Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

browser redirect, can't run antimalware [Solved]


  • This topic is locked This topic is locked

#16
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
Lets try an alternate Recovery Console.

  • Please download BurnAtOnce and save it to your desktop. Click on Downloads, then on burnatonce 0.99.5
    • Install it by double-clicking on the file bao0995.exe that you downloaded.
    • Click Next, accept the license agreement, and click Next until the button says "Install". Click "Install" to finish.
  • Download the rc.iso file.
  • Save it to your desktop.
  • Put a blank CD in your computer’s burner.
  • Right-click on the file rc.iso, and select "burnatonce" from the menu.
  • Confirm that the box under the menu at the top says "rc.iso".
  • Click the "Write" button.
  • When the disk finishes, eject the CD.
  • Configure the computer to start from the CD-ROM or DVD-ROM drive. For information about how to do this, see your computer documentation, or contact your computer manufacturer.
  • Insert the Image of rc.iso that you copied to CD into your CD-ROM or DVD-ROM drive, and then restart your computer.
  • When you receive the "Press any key to boot from CD" message, press a key to start your computer from the Windows XP CD-ROM.
  • You will be prompted with the following options:

    A. To setup Windows XP, press Enter.
    B. To repair Windows XP installation using recovery console, press R.

    Choose the option, "To repair the Windows XP installation using recovery console", press R. If an Administrator Password have been established, you will be prompted to type it in. If no Administrator Password exists, just press ENTER.

  • You will be presented with the following:


    Microsoft Windows® Recovery Console

    The Recovery Console provides system repair and recovery functionality.
    Type EXIT to quit the Recovery Console and restart the computer.

    1: C:\WINDOWS

    Which Windows Installation would you like to log onto
    (To cancel, press ENTER)?

  • Press the number 1 on your keyboard and hit Enter.
  • At the command prompt, type the following command and press Enter:

    Disable tzkybkkt
    Del c:\windows\system32\drivers\tzkybkkt.sys
    (Make sure you use back slashes "\")

Type Exit and press Enter. Take the CD out of the drive and let the computer restart.
  • 0

Advertisements


#17
pauliede38

pauliede38

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
ok so i downloaded the stuff you told me.. but when i went to write the iso image to the disc i got this from the burn at once program:


Error 70: Permission denied
Error occurred in: frmMain:cmdWrite_Click

App Version: 0.99.5 Windows Version: 6.0.6001


however, i was able to burn the image to the disc by clicking ignore on the prompts that gave me that log above and i used the disk like you said and went throuh the recovery process but i'm still getting the same thing, i don't know maybe when i clicked on the ignore button it skipped some stuff that i might've needed i don't know???
  • 0

#18
pauliede38

pauliede38

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
i tought i should mention that the pc i'm communicating from is running VISTA and the infected pc is running xp i don't know if that makes any difference
  • 0

#19
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts

ok so i downloaded the stuff you told me.. but when i went to write the iso image to the disc i got this from the burn at once program:


Error 70: Permission denied
Error occurred in: frmMain:cmdWrite_Click

App Version: 0.99.5 Windows Version: 6.0.6001


however, i was able to burn the image to the disc by clicking ignore on the prompts that gave me that log above and i used the disk like you said and went throuh the recovery process but i'm still getting the same thing, i don't know maybe when i clicked on the ignore button it skipped some stuff that i might've needed i don't know???

VISTA should not make a difference. Were you able to boot to the Recovery Console? If yes, which prompt, C:\Windows or just C:\?
  • 0

#20
pauliede38

pauliede38

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
This is the command prompt i get:

C:\WINDOWS>
  • 0

#21
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
Lets rename the Boot.ini:

At the C:\WINDOWS> prompt type the following and press Enter:

Ren C:\Boot.ini Boot.ini.old

Type Exit and press Enter to re-start the computer. Ignore any error message. Are you able to boot into windows?

To reverse the above command type:

Ren C:\Boot.ini.old Boot.ini
  • 0

#22
pauliede38

pauliede38

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
:) Nope no luck
  • 0

#23
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
If the above does not force Windows to start, at the C:\Windows prompt type the following and press Enter after each line:

cd ERDNT
Dir


Write down the list of folders on screen and post it in a reply.
  • 0

#24
pauliede38

pauliede38

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
This is what i Got:


The volume in drive C has no label
The volume Serial Number is 087d-eccf

Directory of C:\Windows|ERDNT

08/24/09 10:30P d------- 0 .
08/24/09 10:30p d------- 0 ..
2 file(s) 0 bytes
15682383872 bytes free
  • 0

#25
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
There is a lot of information missing. Since you ran Combofix, although from the D:\ drive, there should be a couple of folders within the ERDNT folder such as sUBs and hiv-backup.

At the C:\Windows prompt type cd ERDNT\subs. Does it returns an error message?
  • 0

Advertisements


#26
pauliede38

pauliede38

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
yes it states the following:


The system cannot find the file or directory specified.
  • 0

#27
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
All registry backups are no longer available.

Have you tried booting in Safe Mode, Last Known Configuration, Safe Mode with command prompt... Etc..?
  • 0

#28
pauliede38

pauliede38

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
yes i have tried all of them, no luck...
  • 0

#29
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
I don't know if the problem is due to missing files and folders, which is what it seems to be, but I can attempt to load the First Run Registry and give it a try. Make sure you use the exact syntax.

At the C:\Windows prompt type the following and press Enter after each line:

cd System32\Config
Ren System System.old
Ren Sam Sam.old
Ren Security Security.old
Ren Software Software.old
Ren Default Default.old
Copy C:\Windows\Repair\System
Copy C:\Windows\Repair\Sam
Copy C:\Windows\Repair\Security
Copy C:\Windows\Repair\Software
Copy C:\Windows\Repair\Default


Type Exit to restart the computer.
  • 0

#30
pauliede38

pauliede38

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
well it looks like we might be getting somewhere it's now performing a diskcheck its in the CHKDSK mode it's deleted a few corrupt attributes so i'm gonna let it run and see what happens
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP