Removed viruses and now the computer won't boot into Windows...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by sa91899, Apr 6, 2012.

  1. sa91899

    sa91899 Private E-2

    Hello,

    I hope someone here can provide some assistance with this issue. I am sort of at a loss...

    A friend asked me to look at their computer because they thought they may have a virus, so I got the laptop here I turned it on and before booting into windows it did a chkdsk so I waited for the chkdsk to finish then it restarted booted into windows 7. I noticed that it was running a bit slower than I expected but I was able to get on line and download Microsoft Security Essentials. I ran security essentials and it found 6 viruses. (Can't tell you what they were) but it suggested that I reboot to finish fixing the infestation. I rebooted and now I have an issue that it will not boot into windows. It will get to the screen where the multi-colored dots come together to form the Windows logo then it will reboot.

    I have tried to go into safe mode however it pauses and reboots when it gets to the file Windows/System32/drivers/classpnp.sys. A blue screen flashes for a split second then reboots. I was able to determine what the blue screen says after multiple times of rebooting. It says, "CR 00000135 The program can not start because %h$ is missing from your computer. Please try re0installing the program to fix this issue."

    After it reboots, if I do nothing it does come to a screen asking if I want to run windows recovery. If I choose that option Windows recovery comes up and asks if I want to do a restore. It tells me after waiting some time that the restore option will not work. So when I reboot and try the recovery option again, I chose no to the restore option and it tries to run the recovery tool. It now has a screen that says attempting repairs with the progress bar that keeps moving left to right like it is scanning the system, but it has been like that for close to 2 hours now.

    That's all the info I can give you right now and that is where I am...

    Hope someone can help me.

    I would appreciate any information you could provide.

    Thanks,

    Steve
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please do the below so that we can boot to System Recovery Options to run a scan.

    For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  3. sa91899

    sa91899 Private E-2

    Scan result of Farbar Recovery Scan Tool Version: 15-03-2012
     

    Attached Files:

    Last edited by a moderator: Apr 9, 2012
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is not the FRST.txt log I need. You attached a copy of the procedure I gave you.
     
  5. sa91899

    sa91899 Private E-2

    I didn't attach anything. I posted the log file results right in the thread. Someone edited it and took it out. I am not sure why they did that...

    Here is the correct file attached that I originally copy and pasted into a reply...
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download this >> View attachment fixlist.txt

    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows if possible and continue with the below.


    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide
     
  7. sa91899

    sa91899 Private E-2

    Chaslang thanks for the help. I ran the fixlist and have attached the log.

    I restarted the pc and it came up with a chkdsk screen that said it aborted and then rebooted. Once it rebooted Windows opened :) Finally after how long I forgot...

    Running the READ & RUN ME FIRST Guide now.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Okay, just attach the requested logs when you finish.
     
  9. sa91899

    sa91899 Private E-2

    Here are the logs from the RUM ME FIRST guide.

    I did not run Root Repeal since this is a 64bit system...
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay first you need get ComboFix.exe on your Desktop as requested or you will not be able to follow future instructions and cleanup procedures. You have it here >> e:\computer stuff\ComboFix.exe

    Did you have your PC disconnected from your network connection when you ran the last MGtools scan? If you did, then don't do that. Only do what we ask. If you did not have it disconnected, then I would ask the obvious which is "Are you having problems connecting to the internet?"

    You have some left overs from McAfee and a few other misc things to remove.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?l=dis&o=14196
    O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds