1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

Vista Won't Start, Normally Or Repair Mode, Black Screen

Discussion in 'Malware Removal Help' started by CarolsSis, Jun 23, 2012.

  1. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    After my last post, I removed the flash drive, powered off. Powered back on, only. Black screen, cursor in upper left, white lettering
    NO OPERATING SYSTEM FOUND. I found my 'recovery discs, and installed them all. I was not given an option to reformat the hard drive, which I wish had been an option. It appears to be up and working.
    to answer your question, when the popups from Avira were happening, it was saying it had detected malware, no specific name, and putting the file into quarantine. Maybe I'm not as smart as all of you, but I never thought the entire file would be either quarantined or removed, especially by an antivirus program. I would think the antivirus program would quarantine the malware or virus, not the program it was found in. To remove an operating system file is just unbelievable. How could that happen?
    I'm sorry I didn't wait for further instructions, but I have installed the os on both of my machines, several times in the past. I hope you['re not upset that I didn't wait to see what you wanted me to do next. Now my dilemas are to remove the same antivirus from this machine and find another to use on both of them. I have read on other forums that Avast has a free one that is good. I would also like advise on an uninstaller program to completely remove all of Avira's files. Thanks so much for all your time and expertise and patience. I can't express how important it has been to me to have your help and support. In the past, I was always on my own to try to figure this stuff out. Some times I got lucky and did it right, but having knowlegleable help is beyound compare. Any other suggestions or advise would be most welcome. Thanks.
     
  2. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    I posted here, it's gone. Avira was not detecting a virus, at least I didn't see one. But, Like I said, the pop ups were going up and down too fast to read. I did catch one that said malware.
    I powered on my laptop without any flash or F8 or 12. Black screen, cursor on top left. No operating system found.
     
  3. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    OK, let's make sure I understand.

    You reinstalled the recovery CD. That is good.

    In regards to the OS file, when it's patched, we can only remove it. Now...we can manually replace it, but the antivirus will quarantine it as it is dangerous. They usually don't check for a replacement, which is where the manual approach comes in. I've helped folks with this issue with every antivirus

    Everything appears to be OK in your first post above...

    ...but in the next post, is the computer now not booting again or are you talking about the initial issue?

    You can remove Avira via their removal tool:
    http://www.avira.com/en/support-download-avira-antivir-removal-tool

    I personally use Avast, although Microsoft Security Essentials is another good one that is also free for home use.
     
  4. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    Thanks so much for your recommendation for antivirus. Laptop is booting just fine. So Sorry to be all over the place in my posts, this has pretty well freaked me out, am getting paranoid. Wondering if I was hacked or just routine malware or virus attack? Can you explain why the avira took out the operating system files instead of just removing the malware? I know I hit the "remove" button on the popup accidentally. That's when everything went off.
    I dated my recovery discs, and they were done approximately one month after I received the laptop as a gift. I'm hoping the recovery discs will have the patches, fixes and updates from Microsoft for Vista on them. Will check add.remove programs for that. Thanks again for the recommendation and link for removal. Will remove it from this machine as well. Did the Spybot and malwarebytes on this machine last night, spybot found 6 tracking cookies, one registry entry change, Microsoft security center saying the antivirus override is not, and then stopped. I hope that is fixed.
    Again, thanks so much for all the help. I know I'll be posting again, had much trouble with router set up last two times, don't expect any easier experience this time.
     
  5. BeeCeeBee

    BeeCeeBee ADMINISTRATOR IN MEMORY

    Joined:
    Apr 20, 2009
    Messages:
    7,201
    Location:
    New Jersey "Stronger than the Storm"
    Operating System:
    Windows 7
    This is as much for all members as it is for CarolsSis.

    I appreciate that this thread may have been moved into malware removal and not originally posted here. However this partiular Malware Removal forum has a very specific purpose and we have specialists who are here to help in this process and requires that their directions are followed.

    In this instance since you seem to feel that the issue has been "resolved" you may or may not wish to continue. There remains a good possibility that you are still infected but it just is not manifesting itself in a way that is obvious or apparent. The choice to continue is yours but you need to let etavares know and post the logs he requests. Posts by other staff including my own are only permitted if the member needs help with the specific directions given by the experts.

    As for Avira removing the OS. It did not. You selected to remove rather than quarantine the effected files. Had you quarantined them and things went wrong we could look to fix or replace the quarantined file. Your logs will tell you what has been removed (I think) it has been a long time since I used Avira.

    If you choose to leave things alone we will consider this topic as closed and you will need to start a new topic if there are other issues. :)
     
  6. BeeCeeBee

    BeeCeeBee ADMINISTRATOR IN MEMORY

    Joined:
    Apr 20, 2009
    Messages:
    7,201
    Location:
    New Jersey "Stronger than the Storm"
    Operating System:
    Windows 7
    This thread is closed and I refer you to here: http://computerhelpforums.net/topic/41065-8-new-problems-with-new-install/
     
  7. BeeCeeBee

    BeeCeeBee ADMINISTRATOR IN MEMORY

    Joined:
    Apr 20, 2009
    Messages:
    7,201
    Location:
    New Jersey "Stronger than the Storm"
    Operating System:
    Windows 7
    I have reopened this thread and I now believe that CarolsSis has a much better grasp of what we are trying to do. I suggest we simply wait for her next post and leave it to the Malware Removal Team to sort out what, if anything, can or should be done.
     
  8. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    I'm ready and willing to do what ever I need to do. How do I set this up so I know when there is a new post, other than checking?
     
  9. BeeCeeBee

    BeeCeeBee ADMINISTRATOR IN MEMORY

    Joined:
    Apr 20, 2009
    Messages:
    7,201
    Location:
    New Jersey "Stronger than the Storm"
    Operating System:
    Windows 7
    Go to the top of the page where the original topic title appears and look to the upper right there is a box that you can check to "Follow This Topic" select "instantly." I will look at your personal notification setup and make sure that you are getting email notification.
     
  10. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    I checked, it's set for instantly. Have no email and I did check that my email address is correct. Thanks
     
  11. BeeCeeBee

    BeeCeeBee ADMINISTRATOR IN MEMORY

    Joined:
    Apr 20, 2009
    Messages:
    7,201
    Location:
    New Jersey "Stronger than the Storm"
    Operating System:
    Windows 7
    I have set your notifications for you. You should get an email for this post. Let me know if you do not by PM. Lets keep this thread for the topic now.
     
  12. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    Hi CarolSis,

    We'll do our best to help you get this straightened out. I did read your other thread, and we'll need to get logs now that it is booting to understand what is happening.

    Please do three things:
    1. Please follow my instructions and only my instructions. Feel free to ask questions before, during and after to help clarify. Anything else will mean that I won't have a current understanding of your machine. Best case that means I'll always be a step behind and wont' be able to help. Worst case is that we'll fight each other without knowing it and create further damage to your operating system.
    2. Please follow the instructions in this post: Preparation for Malware removal help and post the requested logs in reply to this post.
    3. Please clearly list all the issues you are encountering. If possible, please list error codes or messages if it has any. If you want to post screenshots if that is easier, feel free to. That way I have a list of all the issues, I can prioritize, check, them in the logs and start to resolve them.

    Thanks!
    -etavares
     
  13. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    Malwarebytes Anti-Malware 1.61.0.1400
    www.malwarebytes.org
    Database version: v2012.06.30.01
    Windows Vista Service Pack 2 x86 NTFS
    Internet Explorer 9.0.8112.16421
    Jan :: TRAVELER [administrator]
    7/3/2012 6:41:20 PM
    mbam-log-2012-07-03 (18-41-20).txt
    Scan type: Full scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 315424
    Time elapsed: 2 hour(s), 27 minute(s), 31 second(s)
    Memory Processes Detected: 0
    (No malicious items detected)
    Memory Modules Detected: 0
    (No malicious items detected)
    Registry Keys Detected: 0
    (No malicious items detected)
    Registry Values Detected: 0
    (No malicious items detected)
    Registry Data Items Detected: 0
    (No malicious items detected)
    Folders Detected: 0
    (No malicious items detected)
    Files Detected: 0
    (No malicious items detected)
    (end)
    Malwarebytes Anti-Malware 1.61.0.1400
    www.malwarebytes.org
    Database version: v2012.06.30.01
    Windows Vista Service Pack 2 x86 NTFS
    Internet Explorer 9.0.8112.16421
    Jan :: TRAVELER [administrator]
    7/3/2012 6:41:20 PM
    mbam-log-2012-07-03 (18-41-20).txt
    Scan type: Full scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 315424
    Time elapsed: 2 hour(s), 27 minute(s), 31 second(s)
    Memory Processes Detected: 0
    (No malicious items detected)
    Memory Modules Detected: 0
    (No malicious items detected)
    Registry Keys Detected: 0
    (No malicious items detected)
    Registry Values Detected: 0
    (No malicious items detected)
    Registry Data Items Detected: 0
    (No malicious items detected)
    Folders Detected: 0
    (No malicious items detected)
    Files Detected: 0
    (No malicious items detected)
    (end)
     
  14. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
    Run date: 2012-07-03 22:03:13
    -----------------------------
    22:03:13.834 OS Version: Windows 6.0.6002 Service Pack 2
    22:03:13.835 Number of processors: 2 586 0xF0D
    22:03:13.836 ComputerName: TRAVELER UserName: Jan
    22:03:19.934 Initialize success
    22:03:20.803 AVAST engine defs: 12070301
    22:03:58.235 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2
    22:03:58.238 Disk 0 Vendor: Hitachi_HTS542512K9SA00 BB2OC31P Size: 114473MB BusType: 3
    22:03:58.257 Disk 0 MBR read successfully
    22:03:58.261 Disk 0 MBR scan
    22:03:58.268 Disk 0 unknown MBR code
    22:03:58.272 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 9993 MB offset 63
    22:03:58.294 Disk 0 Partition 2 80 (A) 06 FAT16 NTFS 52371 MB offset 20467712
    22:03:58.322 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 52107 MB offset 127723520
    22:03:58.330 Disk 0 scanning sectors +234438656
    22:03:58.405 Disk 0 scanning C:\Windows\system32\drivers
    22:04:06.282 Service scanning
    22:04:40.606 Modules scanning
    22:04:56.618 Disk 0 trace - called modules:
    22:04:56.644 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS intelide.sys PCIIDEX.SYS atapi.sys
    22:04:56.654 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85005968]
    22:04:56.664 3 CLASSPNP.SYS[883ac8b3] -> nt!IofCallDriver -> [0x840c8a70]
    22:04:56.674 5 acpi.sys[8069b6bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-2[0x840cfb98]
    22:04:57.511 AVAST engine scan C:\Windows
    22:04:59.992 AVAST engine scan C:\Windows\system32
    22:07:06.763 AVAST engine scan C:\Windows\system32\drivers
    22:07:15.532 AVAST engine scan C:\Users\Jan
    22:08:52.573 AVAST engine scan C:\ProgramData
    22:09:12.809 Scan finished successfully
    22:09:37.596 Disk 0 MBR has been saved successfully to "C:\Users\Jan\Documents\MBR.dat"
    22:09:37.603 The log file has been saved successfully to "C:\Users\Jan\Documents\aswMBR.txt"
     
  15. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    Hi CarolsSis,

    In addition to the list of issues and the OTL log (instructions in the preparation link I posted earlier), please update Malwarebytes' ANti-Malware (MBAM). The definitions were a few days old. You can update by launching MBAM, clicking the Update tab, and clicking Check for Updates. Let it update anything it needs to, then please re-run a Quick Scan and post the resulting log.

    Please also attach this file [background=rgb(252, 252, 252)]C:\Users\Jan\Documents\MBR.dat [/background] to your reply. If it will not allow you to attach that tyupe of file, please rename it to MBR.txt and attach that. The partition structure on this is interesting. What brand of computer is it? E.g. a Dell, HP, etc.

    So, in your reply, please:
    • Post the OTL log
    • Post the updated MBAM log
    • Attach the MBR.dat file
    • List out the issues you are experiencing

    Thanks!
     
  16. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    The documents folder on this laptop does not have an "edit" so I can't copy and paste the data file from malwarebytes. This is an Acer Aspire 4720Z laptop. I was wondering about the two hard drives also. After doing the check disc (instructed from forum) I noticed so much use of both, and no reason why, I have no saved music, videos,documents, photos.
    3 tries at posting new malwarebytes scan, no infection found. Also, I screwed up, I didn't back up the registry, the desktop icons were put behind the Acer empowering bar, and I forgot.
    found edit, have tried 6 times, it highlights all 4 files, I chose copy, go to forum, and paste stays greyed out.
     
  17. BeeCeeBee

    BeeCeeBee ADMINISTRATOR IN MEMORY

    Joined:
    Apr 20, 2009
    Messages:
    7,201
    Location:
    New Jersey "Stronger than the Storm"
    Operating System:
    Windows 7
    I am just posting here to help the process along;
    You can copy mist anything here from the logs and reports that you get. There is no need to save them into documents. Simply highlight the entire text and copy. The return to here and select Paste to copy it to your post.

    In the instructions it suggested you get erunt to back up your registry. Did you do that?
     
  18. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    No, I did not back up the registry. I forgot, it was behind the empowering bar on the desktop.
    I was asked fo rthe OTL and it's saved in my documents file. will try again to post requested data files.
    trying to post requested files, I copy and return to forum, paste, and white box above start button reads: javascript, void, paste
     
  19. CarolsSis

    CarolsSis Registered Members

    Joined:
    Aug 28, 2011
    Messages:
    206
    Location:
    home
    Operating System:
    Windows Vista Enterprise
    Started to run ERDNT. Message reads- ERU for Windows File:
    C:\Windows\ERDNT\7-4-2012\ERDNT.INF
    Registry back up will continue, but no restore information for the ERDNT progrmam will be saved. This means that later restoration of the regisrty can only be done manually, by using another OS to copy back the files.

    Should I click yes?
     
  20. etavares

    etavares Malware Removal Specialist - Moderator

    Joined:
    Aug 6, 2011
    Messages:
    259
    Location:
    USA (GMT -5)
    HI CarolSis,

    For posting the logs, please open them by double-clicking on the file. IT should launch notepad and open the log. Then, the edit menu is active and you can copy/paste all the text from the log. Copy/Paste the file itself into the post will not work, we need to copy the text.

    Click Yes for for ERUNT and let it complete its backup. As long as it backs up, we can restore it ourselves with a bit of work if we need to.

    Thanks,
    -etavares
     

Share This Page