also @ TechSpot: Android 4.0: Tracking Ice Cream Sandwich's Availability on Smartphones

TechSpot

[Inactive] Redirect virus; Staples remote help couldn't get rid of it; restore not working

Discussion in 'Virus and Malware Removal' started by laladawn, Jan 4, 2012.

  1. Broni Malware Annihilator

    Please Boot to the System Recovery Options
    If you have Windows 7 installation disc, just insert a DVD to the drive, restart computer and it should load automatically (option two presented in the article).
    It's possible also that your computer has a pre-installed recovery partition instead - in such a case use a method one (by pressing F8 before Windows starts loading)...

    On the System Recovery Options menu you will get the following options:

    • Startup Repair
    • System Restore
    • Windows Complete PC Restore
    • Windows Memory Diagnostic Tool
    • Command Prompt

    Choose Command Prompt
    You should see X:\SOURCES>...

    Execute the following commands in bold.
    Press Enter after every one of them.

    bootrec /fixboot (<--- there is a "space" after "bootrec")

    exit

    Restart computer.
  2. laladawn Newcomer, in training

    trouble following exactly

    okay, I don't have a windows disk, and I cannot get to the system recovery menu from where I am. F8 does not work at all...I have tried so many times that I have probably broken the key.

    But, if I go in and change the boot to the recovery label partition in gparted, then I can get to the system recovery menu (aha! by pressing F8!)...the only thing is that once I get to the command prompt, the path is X:\windows\system32> instead of what you have listed above.

    I don't know if I am where I need to be or not, but I cannot get to that menu any other way...I can go back to where I was if I just went in the wrong direction...

    thanks again for your help!!
  3. Broni Malware Annihilator

    Try the command from X:\windows\system32> prompt
  4. laladawn Newcomer, in training

    after the command, it says it was completed successfully (after only a few seconds), but when it reboots, it will not load windows and it goes into this startup repair which runs, but then says it cannot repair the startup after running for about an hour...
  5. Broni Malware Annihilator

    Try Startup Repair.
  6. laladawn Newcomer, in training

    Startup repair says it could not detect a problem then restarts
    It looks like Windows is about to load, then it flashes quickly to a blue screen with white letters then goes back to startup repair which then says it could not detect a problem...

    It does ask Do you want to restore your computer using system restore?IBM
  7. Broni Malware Annihilator

    Try to run two commands;

    bootrec /fixmbr (<--- there is a "space" after "bootrec")

    then...

    bootrec /fixboot (<--- there is a "space" after "bootrec")
  8. laladawn Newcomer, in training

    both commands said they completed successfully

    Upon reboot, I get the windows error recovery message again saying windows failed to start
  9. Broni Malware Annihilator

  10. laladawn Newcomer, in training

    Do I just download the three links from that linked article and burn onto a DVD? I had to be able to get to another computer to do this since mine isn't working at all now...I want to be sure I do that right for the Windows DVD.

    thanks!
  11. Broni Malware Annihilator

    Yes you have to download all three files and then read "hack to create or make bootable Windows 7 DVD ISO images out of downloaded files".
  12. laladawn Newcomer, in training

    I made the DVD...what is the next step?

    thanks!
  13. Broni Malware Annihilator

    Follow my reply #21
  14. laladawn Newcomer, in training

    I was able to do everything listed and get to the command prompt at X:\sources

    I did the fixmbr and the fixboot

    I still get the same error message when I reboot: BOOTMGR is missing
  15. Broni Malware Annihilator

    I'm afraid this is beyond repair and you'll have to reinstall Windows.
  16. laladawn Newcomer, in training

    OK...I reinstalled Windows and other programs that I lost. I re-downloaded the bootkit and reran it. Here is the log:

    Bootkit Remover
    (c) 2009 Esage Lab
    www.esagelab.com

    Program version: 1.2.0.1
    OS Version: Microsoft Windows 7 Home Premium Edition (build 7600), 64-bit

    System volume is \\.\C:
    \\.\C: -> \\.\PhysicalDrive0 at offset 0x00000003`afd00000
    Boot sector MD5 is: bb4f1627d8b9beda49ac0d010229f3ff

    Size Device Name MBR Status
    --------------------------------------------
    465 GB \\.\PhysicalDrive0 OK (DOS/Win32 Boot code found)


    Done;
    Press any key to quit...
  17. Broni Malware Annihilator

    That looks good :)
  18. laladawn Newcomer, in training

    No more redirects either. Thank you so much for all of your help!
  19. Broni Malware Annihilator

    You're very welcome [IMG]