mutliple issues winXP

With the problems that you are experiencing - I believe it to be a system corruption problem as opposed to malware, which is why I would recommend a reformat

I have a tutorial here http://www.geekstogo.com/forum/topic/173729-reformat-and-install-of-windows/
Any questions then do not hesitate to ask

I think I may have found the cause of the bsods.

I found some help on the dell support page, the windows debugger.

I opened the dump file from the bsods, and found that two files are causing the crashing:

atapi.sys
ntkrpamp.exe

Any Ideas?

I also got combfix to work, here is the log.

Hi,

My Pc is virus infected , the problem is that virus create a sub folder of the main folder and the processing is very slow , please tell what should i do ?

@gsellmed
Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

http://i1224.photobucket.com/albums/ee362/Essexboy3/aswmbrscan.gif

Click the “Scan” button to start scan

http://i1224.photobucket.com/albums/ee362/Essexboy3/aswmbrsavelog.gif

On completion of the scan click save log, save it to your desktop and post in your next reply

@Ilonaandrews could you start your own topic with a description of your problems please

aswMBR version 0.9.5 Copyright(c) 2011 AVAST Software
Run date: 2011-04-29 15:10:18

15:10:18.906 OS Version: Windows 5.1.2600 Service Pack 3
15:10:18.906 Number of processors: 2 586 0xE08
15:10:18.906 ComputerName: DLAPTOP UserName:
15:10:19.421 Initialize success
15:11:46.906 Disk 0 (boot) \Device\Harddisk0\DR0 → \Device\Ide\IdeDeviceP0T0L0-3
15:11:46.921 Disk 0 Vendor: ST96812AS 8.03 Size: 55796MB BusType: 3
15:11:46.937 Device \Driver\atapi → DriverStartIo 8749d33b
15:11:46.937 Disk 0 MBR read error 0
15:11:46.953 Disk 0 MBR scan
15:11:46.953 MBR BIOS signature not found 0
15:11:46.968 Disk 0 scanning sectors +114254280
15:11:46.984 Disk 0 scanning C:\WINDOWS\system32\drivers
15:11:57.187 Service scanning
15:11:58.843 Disk 0 trace - called modules:
15:11:58.843 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8749d4f0]<<
15:11:58.859 1 nt!IofCallDriver → \Device\Harddisk0\DR0[0x874b0ab8]
15:11:58.875 3 CLASSPNP.SYS[f75fdfd7] → nt!IofCallDriver → \Device\00000089[0x875ab030]
15:11:58.890 5 ACPI.sys[f7389620] → nt!IofCallDriver → [0x87523d98]
15:11:58.984 \Driver\atapi[0x87554218] → IRP_MJ_CREATE → 0x8749d4f0
15:11:59.000 Scan finished successfully
15:12:17.250 Disk 0 MBR has been saved successfully to “C:\Documents and Settings\TEMP\Desktop\MBR.dat”
15:12:17.281 The log file has been saved successfully to “C:\Documents and Settings\TEMP\Desktop\aswMBR.txt”

OK I would like to do a test as there is a new variant TDL at the moment - lets call it TDL5 as it is wildly different from the others

Please read carefully and follow these steps.

[*]Download TDSSKiller and save it to your Desktop.
[*]Extract its contents to your desktop.
[*]Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.

http://i466.photobucket.com/albums/rr21/JSntgRvr/TDSSKillermain.png

[*]If an infected file is detected, the default action will be Cure, click on Continue.

http://i466.photobucket.com/albums/rr21/JSntgRvr/TDSSKillerMal-1.png

[*]If a suspicious file is detected, the default action will be Skip, click on Continue.

http://i466.photobucket.com/albums/rr21/JSntgRvr/TDSSKillerSuspicious.png

[*]It may ask you to reboot the computer to complete the process. Click on Reboot Now.

http://i466.photobucket.com/albums/rr21/JSntgRvr/TDSSKillerCompleted.png

[*]If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
[*]If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of “TDSSKiller.[Version][Date][Time]_log.txt”. Please copy and paste the contents of that file here.

OK

I get to *80% on the initialization phase and then a window pops up saying there is a problem and needs to close.

OK that is an indication of the new variant

Did combofix install the recovery console ?

[*]When selecting F8 during start up you are prompted with options of all the windows to start (a bunch of safe modes, last know working, and normal). On the bottom is the option to select other OS to boot from. You need to select the other OS to boot from to get to the Windows Recovery Console.

http://tiplet.com/wp-content/uploads/recoveryconsole-startup.gif

[*]When Recovery Console starts, it will prompt you to enter a number corresponding to the Windows XP installation that you need to repair. In most cases, you’ll enter “1” (which will be the only choice). If you press ENTER without typing a number, Recovery Console will quit and restart your computer.
[*]Enter your Administrator password. If you do not have a password then press enter.
[*]At the Recovery Console command prompt, type fixmbr and then verify that you want to proceed.
[*]Once done type exit to leave the recovery console and rebbot

When that has completed reboot to normal mode and re-run TDSSKiller - let me know if it runs fully

ok that worked. it is a suspicious file.

Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
2011/04/29 17:37:31.0687 4420 sptd - detected Locked file (1)

SPTD is not a problem ;D

But as it ran it means the MBR fix worked… Need to add random blue screens now to the symptoms of this one

What problems now?

I’m not sure actually, I guess I will run some scans and see if the blue screens come back. And if it doesn’t, I assume the scans would take care of anything else. Thank you again, you saved me a lot of time and trouble. I will let you know how the scans go.

That was a nasty little thing, I’ve never had anything that a scan couldn’t take care of.

While I am thinking of it, what combination of programs do you suggest to keep my system protected?

This variant is only a few days old - so we are still feeling our way around it… What it does is hide the true MBR and shows a fake one to any tool that looks at it

Myself I just use Avast and Malwarebytes if I remember ;D

Let me know when you are happy and I will remove my tools and tidy you up

I have run multiple scans, all without getting a blue screen. On running a full scan, avast found a win32, called itlpfw32.dll.vir, it was in C:qoobox/quarantine/c/windows/system32. Last modification time is on 4/20, which sounds about right. Let me know if you want anymore information about it, if it will help you help others.

I guess I am ready to clean thing up. I should be around for the next few hours

I forgot to add that avast was successful in moving the win32 to the virus vault.

That was allready quarantined anyways so not a problem

Subject to no further problems :slight_smile:

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems

Now the best part of the day ----- Your log now appears clean :thumbsup:

A good workman always cleans up after himself so…The following will implement some cleanup procedures as well as reset System Restore points:

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

:Commands [resethosts] [purity] [emptytemp] [EMPTYFLASH] [CLEARALLRESTOREPOINTS] [Reboot]

[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done

Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /Uninstall

Run OTL and hit the cleanup button. It will remove all the programmes we have used plus itself.

We will now confirm that your hidden files are set to that, as some of the tools I use will change that

[*]Click Start.
[*]Open My Computer.
[*]Select the Tools menu and click Folder Options.
[*]Select the View Tab.
[*]Under the Hidden files and folders heading select Do not show hidden files and folders.
[]Click Yes to confirm.
[
]Click OK.

http://users.telenet.be/bluepatchy/miekiemoes/images/javaicon.gif
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application.

Upgrading Java:

[] Go to this site and click Do I have Java
[
] It will check your current version and then offer to update to the latest version

SPRING CLEAN

Download and run Puran Disc Defragmenter
For the first run I would recommend a boot defrag and disk check

http://i1224.photobucket.com/albums/ee362/Essexboy3/Puran.gif

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

http://img233.imageshack.us/img233/7729/mbamicontw5.gif
Malwarebytes. Update and run weekly to keep your system clean

Download and install FileHippo update checker and run it monthly it will show you which programmes on your system need updating and give a download link

It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To keep your operating system up to date visit
[*]Microsoft Windows Update

To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?
Keep safe :wave:

you had me use ots not otl, should i get otl or will ots do the same job. Also, did you want me to wait the 24 hours to clean things up? or just report back at that point?

Sorry different tools different forums - clean up now and just run as normal. If no further problems then you are good to go ;D

Start OTS. Copy/Paste the information in the quotebox below into the panel where it says “Paste fix here” and then click the Run Fix button.

[Empty Temp Folders]
[EmptyFlash]
[ClearAllRestorePoints]
  

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished.

then

Run OTS and hit the cleanup button. It will remove all the programmes we have used plus itself.

OK I am all cleaned up now, thank you again for your help.

Just a note, if you use windows debugger at all to help in your diagnosis of others, first make sure they have things set up to create the memory dump files. Throughout all of this I probably had 50+ bluescreens, but when I finally got to that I had no dump files to use.

I guess that is it, thank you, you are awesome.