My netbook was infected with Antimalware Doctor. After several days and a whole lot of help, the infection was removed. During the removal process, I kept getting errors with System Restore and Roxio Backon Track. I was advised to post in this forum for additional help since the remaining issues are System Restore and Roxio related.
The original topic is here: Netbook infected with Antimalware Doctor. There are a lot of posts in this topic, including a bunch of log files, so I'm including a summary of steps taken at the end of this post.
Here's a summary of the current issues:
When I try to shut down or restart the machine via the start menu, it goes to the "windows is shutting down" screen, but never shuts down. I end up having to manually power the machine off and turn it back on. When powering it back on, the screen that appears is prompting me to select a start up mode (safe mode, last known good, normal, etc.) Have tried both safe mode and normal - just bings me back to the same screen. The option that allows me to boot up is the "last known good configuration" option. Safe mode and normal mode were working until I disabled system restore again (per the instructions in post #47)
Disk Check will not run. The last time I tried was from within safe mode and received a message sayig that it needed to access files that were in use. I selected the eoption to have it run @ restart. Now, when restarting the machine (via last known good configuration), the disk check screen comes up and shows "cannot open the volume for direct access" then it exits and the startup continues.
I think there are still some "pieces" of Roxio left on the machine because there are some roxio-related errors showing in Event Viewer (see post #46)
Steps taken so far:
- Had malware infection
- couldn't run gmer unless only "sections" option selected
- tried to disable AVG but some of its processes were still running
- combofix would't go past the "sholdnt be longer than 10 mins screen"
- couldn't uninstall AVG, had to use avgremover (post #13)
- diasbled Roxio Backon Track (botservice.exe) and combofix was able to run (16)
- issue updating java, froze during uninstall of old version and new version would not install via offline install. was able to install via online install. (19)
- am still not 100% positive that java is installed poperly (21)
- malware infection deemed removed and was given additional steps to follow but did not get past resetting system restore (25)
- (28) machine froze turning off system restore and had to be manually restarted **this is when rebooting the machine stopped working properly**
- Couldn't open system properties to turn system restore back on
- unable to run disk check (30) machine would not fully boot, system restore tab missing
- reinstalled system restore but still wont run
- unsuccesful uninstal of roxio using revo (35)
- disk check *almost* works: In safe mode with both boxes checked, got a message saying that there were files in use that needed to be acessed for the scan and clicked "yes" on schedule scan to run @ next restart. When I restarted, the scan screen (w/blue background) came up for a few seconds. Error mesage "cannot open the volume for direct access" then the startup process continued.
- (43) tried running combofix after adding a script, stalled @ windows is shutting down
- (45) ran combofix after adding a different script, stalled again @ same point **this is when I became unable to boot to either safe or normal mode and have to use "last known good configuration"**
- (46) event viewer errors from last run of combofix
- (48) can't disable roxio saib service and freeze when trying to disable system restore
ps - sorry if there are spelling errors...tried to use the spellcheck but am getting a mesage saying "ieSpell not detected". It prompts me to go to the download page, but I'd rather not add anything new right now and potentially cause more my poor machine any additional troubles.
Edited by marisajoy, 06 June 2010 - 04:39 PM.