Maxonx
asked on
I get a BSOD when I try to install antivirus!!
Greetings,
I am trying to fix a computer that was infected with some viruses, I used the eset online scanner and found 19 viruses, then I used ad aware and removed all of the spyware that it found then I installed malwarebytes but it would not run. then I tried to install a antivirus program and everytime I do even in Safemode it goes to BSOD.
I ran the eset online scanner again and bit torrent and both said the machine is clean.
So what now?
Thanks
I am trying to fix a computer that was infected with some viruses, I used the eset online scanner and found 19 viruses, then I used ad aware and removed all of the spyware that it found then I installed malwarebytes but it would not run. then I tried to install a antivirus program and everytime I do even in Safemode it goes to BSOD.
I ran the eset online scanner again and bit torrent and both said the machine is clean.
So what now?
Thanks
Could you also attach Eset's logfile>location:
C:\Program Files\EsetOnlineScanner\lo g.txt
C:\Program Files\EsetOnlineScanner\lo
ASKER
This is vista! Combo fix isnt for Vista.
I wish it was.
I wish it was.
It does run on Vista, unless its 64 bit :)
I would suggest that you first removed the hard drive from the current machine and plug it into another computer with MalwareBytes installed. Scan it from there.
Then place it back. You might need to repair the startup if it does not boot after removing the malware. You also might need to run from the command prompt:
sfc /scannow
To make sure all critical system files are present and not damaged.
After this, if the computer continues to give you problems you might need to do a clean repair install of Vista. Microsoft changed the way it names the repair install in XP to Upgrade Install in Vista. It also assumes that you must be able to be in Vista to run it.
If you need additional info on the repair install let me know.
Keep me posted on your progress.
Bits...
Then place it back. You might need to repair the startup if it does not boot after removing the malware. You also might need to run from the command prompt:
sfc /scannow
To make sure all critical system files are present and not damaged.
After this, if the computer continues to give you problems you might need to do a clean repair install of Vista. Microsoft changed the way it names the repair install in XP to Upgrade Install in Vista. It also assumes that you must be able to be in Vista to run it.
If you need additional info on the repair install let me know.
Keep me posted on your progress.
Bits...
Your system,it seems,is still infected and some virus generated service
is preventing the installation or successful scanning of your drive.
You can not install programs in safe mode.That must be done
within the active system.
To accomplish this we must remove this rogue service and startup entries that trigger it.
To do this we must boot into safe mode.
Do you understand this far ?
is preventing the installation or successful scanning of your drive.
You can not install programs in safe mode.That must be done
within the active system.
To accomplish this we must remove this rogue service and startup entries that trigger it.
To do this we must boot into safe mode.
Do you understand this far ?
ASKER
Ok Sorry I havent replied..Ive been sick and was out of town on vaca, but heres the skinny now, I ran combo fix in safe mode and then when it went to reboot I get a BSOD with a stop error STOP: 0X0000007E (0x080000003, 0X829F84AD,0X80405770,0X80 40546C) and I tried doing the startup repair and it failed and then I tried running sfc/scannow from the C: prompt and it says "There is a system repair pending which requires reboot to complete. Restart Windows and run sfc again."
But it wont restart only gives the BOSD..
I ran a chkdsk /r and it completed but didnt seem to acomplish anything..
Thanks
But it wont restart only gives the BOSD..
I ran a chkdsk /r and it completed but didnt seem to acomplish anything..
Thanks
Is your machine 32bit or 64bit?
Try startup repair again and when it fails to repair system, opt launch System Restore.
Pick a date prior to running Combofix.
Once restored, manually create a restore point and note whatever name you call it.
If 32bit
Rerun Combofix in normal mode and attach its logfile after.
From above link. Read its proceedure carefully on Combofix's running
Try startup repair again and when it fails to repair system, opt launch System Restore.
Pick a date prior to running Combofix.
Once restored, manually create a restore point and note whatever name you call it.
If 32bit
Rerun Combofix in normal mode and attach its logfile after.
From above link. Read its proceedure carefully on Combofix's running
Also attach Esets logfile:
C:\Program Files\ESET\ESET Online Scanner\log.txt
C:\Program Files\ESET\ESET Online Scanner\log.txt
ASKER
Tried that but There arent any restore points
Ok, Any of these boot options work:
Last Known Good Configuration
Safe Mode with Networking
Safe Mode with command prompt
Safe Mode
Last Known Good Configuration
Safe Mode with Networking
Safe Mode with command prompt
Safe Mode
ASKER
Negative..tried them all, What about going into C:\Windows\winsxs\pending. xml and deleting the pending.xml ?
That would clear any updates "stuck" but unsure of the consequences :(
ASKER
Ok tried to delete the pending.xml and it deleted it but that didnt do anything, Is there away to delete the pending system repair?
Launch System Repair again. If it fails try System Restore and select to pick an older System Restore point, if any.
Be careful not to select full computer restore or restore to factory image as all will be gone!
I came accross this article which has a few methods to try
http://social.technet.microsoft.com/forums/en-US/itprovistasp/thread/31ca7aee-2c6c-400c-aeee-bb00286d192a/
Be careful not to select full computer restore or restore to factory image as all will be gone!
I came accross this article which has a few methods to try
http://social.technet.microsoft.com/forums/en-US/itprovistasp/thread/31ca7aee-2c6c-400c-aeee-bb00286d192a/
ASKER
When I launch system repair and chose system restore it says "No restore points have been created on your computers system disk. To create a restore point open System proctection."
ASKER
I used a Knoppix cd and recovered some files from the hd, Now is there anyway of deleting the pending system repair?
From above link:Quote:
After BIOS screen, hit F8 for the windows boot menu.
- Select the "repair" option (it is first on the list)
- Open a command prompt.
- Rename the following files:
C:\windows\winsxs\pending. xml C:\windows\winsxs\pending. old.xml
C:\windows\winsxs\cleanup. xml -> C:\windows\winsxs\cleanup. old.xml
After BIOS screen, hit F8 for the windows boot menu.
- Select the "repair" option (it is first on the list)
- Open a command prompt.
- Rename the following files:
C:\windows\winsxs\pending.
C:\windows\winsxs\cleanup.
ASKER
I deleted the winsxs folder on accident ..lol
Can I replace this from the disc and what would be the cmd line for that?
Thanks
Can I replace this from the disc and what would be the cmd line for that?
Thanks
I think it can only be replaced if the system boots correctly.
You can try a repair but I doubt it.
Since you have a backup a full system recovery maybe the only option :(
You can try a repair but I doubt it.
Since you have a backup a full system recovery maybe the only option :(
ASKER
I think you are right about that and thats what I didnt want to hear..as I do not have the original vista home premium disc.
I wish there was a way to get rid of that pending system repair, I tried running sfc/scannow again and it said the same thing.
Thanks for your help!
I wish there was a way to get rid of that pending system repair, I tried running sfc/scannow again and it said the same thing.
Thanks for your help!
Whats the make and model of machine?
ASKER
Hp Pavillion dv6000
I think its the only option is to factory restore the machine.
You have your data backed up, which is good.
You will lose programs you installed, unless you have the cds to reinstall after factory restore.
When you go into launch startup repair is there an option to put machine back to factory settings from an image or something like that
You have your data backed up, which is good.
You will lose programs you installed, unless you have the cds to reinstall after factory restore.
When you go into launch startup repair is there an option to put machine back to factory settings from an image or something like that
ASKER
yes there is..
ASKER
Isnt there a way to go into bcdedit from cmd prompt and delete the pending system repair on reboot?
Ok well full system recovery is there which is good.
This is from above link i gave.
Read through this and try from step14 onwards.
Reason is you dont have a installation DvD and winsxs is gone!
1. Insert the Windows Vista install DVD, and restart the computer.
2. Press any key when it asks you if you want to boot from the dvd.
3. Select your language, country, and keyboard type from the prompt. If you are in the US its probably already right.
4. choose "Repair your Computer".
5. Select your operating system from the list and click next.
6. on the system recovery options page, click Command Prompt.
7. Type regedit and press enter
8. Select HKEY_LOCAL_MACHINE. Don't expand it, just click the title to highlight it.
9. Click file and click load hive.
10. Locate the folder c:\Windows\winsxs.
11. Find the file named pending.xml.
12. Right click on the file and click rename.
13. Change the name from pending.xml to pending.old
14. Then navigate to the folder C:\windows\system32\config \component s.
15. When prompted for a name "Offline_Components"
16. Open the registry HKML\Offline Components and delete the file AdvancedInstallersNeededRe solving.
17. Then delete PendingXmlIdentifier.
18. Restart the computer and it should be fixed.
This is from above link i gave.
Read through this and try from step14 onwards.
Reason is you dont have a installation DvD and winsxs is gone!
1. Insert the Windows Vista install DVD, and restart the computer.
2. Press any key when it asks you if you want to boot from the dvd.
3. Select your language, country, and keyboard type from the prompt. If you are in the US its probably already right.
4. choose "Repair your Computer".
5. Select your operating system from the list and click next.
6. on the system recovery options page, click Command Prompt.
7. Type regedit and press enter
8. Select HKEY_LOCAL_MACHINE. Don't expand it, just click the title to highlight it.
9. Click file and click load hive.
10. Locate the folder c:\Windows\winsxs.
11. Find the file named pending.xml.
12. Right click on the file and click rename.
13. Change the name from pending.xml to pending.old
14. Then navigate to the folder C:\windows\system32\config
15. When prompted for a name "Offline_Components"
16. Open the registry HKML\Offline Components and delete the file AdvancedInstallersNeededRe
17. Then delete PendingXmlIdentifier.
18. Restart the computer and it should be fixed.
ASKER
Ok I opened a cmd prompt and I typed in C:\windows\system32\config \component s but it says " the directory name is invalid' So i tried C:\windows\system32\config \ and that worked then I typed in dir and components is there so is components.sav.. Well I typed in regedit and clicked on HKEY_LOCAL_MACHINE and then clicked on file and loaded the hive and components is there..I opened it with notepad but now what should I do?
Thanks
Thanks
ASKER
Right I think I got this but I need some clarification.. #15 when and how am I promted for a name?( thats not happing)
I foumd the files in 16 &17 Under hkey_local_machine_Compone nts should I just proceed or do I need to make a new string called 'Offline components"?
Thanks
I foumd the files in 16 &17 Under hkey_local_machine_Compone
Thanks
ASKER
Also when I booted from knoppix I seen that there was a hp recovery partition could I use that to fix this?
Sorry, start with step7 and load the hive.
Hp recovery partition will restore machine to factory settings.
Hp recovery partition will restore machine to factory settings.
ASKER
Ok I did everything from #7 on down and rebooted and same results bsod then it reboots...This blows!
Boot into Knoppix and grab ten recent minidump files to attach here.
Located at c:\windows\minidump
Also get Esets logfile:
C:\Program Files\ESET\ESET Online Scanner\log.txt
Located at c:\windows\minidump
Also get Esets logfile:
C:\Program Files\ESET\ESET Online Scanner\log.txt
ASKER
I just found out a friend of mine has a copy of Vista premium from dell and Im gona just reinstall it..
No prob.
The recovery partition will do that for you and will have all drivers installed.
The recovery partition will do that for you and will have all drivers installed.
ASKER
Vista is such a POS I cannot belive that microsoft was alowed to release it and get away with it!!
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Follow it's instructions from following link.
Attach logfile here after
http://www.bleepingcomputer.com/combofix/how-to-use-combofix