Dell Latitude Laptop - No Boot

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Edrox, Jan 23, 2012.

  1. Edrox

    Edrox Private E-2

    Girlfried was using her Dell Latitude. Sufice to say she clicked a link she shouldnt have. She says there were LOTS of popup windows and then the compy shut down.

    Now, when we boot it we get the start screen them it goes black - never booting up.

    I booted from the CD, and tried a system restore - no good. Tried a repair - no good.

    So, here I am again axing for HALP!
     
  2. Edrox

    Edrox Private E-2

    UPDATE (Not a bump) : Got computer to boot to original Dell Win7 CDR. Tried a startup repair but got nowhere. system restore not working. Do I re-install W7 or what?

    Thanks in advance for all help

    Oh - forgot one thing

    When I try to run the system repair from teh DVD, I get this mssg:

    Startup Repair could not detect a problem. If you have recently attached a device to this computer, such as a camera or portable music player, remove it and restart. If you continue to see this mssg, contact your system admin or manufacturer for assistance.
     
    Last edited: Jan 24, 2012
  3. thisisu

    thisisu Malware Consultant

    Hello Edrox,

    [​IMG] For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.
    On the System Recovery Options menu you will get the following options:

    • Startup Repair
    • System Restore
    • Windows Complete PC Restore
    • Windows Memory Diagnostic Tool
    • Command Prompt
    Select Command Prompt
    In the command window type in notepad and press Enter.
    The notepad opens. Under File menu select Open.
    Select "Computer" and find your flash drive letter and close the notepad.
    In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    Note: Replace letter e with the drive letter of your flash drive.
    The tool will start to run.
    When the tool opens click Yes to disclaimer.
    Press Scan button.
    It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  4. thisisu

    thisisu Malware Consultant

    This should not be necessary and it is a last resort. Reinstalling Windows would also cause you to lose all your data / programs which I doubt you want to do all over again.

    Let's get a FRST log first so I can get a better idea of what is going on.

    sach2 pointed me to your thread in Software. I have reviewed this. Just letting you know ;)
     
  5. Edrox

    Edrox Private E-2

    thats part of the issue - on restart, F8 does nothing for me. Cant get it into the advanced options at all
     
  6. Edrox

    Edrox Private E-2

    will this work if I boot from the CD? I can get to the command prompt that way
     
  7. thisisu

    thisisu Malware Consultant

    Yes it will work.
     
  8. Edrox

    Edrox Private E-2

    Logfile attached
     

    Attached Files:

  9. Edrox

    Edrox Private E-2

    just in case it changed something. I followed the advice and reset partition 1 active. Ran startup repair. Re-ran FRST64.exe

    new logfile attached
     

    Attached Files:

  10. thisisu

    thisisu Malware Consultant

    Ok don't change anything else until we do the below:

    Boot back into Windows Vista Recovery Environment. Go back into the command prompt window, and then type the below commands in this order:

    1. diskpart
    2. select disk 0
    3. select partition 4
    4. active
    5. exit
    6. exit

    Then reboot your system.

    If it does not boot all the way to desktop, then run another Scan with FRST64 and then attach the new log
     
  11. Edrox

    Edrox Private E-2

    didnt boot

    re-scanned

    logfile attached
     

    Attached Files:

  12. thisisu

    thisisu Malware Consultant

    [​IMG] Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. Save it on the flashdrive as fixlist.txt

    Code:
    start
    HKLM\...\RunOnce: [*Restore] C:\Windows\system32\rstrui.exe /RUNONCE [296960 2009-07-13] (Microsoft Corporation)
    cmd: diskpart
    cmd: select disk 0
    cmd: select partition 3
    cmd: active
    cmd: exit
    cmd: bootrec /fixmbr
    cmd: bootrec /fixboot
    cmd: md h:\BSODlogs
    cmd: copy /y C:\Windows\Minidump\011812-19297-01.dmp h:\BSODlogs
    cmd: bcdedit /enum all
    end
    
    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    On Vista or Windows 7: Now please enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.
     
  13. thisisu

    thisisu Malware Consultant

    I assume the script is still saying Fixing... ? (it hanged)

    In which case I will need to guide you through this step by step
     
  14. Edrox

    Edrox Private E-2

    the fix has been running a very long time. is this normal?
     
  15. Edrox

    Edrox Private E-2

    OOPS - just saw your previous post

    yes, its hung up
     
  16. thisisu

    thisisu Malware Consultant

    No problem, I was trying to get output from FRST so I could get exact output to see which steps completed successfully and which did not.

    So now you will need to be specific ;)

    For this next part I need to know what certain commands below tell you. For future reference, I will put a bold red * symbol next to the command. These I need exact messages on what each of these say. The rest of the commands that do not have a * I don't need any information from.

    Reboot the PC back into Windows Vista Recovery Environment -> Command Prompt

    Let's start small:

    Type the following commands into the Command Prompt using your CD:

    1. diskpart
    2. select disk 0 *
    3. select partition 3 *
    4. active *
     
  17. Edrox

    Edrox Private E-2

    diskpart
    select disk o = disk 0 is now the selected disk
    select partition 3 = partition 3 is now the selected partition
    active = diskpart marked the current partition as active
     
  18. thisisu

    thisisu Malware Consultant

    Continuation:

    • detail partition *

    I don't expect you type out the ------- :p

    All I need from this is what is under Volume ###, Ltr, Fs, Type, Size, and Status

    And double check that Active: = Yes


    Note: You should stay in Windows Recovery with the Command Prompt open for the remainder of this. Don't try to reboot or even leave diskpart yet, as we are not ready to test if you can boot properly
     
    Last edited: Jan 25, 2012
  19. Edrox

    Edrox Private E-2

    volume 2
    Letter E
    Label OS
    FS = NTFS
    type = partition
    size 58Gb
    status healthy
    active yes
     
  20. thisisu

    thisisu Malware Consultant

    That looks correct.

    Now type in the following commands:
    1. exit (this will cause you to leave diskpart)
    2. bootrec /fixmbr *
    3. bootrec /fixboot *

    Note: There is only a SPACE between 'bootrec' and '/'
     
  21. Edrox

    Edrox Private E-2

    /fixmbr completed successfully
    /fixboot completed successfully
     
  22. thisisu

    thisisu Malware Consultant

    Good, now type in:
    • exit

    Leave command prompt and Windows Recovery environment and reboot your PC as it's time to see if you can boot properly (don't boot from the Cd/DVD / eject it if you need to)

    If the PC does not boot properly, let me know exactly what error message you receive.
     
  23. Edrox

    Edrox Private E-2

    HELL YEAH


    You are the man! I will have your children


    anything else I need to do? I am obviously going to doo a deep scan on the HD for any other nasties that may be there. But otherwise?
     
  24. thisisu

    thisisu Malware Consultant

    :-D Glad to hear you are up and running again.
    A deep scan with what? I'd rather you go through this: READ & RUN ME FIRST Malware Removal Guide

    This is much more thorough than any single anti-virus scan IMO. It was your anti-virus that did not block the infection in the first place remember? Plus this way we can remove ALL traces of infection, and not just the obvious ones.
     
  25. Edrox

    Edrox Private E-2

    yeah - I actually use Malwarebytes and SPybot for routine scheduled scans on my personal comp. I keep avast running real time. Usually I am ok. This was not my laptop, it was hers. God knows the last time she did a real clean on in. I will go through all the steps though

    You are the best - thank you so much.
     
  26. thisisu

    thisisu Malware Consultant

    No problem.
    Whenever you get around to it, attach the logs from the scans in the Malware Removal Guide here in this thread so I can double-check them.
     
  27. Edrox

    Edrox Private E-2

    will have to be tomorrow - I am beat and 5am is m y start time


    Again - thanks a million!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds