WAS "Help with system recovered from serious error msg" NOW machine won't boot

Discussion in 'Malware Help (A Specialist Will Reply)' started by LuniLadi, Nov 29, 2012.

  1. LuniLadi

    LuniLadi Private E-2

    Towards the beginning of the month, when I went to start PSE v7, my machine rebooted. After checking the threads on the forum, I started a thread in the Hardware Forum thinking that possible my machine needed additional memory. Caliban and Satrow were helping me there. Aftering looking at some dump files and a screen shot where AVG (Internet Security v9) picked up a Microsoft file as infected, Satrow suggested I move over into the Malware Forum.

    I downloaded the malware removal programs onto a jump drive to copy to the desktop and start the log files. The computer rebooted whenever I plugged the jump drives into the USB port.

    I fought off a very nasty rootkit infection a year ago that ended up crashing my hard drive because it rebooted and regenerated so often. So I panicked when this began to happen. :(

    I went into BIOS and booted from the CD drive. I ran Dr. Web Live CD. It identified/cleaned 2 files infected with TrojanDownloader 7 but stalled at 62%.
    It also identified a ScriptVirus but couldn't access those .pdf files for some reason.

    After that the machine wouldn't boot. :cry

    Yesterday I ran AVG Recue CD. It identified and cleaned 2 Trojan Generic files but the machine still wouldn't boot. Not in normal or safe mode.

    Today I tried repairing Windows. I got:
    IRQL_NOT_LESS_OR_EQUAL
    Stop: 0x0000000A (0xF000E989, 0x00000002,0x00000001, 0x808247A4)
    and couldn't continue. Recently I upgraded to 2Gb RAM.

    I'm freaked. Please help. A million thanks
    LuniLadi
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Bad idea. You should have run our scans. Running stand alone CDs means the operating system is not running and system files are not protected. This scans from these CDs can freely delete required system files which will break your PC. Names of infections are basically useless since they every company just invents their own meaningless names. You need to tell us EXACTLY what files names and or registry keys were deleted. The best thing to do right now would be to restore what you deleted. I cannot tell you what to restore because I don't know what you deleted.

    Another choice may be if you have your Windows Boot CD to either run a System Restore or a Repair. This you can ask about in the Software Forum.

    Double trouble. Now you ran two CDs that may have deleted system files you need.
     
  3. LuniLadi

    LuniLadi Private E-2

    Chaslang,
    I have a bootable Windows CD. I made it after I had ZeroAccess rootkit. I tried repairing Windows. No go. That's where I got the error message I posted:
    IRQL_NOT_LESS_OR_EQUAL
    Stop: 0x0000000A (0xF000E989, 0x00000002,0x00000001, 0x808247A4)

    Now when I try to boot the machine I get the black screen saying "Last start up of Windows didn't start normally...." and get a choice of starting Windows normally or in safe mode. No matter which one I pick, the machine boots up to the Gateway/Windows logo screen but doesn't continue. It goes right back to the black screen with the choices again.

    I'm sorry I don't know which files were deleted. :(
    And I know it certainly wasn't the smartest move to run the Live CD :-o
    but, like I said, I panicked. Knee jerk reaction after fighting ZeroAccess for weeks and weeks....and eventually losing my hard drive.

    Is there anything I can do?
    Thanks
    LuniLadi
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try booting the Windows CD and from the command prompt, run the below commands pressing ENTER after each. The last will reboot the PC. See if it will boot up.

    fixmbr
    fixboot
    exit

    If not then you can see if the below procedure will help you by manually restoring a registry hive.

    http://support.microsoft.com/kb/307545

    It that does not work, the files you removed will have to be replace but since you don't know what they are, a reinstall may be the only solution.
     
  5. LuniLadi

    LuniLadi Private E-2

    Chaslang,
    Thank you very much for giving me some options. ::heart::

    The first time I booted from the Windows CD, I missed the "press any key" prompt. Chkdsk ran. File verfication was ok. It deleted a couple of indexes under Index verification. One of them was pagefile.sys which I think might have been infected/removed, and recovered some orphaned files (pagefile.sys was among them). I wrote these down if you think it's helpful.
    The rest of checkdisk went by too fast for me to write anything.

    I was hopeful that Windows would start but, once again, was presented with the black screen and "normal/safe" choices.

    Second boot from Windows CD:
    -- Selected R for recovery console
    -- Selected C:\Windows to log in
    and got the STOP error message screen.

    Did I miss the place where I would get the command prompt?

    I thought I would check in before going on to the Microsoft instructions.
    Thanks again
    Luni
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! You never got to it.

    You will not be able to run them. At least not with this CD since you cannot get to the command prompt.

    There is s slim chance that you could make another special boot CD like the below

    UBCD4Win

    to do this but you would need another PC running Windows XP and a full copy of Windows XP on CD in order to make the CD. And then you would possibly need quite abit of help ( not possible to provide in this forum since it is outside the realm of malware removal and the time we have to spare ) to perform similar instructions to what that Microsoft link gave. This all assume that you can actually boot up from any CD without getting the same error.

    Question: Do you have any devices plugged into USB ports?
     
  7. LuniLadi

    LuniLadi Private E-2

    Chaslang,
    Nope, nothing plugged into USB ports.

    I have an older laptop that's running XP and *might* have a full copy of XP. I keep all drivers/installation disks/etc in one spot until the hardware is tossed. If the machine came with the OS disk, it's there.

    But it sounds like that's not going to be much of an option. :(

    I've also been checking around in Majorgeeks software forum. Something like what you recommended or Hiren's Disk may be over my head but what about Wondershare's LiveBoot CD? It seems to have a simple menu system and "claims" to repair the mbr/boot errors. Do I have anything to lose at this point?

    If that fails am I facing a fresh install?

    I aooreciate you spending valuable time on what appears to be a lost cause.
    Luni
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sometimes and originally full blown Windows Boot CD may work whereas a disk created with just a recovery console may not. That STOP error you received is more typical of a hardware problem or driver problem but you did not seem to be changing, updating, or adding hardware. Is there any other info in the STOP message. Does it indicate any file names?

    While it is possible that one of these kinds of disks can boot up your PC and can repair an MBR, I'm not sure if that will fix your problem. But at this point it may be worth a try to see what happens.

    See what was posted in message # 12 of the below thread and see if you can get this CD to run.

    whistler/black internet@mbr again!


    This is for an older version of Hiren's CD but I would think the menus are still the same. Hopefully the problem is really with your MBR and this fixes it.


    Quite possibly. There are quite a few special boot CDs out there that can be useful, but the details on how to use them to repair things can be quite long and conusing for non-experts.
     
  9. LuniLadi

    LuniLadi Private E-2

    Chaslang,

    << Is there any other info in the STOP message. Does it indicate any file names? >>
    Nope, that's all the info that's given.

    And I had upgraded the RAM amount to 2Gb but I got the specs for my machine's model direct from the mfg (Gateway) website. Also the computer was booting/running with the new memory before I ran the Dr Web Live CD so I don't think that's the problem. Satrow had originally been trying to check on driver/software updates but then sent me to the Malware forum.

    << See what was posted in message # 12 of the below thread and see if you can get this CD to run. >>

    I have the Hiren's CD. Do you want me to follow the directions in post #12 of that thread?

    When the CD boots choose "DOS BootCD".
    At the Hiren's BootCD main menu, select Next and hit Enter.
    At the second menu select 1 MBR (Master Boot Record)Tools
    In the list of MBR Tools select 1 MBR Work 1.08
    This screen will show the hard drive configuration.
    Type 5 to Install standard MBR code then hit Enter
    Type 1 to select Standard then hit Enter
    Type Y then hit Enter to confirm
    Type E then hit Enter to exit
    Press Ctrl+Alt+Del to restart the machine

    (Just double checking...don't want to jump the gun *again*) :)

    I'll try to run the CD and use MBR Work tomorrow.
    Thanks so much
    Luni
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, assuming it runs without getting that STOP error.
     
  11. LuniLadi

    LuniLadi Private E-2

    Chaslang,

    Ran Hiren's Boot CD this morning but I have v 15.2 and the menu system in that post is using v 10.2 and it's not quite the same. I explored a few of the menu items but I couldn't find MBR Work :( so I didn't run anything. (God, I feel like a dunce who needs alot of hand holding)

    I also searched MG and found a post related to v 10.1 but when I went to that site there was no download.

    I'm not sure what to do now.
    Luni
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  13. LuniLadi

    LuniLadi Private E-2

    Ran Hiren's Boot v 10.2. Followed all the menu items and after I selected "1=Standard, Y=confirm" it didn't seem to do much but cycle back to Partition info/menu area. Upon hitting "esc" to exit, I got a black screen:

    Loading SmartDrv
    Type M for menu (when I did that I got the Main Menu for Hiren's)
    R\Tools (if I hit esc, I just got the drive letter R)

    And the machine won't boot.So I guess it didn't work. <sigh>
    Luni
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The instructions said hit E not esc. But it probably does not matter at this point if you susccessfully rewrote the MBR and your PC cannot boot up, you need to replace to files you previously delete with those offline scanners or you need to do the equivlent of a system restore in the hopes that it would restore what is needed. The Microsoft link I gave you showd how to do this. It is long and complicated. It is much easier to do with a CD like the UBCD4Win I mentioned but for me to explain how to do it, is too complex and out of the scope for this forum. You may want to see if you can continue to work in the Software Forum to see what ideas Caliban and Satrow can share with you.


    I never tried the below but perhaps this could work to do a system restore:

    http://www.raymond.cc/blog/restore-unbootable-windows-system-using-offline-system-restore/
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds