Zero Access cannot be removed...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by laltobelli, Feb 13, 2012.

  1. thisisu

    thisisu Malware Consultant

    I am not seeing the problem either :(
    What I really do not understand is why running that OTL fix would have caused this boot issue. We were not even removing much at all.

    Can you try the following while in System Recovery -> Command Prompt

    1. bcdedit /export C:\BCD_Backup
    2. c:
    3. cd boot
    4. attrib bcd -s -h -r
    5. ren c:\boot\bcd bcd.old
    6. bootrec /RebuildBcd
    7. exit (restart PC)
     
  2. laltobelli

    laltobelli Private E-2

    Well at least this is different... loop

    First reboot I get an error:
    Windows failed to start....

    File: \windows\system32\ntoskrnl.exe
    Status: 0xc0000428
    Info: Windows cannot verify the digital signature for this file
     
  3. thisisu

    thisisu Malware Consultant

    Enter System Recovery Options -> Startup Repair

    Let me know what types of problems it detects this time and if it is able to correct them.
     
  4. laltobelli

    laltobelli Private E-2

    Been a busy day...:tired

    Ok booting from a Win 7 CD and kicking off startup repair I get the following:

    Problem Signature 01: 6.1.7600.16385
    Problem Signature 02: 6.1.7600.16385
    Problem Signature 03: unknown
    Problem Signature 04: 21200412
    Problem Signature 05: AutoFailover
    Problem Signature 06: 2
    Problem Signature 07: CorruptFile
    OS Version: 6.1.7600.2.0.0.256.1
    Locale ID: 1033

    Viewing the diagnostic and repair I get an error code 0x0 for all tests performed. The root caused found was:

    Boot critical file c:\windows\system32\ntoskrnl.exe corrupt.

    That's all the info that's really given.
    If I run startup repair again it gives no problem found.
    Root caused found was:
    Boot status indicates that the OS booted successfully.

    I ran startup repair several times after this and it always came back with OS booted successfuly....

    When I did reboot and it came back with the black screen with text:
    Windows failed to start....

    File: \windows\system32\ntoskrnl.exe
    Status: 0xc0000428
    Info: Windows cannot verify the digital signature for this file

    la
     
  5. thisisu

    thisisu Malware Consultant

    Ok, return to System Recovery Options -> Command Prompt

    Type in the following command: chkdsk c: /r

    Let me know if all 5 stages complete successfully.

    This process can take a couple of hours so be patient.

    __________________________________________________________________

    If all 5 stages complete successfully, here is the next command I want you to type: sfc /scannow /offbootdir=c:\ /offwindir=c:\windows

    Looks like this:

    http://img717.imageshack.us/img717/4741/sfcofflinefinish.png

    This command usually takes ~20 minutes
     
    Last edited: Feb 22, 2012
  6. laltobelli

    laltobelli Private E-2

    Got an error:
    Windows Resource Protection could not perform the requested operation.
     
  7. thisisu

    thisisu Malware Consultant

    Did chkdsk c: /r complete? If so, reboot and see if you can get into Windows.

    If not, retry the sfc /scannow /offbootdir=c:\ /offwindir=c:\windows command when in Windows Recovery Environment.
     
  8. laltobelli

    laltobelli Private E-2

    I did run it earlier in the week, but started it again just a few minutes ago. This will take a while.
     
  9. laltobelli

    laltobelli Private E-2

    14% after an hour, well tomorrow is another day...:hammer
     
  10. laltobelli

    laltobelli Private E-2

    Ok, just finished up. to highlight the messages this is what I got (no other error messages):

    Windows has checked the file system and found no problems.
    4 kb in Bad Sectors

    Other messages were just stats on the sectors, etc...

    Rebooting just took me to the ntoskrnl.exe error.

    Tried startup repair, still no go...

    Tried sfc and still got the same error message.
     
  11. thisisu

    thisisu Malware Consultant

    I am afraid we running out of options here. This is the last idea I have for now:

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Now attempt to boot normally.
     

    Attached Files:

  12. laltobelli

    laltobelli Private E-2

    No luck... Still got the ntoskrnl error...
     
  13. thisisu

    thisisu Malware Consultant

  14. laltobelli

    laltobelli Private E-2

    Thanks, I'll take a look.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds