There are two computers on a domain. Both computers were infected with antivirus 360. The viruses have been removed. However, now the computers get stuck while booting. Sometimes they sit at "preparing network connections." Sometimes they sit at "applying computer settings". About every 4th time they'll actually boot all the way to the login screen.
1. I've disabled the network awareness service.
2. I've disabled anything unnecessary in the program startup menu.
3. I've looked at the non-microsoft services and disabled anything unnecessary.
4. I've tried to restore the computers to a previous state without success. One simply will not go past a certain screen. The other does not have any valid restore states.
5. I've removed them from the domain and rejoined them to the domain without success.
6. I've deleted the computers from active directory, unjoined them from the domain and rejoined them. No luck.
7. I've unplugged the network cable and restarted the computer several tiems. The same behavior occurs.
8. It always boots into safe mode properly.
9. Malwarebytes will not install on one of the computers (same as the failing restore point).
Any ideas? The booting problem did not occur before the virus.
Sounds like they are still infected somewhat. Iv'e seen this before actually at my work, if it's possible at all try taking the hard drive out of the machines and connecting them to a different computer (dont boot to the drive) and try running scans on them through the other computer. And also try HiJack This to help remove things (you have to be booted in the infected drive to do this).
Logfile of HijackThis v1.99.1
Scan saved at 8:31:05 AM, on 12/29/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
download Ad-aware, update it the reboot to safemode.
Make a full scan using your Antivirus and Ad-aware, then delete all detected items.
Local Security Guard Internet Security
Those 3 right there are bad. If anything is running from a temp folder on startup... it will always be some sort of malware... legitimate software doesn't start from a temp folder on the hard drive.
------------------------------Desktop: Windows 7 Professional 64-bit; Intel Q6600 CPU; E-VGA 780i SLI motherboard; E-VGA E-GeForce 8800GT; OCZ Vista 4GB dual-channel kit; Ultra X2 750W power supply; 2 x Seagate Barracuda 7200.11 500GB in RAID 0. Laptop: Acer Aspire 8730-6314;
Reply to Zoron
You are about to answer a thread that has been inactive for more than 6 months. If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.