Vista hangs on start-up; cannot load Windows

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by nelson.peter, Nov 23, 2011.

  1. nelson.peter

    nelson.peter Private E-2

    I opened an email attachment a couple of days ago I thought was from the post office and they "got me". It came into my Inbox, past my junk mail filter, and I over rode a couple of security warnings. But when Spybot wanted to change a registry I realized I was going down the wrong path, quickly closed everything, scanned and cleaned, and thought I had made it.

    But when the computer auto-rebooted in the middle of that evening, I woke up in the morning to a hang. It hangs up on the blue Windows screen (not the deathly blue screen). I followed as closely as I could the instructions given on this forum. Thank you VERY much for this resource.

    But to no avail. It still hangs. I can start in Safe Mode w/ Networking. I backed up my Documents folder prior to trying to remove the malware. Scans found several tracking cookies and one Trojan. But still no start up.

    The manufacturer (Toshiba) has kept the installation disk and wants $30 for "shipping and handling"!!! and 7-10 days. I am hoping you can help me avoid that. I am attaching a couple of the logs. If you need more I will look for them on my computer.

    Thanks in advance for all of your assistance. I really do appreciate it!!!

    Peter
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    There is nothing in these logs that indicates malware problems.

    Do you still have Norton Security Suite installed? It shows in ComboFix as enabled but does not show elsewhere as installed.


    Also please attach the below logs
    Code:
    "C:\Users\Peter\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\"
    supera~1.log Nov 23 2011 6944 "SUPERAntiSpyware Scan Log - 11-23-2011 - 08-06-09.log"
     
    "C:\Users\Peter\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs\"
    mbam-l~1.txt Nov 23 2011 1218 "mbam-log-2011-11-23 (08-53-03).txt"
    

    Also goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    • Be sure to attach your log from TDSSKiller
    Now please also download MBRCheck to your desktop.

    See the download links under this icon [​IMG]
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  3. nelson.peter

    nelson.peter Private E-2

    Well, thanks for getting back with me so quickly. I definitely appreciate that. Great way to spend the Thanksgiving holiday, eh?!! Anyhow, much appreciated.

    I downloaded and ran the two programs you suggested and I am going to attach those log files plus the others you requested. Sure hope you find something! AntiSpyware found the Trojan, so maybe there will be something in its log to help you.

    I cannot find the log for TDSSKiller. I can tell you it found one Medium-risk Digital Signature.

    I am lost on this level of stuff, so having some help like this is a big, definite help. Many thanks, and hope you enjoy the holiday.
     
  4. nelson.peter

    nelson.peter Private E-2

    Uploads attached

    I don't know how to upload MBRC.exe, and cannot find the log file for TDSKiller. But the other two are attached.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are not supposed to upload an exe file. You are supposed to follow the instructions and run the scan with MBRcheck and then attach the log from it. The log from TDSSKiller is where the instructions stated. And that is in your root folder ( which the same location where you found MGlogs.zip) . As long as you followed the instructions properly and did as requested you will find the log there.
     
  6. nelson.peter

    nelson.peter Private E-2

    Yeah, you're right. I found them. I didn't read close enough that MBRC.exe was supposed to be on the desktop. I had it in a Downloads folder. Turns out the log file was there on my desktop all along. Sorry about that.

    Ditto with TDSSKiller. Found it in the root.

    See attached.

    Thank you.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. You never answered my question about Norton.

    These logs are also clean. It does not appear that you are having malware problems. You may want to try a System Restore or doing a Startup Repair from the Vista Recovery Environment. These are things you can discuss in our Software Forum.



    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. After doing the above, you should work thru the below link:
     
  8. nelson.peter

    nelson.peter Private E-2

    I had Norton installed, but uninstalled it in advance of the malware ridding process. For some reason Norton Suite stuck around. I would look for it in Control Panel > Programs, but it was uninstalled. So I guess it was just remnants.

    Bummer you can't find anything. Part of that may be because I have run some of these programs a couple of times -- it is an involved process and I either got lost or confused, couldn't find the log, or had some other reason. In any case, it is possible that maybe an earlier log got written over a log that had found and fixed something. Not sure how that all works.

    I do remember SuperAntiSpyware finding a Trojan.

    I will try your recommendation, but I have already tried restoring and repairing and neither worked. But I can try again.

    Thanks for ALL of your assistance. I really do appreciate it. This is a great resource. I don't have much money (like a lot of people!), but I'll try to throw a little something in the pot to at least show my appreciation. I appreciate your efforts in helping me. I wish we had been more successful. I am not looking forward to giving Toshiba $30 for 7-10 day "shipping and handling"!!!!

    Happy Thanksgiving to you!!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you planning on reinstalling?

    Malwarebytes did remove a few items earlier but there is nothing showing anymore in any of your logs. This is why I'm suggesting that it may just be a problem with Windows now.


    False detection.


    You did a System Restore? To what date?

    Also you got into the Vista Recovery Environment and tried a Startup Repair?


    Thank you! The same to you.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note based on the partition information I saw in your logs, your PC may have a factory recovery partition which you could use to put the PC back into the state it was when it came out of the box. You would just need to backup all important data that you need first before trying this. Then you need to figure out how to do it. It may be part of some boot menu or special startup sequence.

    Mayby the below instructions will work:

    http://www.geekpolice.net/t18281-toshiba-recovery-partition-hotkey-instructions


    Or the Using Toshiba HDD Recovery Utility from the recovery partition section of the below:

    Using Toshiba HDD Recovery Utility from the recovery partition
     
  11. nelson.peter

    nelson.peter Private E-2

    Thank you, for the response. I was off the forum for a few days because I thought my situation had been resolved. But I was wrong.

    I left Thurs. a.m. for Thanksgiving dinner and left my computer running a chkdsk. When I came back that evening it had rebooted to the login window! I started using the computer on Friday and followed the advice given here for protecting my computer -- deleting certain programs and installing others. We are presently running Avira AV with the Comodo firewall. After getting my system to where you recommended it, I then ran Vista SP2 update and scanned the computer as well just to make sure everything was OK.

    I then continued working on the computer without rebooting until this morning when I rebooted for an iTunes update and the computer would not reboot! It got hung up on the same screen as before. Grrrr!!!!

    I tried doing a Recover after pressing F8 on start-up. But when I choose that option all I get is to put a start-up disk in the DVD and run it. I do not have anything coming up about a country option or really anything. It is either 'Enter' and I get asked to put a disk in or 'Esc' and goes into boot mode and hangs up on the same ole screen.

    I tried the second set of instructions you provided regarding the Toshiba HDD Recovery Utility, but there was no active link when I clicked so I could not access that information.

    I backed up all of my data days ago in advance of all of this and I am ready to go. Just don't know which direction to take. If I really do have a start-up partition on my Toshiba, I would be interested in learning how to access it.

    Thanks for reading this far. Good luck in helping me!! (I need it!!)
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that. Try the below:

    http://aps2.toshiba-tro.de/kb0/HTD7C02140000R01.htm


    But I do suggest that you post in the Software Forum because you are not having malware problems.
     
  13. nelson.peter

    nelson.peter Private E-2

    OK. I'll go to the software forum from here on out. Thanks for your help.

    But this is awesome! I found the Recovery Disk Creator. And while I have to wait till tomorrow to pick up 4 DVDs to move forward, it might just save me $30 and 7-10 days! Of course Toshiba doesn't tell me I have that partition when I call in and give them my serial #!!! So thanks a million.

    I'll try to get back here and tell ya how it went. I (hopefully) won't be looking for help -- I'll go to the software forum for that. But thought you might like the feedback.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome and good luck.
     
  15. nelson.peter

    nelson.peter Private E-2

    Man, I am frustrated!! I got the DVDs and started to write Recovery Disks and on the first one I get an error code! I am soooo frustrated!

    I will head over to the software forum and see if anyone has a work-around on this. But it isn't looking good.

    Grrrrrr!!!!!!!!!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well hopefully someone in the Software Forum can help you thru this.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds