Possible MBR Virus? Computer freezes and beeps

Discussion in 'Malware Help (A Specialist Will Reply)' started by timgonz98, Mar 1, 2010.

  1. timgonz98

    timgonz98 Private E-2

    OK I have been trying to find the root cause of my computer, (Windows XP Media center), freezing up and then sounding a constant tone. This only happenes when I am running and doing a lot of mouse activity on any program except internet explorer. First I tested my ram hardware by switching them out one by one thinking that I had a Hardware issue. I then unpluged all of my hardware and pluged them back in (i did not mess with my processor). This did not fix anything. I downloaded and installed the reccomended programs on the read me first forum. I did not run the combofix or MG tools yet. roorepel detcted a MBR rootkit but I don't know how to get rid of it.

    I have one Windows XP insalled on my C: Drive and one Windows XP on my D: Drive. I also have Windows 7 installed on my D: drive. The freezing does not happen in Windows 7 OS.

    Please help me figure out why my computer freezes up.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Which OS did RootRepeal detect an mbr rootkit on?

    Whichever one it was then log into it and run ALL of the requested scans, in order, including SAS, MBAM, (attach the log from RootRepeal) Combofix and MGTools. Attach logs from each. :)
     
  3. timgonz98

    timgonz98 Private E-2

    Here is the Malwarebytes log and the rest is attached. I got a "16 Bit MS-DOS Subsystem" Error message and atempted to fix it without any luck. I was still getting the message after I followed the procedure to fix it. My computer automatically restarted and ran a check disk during the ComboFix scan for some reason. I did not see anything in the procedure stating that the computer will reboot.

    Malwarebytes' Anti-Malware 1.44
    Database version: 3809
    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    3/1/2010 12:39:07 PM
    mbam-log-2010-03-01 (12-39-07).txt

    Scan type: Quick Scan
    Objects scanned: 172463
    Time elapsed: 16 minute(s), 10 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 2
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Scroll down to Error Message Type 2 to address this.

    using MGTools

    Why did you not run SUPERantispyware?

    1. Please go to Add/Remove programs and uninstall the following software:

    • Java 2 Runtime Environment, SE v1.4.2_03
    • Java(TM) 6 Update 17
    • Java(TM) 6 Update 3
    • Java(TM) 6 Update 5
    • Java(TM) 6 Update 7


    2. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Folder::
    C:\Documents and Settings\HelpAssistant.TIM.000
    C:\Documents and Settings\HelpAssistant.TIM
    C:\Documents and Settings\HelpAssistant
    c:\documents and settings\Tim Gonzales\Local Settings\Application Data\pcausk
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    3. Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.

    4. Now download and run SUPERAntispyware as per the instructions in the Read & Run Me First Guide.

    5. Attach the log from doing so in your next reply.

    6. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    7. You did not agree to the Trend Micro HJT license when you first ran MGTools.exe. (There is a bug and you will have to click "accept" twice!) So let's try again:

    8. Double click the C:\MGtools.exe to run it, this time round agreeing to the TM HJT license.

    9. Attach the C:\Mglogs.zip into your next reply, as well as the log from running combofix, TDSSKiller and SAS.

    10. How is your computer behaving now?
     
  5. timgonz98

    timgonz98 Private E-2

    1. I failed to mention that I ran SUPERantispyware which found no threats before my last post. There was no log of my scan in the logfile. I ran it again per your request and attached the current log.

    2. I removed Java and re-installed in your specific order of operation.

    3. I used combofix (log attached).

    4. I used TDSSKiller, There were no instructions to "delete" anything when I ran it. below is all I saw when I ran it. The log is attached.

    TDSS rootkit removing tool, Kaspersky Lab, 2010
    version 2.2.7.1 Feb 27 2010 13:29:25

    Scanning Services ...

    Scanning Kernel memory ...

    Completed

    Results:
    Memory objects infected / cured / cured on reboot: 0 / 0 / 0
    Registry objects infected / cured / cured on reboot: 0 / 0 / 0
    File objects infected / cured / cured on reboot: 0 / 0 / 0

    Press any key to continue . . .


    5. I ran MGTools.exe again but I was never asked to accept the Trend Micro HJT license. I tried reinstalling MGTools but that did not make a difference. How do I find and accept the licence agreement?

    I don't know what I am doing wrong when trying to repair the "16 Bit MS-DOS Subsystem" Error message. I Scrolled down to Error Message Type 2 to address this error. I followed the procedure but it didn't seem to get rid of the error. I clicked on Start > Run typed in regedit and located HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\VirtualDeviceDrivers\VDD. I deleted VDD and added a new Multi-string Value and renamed it VDD.

    Microsoft says, "If the issue continues to occur, verify that the proper version of the Command.com file is installed in the systemroot/System32 folder on your computer." I dont know how to verify that I have the proper version installed.

    COMMAND.COM
    Type of file: MS-DOS Application
    Description: COMMAND
    Location: C:\WINDOWS\SYSTEM32
    Size: 49.4 KB (50,620 bytes)
    Size on Disk: 52.0 KB (53,248 bytes)
    Created: Tuesday, August 10, 2004, 3:00:00 AM


    6. My computer has not froze since this morning while running SUPERantispyware. I had to restart the scan this morning.

    7. Should I re-enable my antivirus?
     

    Attached Files:

    Last edited: Mar 3, 2010
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just attach the C:\Mglogs.zip anyway into your next reply please.
     
  7. timgonz98

    timgonz98 Private E-2


    Attached are the logs.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Run this batch file:

    Open NOTEPAD and copy/paste the text in the codebox below into it. Do not include Code


    • Double click the Helpass.bat and post the log it produces.

    2. Next run this:

    Profiles.

    Please download Profiles.exe by Noahdfear and save it to your desktop.

    • Double click Profiles.exe to run the tool
    • Notead will open - Post the contents in your next reply.

    3. Then run this.


    Download HelpAsst_mebroot_fix.exe by noahdfear and save it to your desktop.
    • Double click HelpAsst_mebroot_fix.exe to run the tool.
    • When the tool completes it will inform you HelpAssistant was successfully removed, or it may require a reboot

    Whether the tool requires a reboot or not go to Start > Run and copy/paste the following into the run box (Do Not include code: ) If the tool does need a reboot, do this before rebooting

    4. Now reboot.

    5. Open NOTEPAD and copy/paste the text in the codebox below into it. Do not include Code.

    6. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the logs from running Helpass.bat, profiles.exe & MBRlook.bat.


    7. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
    Last edited: Mar 5, 2010
  9. timgonz98

    timgonz98 Private E-2

    1. Ran Helpass.bat successfully. The log is attached.

    2. Ran profiles.exe successfully. The log is attached.

    3. HelpAsst_mebroot_fix.exe tool removed the HelpAssistant. Before rebooting I ran \MBR -f. I got an error message that read:

    "Windows cannot find '\MBR'. Make sure you typed the name
    correctly, and then thry again. To search for a file,
    click the Start button, and then click search."


    4. I still rebooted and then...

    5. ran MBRlook.bat . A screen pops up that reads...

    "The system cannot find the file specified.
    '\mbr.exe' is not recognized as an internal or external command,
    operable program or batch file."


    and at the same time an mbr.log error pops up that reads...

    "Windows cannot find 'mbr.log'. Make sure you typed the name correctly, and then try again.To search for a file, click the Start button, and then click Search."

    I promise I followed your instruction exactly!

    6. I ran C:\MGtools\GetLogs.bat file and attached the log.

    I will have to run my computer a little longer to see if it still locks up. Thanks for you time.
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not forgotton you. Just figuring out what move to make next :)
     
  11. timgonz98

    timgonz98 Private E-2

    I dont know if it matters but It looks like you edited the HelpAsst_mebroot_fix.exe link at 2211. I might have used the link before then which means I possibly used the old origional link you posted. Was the new link different from the old link?

    Another observation was that in other forums here I noticed that other users had to download a file called mbr.exe before Useing "mbr.exe -f" to fix. the only difference is that you had me run \MBR -f and others run mbr.exe -f. You know a whole lot more than me so I trust your judgement. This was just an observation as I was searching for the meaning of \MBR -f.

    Thanks.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download the latest version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Double click it and run it. After running it:

    • With Windows Explorer, navigate to the C:\MGtools folder and double click on mbrfix.bat ( If not sure how to use Windows Explorer, you can optionally click Start > Run and enter C:\MGtools\mbrfix.bat into the run box and click OK. ) This will run quickly flashing a black screen in front of you too fast to read.
    • NOW REBOOT!
    After reboot run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the new C:\MGlogs.zip file

    Make sure you tell me how things are working now!
     
    Last edited by a moderator: Mar 6, 2010
  13. timgonz98

    timgonz98 Private E-2

    Ran everything you told me to. I am still getting the "16 bit MS Dos subsystem" error when I run MGTools.exe. The log is attached.

    The computer seems to be running faster and I have not yet had it lock up on me but it's only been about 30 minutes. When I boot up it takes about 5 minutes to do so. So it is a real slow boot up.

    I will have to run the computer little longer to see if it still locks up on me.

    Thanks.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This error message was explaing in the Using MGtools link in the cleaning procedure. You should run the given fix.



    However more important is that you are still infected so let's try the fix with a slightly different method. Let's download one of the tools again to be sure we have the correct version.

    Please download HelpAsst_mebroot_fix.exe by noahdfear and save it to your Desktop.
    • Double click HelpAsst_mebroot_fix.exe to run the tool.
    • When the tool completes it will inform you HelpAssistant was successfully removed, or it may require a reboot. DO NOT reboot at this point if it tells you this. Do the below first.
    • With Windows Explorer, navigate to the C:\MGtools folder and double click on mbrfix.bat ( If not sure how to use Windows Explorer, you can optionally click Start > Run and enter C:\MGtools\mbrfix.bat into the run box and click OK. ) This will run quickly flashing a black screen in front of you too fast to read.
    • NOW REBOOT IMMEDIATELY!
    After reboot, delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp

    C:\Documents and Settings\Tim Gonzales\Local Settings\temp
    • Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.
    • Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).
    Then attach the new C:\MGlogs.zip file

    Make sure you tell me how things are working now!
     
  15. timgonz98

    timgonz98 Private E-2

    I Scrolled down to Error Message Type 2 to address the "16 bit MS Dos subsystem" error. I followed the procedure but it didn't seem to get rid of the error. I clicked on Start > Run typed in regedit and located HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\VirtualDeviceDrivers\VDD. I deleted VDD and added a new Multi-string Value and renamed it VDD.

    Microsoft says, "If the issue continues to occur, verify that the proper version of the Command.com file is installed in the systemroot/System32 folder on your computer." I dont know how to verify that I have the proper version installed.

    My computer still has a very slow boot up. I noticed when I click on my media center in my windows XP media center edition it opens fine. But when I click on live TV media center shuts down by itself. I am just noticing other symptoms and thought I would share them with you. My computer did freeze and beep this morning. I will have to run my computer longer to see if it still is locking up. I have a feeling it will by the way my computer is running slower than usual and I get the slow boot up.

    The log is attached.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like the HelpAsst_mebroot_fix is not working for you. Do you have your Windows XP boot CD? You will need it to boot to the Recovery Console where you will need to run the fixmbr command. So if you have your CD, continue with the below.

    Now boot to the Recovery Console and run the fixmbr to clear a Master Boot Record infection that you have.

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654


    After running the fixmbr command and boot back to normal mode, continue with the below. Don't bother doing any of the below until you have run fixmbr as the below will be a waste of time until fixmbr has run.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  17. timgonz98

    timgonz98 Private E-2

    After running fixmbr on teh Recovery Console, my boot up was a lot faster. I got my tv back on my Media Center in my Windows XP Media Center Edition . I think we are making good progress here. My boot up process is still not as fast as I would like it to be but I think that is just because I have a lot of programs in my start menu. If I try to disable any items in my start up bu using MSconfig my system configuration goes to "selective startup" and no longer is in "normal start up".

    Another issue I have is when my computer boots up I have a choice to boot from 3 different Windows XP operating systems (in my boot menu). Two are active and one is not active. I would like to get rid of the one that is not active. When I use MSconfig to delete the inactive one it will not be there at start up. But after boot up, my system configuration goes to "selective startup" and no longer is in "normal start up". I try to select "Normal startup" and the inactive Windows XP reappears in my boot menu.

    I did not notice any differences after running The Avenger by Swandog46.

    The log files you requested are attached.

    So did my MBR get infected or was it just corrupted somehow?

    Thanks.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do not use MSconfig. Just use Autoruns like mentioned in the READ & RUN ME and like you are already doing.

    This is not a malware problem, it appears that you have added multiple boot partitions into your boot.ini file. Just edit your boot.ini file and remove the last 2. Make a backup first. And also note that the boot.ini file is normally read-only so you will have to change the permissions first.


    Let's continue with your MBR infection cleanup. We have some more to do.

    First please delete the C:\Avenger and C:\QooBox folders which are getting large due to the infection being removed.

    Now download and run the newest MGtools which was just updated. Just download and run it. I don't want you to attach a log right now. We just need the new program installed before we can do the below.

    Now run the C:\MGtools\hafix.bat file ( note the name is hafix.bat this time not mbrfix.bat ) by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). When it finishes, it will pause, take note of any error message before hitting a key and then hit any key to close the command prompt window.

    Now REBOOT your PC.

    After reboot run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the new C:\MGlogs.zip file

    Make sure you tell me how things are working now!
     
  19. timgonz98

    timgonz98 Private E-2

    All of my programs in my start menu are no longer there. everything on my desktop is gone except Internet Explorer, Recycle Bin and My Computer. I dont know if this happened after running hafix.bat or when I deleted the C:\Avenger and C:\QooBox folders. Is there any way to restore my desktop and my programs listed in the start menu? Do you know what happened to all of my programs? :confused

    The computer has not locked up since I ran the Recovery Console yesterday.

    hafix log:

    grep: C:\MGTools\UserInfo2.txt: No such file or directory
    Access denied - C:\Documents and Settings\All Users\Application Data\McAfee\MPS
    Access denied - C:\Documents and Settings\All Users\Documents\Recorded TV\TempRe
    c\TempSBE\SBE21.tmp
    Access denied - C:\Documents and Settings\LocalService\Application Data\Microsof
    t\CLR Security Config\v2.0.50727.42\security.config.cch
    Access denied - C:\Documents and Settings\Tim Gonzales\Application Data\Microsof
    t\CLR Security Config\v1.1.4322\security.config.cch
    Access denied - C:\Documents and Settings\Tim Gonzales\Application Data\Microsof
    t\SystemCertificates\My
    Access denied - C:\Documents and Settings\Tim Gonzales\Local Settings\Applicatio
    n Data\Microsoft\Portable Devices
    Access denied - C:\Documents and Settings\Tim Gonzales\Local Settings\temp\~DF42
    15.tmp
    Access denied - C:\Documents and Settings\Tim Gonzales\Local Settings\temp\~DF4D
    29.tmp
    Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

    device: opened successfully
    user: MBR read successfully
    kernel: MBR read successfully
    user & kernel MBR OK
    copy of MBR has been found in sector 0x094FE9BD
    malicious code @ sector 0x094FE9C0 !
    PE file found in sector at 0x094FE9D6 !
    updating: mbr.log (188 bytes security) (deflated 37%)
    Zipping C:\MGTools\hafix.log
    updating: hafix.log (188 bytes security) (deflated 36%)
    Finished Zipping hafix.log
    Press any key to continue . . .
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Darn!!! I extremely sorry about this! :-o Not sure what went wrong but this automated fix some how lost information and deleted the wrong folders instead of the HelpAssistant user account only. I'm try to see if there is any file recover software that could possibly be used to help recover the deleted info. Not sure if this will work. In the meantime it would be best not to install/run any addition sofware on the PC ( if that is even possible now) since it would make recovery more difficult.I extremely sorry about this!
     
    Last edited: Mar 10, 2010
  21. timgonz98

    timgonz98 Private E-2

    Thanks for checking into that for me. No reason getting upset about it since the damage is already done. Good thing I have most of my files backed up on another hard drive. The only thing I would really like to recover is my turbo tax information and files. I meant to back this info up but I forgot. will windows recovery get this stuff back by chance? I usually store all of my files on a different hard drive than my the one my OS is on. If anything, is there a log somewhere to show me what was deleted? It would be really great if there was a file recovery software to use to get my files back.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks for your understanding!

    I still feel really bad about this anyway. It is not something that happens that often. In fact something like this has never happened. I already found the bug and it was such a simple thing which caused such a big problem.

    Do you mean System Restore? If so, I'm not sure since it does not save everything. It is not meant to be a full backup program. It really is primarily a back up Windows OS files and folders.

    Basically it looks like things under C:\Documents and Settings

    If you can install anything, see if the below will run:

    Recuva (Slim)

    Choose to recovery all the possible File types and then on the File location form select the option In a specific location and then click the Browse button and select C:\Documents and Settings

    See if this can recover anything.
     
  23. timgonz98

    timgonz98 Private E-2

    I just want to thank you guys for your help and want you to know that I understand mistakes happen. We will just blame it on the program and not the people here. You guys do a lot to help others out, thanks for your time.

    I used the Recuva program and it did recover everything I was concerned about :). I backed up all I recovered and tried to run the f11 Dell system restore partition function at boot up. It seems like that part was deleted too. I tried to look in my admin tools to see if the recovery partition was still on my hard drive but my admin tools were also missing. I did some online resarch and found a dos program called dsrfix. I ran dsrfix which repaired my Dell System Restore (DSR) feature. I then restored my Windows XP back to its origional state.

    One thing that happened when I did this was that I no longer have the option to boot to Windows 7 or my secondary Windows XP at start up :cry. Is there any support forum or anyone here to help me fix this issue? I already tried to fix this by booting from my Windows 7 DVD and doing the boot repair feature. This did not work for me, my computer still boots directly to XP on my C: drive.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks again for understanding. :)

    Well at least that is good news!

    Excellent!

    Back in an earlier message you said the below:

    To which I said to remove the last 2 lines from your boot.ini file. You never did remove those lines according to the follow up logs you had attached. Perhaps you really did not want to remove them since now you are saying you had other boot partitions. Maybe to get them back, you need edit your current boot.ini file to put back in what you used to have.

    You previous boot.ini file looked like below:
     
  25. timgonz98

    timgonz98 Private E-2

    Meaning I want to keep the two that are active and delete the one that is not active. I didnt know how to delete the inactive one.

    I guess MSconfig only hides the boot entrys if you try deleting it from MSconfig. So in order to delete the inactive one I would have had to edit the boot.ini file by going to the Control Panel/system, click on the advanced tab and select settings under startup and recovery. Under system startup click edit (to edit the boot.ini file) and delete the last entry under [operating systems].

    I only wanted to remove the inactive Windows XP.

    Correct, I figured out that I had to edit my boot.ini file to get my other Windows XP on my secondary hard drive to boot up. Windows 7 was a little more difficult to get back. Since Windows 7 doesn't use the same boot menu as Windows XP I had to download a boot manager for Windows 7. I used EasyBCD for Windows 7. I had to create a second boot loader for Windows 7 by using EasyBDC for windows 7. This program walks you through creating a boot menu for Windows 7. I now have all of my boot options back.

    I think all of my issues are now solved, I just have a few more things to do but I think I could handle it frome here. Thank you for the help.
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Chaslang has been without power since Saturday and can not access the web. If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  27. timgonz98

    timgonz98 Private E-2

    Thank You TimW. Since I restored my computer to it's origional state I dont think I have any of the programs used by you guys on my computer anymore. I will definately work through How to Protect yourself from malware!
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds