Can't log on after Norton Power Eraser - frst log attached

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ClubSport, Dec 24, 2013.

  1. ClubSport

    ClubSport Private E-2

    Hello, I'm trying to remove something called bloodhound.pdf.21 from my in-laws computer. Win7 SP1 - 64 bit. NPE told me it had to reboot to check for rootkits etc. So I clicked ok. After getting back to the windows log in screen, I type the password and it says "The user profile service failed the logon. User profile cannot be loaded".

    I am now logged in under safe mode. The password works and I get a notification saying default user profile is in use. I found this website after a google search and ran the farbar tool. Attached is the log.
    Thanks very much for any assistance in getting this corrected.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    We do not recommend running tools like Norton Power Eraser (NPE), Windows Defender Offline (WDO).....etc because quite frequently the end result is an unbootable PC.

    Since we do not know what NPE did, it may not be easy to repair. Since you can boot in safe mode, a System Restore may be the way to go. However there is some junk to remove and we can remove that with FRST and see what happens before trying a System Restore.


    Download this >> View attachment fixlist.txt


    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now see if you can boot into normal Windows!
     
  3. ClubSport

    ClubSport Private E-2

    Hi, and thanks for the quick reply.
    I did what you asked and attached the fix log. I rebooted and tried to log on in normal mode, but still could not. I have never done a system restore before, and I asked the in-laws for any kind of Windows CD, but they say nothing came with this Dell.

    I don't know if it's relevant, but when I run frst64 from the command line I get an error message saying there is no disk in the drive, with some kind of path named. I press continue and it seems to work after that.
     

    Attached Files:

  4. ClubSport

    ClubSport Private E-2

    Well what I ended up doing for now is enabling the hidden Administrator account and logging in with that. I created another admin for me to use, and a standard account for the old folks. I managed to save all their pictures and move them over to the new account. That's about all the personal files they had. I disabled the hidden account after that. I think NPE removed the bloodhound thing, for all the damage it ended up doing. I don't see any new quarantine notifications from symantec endpoint.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds to me like you are saying NPE deleted or broke the previous user account. Not sure why Symantec would even recommend using NPE for this infection. It should not be that difficult to remove. At anyrate, NPE supposedly has the ability to undo what it does. The below is a quote from its docs:
    Instructions to undo are here:

    https://support.norton.com/sp/en/us/home/current/solutions/v70458950_EndUserProfile_en_us?src=smr2011
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds