I think I really messed up.

Discussion in 'Malware Help (A Specialist Will Reply)' started by newbieputerbuf, Sep 1, 2012.

  1. newbieputerbuf

    newbieputerbuf Private E-2

    Go to do Few things on my Grandson's computer and I fire up Windows Internet Explorer and find the toolbar about 1/4 of the page. Go to the Majorgeeks link on cleaning up wimdows as I can't delete the Whitesmoke or Babylon toolbars, and the neither Momzilla or Internet Explorer go to the saved homepage - they go to something with babylon in the URL.

    Wel go to Majorgeeks page and download Ll the recommended software (RogueKiller, Hitman, TtDSSKiller, etc.) and after runng TDSSKiller I ,made the mistake of sending some file to Quarantine
    - not reading the instructions that specifically told me to just do default. Filename, to the vest of my recollection was something like "NVSTAT" or something and I selected Quaraninte. Well during reboot it did not come up and recycled, and then I selected the option to get last desired. Well that didn't work, and then I tried the other 2 or 3 options including Safemode. Well each one reboots. I see some blue screen come up with a bunch of text, but it goes away so quick I can't read it.

    How bad am I hosed? Is there any chance I can restore this file? I'm guessing it's probably some Windows system file.

    This Babylon and Whitesmoke toolbars are bears to remove. I did an uninstall on both, but they pop up after rebooting - but did not show in the Add/Remove Programs nor through JV16 or the other Uninstall program (not remembering name) recommends through Majojrgeeks.

    Appreciate if someone can direct me back to at least being Ble to reboot so I can do the clean procedure.

    Thanks,

    Dave
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What version of Windows?

    Also do you have the Windows Boot CD/DVD?
     
  3. newbieputerbuf

    newbieputerbuf Private E-2

    chaslang - thanks for the reply. Sorry I didn't specify that key piece of info - it's Windows XP and I do not have a boot disk, but will now go in and see if I remember how to build one.

    Thanks
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can't. At least not legally.

    You need to figure out exactly what you deleted with TDSSkiller and restore it. Guessing at file names is not going to help us.

    There's a possibility you could make an Ubuntu CD like below and boot up with it.

    Ubuntu LiveCD

    Then locate the C:\TDSSKiller_Quarantine folder and see if you can find out what was deleted. However even this may be hard to do since Kaspersky renames everything which makes manual fixing difficult. I'm not sure if Kaspersky's own boot CD can be used to restore things that TDSSkiller has removed. You may want to check out the below.

    Kaspersky Rescue Disk

    And this help link >>> http://support.kaspersky.com/viruses/rescuedisk/all?qid=208282173
     
  5. newbieputerbuf

    newbieputerbuf Private E-2

    Found a Bart PE CD and was able to get in and find a file tied to TDSSKiller and the file quarantined was NVSTAT.sys. I can not find the file itself, so is there any way to download it?

    Thanks
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As far as I know, that is not a Windows file. Are you sure about that name?
     
  7. newbieputerbuf

    newbieputerbuf Private E-2

    Yea it is correct. Doing a google on it, it appears its part of a set of drivers from NVIDIA
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have heard of nvstor32.sys for Nvidia but not nvstat.sys
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds