Can't run TDSS Fixers

Discussion in 'Malware Help (A Specialist Will Reply)' started by occcctane, Oct 26, 2012.

  1. occcctane

    occcctane Private E-2

    Attached is the RogueKiller log. Hitman found nothing, and generated no log as a result. I took a screenshot of the final screen that it gave me, and it is attached.

    I also tried again to go to "Repair Compter" from a dead stop, and it still goes to the black screen.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay the MaxSS MBR infection is still showing. Since you do not have a Windows 7 boot DVD, and you cannot get FRST to run, our options are limited. We will try some other tools to see if they can fix the MBR but frequently the only method that will work is a boot CD.

    Let's first run a scan with the below and see what it shows.


    Please download aswMBR ( 511KB ) to your desktop.
    • Double click the aswMBR.exe icon to run it
    • Click the Scan button to start the scan
    • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
     
  3. occcctane

    occcctane Private E-2

    No matter whether I double-click or Run as Admin, all I get is a brief blue circle, and then nothing.

    Are there any conditions I need to have my computer in (UAC, Internet, etc.?)
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should never have reenabled UAC. It should remain disabled until we are finished. So disable it and reboot for it to take effect. If you cannot get aswMBR to run in normal boot mode, try safe boot mode.
     
  5. occcctane

    occcctane Private E-2

    Actually, my UAC was still disabled, but I've since enabled it, while I await your response. So, I disabled it, rebooted, and tried again with the same results. I rebooted to Safe Mode and the same thing happens (both double-click and Run-as-Admin).

    So, I re-downloaded the file and saved it directly to the desktop. I usually save to a USB and then transfer because of the slow speeds. Now when I double-click I get a warning that the file's publisher could not be verified, but I click on 'Run' and not 'Cancel.' Then I get the blue circle again for a brief moment and then nothing. I get just the brief circle and then nothing with trying to Run-as-Admin.

    What else can I try?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    A Windows Boot CD because nothing runs on your PC. Other possible choice is to use a factory reovery partition to reimage back to factory ship state but remember this will wipe all of you data and setting so you must backup everything you need before doing this.

    POSSIBLE ALTERNATIVE: Or another possible option may be to try what was posted in message # 12 of the below thread and see if you can get this CD to run.

    whistler/black internet@mbr again!

     
  7. occcctane

    occcctane Private E-2

    I was able to create the disk, as far as I can tell. I'm not sure the other instructions that were in that post apply to me, however, so I am going to wait for you to tell me what to do.

    I came up with somebody through the Freecycle community that at first was saying they could create a boot disk for me, but then decided that if I didn't fix my system their way, they weren't going to help me. Some people are just mean-spirited.

    I'm having something funky starting today in my browsers. When I try to click in a box, such as the login/pw box on this site, and even the Quick Reply box, I can't get the cursor or type anythin. On my classroom site where I have to click on one area, and then choose from a menu that appears, I can't click in the menu area. It just disappears. Hopefully we can get this fixed before the system totally melts down!
     
  8. occcctane

    occcctane Private E-2

    Just FYI- I ran Malwarebytes because of all the trouble I was having. I couldn't even get into my email, and I HAVE to keep up with that for school. I've attached the log, in case it will mean anything to you. Now that I've done that, I don't have the problems clicking in text boxes, and I can get into my email.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All of message #12 applies to you which is why I sent you there. You need to get your MBR fixed. All of what Malwarebytes is finding is just due to the same infection we have been trying to fix. But since you have not been able to any tools and you don't have your Windows Boot Disk. You need to try this Hiren's Disk and procedure. Remember that it is highly recommended that all important personally data be backed up first.
     
  10. occcctane

    occcctane Private E-2

    OK, so I did that. I chose MBR Code Base "Standard" and not "Windows 7" because that was what the instructions stated. Now I've returned to boot from HD, and when it tries to boot up, it says "Windows failed to start. A recent hardware or software change might be the cause. If Windows files have been damaged or configured incorrectly, Startup Repair can help diagnose and fix the problem. ....." It gives me the option to "Launch Startup Repair (recommended)" or to "Start Windows Normally." When I choose the second one, it fails and returns to this screen.

    Should I allow it to Repair? If so, what should I expect - what choices will I have to make as it does this? I'm guessing I will have to be prepared to see the process through to the end.

    As a reminder, I will have to use public computers to be able to reach you now that my computer won't boot at all. There are time limits on access, so I want to be sure I know every thing I need to do before embarking on the next task.

    My sister thinks she can locate somebody with Win7 Home Premium 64-bit who would be kind enough to generate a DVD for me, so perhaps that will be an option soon.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I was worried about this due to the severity of your infection. Try the Startup Repair and just let it do its thing. Hopefully this will work but I'm not too certain it will. You may need that Windows 7 Boot CD to get anywhere at all, but it may be looking more like you need to reinstall.
     
  12. occcctane

    occcctane Private E-2

    Have I lost everything or will I if I do the repair vs. the reinstall? I will get the boot DVD tomorrow (Monday) so maybe I should just wait for it??
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have not lost everything. It is still there. Getting at it is the problem because you cannot boot up now. You can wait for the DVD ( hopefully it is really a bootable DVD ) and we can try a couple things. But these infections can sometimes cause irrepairable damage which does require a reinstall.
     
  14. occcctane

    occcctane Private E-2

    OK, my sister has sent me a DVD that was made with Windows 7 Home Premium 64-bit, which is the OS that I have. The person wrote "64-bit Repair Disk" on the DVD, and the disc is electronically named "Repair disc Windows 7 64-bit" which I don't know if was done by their computer or by the user. It has two folders in the root directory: boot and surces plus a single file named bootmgr. The first folder has only three files in it: bcd, boot.sdi, and bootfix.bin. The second has one a single file in it called boot.wim.

    Do I have what I need? If not, I know I can ask again. I found a willing helper.

    I have left my computer in the state it was in with Hiren's CD in the drive. When I turn it on, I expect it to ask me to Repair or Boot normally, as it did the last time I tried. I thought I should wait to see if you instruct me to go ahead and do the Repair as you suggested in Post #61, do something different with Hiren's, or to switch to the DVD and try something else. I've done nothing yet because I don't want this tangle to get any worse! :)

    Hope you are having a great week, and plan on a healthy, hearty meal on Thursday!
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like it is just a repair disk, not a full Windows Boot CD, but perhaps we can get it to help us. Let's see if we can get FRST to run now after booting your PC from this disk. We tried this earlier ( back in msg # 9 ) but you could not boot from the hard disk into the Recovery Environment. So try the below booting from the Windows 7 DVD.

    Please do the below so that we can boot to System Recovery Options to run a scan.

    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.



    Enter System Recovery Options by using Windows installation disc:
    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
    If the above works, you don't need to stop to attach the log right now. Will will get it later. Just continue on with the below to see if we can get your PC booting.


    Download this >> View attachment fixlist.txt


    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows ( if possible ) and continue with the below.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the original FRST.txt log
    • Fixlog.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  16. occcctane

    occcctane Private E-2

    I asked my sister about the DVD, and she said they followed the directions for making a boot disk, and that she labelled it according to the directions. I believe it worked OK, because......

    Farbar worked, and I THINK my redirect is gone!! I've google'd places that I've gone before and that I haven't gone to before, and I go where I'm supposed to go..... imagine that! My computer is also faster. Now I have to see if my battery continues to be short-lived and needs to be replaced, or if it was being taxed by the malware's activities.

    Attached are the files you requested.

    Now - how to prevent this?? I do NOT click on unknown email links or download anything without serious consideration, and I don't use social media or anything like that. I play some simple logic games from a single site, and the rest is school, email, and high-profile job boards such as the Washington Post, which often takes me to 'Simply Hired' posts. I have no idea how I got this in the first place because I am extremely careful.

    I keeping my fingers crossed and I'll watch carefully for the next day or so....

    THANKS -- I am breathing a sigh of relief, especially since the libaries are all closed for the next two days! :)
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Now you are aware of how important it is to have a Windows Boot Disk and how negligent it is of PC manufacturers for not shipping them with PCs. ;)

    Looks like you should have Internet access now ?

    We have more to fix from your ZeroAccess infection. We will use another FRST fix.

    Download this >> View attachment fixlist.txt



    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows can continue with the below.



    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • Fixlog.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  18. occcctane

    occcctane Private E-2

    Hmmm. I'm a little confused. I may be getting redirects in Chrome. I randomly Google'd "shannon" and then clicked on the link for Shannon Health. I end up on a lowfares.com page. I repeated the process in IE and got to the Shannon Health page, but I saw it flip through a Facebook page on the way.....

    So, I tried another random search - "valentine" in Chrome and then clicked on the link for valentinesalbany.com and arrived at another one of those funky search pages: http://www.feedsmixer.org/s.php?k=v...//discount-find.in/index.php?search=valentine

    I repeated this in IE and landed on http://valentinesalbany.com/ but saw it flip through youtube on the way.

    I did a booboo in your directions, though. When I clicked on the Repair Windows, I did a double-click rather than "Run as Admin." Let me know if I have to re-do. Attached are the files you requested.

    BTW, the very first thing I did when I got this computer was make a Boot Disk, which I always do, however when my rental home got foreclosed and they changed the locks before I could get everything out, then after 4 months of fighting with them, they cleaned out the house a couple days before they finally granted me access to my things.... so everything was gone, including a couple large boxes of software and hardware. Good ole' Bank of America. What a mess they are!!

    Let me know what I should do now!! I'm feeling a bit vulnerable!
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall Chrome and then reboot.

    After reboot, delete the below folder.
    C:\Users\Tiger\AppData\Local\Google

    Then use IE to download and install the below if you still want Chrome:
    Google Chrome 21.0.1180.89 Final
     
  20. occcctane

    occcctane Private E-2

    OK! :) It looks like all is clean :) WOOHOO!! Back to school!

    Should I use Google Safe Browsing to help me in the future? Chrome is not my browser of choice, but I could change if it is a good idea. Is it best to place the little icon on my toolbar?
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Personally I prefer Internet Explorer over Google and Firefox. We have more infection/issues with Chrome and Firefox here where they constantly have to be uninstalled to fix problems.

    If you feel that you are not a safe/educated surfer, then perhaps a tool like Google Safe Browsing or McAfee's SiteAdvisor would be useful for you.
     
  22. occcctane

    occcctane Private E-2

    I prefer IE as well, but there are a couple sites that I have to go to that just don't work right in IE.

    I'll keep Malwarebytes and run it to keep me safe.

    I hope I don't have to go through all this again.... and HAPPY HOLIDAYS!!!

    You are so patient and kind!! AWESOME!
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Happy Holidays to you too.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  24. occcctane

    occcctane Private E-2

    Wow, that was a lot of reading! All the scans turned up clean, so I completed all the steps. I also read through the continuing protection links and have a question about disabling the AutoRuns. I didn't see a procedure for doing this in Win7. Can it be done or has Microsoft done something different for Win7?

    Thanks again for all the help. So glad that Sandy didn't disable your access!! I know it's still awful up there.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Just use the below tool.

    Autorun Eater
     
  26. occcctane

    occcctane Private E-2

    I finally got to it. Was working frantically to get caught up on school. Have an exam tonight.... :)

    Thanks again, and have a great holiday!!
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds