Please help virus destroyed BCD - no error message

Page 1 of 2 12 LastLast

  1. Posts : 6
    Windows 7 Ultimate x64
       #1

    [Solved] Please help virus destroyed BCD - no error message


    Hi, I'm writing this from a KNOPPIX Live CD as my computer cannot boot.
    I have a triple boot system (7, vista, XP) and Windows 7 is my main OS. I was using it to surf the web only a few hours ago and suddenly my anti virus software which is Avast! (free) started popping windows about a program being blocked, I did not have enough time to read it but the title of the window was vid<something>.info , the "<something>" is the part I don't remember. Also, there was the name of the executable of the program and it was 4 letters, something like vwfv.exe , again I hadn't much time to look because after a few seconds a window popped up in the top left corner and immediately the screen went black for two seconds and then showed a BSOD but this was not a regular BSOD, it only had a few words in the top left part of the screen. I pressed the reset button and the computer passed POST but did not show the Windows 7 boot manager. There was no error message, only a blinking cursor in the top left corner.

    I inserted the Win7 DVD and chose to repair windows. It said it found problems and restored the BCD and that the old BCD is backed up. I rebooted but nothing was changed - still only a blinking cursor. I booted the W7 DVD again and this time it let me to the advance repair options. I chose Command Prompt and verified that my files were still there - they are, so I believe the MBR and HDD data are OK it's just the boot process files that got sabotaged by the virus.
    I tried to run SFC /SCANNOW but it won't let me do that from the DVD.
    I'm stumped, any help would be REALLY greatly appreciated!

    Some more useful info:
    My main OS is Windows 7 Ultimate x64. My motherboard is ASUS M4N68T-M and my CPU is Athlon x3 435.
    I'm using the onboard RAID in RAID 0 configuration (2 500GiB HDDs as one 1TiB drive).
    I have several partitions on this drive, NTFS, FAT and FAT32 but the bulk of my data is in a one 500 GiB exFAT partition.
    All of the 3 OSs are on NTFS partitions.

    If I left out something important please be patient, it's very late at night here.

    Thanks in advance,
    OU
    Last edited by OldUser; 10 Feb 2011 at 17:37.
      My Computer


  2. Posts : 6
    Windows 7 Ultimate x64
    Thread Starter
       #2

    Using BOOTREC /FIXMBR got me my boot manager back. I logged on to XP and now downloading the trial version of NIS 2011 that I hope to use to get rid of the virus. Apparently, Avast! sucks.

    If I'll manage to get my W7 working again I will come back and flag this as solved.
      My Computer


  3. Posts : 19,383
    Windows 10 Pro x64 ; Xubuntu x64
       #3

    Hi,

    In addition in NIS, I recommend you also try MalwareBytes - it has a very good reputation here.

    Regards,
    Golden
      My Computer


  4. Posts : 7,781
    Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
       #4

    This forum has a great section on tutorials on how to repair your system. This is the link to a startup repair. Also, at the bottom of that page there are related links (restoring your system, clean install, etc) which may help you out. Peruse those and I think you will find something there that can help you out. I hope this helps and you get it sorted.

    Startup Repair[2]=Performance%20Maintenance

    You could also try using a boot rescue disk to clear out infections, which may still be remaining in the background. You have a choice of these

    http://www.avira.com/en/support-down...-rescue-system

    http://www.avg.com/us-en/avg-rescue-cd

    http://support.kaspersky.com/viruses/rescuedisk
      My Computer


  5. Posts : 6
    Windows 7 Ultimate x64
    Thread Starter
       #5

    Golden: I always do use MBAM in conjunction with my AV software, it has saved my behind numerous times before. MBAM has been running for the last 3 hours now and still going strong (I do have A LOT of files).

    Borg 386: I think I already solved the startup problem, I'll be 100% sure when MalwareBytes finishes.
    Ironically, it actually was the tutorials here that helped me to get it fixed.
      My Computer


  6. Posts : 6
    Windows 7 Ultimate x64
    Thread Starter
       #6

    OK, MBAM finished, I am the proud owner of one Rootkit.TDSS.
    I haven't heard about it until about an hour ago when this thread was just above mine:
    salvaging a TDL3 infected HDD

    Then I googled this TDSS/TDL3 and it turns out it's the Rootkit from hell... Whole systems have been destroyed, or so I understand. Now I'm really scared
    I'll try TDSSKiller and Hitman Pro which turned up while reading some posts about this Rootkit. If anyone has another free tool which specializes in TDSS please tell me about it, I have 10 years of unbackedup data on this computer and it would really suck if everything will be lost because of this malware
      My Computer


  7. Posts : 7,781
    Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
       #7

    Got a couple other possibilities....

    Gmer

    GMER - Rootkit Detector and Remover

    Norton Power Eraser

    http://security.symantec.com/nbrt/npe.asp?lcid=1033
    Eliminates deeply embedded and difficult to remove crimeware that traditional virus scanning doesn't always detect.
      My Computer


  8. Posts : 6
    Windows 7 Ultimate x64
    Thread Starter
       #8

    Thanks Borg, I will try them out.
      My Computer


  9. Posts : 6
    Windows 7 Ultimate x64
    Thread Starter
       #9

    I booted Windows 7 and ran all the malware/antirootkit software from there but nothing was found. It seems like MBAM got rid of it all. I think I was lucky to catch it before it had the chance to wreak havoc and root itself deep within my system.
    Thanks to everyone that helped, I really love your forums :)
      My Computer


  10. Posts : 1,800
    Windows 7 Pro x64 SP1
       #10

    of course you got a free ride and NOW is the time to:

    BACKUP! BACKUP! BACKUP!

    please..

    Rich
      My Computer


 
Page 1 of 2 12 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 13:42.
Find Us