Virus Broke Safemode, where do I go from here

Discussion in 'Software' started by steve_ccc, Mar 9, 2010.

  1. steve_ccc

    steve_ccc Private E-2

    I googled and searched your threads, so I'm pretty sure that the answer isn't up, please direct me to where I can find help if I'm wrong. I was infected with the Dr. Guard virus while removing another virus from someone else's computer (I thought I had decent protection, still not sure how it happened). I followed all the online removal instructions, and when overall that failed, I deleted all the files that multiple how-tos on removing this virus mentioned. It seems to be fixed for the most part with a few exceptions, however I'm having one big problem right now. I have been trying to gete into safe mode, it would load, give me a mouse even, but before going all the way into safe mode, it would reboot. I can't trouble shoot this, because while trying to get into safemode, I set it to log into safemode via msconfig. So now I'm on a cycle, where it trys to log in, takes me to safemode (regardless of what I select after F8) and then when it looks like it will log in it crashes. I look forward to going through the READ & RUN ME FIRST. Malware Removal Guide, but I need to get into some form of windows first, then I can go from there. Also if you have any idea what I can do to get safe mode working again, I'd appreciate that info as well. I'm on a Dell Precision M6300, 4 GB RAM, 250 Gb Hard Drive, Intel Core 2 Duo (don't know exact specs for that) running windows 7, and I just tried an up0grade install after I thought the virus was for the mose part removed, to try to fix my inability to log into safe mode.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I have moved your thread to the software forum so that you can get assistance with getting out of the safe mode loop. Once you are able to boot to normal mode, and after you have done the Read and Run First instructions, you can start a new thread in the malware forum with your logs attached.
     
  3. brandypeppy

    brandypeppy MajorGeek

    Tapping F2 on startup will get you in the BIOS, then select boot order and put Boot from CD/DVD first.

    This will allow you to boot from your install/recover CD, choose Repair.

    Hope your data is backed up, though repair should leave it.:wave:wave
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are now being looped back on your login screen, it means that userinit.exe file has been deleted, infected or corrupted or the registry keys associated with it may have been deleted or corrupted.

    Login Loop
     
  5. steve_ccc

    steve_ccc Private E-2

    Assuming you mean to use my install DVD to repair startup, I already tried that, and it didn't get me anywhere. However in the repair options there is a command windows, so I guess the only thing that comes to my mind would be to use the command prompt window from the disk (or even command prompt under F8 repair your computer) to disable my computer auto booting into safemode. I just don't know if that is possible, or what the commands would be (my DOS is kinda rusty). I am pretty sure that the loop is caused by my own stupidity, Normal Mode worrked, safe mode didn't, and IU told it via MS Config to boot into safemode, thinking that if it failed then it would go back to normal mode, I should know better. If you mean for me to use a different repair disk for windows 7 let me know, I just don't know what I would use.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you can use the recovery console, you will need to first enter:
    bootcfg /list
    Copy the information down, then enter:
    bootcfg /rebuild
    Now re-enter the info:
    When it it prompts for the OS load options. Here type in "fastdetect /noexecute=optin", without quotes. Exite the console, restart windows.

    Tell me if that works.
     
  7. brandypeppy

    brandypeppy MajorGeek

    :waveYou can get a command prompt with that disk?

    Not sure if this will work, but from the command prompt, type msconfig, does that open it so you can reset to normal? I know this program runs from a cmd prompt on my computer, just not sure what you have.

    If this works, you can also open explorer and disable the auto reboot thing.:wave
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you can do what brandypeppy suggests, then go to the "boot ini" and uncheck "safeboot", then restart to launch windows normally.
     
  9. steve_ccc

    steve_ccc Private E-2

    Thanks to both of you, all I'm getting from this is
    ERROR: Invalid syntax.
    Type "BOOTCFG /?" for usage.

    For msconfig, yeah it does have command prompt, both in the startup repair on the disk and on the repair your computer in the F8 menu. However it doesn't let me run windows like explorer, or msconfig
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Type "BOOTCFG /?" for usage. ---> where does that take you? It should show you the right commands.
     
  11. steve_ccc

    steve_ccc Private E-2

    Your right Tim, and I was wondering the same thing, I should have told you want it showed me. I get a list of commands, those aren't in the list. There is (assume / at beginnings) Copy, Delete, Query, Raw, timeout, Default, ems, debug, addsw, rmsw, Dbg1394, and of course ?. That is all that is available using this command in this prompt window
     
  12. steve_ccc

    steve_ccc Private E-2

    Ok here is what I am going to do, I plan on putting a different harddrive I have that has XP in and backing this one to a similar one. Then using laplink (we have a bunch of licenses), I'm going to go from 32 to 64 bit windows on the infected operating system, then I will repost under malware, with the information that is needed there. The only thing is this will leave me with two infected systems, the xp that I am using to back stuff up with, and this 7 installation, but it is better than a complete loss. I had everything cloned before, but the last clone was after I got the virus. If you have any thoughts feel free to chime in.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds