Windows won't boot up

Discussion in 'Malware Help (A Specialist Will Reply)' started by fiockthis, Aug 25, 2008.

  1. fiockthis

    fiockthis Private E-2

    Yesterday I started following the Windows XP Cleaning Procedure that you have on the website (http://forums.majorgeeks.com/showthread.php?t=139313). I downloaded all of the programs, and then I followed the instructions for installing and running SuperAntiSpyware (http://forums.majorgeeks.com/showthread.php?t=127217).

    I restarted my computer, but as it's restarting it's taken to an Improper Shutdown screen, and asks if I want to start it normally or in safe mode. I start it normally, Windows starts to boot up, and then it's taken to a blue screen for a split second before restarting. So it's stuck in an endless loop.. boot screen, windows loading, blue screen and restart.

    So I try and choose to boot in safe mode, but none of the keys on the keyboard work on this screen. I cannot use the arrow keys, and even the caps lock key doesn't work. So I'm unable to get to safe mode.

    The only thing I can do is go into bios before the boot screen appears. I'm not sure if I can do anything in bios or not to help this problem.

    Any suggestions? :confused
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did SUPERAntiSpyware actually finish running and remove malware? Did it ask you to reboot or did it automatically?

    Do you have your Windows XP bootable CD?
     
  3. SUPERAntiSpy

    SUPERAntiSpy Private E-2

    More specifically, which EXACT numeric version of SUPERAntiSpyware were you using? 4.15.1000? 4.20.1046?

    When you boot, try holding down the HOME key which will tell SAS not to do anything on bootup.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If downloaded from the link in the READ & RUN ME yesterday it should be 4.20.1046. And if downloaded from our links before yesterday it would be 4.20.1044
     
  5. fiockthis

    fiockthis Private E-2

    Yes, it finished running and removed malware. I think there was only one.

    It asked me to reboot. I hit no. Closed out of the program, and then rebooted manually.

    I do have the Windows XP boot cd.

    Holding down the HOME key did not work. And I'm not sure which version I'm running.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you download it from one of our links when you started working on this? Or did you already have it installed or was it downloaded from somewhere else?

    Since you have your Windows CD, the below may be your only option now.


    http://forums.majorgeeks.com/showthread.php?t=168038
     
  7. fiockthis

    fiockthis Private E-2

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You mean it takes you to here: http://www.majorgeeks.com/SUPERAntiSpyware_d5116.html

    Which is where you downloaded from? This means as I stated, you were using at least version 4.20.1044 and possibly 4.20.1046 which is the info the Nick was interested in. I have asked him to check back in. In the meantime, start looking at that link I gave you from Microsoft as it may be the only work around other than a Windows repair or reinstall.
     
  9. fiockthis

    fiockthis Private E-2

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  11. fiockthis

    fiockthis Private E-2

    No problem, and yes I downloaded it from that link.

    I'll try out that Microsoft link, and let you know what happens.
     
    Last edited: Aug 28, 2008
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let me know if you have any questions too.
     
  13. fiockthis

    fiockthis Private E-2

    Dang, I can't boot from a CD either. I changed my BIOS setting to only boot from the CD Rom drive, but when it starts to boot it says "Press any key to boot from CD", and nothing happens when I press keys. Then it goes back to the improper shutdown.

    Can I boot from a CD without having to press any keys?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Man when things go wrong....they really go wrong.:(

    What kind of keyboard do you have? PS/2 or USB? If USB, there may be a setting to enable your USB ports in DOS mode. Maybe it reads as "USB DOS"
     
  15. fiockthis

    fiockthis Private E-2

    Oh sweet, there was something in BIOS that said USB Keyboard Resource Help (it's a USB keyboard), or something like that.. and I enabled it, and now I can press a key during the CD rom boot up. Thank you.

    I'm going to try that Windows link you gave me now.

    edit: Ok, I already have a problem. I just started Recovery, and it says to enter a password when asked.. but I'm never asked for a password. It just shows "C:/", and when I type "md tmp" it says "access is denied".

    edit again: I am able to boot up in safe mode now.
     
    Last edited: Sep 1, 2008
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because you are suppose to have a command prompt that says c:\Windows when you get into the Recovery Console. You are not supposed to be in the root folder which is C:\. The prompt should have looked like C:\Windows>

    Okay then before doing anything else. See if you can locate a log from SUPERAntispyware. It will be in a folder like below where USERNAME will be your user account name.

    Code:
    "C:\Documents and Settings\USERNAME\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\"
    supera~1.log  Jun 11 2008        1190  "SUPERAntiSpyware Scan Log - 06-11-2008 - 22-36-57.log"
    The log shown and date above is just an example. Yours will be different if it even exists. I first want to see if SAS actually removed anything at all.
     
  17. fiockthis

    fiockthis Private E-2

    I could not find a log.

    The Application Data folder doesn't exist either.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it does. It is a required folder of Windows. Are you logging into your account, and do you have viewing of hidden and system files and folders enabled like mentioned in step 1 of the READ & RUN ME. Check again.

    Also if you are able to run in safe mode as stated, then download the MGtools.exe file given in the READ & RUN ME (if not already downloaded). And then run it by double clicking on it. Wait for it to finish running and then find the C:\MGlogs.zip file and attach it here. This will also show me if the SAS log exists along with giving us other information.
     
  19. fiockthis

    fiockthis Private E-2

    Ah yes, the folder was hidden.

    I found the SAS log, and it removed one item.. some keygen.

    While running MGTools, during the "Getting System Information" phase, I get a ProcessDLL.exe Application Error "The application failed to initialize properly (0xc0000135)."

    Also, I've been using CleanUp! What's the difference between CleanUp! and CCleaner?
     
    Last edited: Sep 3, 2008
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please attach the log.

    This was explained in the Using MGtools instructions. Please attach the MGlogs.zip file.

    Similar functions but we prefer CCleaner which also has other features.
     
  21. fiockthis

    fiockthis Private E-2

    SAS log attached.

    In the MGTools Instructions it says "Just click any key or OK to continue and ignore the error. To fix it, install the .NET software." I downloaded .Net Framework 1.1, but I cannot install it. When I try, i just get an error message saying Setup Failed. And MGTools terminates when I click ok.
     

    Attached Files:

  22. fiockthis

    fiockthis Private E-2

    MGTools log.
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    SAS just remove a Nero keygenerator (bad idea!!! ) and nothing else. This is no reason for your PC to become unbootable. Since now it has all of a sudden become bootable in safe mode, perhaps you should be trying normal boot mode. There is no other malware showing in the logs you attached so I'm not even sure what problems you had that caused you to start running the cleaning steps to begin with.

    If your PC can still not boot in normal mode, you should try running System Restore from safe mode and restore to a point in time before your problems began (which we would be before Aug 24th). Otherwise backup your important data and then attemp either a Windows Repair or a reinstall if the repair does not work.
     
  24. fiockthis

    fiockthis Private E-2

    I've tried booting in Normal Mode, but I get that quick blue screen real quick still.

    I suppose I'll try to do a System Restore. I really feel like there's something fishy with my computer, that's why I decided to run SAS.

    Thanks for all your help.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Let us know the results of the System Restore. As I stated in my last message, it is your last option before a repair or a reinstall. And I repeat, you should not hestitate in backing up important data before you go any further. Your PC could become unbootable again at any time.
     
  26. fiockthis

    fiockthis Private E-2

    System Restore worked fine. Should I try any other scans?
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does that mean you can boot in normal mode now? If so, only run Malwarebytes and MGtools and attach the logs. Make sure you use the current versions.
     
  28. fiockthis

    fiockthis Private E-2

    Yes, it booted into Normal mode ok. Then I shut down the computer, the next day when I booted it up it ran CHKDSK (which is probably the blue screen I was having problems with), after chkdsk ran, it booted into normal mode again just fine.

    It seems to boot up in normal mode without running chkdsk now. I'm going to run those scans, and I'll post the logs.

    edit: it seems there's an SP3. I'll run the scans after downloading and installing the new service pack.
     
  29. fiockthis

    fiockthis Private E-2

    I got the same MGTools error message.
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean, but you do need to do the below.

    Uninstall the below old versions of Sun Java:
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5

    Then reboot.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now we need to cleanup some items from running ComboFix.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  31. fiockthis

    fiockthis Private E-2

    Thanks, I'll get started now.
     
  32. fiockthis

    fiockthis Private E-2

    I completed all of the steps. And I did receive a success message adding that file to the registry. Thanks for everything.
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds