The system has detected a problem with one or more installed IDE/SATA hard disks

johnb35

Administrator
Staff member
QUOTE=Wolfgang405;1643876]I don't know if it has anything to do with the virus, but I have noticed I cannot watch video without constant buffering every few seconds.

John, my memory is very low. I have several iexplore.exe file running in the task manager. Any ideas ?

Are you running tabs in IE, if so then I beleve for every tab, there is 2 processes running.
 

litefoot

New Member
I hate to say this but your system is beyond fixing at this point, you will need to format and reinstall windows using either the system recovery cd or system recovery partition. The ramnit infection is a file infecting virus like virut and can't be cured. Do not back up any exe files when backing up your data.

OK. Thanks for your help trying to fix it anyway. Without a system recovery CD, how would I go about reinstalling Windows, as an install CD was not provided by the manufacturer? Do you recommend I purchase Windows Vista or 7?
 

johnb35

Administrator
Staff member
If you didn't get a recovery cd with your machine then most likely you have a recovery partition on the harddrive that you need to boot into to reinstall windows. What machine do you have?
 

johnb35

Administrator
Staff member
Look in your start menu and see if you have a program called acer recovery management with an option to restore. Or you may also have to option to make back up recovery cd's. If the option to make back up recovery cd's are there then make them and use them to restore your system.
 

litefoot

New Member
Look in your start menu and see if you have a program called acer recovery management with an option to restore. Or you may also have to option to make back up recovery cd's. If the option to make back up recovery cd's are there then make them and use them to restore your system.

In Control Panel->System Maintenance->Backup and Restore Center there is an option Repair Windows Using System Restore but I'm guessing that isn't what you mean. In the same place there's an option to back up files but I'm guessing this isn't what you mean also.

Acer eRecovery Management is there with

(1) three disc options:

Create factory default disc
Create current system configuration backup disc
Create driver and application backup disc

(2) three restore options:

Restore system to factory default
Recover system from CD/DVD
Reinstall applications/drivers
 

johnb35

Administrator
Staff member
First thing I would do is create the factory default disk, you will need 1,2 or 3 dvd's to do this most likely. After creating the restore disks, then go back and select "restore system to factory default"
 

litefoot

New Member
babystrawberry66,

How's your system running now? Please do the following.

Open hijackthis, click on open misc tools section, click on open uninstall manager, click on save list and save it. Then copy and paste the entire contents of that log back here.

It's good but I think it's a little slower than before. Thanks again! :D

Acrobat.com
Acrobat.com
Activation Assistant for the 2007 Microsoft Office suites
ActiveCheck component for HP Active Support Library
Adobe AIR
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9
Atheros Driver Installation Program
Audition – Season 2
Compatibility Pack for the 2007 Office system
CyberLink DVD Suite
CyberLink DVD Suite
CyberLink YouCam
CyberLink YouCam
Dream Day Wedding Married in Manhattan 2.0.0.9
ESU for Microsoft Vista
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
Google Update Helper
HiJackThis
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotspot Shield 2.04
HP Active Support Library
HP Customer Experience Enhancements
HP Doc Viewer
HP DVD Play 3.7
HP Help and Support
HP Quick Launch Buttons 6.40 H2
HP Total Care Advisor
HP Total Care Setup
HP Update
HP User Guides 0118
HP Wireless Assistant
HPAsset component for HP Active Support Library
Huawei ADSL USB Modem
Java(TM) 6 Update 7
Juno Preloader
LabelPrint
LabelPrint
LightScribe System Software 1.14.17.1
Malwarebytes' Anti-Malware version 1.51.0.1200
Microsoft Live Search Toolbar
Microsoft Office Excel MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Standard 2007
Microsoft Office Standard 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Text-to-Speech Engine 4.0 (English)
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
Mozilla Firefox (3.6.17)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
muvee Reveal
My HP Games
NetWaiting
NetZero Preloader
Norton Internet Security
Oxford Student's Dictionary
Power2Go
Power2Go
PowerDirector
PowerDirector
QUICKfind server v1.1
Realtek 8169 8168 8101E 8102E Ethernet Driver
Realtek USB 2.0 Card Reader
Search-Results Toolbar
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Skype web features
Skype™ 4.1
SPORE Creature Creator Trial Edition
UniKey 4.0 NT
Uninstall LAC VIET mtd2002-EVA
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
WinRAR archiver
Yahoo! Messenger
Yahoo! Software Update
Yahoo! Thanh công c?
 

johnb35

Administrator
Staff member
babystrawberry66,

Lets make sure you don't have an infection that will cause slowness.

Please download and run TDSSkiller

When the program opens, click on the start scan button.

TDSSKiller will now scan your computer for the TDSS infection. When the scan has finished it will display a result screen stating whether or not the infection was found on your computer. If it was found it will display a screen similar to the one below.

infection-found.jpg


To remove the infection simply click on the Continue button and TDSSKiller will attempt to clean the infection.

When it has finished cleaning the infection you will see a report stating whether or not it was successful as shown below.

scan-completed.jpg


If the log says will be cured after reboot, please reboot the system by pressing the reboot now button.

After running there will be a log that will be located at the root of your c:\ drive labeled tdsskiller with a series of numbers after it. Please open the log and copy and paste it back here.


Please uninstall the following programs.

Java(TM) 6 Update 7
Search-Results Toolbar

Then go here to download the latest version of Java.

http://www.java.com/en/download/index.jsp

Also please download and run Ccleaner, this should bring back some of your speed.

http://download.cnet.com/ccleaner/

Just make sure you click where it says download now in black. Download, install and open Ccleaner, click on run cleaner. This may take a few minutes to delete everything.
 

litefoot

New Member
First thing I would do is create the factory default disk, you will need 1,2 or 3 dvd's to do this most likely. After creating the restore disks, then go back and select "restore system to factory default"

I did this last night. On the first reboot I got the same blue screen about an attempt being made to write to read only memory and it tried to go into Startup Repair mode again. However, Windows loaded when I did another reboot.

The system is running very slowly, and a lot of IE windows frequently open without prompting and load up Acer.yahoo.com. I am also getting a lot of dialog boxes titled 'Interactive services dialog detection' without prompting.

Also installed is a tool titled Microsoft Windows Malicious Software removal Tool, which wasn't on my system before. It's running now and has so far found 913 files infected. Looks like restoring the factory settings haven't worked. Thanks for your help though John. Any ideas what to do next?
 

johnb35

Administrator
Staff member
I did this last night. On the first reboot I got the same blue screen about an attempt being made to write to read only memory and it tried to go into Startup Repair mode again. However, Windows loaded when I did another reboot.

The system is running very slowly, and a lot of IE windows frequently open without prompting and load up Acer.yahoo.com. I am also getting a lot of dialog boxes titled 'Interactive services dialog detection' without prompting.

Also installed is a tool titled Microsoft Windows Malicious Software removal Tool, which wasn't on my system before. It's running now and has so far found 913 files infected. Looks like restoring the factory settings haven't worked. Thanks for your help though John. Any ideas what to do next?

If you actually restored it to factory defaults then you wouldn't be having this issue. I would suggest finding someone that is computer savvy to help you do an actual system recovery.
 

litefoot

New Member
First thing I would do is create the factory default disk, you will need 1,2 or 3 dvd's to do this most likely. After creating the restore disks, then go back and select "restore system to factory default"

I definitely did the above. I burnt the discs and then selected

Restore system to factory default

This prompted the following dialog box:

"This will restore your system and overwrite all files on C: drive. Do you want to continue?"

I confirmed and then followed the directions to insert the discs when requested.

Is it possible that infected files were burned onto the factory default discs ?

All the infected files are dlls if that suggests anything.
 

johnb35

Administrator
Staff member
The system recovery disks are created from the recovery partition files, no where else.

Try it again, but this time go into acer recovery management and choose to

restore system to factory default

do not use the recovery cd's.

What files are being detected by MSRT(malicious software removal tool)?
 

t91989

New Member
THANK YOU JOHN for all your help and your easy to follow directions!

I, too, found this forum because I had the virus and am extremely grateful for your detailed help. I followed the steps and installed malware, the rkill (many many times) the unhide and the combofix. I still have issues but on my way to my ol' computer but I now have successfully back upped a bunch of photos, etc. that I was worried about.

I'm sure you have helped MANY more people that aren't registered to say thanks.

THANK YOU!!!!
 

johnb35

Administrator
Staff member
t91989,

Even though you have ran combofix, that doesn't mean you are infection free. You should post the log for me to go through and see if you are clean or not.

Also what issues are you still having?
 

t91989

New Member
I'm sure I'm not in the clear yet, but I truly appreciate all your assistance this far.

I just emailed you my combofix logs - just maybe I'm lucky and its ok. (BUT thank you so much for checking it over.)

Thank you again!
 

cutyhammy

New Member
All menu on my Window has disappeared

Download and run Unhide.exe. This should restore your missing file/folder/etc..

Hi John,

thanks so much for giving the malware program and the steps to get rid of the virus. You saved my computer today :)

i've also run the "unhide.exe" program which unhide all the files and folders.

But i still have one problem *hope that you can help* (or anyone pls)
All the program in my Windows menus has dissapears.
The program is stil there in the Programs folder, but i just can't seem them on Windows menu [e.g Start > All Programs > Itunes > (Empty)]

Do you have any solution on how i can fix that?

Thanks again for ya help :D
 

Attachments

  • hidden.JPG
    hidden.JPG
    74 KB · Views: 137
Top