Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Error Loading Messages At Boot Up


  • Please log in to reply
5 replies to this topic

#1 pcmaddeanp

pcmaddeanp

  • Members
  • 147 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Southampton, UK
  • Local time:01:32 PM

Posted 25 July 2008 - 05:07 AM

Hi,

When I boot up my Windows XP Home PC there are a number of errors that pop up.
These error messages are:
"Error Loading c:\windows\system32\giveximi.dll"
"The application or DLL C:\WINDOWS\system32\nrbwdkf.dll is not a valid Windows image. Please check this against your installation diskette."
"Error loading C:\WINDOWS\system\nrbwdkaf.dll %1 is not a valid Win32 application."

What is wrong?

pcmaddeanp

Server Room Geek - IT Professionals Community


BC AdBot (Login to Remove)

 


#2 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,289 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:08:32 AM

Posted 25 July 2008 - 07:16 AM

It's not unusual to receive such an error after using tools to remove malware infection.

A "Cannot find...", "Could not run...", "Error loading... or "specific module could not be found" message is usually related to malware that was set to run at startup but has been deleted. Windows is trying to load this file but cannot locate it since the file was mostly likely removed during an anti-virus or anti-malware scan. However, an associated orphaned registry entry remains and is telling Windows to load the file when you boot up. Since the file no longer exists, Windows will display an error message. You need to remove this registry entry so Windows stops searching for the file when it loads.

To resolve this, download Autoruns, search for the related entry and then delete it.
  • Create a new folder on your hard drive called AutoRuns (C:\AutoRuns) and extract (unzip) the file there. (click here if you're not sure how to do this.)
  • Open the folder and double-click on autoruns.exe to launch it.
  • Please be patient as it scans and populates the entries.
  • When done scanning, it will say Ready at the bottom.
  • Scroll through the list and look for a startup entry related to the file(s) in the error message.
  • Right-click on the entry and choose delete.
  • Reboot your computer and see if the startup error returns.

.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#3 pcmaddeanp

pcmaddeanp
  • Topic Starter

  • Members
  • 147 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Southampton, UK
  • Local time:01:32 PM

Posted 25 July 2008 - 07:50 AM

Thanks for the fast reply.
I have told my friend, because it's his PC that is playing up, to install Malwarebytes and do a scan because yesterday no programs would open except from MSN Messenger.
Also, there was Messenger Spam that kept being sent. I did a search on this and found it is Adaware so thats another reason why I said to scan the PC with Malwarebytes. He is going to also do a scan using Ad-Aware 2008 Free.

pcmaddeanp

Server Room Geek - IT Professionals Community


#4 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,289 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:08:32 AM

Posted 25 July 2008 - 04:21 PM

Spambots, Bots and Email relays typically come packaged with rootkits so a rootkit check should be performed. I also recommend performing a scan with Sophos Anti-rootkit or Panda AntiRootkit.

Before performing a scan it is recommended to do the following to ensure more accurate results and avoid common issues that may cause false detections.
  • Disconnect from the Internet or physically unplug you Internet cable connection.
  • Close all open programs, scheduling/updating tasks and background processes that might activate during the scan including the screensaver.
  • Temporarily disable your anti-virus and real-time anti-spyware protection.
  • After starting the scan, do not use the computer until the scan has completed.
  • When finished, re-enable your anti-virus/anti-malware (or reboot) and then you can reconnect to the Internet.
Note: Not all hidden components detected by ARKs are malicious. It is normal for a Firewall, some Anti-virus and Anti-malware software (ProcessGuard, Prevx1, AVG AS), sandboxes, virtual machines and Host based Intrusion Prevention Systems (HIPS) to hook into the OS kernal/SSDT in order to protect your system. You should not be alarmed if you see any hidden entries created by these software programs after performing a scan.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#5 pcmaddeanp

pcmaddeanp
  • Topic Starter

  • Members
  • 147 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Southampton, UK
  • Local time:01:32 PM

Posted 29 July 2008 - 11:52 AM

Thanks for your help quietman7

After doing scans, there was ALOT of malware on his PC!
The most malware-infested PC I have ever seen.
We cleaned the PC by doing a reboot, like it said, and PC ran like new.

Unfortunatly, A few days later the PC wouldn't boot. Not even into safe mode. The XP Boot Screen appears, the a BSOD happens.
He did a system recovery and strangly enough, everything on the main hard drive has backed up onto another hard drive that was in the PC.
The PC now runs fine. A little slow but it has only got 256Mb of RAM which is going to be upgraded soon.

pcmaddeanp

Server Room Geek - IT Professionals Community


#6 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,289 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:08:32 AM

Posted 29 July 2008 - 11:58 AM

You're welcome.

Glad to hear the issue has been resolved. Tell your friend to read Tips to protect yourself against malware and reduce the potential for re-infection, be sure to read:
• "Simple and easy ways to keep your computer safe".
• "How did I get infected?, With steps so it does not happen again!".
• "Best Practices - Internet Safety for 2008".
• "Hardening Windows Security - Part 1 & Part 2".
• "IE Recommended Minimal Security Settings" - "How to Secure Your Web Browser".

• Avoid online gaming sites and peer-to-peer (P2P) or file sharing programs as they are a security risk which can make your system susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans target and spread across P2P files sharing networks and gaming sites. In some instances the infection may cause so much damage to your system that recovery is not possible and the only option is to wipe your drive, reformat and reinstall the OS. The best way to reduce the risk of infection is to avoid gaming sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users