Problems remain after clean install

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by axnxn, Jun 24, 2011.

  1. axnxn

    axnxn Private E-2

    My 64-bit Windows 7 desktop recently had an "interactive logon process not available" error on startup. Couldn't easily fix it any other way than to do a reinstall.

    I used Dell DataSafe Backup/Restore.

    Despite being "clean" (ish?) we began noticing internet redirect issues almost immediately. I'd try to load a webpage and could see that the browser was loading something other than what I was requesting, but then the page would just show up blank.

    Began downloading all of the clean-up tools last night, but kept running into the blank page redirect.

    Today, we started getting more and more popups and then on reboot, the System Repair option screen came. The first option, to repair, didn't work. The second option, System Restore wouldn't restore to the point I had set right after the clean install.

    Rebooted into Safe Mode and then was told the System Restore was successful.

    Began downloading all of the clean-up tools and after rebooting after combofix and coming back to the forum, the pop-ups began again.

    Still booted up in Safe Mode.

    Logs attached.

    Oh, one more thing. Combofix said McAfee and Avira were both running. I had uninstalled McAfee, but found a process still running in the task manager, which I killed. Avira says it's not running and I didn't see any processes in the Task Manager. But Combofix still said they were running (but ran anyway).

    Also, can't uninstall Java -- am told the Installer can't be found.

    Thanks in advance for your help!
    ann
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    Be sure to attach your log from TDSSKiller
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You attached logs from Safe Boot Mode. You should be running in normal boot mode unless that is not possible.

    What browser are you using when have popups and what are the popups for? What do they say? Are you have browser redirections when doing searches?


    See if you can use the below to uninstall the old Java version.

    Revo Uninstaller


    QUOTE=axnxn;1639013]Oh, one more thing. Combofix said McAfee and Avira were both running. I had uninstalled McAfee, but found a process still running in the task manager, which I killed. Avira says it's not running and I didn't see any processes in the Task Manager. But Combofix still said they were running (but ran anyway).
    [/QUOTE] Many things from McAfee still remain and we will fix them below.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. axnxn

    axnxn Private E-2

    Thanks for your quick response.

    Unfortunately I'm sort of back to where I started.

    I originally ran the scans in Safe Mode because I couldn't boot normally

    But I tried a normal boot after I saw your message, and that worked. Ran Combofix, which deleted about a gazillion Macafee files. When it went to show the log, however, I got an error c:/users/home/ApplicationData/Local/temp/log.txt file not found. I checked at C:, though, and the actual log was there.

    Then I ran TDSSkiller - I know that was slightly out of order, but I saw that post after the Combofix post. It found something, "cured" it and rebooted.

    But then -- couldn't start up again, even in safe mode. I get an option for Windows Error recovery, which fails. I'm trying to run System Restore right now...not working yet.

    I'm sending this from my Blackberry, so I can't attach any logs, sorry.

    Any suggestions about what to do next? I might have to go way back in my recovery points...the most recent ones aren't working yet.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Power off your PC for a few minutes. Then start it up and see if you can run System Restore. If not, you may have to do a repair of Windows. Do youhave your Windows 7 DVD. Can you access the Windows 7 Recovery Environment? Sometimes this Environment is already installed on a PC and you can boot up to it.
     
  6. axnxn

    axnxn Private E-2

    Ack, what a nightmare.

    My only option is to boot to system Repair mode. System repair doesn't work. System Restore doesn't work (I tried several points).

    And I even went all the way back in Dell Datasafe Restore to factory installed (no backup) and still can't boot up.

    I ordered a replacement Windows 7 installation cd a few days ago - I think that's my last option, yes?

    Thank you!
    Ann
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It looks to me like your hard disk may have a factory recovery partition on it that you can restore to. However, do note that if you use this, you will lose any personal data save on your PC because it reimages the drive so that your PC will be in the same state it was when you took it out of the box.

    If you cannot boot your PC at all, it is rather difficult to do backups now. You would need to use another PC to possibly create a special boot CD that allows network or USB access so that you could backup important data ( if you have not already been doing backups ). Or another choice would be to remove your hard disk and slave it to another PC where you could copy files.

    Do you know what the name of the file was that TDSSKiller found and cure? It was most likely an important Windows file but it was infected.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Oh and yes I know that Dell DataSafe is supposed to be the below
    But since it did not work, a full reimage may be the only choice.
     
  9. axnxn

    axnxn Private E-2

    Fortunately I have all of my personal data backed up, so that's not a problem.

    And I was able to grab the TDSS log during the Dell DataSafe backup option (even though the restore itself failed). I've attached it here. It said it found Rootkit.Win32.TDSS.tdl4

    Is there a way to go about this without the installation cd?
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It appears that no files were removed by TDSSKiller. It found an infection on your hard disk that was most likely in the Master Boot Record.

    Do you have an option when you boot the PC to get into the Windows 7 System Recovery Environment? If you do, it may be possible to repair the boot record from there.

    There is a good tutorial on the Recovery Environment in the below link:

    http://www.bleepingcomputer.com/tutorials/tutorial161.html
     
  11. axnxn

    axnxn Private E-2

    I do have access to the Windows 7 Recovery Environment.

    I've got a command window open...
    any ideas? ;)
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if you can enter the below command to repair the MBR. Not there is a space after bootrec:

    bootrec /fixmbr

    Then reboot and see if it helped or not.​
     
  13. axnxn

    axnxn Private E-2

    Ran it. It finished very quickly. But reboot took me back to "Windows failed to start."
     
  14. axnxn

    axnxn Private E-2

    Also, I ran the other bootrec commands, and ScanOs and RebuildBcd returned:

    Total identified Windows installations: 0

    That seems odd.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmm! This is not good.

    At the command prompt enter the below and tell me what happens:

    bcdedit | find "osdevice"
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also I have a question. When you boot up, do you get a message like: "Bootmgr is missing"
     
  17. axnxn

    axnxn Private E-2

    bcdedit | find "osdevice" returns
    osdevice partition=C:

    I don't get bootmgr missing

    I get a screen that says
    Windows failed to start. A recent hardware or software change might be the cause.

    If windows files have been damaged or configured incorrectl, Startup Repair can help diagnose and fix the problem...etc.

    Then I have the option to run Startup Repair or Start normally.

    Startup Repair checks the system
    Startup Repair cannot repair this computer automatically
    The problem details window says
    Problem signature: StartupRepairOfflince
    Problem signature01: 6.1.7600.16385
    Problem signature02: 6.1.7600.16385
    Problem signature03: unknown
    Problem signature03: 21200953
    Problem signature05: AutoFailover
    Problem signature06: 6
    Problem signature07: FailureDuringSetup
    OS version: 6.1.7600.2.0.0.256.1
    Locale ID: 1033

    I then usually choose View advanced options for system recovery and support which brings me to the System Recovery Options

    The command prompt is originally at X:\windows\system32
    but I've been changing to C: because I ran the bcdedit command to find the OS and it said C:

    If I run the bootrec fixes from X:, I still end up at "Windows failed to start"
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may want to consider waiting until you get that DVD from Dell and then call them to see if they can walk you though a possible repair for this. It just seems like it may be looking in the wrong place for an activated Windows partition. However, it could become necessary to reinstall and they should be able to help you with that too.
     
  19. axnxn

    axnxn Private E-2

    I received the install disk today and the clean install seems to be working. I'm in the process of loading software...fingers crossed.

    Thanks for your help!
    ann
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds