also @ TechSpot: Razer brings the arcade experience home with the Atrox Arcade Stick

Laptop taken over by apype and smartwebsearch

Discussion in 'Virus and Malware Removal' started by frh, Nov 19, 2011.

  1. Broni Malware Annihilator Posts: 39,189   +175

    Very good :)

    Give me fresh Bootkit Remover log.
  2. frh Newcomer, in training Posts: 41

    Hi Broni.

    I spoke too soon :/

    Not long after the FixTDSS procedure and whilst browsing, I got a blue screen. I tried a system repair twice, which failed:

    Prob event name: StartupRepairOffline
    Prob Sig 01: 6.1.7600.16385
    02: ditto
    O3 unknown
    04 157 (on second run showed as 21200625)
    05 AutoFailover
    06 1 (on second run showed as 3)
    07 0x109
    Os version 6.1.7600.2.0.0.256.1
    Locale ID 1033

    From the dump log, which I can only access via windows command prompt, I isolated this:

    Root cause found:
    Unknown Bugcheck: Bugcheck 109. Parameters = 0xa3a039d89b5a7519, 0xb3b7465eedd8ab9b, 0xfffff80000bac5cc, 0x1

    What now?

    Thanks.
  3. Broni Malware Annihilator Posts: 39,189   +175

    Please Boot to the System Recovery Options
    If you have Windows 7 installation disc, just insert a DVD to the drive, restart computer and it should load automatically (option two presented in the article).
    It's possible also that your computer has a pre-installed recovery partition instead - in such a case use a method one (by pressing F8 before Windows starts loading)...

    On the System Recovery Options menu you will get the following options:

    • Startup Repair
    • System Restore
    • Windows Complete PC Restore
    • Windows Memory Diagnostic Tool
    • Command Prompt

    Choose Command Prompt
    You should see X:\SOURCES>...

    Execute the following commands in bold.
    Press Enter after every one of them.

    bootrec /fixmbr (<--- there is a "space" after "bootrec")

    bootrec /fixboot

    exit

    Restart computer.
  4. frh Newcomer, in training Posts: 41

    Hi Broni,

    I followed your fixmbr/fixboot instructions. After each a "success" message was displayed.

    On restart windows begins to load, however there is a brief flash of a blue screen, and a divert to the repair screen. Startup Repair fails. I did try a restore to earlier system backup earlier today. This also failed.

    Thanks.
  5. Broni Malware Annihilator Posts: 39,189   +175

    Did you try Safe Mode?
  6. frh Newcomer, in training Posts: 41

    Same problem with Safe Mode.
     
  7. Broni Malware Annihilator Posts: 39,189   +175

    Let's see, if we can look at your computer booting from an external source.

    Please download OTLPE (filesize 120,9 MB)

    • When downloaded double click on OTLPENet.exe and make sure there is a blank CD in your CD drive. This will automatically create a bootable CD.
    • Reboot your system using the boot CD you just created.
      • Note : If you do not know how to set your computer to boot from CD follow the steps HERE
    • Your system should now display a REATOGO-X-PE desktop.
    • Depending on your type of internet connection, you should be able to get online as well so you can access this topic more easily.
    • Double-click on the OTLPE icon.
    • When asked Do you wish to load the remote registry, select Yes
    • When asked Do you wish to load remote user profile(s) for scanning, select Yes
    • Ensure the box Automatically Load All Remaining Users" is checked and press OK
    • OTL should now start.
    • Press Run Scan to start the scan.
    • When finished, the file will be saved in drive C:\OTL.txt
    • Copy this file to your USB drive if you do not have internet connection on this system
    • Please post the contents of the OTL.txt file in your reply.
  8. frh Newcomer, in training Posts: 41

    HI Broni,

    I made the bootable CD as per your instructions.

    When I attempted to boot the machine using the CD, it showed the REATOGO-X-PE load-bar, then an XP splash screen. Before any desktop was displayed there was a boot screen, advising a check for viruses and the performance of CHKDSK /F.

    I tried again, and after the load bar filled the machine powered off. I have tried to get into the system repair options and again the machine powered off.

    Looking desperate now ............

    Thanks.
  9. frh Newcomer, in training Posts: 41

    I have tried again after leaving the machine off for a little while. It is now attempting to boot from the CD again .......
  10. frh Newcomer, in training Posts: 41

    As before; blue screen after trying to boot from CD. At least it has stopped powering off ........
  11. Broni Malware Annihilator Posts: 39,189   +175

    We may have some hard drive problem.

    Run hard drive diagnostics: http://www.tacktech.com/display.cfm?ttid=287 (or http://www.bleepingcomputer.com/forums/index.php?showtopic=28744&hl=hard drive diagnostic)
    Make sure, you select tool, which is appropriate for the brand of your hard drive.
    Depending on the program, it'll create bootable floppy, or bootable CD.
    If downloaded file is of .iso type, use ImgBurn: http://www.imgburn.com/ to burn .iso file to a CD (select "Write image file to disc" option), to make the CD bootable.
    For Toshiba hard drives, see here: http://sdd.toshiba.com/main.aspx?Pa...rivesUSandCanada/SoftwareUtilities#diagnostic

    Note : If you do not know how to set your computer to boot from CD follow the steps HERE
  12. frh Newcomer, in training Posts: 41

    Hi Broni,

    I went for the DOS version of DLG; I assume this was the correct thing to do?

    I booted from the disk. I immediately got a "NO CRIVE FOUND ERROR/STATUS CODE: 0120" message.

    I don't know how relevant it is, but yesterday I managed to use the Dell Recovery disk utility to back up data from the hard drive to an external USB drive. I.e. the drive is there and recognisable to some extent.

    I see from forums that others have had similar boot issues after running FixTDSS. Is it possible that this is the problem for me?

    Thanks.
  13. Broni Malware Annihilator Posts: 39,189   +175

    The drive may be still accessible to backup data but it may be damaged enough to not be able to boot.
    This is what WD says about error 120: http://support.wdc.com/techinfo/general/errorcodes.asp