Author Topic: Problem - Google searches being redirected, 3 days of scanning, can't fix  (Read 16803 times)

0 Members and 1 Guest are viewing this topic.

wam4

  • Guest
Ok, here is the new AVP tool log.  I don't think it likes running in safe mode, but it seemed to work.

Mediafire verified this one ok (it's a zip file, so I couldn't attach here).
Thanks!

http://www.mediafire.com/?anqc81w4ioaeneu

wam4

  • Guest
I've looked everywhere I can think of to try to figure out what's wrong with my startup process...perhaps the virus changed some key files? Before closing down for the night, however, I decided to work on capturing the screen message that pops up so quickly when I try to start Windows normally.  I used my iPhone to take a movie of the moment and look back frame by frame - here is what the message says:

"A problem has been detected and Windows has been shut down to prevent damage to your computer If this is the first time you've seen this stop error screen, restart your computer. If this screen appears again, follow these steps:
Check to be sure you have adequate disk space.  If a driver is identified in the stop message, disable the driver or check with the manufacturer for driver updates. Try changing video adapters.
Check with your hardware vendor for any bios updates. Disable bios memory options such as caching or shadowing.  If you need to use safe mode to remove or disable components, restart your computer, press F8 to select advanced startup options, and then select safe mode.
Technical information:
***STOP:  0x000000"

Any ideas?  Thanks very much for all your help,
Bill

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Ta got it... Well there is nothing apparent in there that would stop the normal boot, do you have a windows CD as we could try a repair install

wam4

  • Guest
Ok, sorry for the delay. I have the Windows CD and have the machine booting from CD now.  Shall I just run the repair program?  As I remember, that won't impact my document files and things...

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes

wam4

  • Guest
Ok...I just ran the repair process completely, then let the machine restart and that damned blue screen popped up just like before, keeping it from loading Windows normally. 
Do you think there's something leftover in my registry? 

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
No it sounds very much like a hardware/driver problem

Was a minidump created ?

Could you set your system to generate minidumps - details here http://kb.acronis.com/content/2191

wam4

  • Guest
Well, Windows won't finish the repair after the reboot (as it says it should).  And now it won't even get to safe mode.  I did, however, disable the auto-restart on system failure and now I have the complete info on the failure:

*** STOP: 0x0000007e (0xC0000005, 0xF760EA8D, 0xF7A26528, 0xF7A26224)

*** isapnp.sys - Address F760EA8D base at F7607000, Datestamp 3b7d8559


DonZ63

  • Guest

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
OK now I know where to look - it is a driver problem


  • Run OTL.
  • Select All Users
  • Under the Custom Scan box paste this in
netsvcs
/md5start
isapnp.*
/md5stop
Drives

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open a notepad window.
    • Attach the  log

wam4

  • Guest
Will OTL run from the prompt at the Recovery Console?  That's as far as I can get...it won't get to safe mode, supposedly because of that asipnp.sys related error.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
So we are now not able to achieve safe mode ?

Follow the destructions at DonZ63's link http://support.microsoft.com/kb/315311

You will need to copy the file from the xp cd

Let me know if you understand what to do - if not let me know where you are stuck and I will walk you through it

wam4

  • Guest
Ok, working on that now...tried it before, but it won't let me create the expanded file, so some reason.  It responds, "Unable to create file isapnp.sys" I can copy the .sy_ version of the file over to the directory but it won't expand.
I am going to expand the file on another machine and copy it to a disc and see if I can get it into place that way.

wam4

  • Guest
For some reason it won't let me open the disc tray after I boot from the Windows CD.  I copied the disk and added the sys file and then it wouldn't stop and recognize the CD and boot from it!  It works perfectly on other machines - but only the actaul Windows CD will work. 
I'm going to shoot myself in the head.  :-)

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Could you transfer using a USB stick ?