Started as redirect now it wont boot

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by az240wanted, Mar 31, 2012.

  1. az240wanted

    az240wanted Private E-2

    My thinkpad laptop running Windows Xp had the google redirect virus. I started to go through the cleaning outline and got as far as the superantispyware when I got a blue screen with an error message. Now it wont even boot in safe mode or to last known working settings, it just gets stuck in a loop with a "blue screen of death". I can get to the recovery console but that's about it. Any help would be greatly appreciated.

    Also on the blue error screen under technical info is says:
    STOP:0x0000007a (0xBA4CF524, 0xC0000034, 0x00000000, 0x00000000)

    not sure if that means anything or not.

    thanks
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Do you know what SUPERAntuSpyware deleted exactly?

    My guess is some system related file that was likely infected with Zero Access.

    Try booting to the Recovery Console and running the below commands:

    • fixmbr
    • fixboot
    • exit
    The 'exit' will cause a reboot. See if it will reboot normally
     
  3. az240wanted

    az240wanted Private E-2

    I have no idea what superantispyware deleted or even if it did delete anything.

    I tried what you suggested and I'm still getting the same error and still stuck in the bootup loop. Is there anything else I can try?

    Thanks for the help.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is there more than the below in the in the blue screen?
    You may be a step or so away from a reinstall. But try the below. It is long and complex, but I frequently can get a PC going again.

    http://support.microsoft.com/default.aspx?scid=kb;en-us;307545&sd=tech
     
  5. az240wanted

    az240wanted Private E-2

    That is the only error code of the blue screen but here is the whole thing:

    A problem has been detected and windows has been shut down to prevent damage to your computer.

    If this is the first time you've seen this stop error screen, restart your computer. If this screen appears again, follow these steps:

    Check for viruses on your computer. Remove any newly installed hard drives or hard drive controllers. Check your hard drive to make sure it is properly configured and terminated. Run CHKDSK /f to check for hard drive corruption, and then restart your computer.

    Technical information:

    *** STOP: 0x0000007B (0xBA4CF524,0xC0000034,0x00000000,0x0000000)

    and that's it.

    Also with the link you posted there is a warning talking about not using that method on OEM installed OS. I believe my OS is OEM installed but how would I know?

    Also, I don't have a boot disk which is required in that method.

    PLEASE tell me there is still a way to fix my computer.

    Thanks
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't have much of a choice.

    Then how are you getting to the Recovery Console.
     
  7. az240wanted

    az240wanted Private E-2

    Ok, well I guess I'll try to get a hold of a disk then.

    When my computer is booting up, just before the screen that gives the option for various safe modes or normal start up, there is a screen that gives me an option to start windows recovery console or windows xp professional. Am I not actually getting to the recovery console when I choose it then?

    Thanks
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ah! So you have the Recovery Console already installed to your hard disk. You can therefore use it to follow those instructions.
     
  9. az240wanted

    az240wanted Private E-2

    I started the procedure you linked and completed step one, however step two requires that you log into windows to change some files and I still cant log into windows. I am still stuck in a boot up loop with the blue screen of death and same error. What can I do now?

    Is there any way to copy over some folders to a flash drive from windows using the recovery console?

    Thanks
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not from the recovery console. You will have to either put the hard disk into another PC as a slave drive, or you will need to make some other special boot CD to use. This backup topic is not really a topic for this forum but CDs like below may be of some use. Especially see the link for Ubuntu and using it to do backups.
     
  11. az240wanted

    az240wanted Private E-2

    I got a hold of a recovery disk and used the repair feature. The computer now starts up but it takes a really long time to log off or shut down. Also in the add/remove programs it only shows a few programs (about 10) most of the programs will not show up. I was trying to uninstall avg and download the newer java and neither would show up on the add/remove list.

    thanks
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which disc did you wind up using?

    Please download and save the below to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it ( if you are running Vista or Win 7, use right click and select Run As Administrator ). Did that help with your missing items?

    Now skip most of the READ & RUN ME cleaning procedure and let's just run MGtools per the below:

    Using MGtools
     
  13. az240wanted

    az240wanted Private E-2

    The disk just says windows xp professional on it.

    I downloaded unhide and ran it but it didn't help.

    I then ran the mg tools and got a .NET error. I tried to download the fix from Microsoft and got errors from that when I tried to install it.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ah! Now I see why you are missing things from Add/Remove Programs. You did a repair with Windows which likely did a form of a System Restore which means anything that anything you had previously installed that was after a point in time that you restored to is effectively gone. Even though the files for the programs may remain on your PC, your registry no does not know of them due to the restore. Hence they are gone and you will have to reinstall anything you want to reinstall.

    Another possibility may be to see if there is a more recent restore point that you can restore to but this seems unlikely since I only see a few different restore points from March 31st. The ones from April 15 are after you already did your repair. But even so, one of the ones on March 15 may be useful..... like the oldest one which is

    24,576 2012-03-31 04:34:11 C:\system volume information\_restore{454A983E-8012-4A52-AA8F-FCBC6EDF9B4D}\RP1\snapshot\_REGISTRY_MACHINE_SAM
    49,152 2012-03-31 04:33:32 C:\system volume information\_restore{454A983E-8012-4A52-AA8F-FCBC6EDF9B4D}\RP1\snapshot\_REGISTRY_MACHINE_SECURITY
    40,108,032 2012-03-31 04:33:56 C:\system volume information\_restore{454A983E-8012-4A52-AA8F-FCBC6EDF9B4D}\RP1\snapshot\_REGISTRY_MACHINE_SOFTWARE
    11,083,776 2012-03-31 04:34:11 C:\system volume information\_restore{454A983E-8012-4A52-AA8F-FCBC6EDF9B4D}\RP1\snapshot\_REGISTRY_MACHINE_SYSTEM
    503,808 2012-03-31 04:33:32 C:\system volume information\_restore{454A983E-8012-4A52-AA8F-FCBC6EDF9B4D}\RP1\snapshot\_REGISTRY_USER_.DEFAULT
     
    Last edited: Apr 19, 2012

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds