11

Posted 08 February 2012 - 08:38 AM

Good Morning

No problem, is compeletely understood.. real life always takes priority, and is always good to take a breather and clear your head from the computer from time to time :thumbup2:

Avast was uninstalled so maybe it was a ghost image? i did d/l the install exectutable but didnt install it to make sure it wasnt/wouldnt interfere with any of the programs/fixes that we was trying at the time.

I havent really used that computere since our last attempts to fix the windows update, I powered it down and havent used it til yesterday when i installed Avast Antivirus and Canon Printer software then deleted a couple large game files (flight sim 4, entropia universe, & star wars galaxies) since i havent used them in few years and dont play games on that computer anymore.

As far as i can tell the computer is running everything fine with the exception of windows update and the flash player update on that last security check log(updated to 11.1.102.55 but log still shows prev version 10.0.45.2), the few things ive tried on it all seem to be running normal.. email, general web surfing, printing, etc. (i may even try reinstalling the sound card unless you think i should hold off on that for a bit?)

#50 User is offline   AustrAlien 

  • Inquisitor
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 4,713
  • Joined: 15-July 09
  • Gender:Male
  • Location:Cowra NSW Australia

Posted 10 February 2012 - 04:14 AM

Go ahead and install the sound card and use the computer as normal. Let us know if you find any new issues.

Give it a couple of days .... or however long you need ... and then post back. I will then ask if gringo_pr will check over the system again now that you are able to load Windows normally, instead of being confined to Safe Mode .... and he can then fix up the ttool startup entry along with anything else he may find.
AustrAlien
Google is my friend. Make Google your friend too.

Posted Image

#51 User is offline   dsk6320 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 96
  • Joined: 08-December 11

Posted 10 February 2012 - 04:25 AM

I actually did install it this morning already and it was running fine, I will try it out for a few days as you suggested now that its pretty much back to normal and can be used in day to day activities again.

Will keep you posted.

#52 User is offline   dsk6320 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 96
  • Joined: 08-December 11

Posted 20 February 2012 - 01:01 PM

Hello, so far so good.. havent had any issues with the computer other than not being able to update windows, have even been able to log into my wife and daughters partitions and everything seems smooth there also.

only thing ive held off on was any kind of banking on it til its fixed and malware free.. if you think were ready to check back with gringo let me know.. thanks

#53 User is offline   dsk6320 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 96
  • Joined: 08-December 11

Posted 07 March 2012 - 12:43 PM

Morning, its been a while and havent heard anything back yet.. have you had a chance to get with gringo by chance?

#54 User is offline   AustrAlien 

  • Inquisitor
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 4,713
  • Joined: 15-July 09
  • Gender:Male
  • Location:Cowra NSW Australia

Posted 07 March 2012 - 02:56 PM

Thanks for the gentle nudge. I have no excuse for neglecting you: My apologies ... once again!

Re: Vista update issue
Gringo has recently stated to me that "the only thing I have found to work is an in place upgrade"
In order for you to be able to perform an "installation repair" or "in place upgrade", I think you will likely need a genuine retail Microsoft Vista installation disk ... but I am not sure about that.

In any case, I think Gringo would like to have a final check on your system now that you can run Windows normally and are not confined to Safe Mode any longer, as well as remove the malware-related registry entry that remains, namely:

Quote

ttool c:\windows\9129837.exe HOMEPC\Donnie HKU\S-1-5-21-1109359870-4165961621-2860427330-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


I will now (immediately) send a PM to Gringo and ask him to respond to your previous topic with him:
http://www.bleepingcomputer.com/forums/topic432236.html/page__view__findpost__p__2573976
Edit to add: DONE!

This post has been edited by AustrAlien: 07 March 2012 - 03:02 PM

AustrAlien
Google is my friend. Make Google your friend too.

Posted Image

#55 User is offline   dsk6320 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 96
  • Joined: 08-December 11

Posted 07 March 2012 - 05:43 PM

Is no prob, life has a way of complicating things when we least expect or want it to, lol

If that upgrade is the same one im thinking of it wont work because like you said, it requires a retail disc and i only have my oem disk from the mfg, but i may be thinking of another procedure all together.. will check with gringo once he responds and make sure.

Thank You for all your help and patients.. if nothing else can be done, atleast its stable and usable again :thumbup2:

Share this topic:


  • 4 Pages +
  • « First
  • 2
  • 3
  • 4
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users