shutdown message problem

Reply

Join Date: May 2005
Posts: 3,204
Reputation: gerbil will become famous soon enough gerbil will become famous soon enough 
Solved Threads: 188
gerbil gerbil is offline Offline
Nearly a Senior Poster

Re: shutdown message problem

 
0
  #21
Jul 21st, 2008
Arthas, I need a good slapping. Ignore my post about those two shell keys - that's something I put in my sys.
But do try post #18
Deep, deep in the woods, but walking about.
Reply With Quote Quick reply to this message  
Join Date: Jul 2008
Posts: 1
Reputation: hcdin is an unknown quantity at this point 
Solved Threads: 0
hcdin hcdin is offline Offline
Newbie Poster

Re: shutdown message problem

 
0
  #22
Jul 26th, 2008
I also had this problem and miraculously I cured it

I want to share it here - After using removal.bat, I also got the "registry can not be imported..." kind of message, I continued it and then I manually searched the registry for "iph.exe". I deleted each and every value which I found. AND viola !!! I got my problem fixed.

Hey seniors, try this and you will get the solution

Please do reply if it helps...

Harish Dobhal
http://indexviews.blogspot.com
Reply With Quote Quick reply to this message  
Join Date: Jun 2008
Posts: 15
Reputation: Arthas is an unknown quantity at this point 
Solved Threads: 0
Arthas Arthas is offline Offline
Newbie Poster

Re: shutdown message problem

 
0
  #23
Jul 27th, 2008
I also tried gebrils post #18. But whenever I ran that runthis.bat in safe mode, it complained after sometimes that
16 bit MS-DOS Subsystem
SDFix
c:/Program../Symantec/S32ENIL.dll. An installable Virtual driver failed DLL initialization.
Choose close to ternimate the app.
(It all came in a dialog box)
When I chose Ignore, it says "Cannot load VDM IPX/SPX support". I have to now quit the shell.
Now when I restart in normal mode, it says finalizing.. and again displays the same .dll problem. Here also when I chose ignore it does sth. I have got a report. How is it that I send it to you people if needed.
I also tried the removing of the iph.exe's from the regisery. But it had not done me faour. Is it that I did not know the proper sequence of removing the values. And is it due to the same that I am being tortured(I mean iph.exe).
Attached Files
File Type: txt Report.txt (5.6 KB, 1 views)
Reply With Quote Quick reply to this message  
Join Date: Jun 2008
Posts: 15
Reputation: Arthas is an unknown quantity at this point 
Solved Threads: 0
Arthas Arthas is offline Offline
Newbie Poster

Re: shutdown message problem

 
0
  #24
Jul 27th, 2008
I also tried searching the "iph.exe" int the registry, but nothing was found. I thing there nothing called iph.exe in my registry.
Reply With Quote Quick reply to this message  
Join Date: Jun 2008
Posts: 15
Reputation: Arthas is an unknown quantity at this point 
Solved Threads: 0
Arthas Arthas is offline Offline
Newbie Poster

Re: shutdown message problem

 
0
  #25
Jul 27th, 2008
And here is the HJT log of my system.
Please analyse it.
Attached Files
File Type: txt hijackthis.txt (9.5 KB, 0 views)
Reply With Quote Quick reply to this message  
Join Date: May 2005
Posts: 3,204
Reputation: gerbil will become famous soon enough gerbil will become famous soon enough 
Solved Threads: 188
gerbil gerbil is offline Offline
Nearly a Senior Poster

Re: shutdown message problem

 
1
  #26
Jul 27th, 2008
Symantec/S32ENIL.dll .. is there any chance you typed that incorrectly, arthas? It should be the name of a dll that exists in that Symantec S32 directory under program Files. Anyway, i notice that you are running Avast from Alwill Software, so that Symantec error is a leftover from an incomplete uninstallation of Symantec. To fix that you should go to Symantec's website for the removal tool for the edition of their AV that you were using. For your immediate problem you can do this....
==Navigate to this key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\VirtualDeviceDrivers
-in the right pane rclick VDD and delete it.
-in the Edit menu point to New and then select Multi-string Value.
-type VDD in the Value Name box, press ENTER.
-exit Regedit.

The Symantec tool will clear out all ? remnants though....
[with Avast installed I am surprised you do not have this entry for VDD at that key:
C:\Program Files\Alwil Software\Avast4\aswMonVd.dll ... but anyway..]
That is an incomplete SDFix log. Try running it again.
Deep, deep in the woods, but walking about.
Reply With Quote Quick reply to this message  
Join Date: Jun 2008
Posts: 15
Reputation: Arthas is an unknown quantity at this point 
Solved Threads: 0
Arthas Arthas is offline Offline
Newbie Poster

Re: shutdown message problem

 
0
  #27
Jul 28th, 2008
I did what you said. I deleted VDD and re added it.
I ran the runthis.bat and it went on well.
Down is the report of it( hope this time it is complete).
Attached Files
File Type: txt Report.txt (6.3 KB, 3 views)
Reply With Quote Quick reply to this message  
Join Date: May 2005
Posts: 3,204
Reputation: gerbil will become famous soon enough gerbil will become famous soon enough 
Solved Threads: 188
gerbil gerbil is offline Offline
Nearly a Senior Poster

Re: shutdown message problem

 
0
  #28
Jul 29th, 2008
I see that SDFix detected no malware. Please run this scan to see what it turns up:
==Download this file to your desktop: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
- to run it dclick combofix.exe and follow the prompts to start it. When finished, it will produce a log, C:\Combofix.txt - post that log in your next reply.
A word of caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs reboot to restore the desktop.
Deep, deep in the woods, but walking about.
Reply With Quote Quick reply to this message  
Join Date: Jun 2008
Posts: 15
Reputation: Arthas is an unknown quantity at this point 
Solved Threads: 0
Arthas Arthas is offline Offline
Newbie Poster

Re: shutdown message problem

 
0
  #29
Aug 6th, 2008
I ran combo fix on my system, and I think it worked. I have attached the log of it below.
I can finally run DOS commands without hesitation. Thanks a lot everyone, and especially gebril and sattis.
And would you plz tell me what combofix did to my system. It would be more interesting to know how to manually fix the problem.
Attached Files
File Type: txt log.txt (28.6 KB, 2 views)
Reply With Quote Quick reply to this message  
Join Date: May 2005
Posts: 3,204
Reputation: gerbil will become famous soon enough gerbil will become famous soon enough 
Solved Threads: 188
gerbil gerbil is offline Offline
Nearly a Senior Poster

Re: shutdown message problem

 
0
  #30
Aug 7th, 2008
ComboFix does operations that are in general terms similar to other anti-malware tools. Briefly, I would not dream of attempting to emulate it manually. Check its bat file for some of its operations.
I see the point of your infection - a USB device.

==Download this temp file cleaner from http://www.atribune.org/ccount/click.php?id=1 --click in the download window to run it, and when ATF Cleaner opens go Select all, and then Empty Selected.
Next click Firefox [if you have that browser..] at the top, Select All again, and Empty Selected again. Follow that procedure also if you have Opera. Repeat in other User profiles.
Close ATF.
==Please use IE or Firefox to do an online scan at panda:- http://www.pandasecurity.com/homeuse...s/activescan/?
-for the free online virus scan select the link Scan your PC, then Register [otherwise there will be no disinfection, merely detection] with a valid email and follow through.
Please ATTACH to your post the log it produces.
==download hijackthis: http://www.majorgeeks.com/download5554.html
-copy it to a new FOLDER placed either alongside your program files or on your desktop and then... rename hijackthis.exe to imabunny.exe
-in that folder start HijackThis by dclicking the .exe; now close ALL other applications and any open windows including the explorer window containing HijackThis.
-click the Scan and Save a Logfile button. Post the log here.
Deep, deep in the woods, but walking about.
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Windows NT / 2000 / XP Forum


Views: 3709 | Replies: 29
Thread Tools Search this Thread



Tag cloud for Windows NT / 2000 / XP
About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC