Google Redirect
Started by
Apocalypse_VC
, Apr 19 2011 08:38 PM
#61
Posted 28 April 2011 - 09:51 AM
#62
Posted 01 May 2011 - 06:36 PM
Any solution yet ?
If not,I'd like some one else to help me if you can't seem to solve it.
If not,I'd like some one else to help me if you can't seem to solve it.
#63
Posted 01 May 2011 - 07:14 PM
Sorry for the delay. I had to wait to the tool development.
Download aswMBR.exe ( 511KB ) to your desktop.
Double click the aswMBR.exe to run it
Click the "Scan" button to start scan
On completion of the scan click save log, save it to your desktop and post in your next reply
Download aswMBR.exe ( 511KB ) to your desktop.
Double click the aswMBR.exe to run it
Click the "Scan" button to start scan
On completion of the scan click save log, save it to your desktop and post in your next reply
#64
Posted 01 May 2011 - 08:03 PM
aswMBR version 0.9.4 Copyright© 2011 AVAST Software
Run date: 2011-04-22 22:09:33
-----------------------------
22:09:33.783 OS Version: Windows x64 6.1.7600
22:09:33.784 Number of processors: 2 586 0x602
22:09:33.787 ComputerName: RAVI-PC UserName: Ravi
22:09:37.034 Initialize success
22:09:43.291 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000058
22:09:43.295 Disk 0 Vendor: WDC_WD50 01.0 Size: 476940MB BusType: 11
22:09:45.328 Disk 0 MBR read successfully
22:09:45.332 Disk 0 MBR scan
22:09:45.337 Service scanning
22:09:47.024 Disk 0 trace - called modules:
22:09:47.031 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xfffffa800444b2c0]<<
22:09:47.036 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004991790]
22:09:47.042 3 CLASSPNP.SYS[fffff8800120143f] -> nt!IofCallDriver -> [0xfffffa8004921040]
22:09:47.048 \Driver\amdxata[0xfffffa8004906db0] -> IRP_MJ_CREATE -> 0xfffffa800444b2c0
22:09:47.054 Scan finished successfully
aswMBR version 0.9.4 Copyright© 2011 AVAST Software
Run date: 2011-04-22 22:20:19
-----------------------------
22:20:19.263 OS Version: Windows x64 6.1.7600
22:20:19.263 Number of processors: 2 586 0x602
22:20:19.263 ComputerName: RAVI-PC UserName: Ravi
22:20:21.385 Initialize success
22:20:26.080 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000057
22:20:26.080 Disk 0 Vendor: WDC_WD50 01.0 Size: 476940MB BusType: 11
22:20:28.124 Disk 0 MBR read successfully
22:20:28.139 Disk 0 MBR scan
22:20:28.139 Service scanning
22:20:38.654 Disk 0 trace - called modules:
22:20:38.670 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xfffffa800446e2c0]<<
22:20:38.685 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80049b3330]
22:20:38.685 3 CLASSPNP.SYS[fffff880012ae43f] -> nt!IofCallDriver -> [0xfffffa80049147b0]
22:20:38.685 \Driver\amdxata[0xfffffa8004927610] -> IRP_MJ_CREATE -> 0xfffffa800446e2c0
22:20:38.701 Scan finished successfully
aswMBR version 0.9.5.232 Copyright© 2011 AVAST Software
Run date: 2011-05-01 22:01:28
-----------------------------
22:01:28.218 OS Version: Windows x64 6.1.7600
22:01:28.218 Number of processors: 2 586 0x602
22:01:28.219 ComputerName: RAVI-PC UserName: Ravi
22:01:32.474 Initialize success
22:01:46.698 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000058
22:01:46.703 Disk 0 Vendor: WDC_WD50 01.0 Size: 476940MB BusType: 11
22:01:48.722 Disk 0 MBR read successfully
22:01:48.727 Disk 0 MBR scan
22:01:48.732 Disk 0 unknown MBR code
22:01:48.737 Service scanning
22:01:49.933 Disk 0 trace - called modules:
22:01:49.940 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xfffffa8003b2d2c0]<<
22:01:49.946 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80049906f0]
22:01:49.952 3 CLASSPNP.SYS[fffff88000c0143f] -> nt!IofCallDriver -> [0xfffffa80049204e0]
22:01:49.957 \Driver\amdxata[0xfffffa8004905060] -> IRP_MJ_CREATE -> 0xfffffa8003b2d2c0
22:01:49.961 Scan finished successfully
22:02:17.449 Disk 0 MBR has been saved successfully to "C:\Users\Ravi\Desktop\MBR.dat"
22:02:17.479 The log file has been saved successfully to "C:\Users\Ravi\Desktop\aswMBR.txt"
Run date: 2011-04-22 22:09:33
-----------------------------
22:09:33.783 OS Version: Windows x64 6.1.7600
22:09:33.784 Number of processors: 2 586 0x602
22:09:33.787 ComputerName: RAVI-PC UserName: Ravi
22:09:37.034 Initialize success
22:09:43.291 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000058
22:09:43.295 Disk 0 Vendor: WDC_WD50 01.0 Size: 476940MB BusType: 11
22:09:45.328 Disk 0 MBR read successfully
22:09:45.332 Disk 0 MBR scan
22:09:45.337 Service scanning
22:09:47.024 Disk 0 trace - called modules:
22:09:47.031 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xfffffa800444b2c0]<<
22:09:47.036 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004991790]
22:09:47.042 3 CLASSPNP.SYS[fffff8800120143f] -> nt!IofCallDriver -> [0xfffffa8004921040]
22:09:47.048 \Driver\amdxata[0xfffffa8004906db0] -> IRP_MJ_CREATE -> 0xfffffa800444b2c0
22:09:47.054 Scan finished successfully
aswMBR version 0.9.4 Copyright© 2011 AVAST Software
Run date: 2011-04-22 22:20:19
-----------------------------
22:20:19.263 OS Version: Windows x64 6.1.7600
22:20:19.263 Number of processors: 2 586 0x602
22:20:19.263 ComputerName: RAVI-PC UserName: Ravi
22:20:21.385 Initialize success
22:20:26.080 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000057
22:20:26.080 Disk 0 Vendor: WDC_WD50 01.0 Size: 476940MB BusType: 11
22:20:28.124 Disk 0 MBR read successfully
22:20:28.139 Disk 0 MBR scan
22:20:28.139 Service scanning
22:20:38.654 Disk 0 trace - called modules:
22:20:38.670 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xfffffa800446e2c0]<<
22:20:38.685 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80049b3330]
22:20:38.685 3 CLASSPNP.SYS[fffff880012ae43f] -> nt!IofCallDriver -> [0xfffffa80049147b0]
22:20:38.685 \Driver\amdxata[0xfffffa8004927610] -> IRP_MJ_CREATE -> 0xfffffa800446e2c0
22:20:38.701 Scan finished successfully
aswMBR version 0.9.5.232 Copyright© 2011 AVAST Software
Run date: 2011-05-01 22:01:28
-----------------------------
22:01:28.218 OS Version: Windows x64 6.1.7600
22:01:28.218 Number of processors: 2 586 0x602
22:01:28.219 ComputerName: RAVI-PC UserName: Ravi
22:01:32.474 Initialize success
22:01:46.698 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000058
22:01:46.703 Disk 0 Vendor: WDC_WD50 01.0 Size: 476940MB BusType: 11
22:01:48.722 Disk 0 MBR read successfully
22:01:48.727 Disk 0 MBR scan
22:01:48.732 Disk 0 unknown MBR code
22:01:48.737 Service scanning
22:01:49.933 Disk 0 trace - called modules:
22:01:49.940 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xfffffa8003b2d2c0]<<
22:01:49.946 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80049906f0]
22:01:49.952 3 CLASSPNP.SYS[fffff88000c0143f] -> nt!IofCallDriver -> [0xfffffa80049204e0]
22:01:49.957 \Driver\amdxata[0xfffffa8004905060] -> IRP_MJ_CREATE -> 0xfffffa8003b2d2c0
22:01:49.961 Scan finished successfully
22:02:17.449 Disk 0 MBR has been saved successfully to "C:\Users\Ravi\Desktop\MBR.dat"
22:02:17.479 The log file has been saved successfully to "C:\Users\Ravi\Desktop\aswMBR.txt"
#65
Posted 01 May 2011 - 08:06 PM
Ok this is what were going to do. We'll create a back-up of the MBR outside of windows then proceed to fixing that new variant with asWMBR.
Step One
We need to create a bootable CD with MBRTool on it. Goto this page to find out about MBRTool
Download MBRTool.exe and save it to your desktop.
Double-click MBRTool.exe to install it.
When you click Finish at the end of the installation "MBRTool Boootable Media Builder" will start.
Put the CD in the CD-ROM on the infected computer.
Reboot the infected computer from the CD
You will be presented with this menu.
Select the Command Prompt
Then type in - MBRTool.exe /bck /dsk:0 /sec:10
Power down the machine, remove the CD and boot back to normal mode.
Step Two
Re-Run aswMBR
Click Scan
On completion of the scan
Click the Fix for TDL4 or FIXMBR for Whistler Button Select as appropriate
Save the log as before and post in your next reply
Step One
We need to create a bootable CD with MBRTool on it. Goto this page to find out about MBRTool
Download MBRTool.exe and save it to your desktop.
Double-click MBRTool.exe to install it.
When you click Finish at the end of the installation "MBRTool Boootable Media Builder" will start.
- Put a blank CD in your CD-ROM.
- Select create Boot CD/DVD
- Click Go >>
- The CD will be created.
Put the CD in the CD-ROM on the infected computer.
Reboot the infected computer from the CD
You will be presented with this menu.
Select the Command Prompt
Then type in - MBRTool.exe /bck /dsk:0 /sec:10
Power down the machine, remove the CD and boot back to normal mode.
Step Two
Re-Run aswMBR
Click Scan
On completion of the scan
Click the Fix for TDL4 or FIXMBR for Whistler Button Select as appropriate
Save the log as before and post in your next reply
#66
Posted 01 May 2011 - 08:15 PM
How do I make it boot from the CD ?
#67
Posted 01 May 2011 - 08:19 PM
Try pressing F12 while booting to bring the boot order menu.
#68
Posted 01 May 2011 - 08:36 PM
When I select Command Promt the following message appears :
"FreeBOS HIMEM 64 3.12 [Sep 11 2005] © 1995,Trill Ferken 2001-2005 tom ehlert.
HIMEM- BIOS A20 method used
kernel:allocated 41 Diskbuffers = 21812 Bytes in HMA"
or something along the lines.I tried entering something,but nothing happened.
"FreeBOS HIMEM 64 3.12 [Sep 11 2005] © 1995,Trill Ferken 2001-2005 tom ehlert.
HIMEM- BIOS A20 method used
kernel:allocated 41 Diskbuffers = 21812 Bytes in HMA"
or something along the lines.I tried entering something,but nothing happened.
#69
Posted 01 May 2011 - 08:44 PM
Boot again using the MBRTool disc but this time select option 1 (Start MBRTool) then select 1 - perform automatic backup of all MBRs to disk.
Once done, proceed to Step Two.
Once done, proceed to Step Two.
#70
Posted 01 May 2011 - 08:50 PM
The same thing happens.I selected 'StartMBR Tool' and that same message appears,and there's nothing further I could do.
#71
Posted 01 May 2011 - 08:54 PM
Proceed with Step Two of my instruction.
#72
Posted 01 May 2011 - 08:59 PM
I cannot do anything after that.
#73
Posted 01 May 2011 - 09:01 PM
Remove the CD then restart the computer to normal mode.
Download the latest aswMBR.exe ( 511KB )
Run aswMBR
Click Scan
On completion of the scan
Click the Fix for TDL4 or FIXMBR for Whistler Button Delete as appropriate
Save the log as before and post in your next reply
Download the latest aswMBR.exe ( 511KB )
Run aswMBR
Click Scan
On completion of the scan
Click the Fix for TDL4 or FIXMBR for Whistler Button Delete as appropriate
Save the log as before and post in your next reply
#74
Posted 01 May 2011 - 10:19 PM
I can only select FixMBR,and I get the message:
http://img638.images...us/i/swads.jpg/ Do I click yes ?
http://img638.images...us/i/swads.jpg/ Do I click yes ?
#75
Posted 01 May 2011 - 10:35 PM
Yep, please go ahead then post the log.
Similar Topics
1 user(s) are reading this topic
0 members, 1 guests, 0 anonymous users