Windows 7 Forums

Welcome to Windows 7 Forums. Our forum is dedicated to helping you find support and solutions for any problems regarding your Windows 7 PC be it Dell, HP, Acer, Asus or a custom build. We also provide an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.


Windows 7: Used windows defender offline now windows won't start

29 Apr 2013   #41
empresssoul

windows 7 64 bit
 
 

so open notepad on the clean computer?


My System SpecsSystem Spec
.
29 Apr 2013   #42
cottonball

Windows 7 Home Premium
 
 

empresssoul,

Please await my instructions before you do anything else!

Do not run the script above.

Thanks!
My System SpecsSystem Spec
29 Apr 2013   #43
VistaKing

Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
 
 

Yes . Sorry I wasn't very clear .
My System SpecsSystem Spec
.

29 Apr 2013   #44
cottonball

Windows 7 Home Premium
 
 

empresssoul,

On the clean computer, please open: Notepad
Copy/paste all the contents of the quote box below to Notepad (do not copy the word 'Quote').
Save it on the flash drive as: fixlist.txt

Quote:
start
C:\Windows\svchost.exe
TDL4: custom:26000022
ATTENTION: Malware custom entry on BCD on drive e: detected.
cmd: bootrec /fixmbr
cmd: bootrec /fixboot
end
WARNING: This script is written specifically for empresssoul, for use on this particular computer.
Running the script on another computer may cause damage to the Operating System.

Now, in the infected computer, plug in the USB flash drive, and enter System Recovery Options as you did before.

Run FRST again, but this time press the Fix button just once, and wait.

When done, the tool makes a log on the flash drive. This time it is called: Fixlog.txt

Try to boot the computer into normal mode and post back on what happens.

Also, please post Fixlog.txt in your reply.


If the computer still does not boot into Windows, just hang in there.
My System SpecsSystem Spec
29 Apr 2013   #45
VistaKing

Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
 
 

Cottonball

Wouldn't it be "ATTENTION: Malware custom entry on BCD on drive e: detected"
My System SpecsSystem Spec
29 Apr 2013   #46
empresssoul

windows 7 64 bit
 
 

It worked....I am on my desktop!
when I selected Internet explorer it won't open, but google chrome did, also my micro secur Essen is off and when attempting to turn on it comes back with an error message
My System SpecsSystem Spec
29 Apr 2013   #47
cottonball

Windows 7 Home Premium
 
 



Great job, empresssoul!!
You are very good at applying instructions.

My bad on: Malware custom entry on BCD on drive e: detected. (Your drive was not: y)
However, it does not matter, since that is not a crucial entry.
The rest of the entries is what matters.



Now, let's see where the damage is, and give it a whirl.

Please press on with Downloading Farbar Service Scanner
Save to the Desktop
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
  • Press: Scan
  • FSS creates a log, FSS.txt, on the Desktop.
Please provide the FSS.txt in your reply.
My System SpecsSystem Spec
29 Apr 2013   #48
empresssoul

windows 7 64 bit
 
 

Farbar Service Scanner Version: 14-04-2013
Ran by Empress (administrator) on 29-04-2013 at 22:51:23
Running from "C:\Users\Empress\Downloads"
Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Attempt to access Yahoo IP returned error. Yahoo IP is offline
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============

Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****
My System SpecsSystem Spec
29 Apr 2013   #49
cottonball

Windows 7 Home Premium
 
 

Not the results expected...

When you open IE, what happens? Does it just flash and close, or, does it give you an error message?
If so, describe.

On MSE, what is the error message you are getting?
My System SpecsSystem Spec
29 Apr 2013   #50
cottonball

Windows 7 Home Premium
 
 

Also, please go to the TDSSKiller Download
Select the .exe version
Double-click on TDSSKiller.exe to run the program.


When the TDSSKiller console opens, click on: Change Parameters
Under Additional Options, place a check in the box next to: Detect TDLFS File System
Click: OK


Press: Start Scan

•If a suspicious object is detected by this program, the default action is Skip. Leave this action as is, and click on: Continue
•If malicious objects are found, they show in the Scan results.
Ensure Cure (the default action) is selected, then click: Continue > Reboot now, to finish the cleaning process.
(Note: If Cure is not available, select Skip, >>Do not select: Delete<<)


When done, the tool creates a log on the disk with the Windows Operating System, normally C:\


Logs have a name like:
C:\TDSSKiller.X.X.X_29.04.2013_15.31.43_log.txt


Please post or attach the TDSSKiller log in your reply.
My System SpecsSystem Spec
Reply

 Used windows defender offline now windows won't start




Thread Tools Search this Thread
Search this Thread:

Advanced Search




Similar help and support threads
Thread Forum
Windows Defender Offline
How to Use Windows Defender Offline The former Microsoft Standalone System Sweeper (MSSS) BETA has been rebranded and available as Windows Defender Offline now. Windows Defender Offline is a free standalone, bootable malware and virus remover from Microsoft that performs an offline scan...
Tutorials
cant reboot after windows defender offline
hello, i read another similar but not sure what will apply in my case.... After being notified my computer was infected I followed the suggestion to use Windows Defender Offline to remove the trojan. Once completed, and having cleaned the trojan, the computer would not reboot. It has a black...
System Security
I used Windows Defender Offline now Windows 7 Home Premuim won't load
I ran MSE on this computer and it picked up the Trojan Alureon. It said it couldn't completely unistall it and I had to use Windows Defender Offline. I installed WDO on my USB and ran it. Now I can't get windows to load and Startup Repair can't fix the problem. I've run it a few times and I've...
System Security
windows defender offline error
I'm trying to download and install windows defender offline to a flash drive for use on another computer. During the 4-step process, I get error 0007-8004DD1D "error formatting drive" when it tries to format the flash drive. I have tried several time using different flash drives. I manually...
System Security


Our Sites

Site Links

About Us

Find Us

Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd

All times are GMT -5. The time now is 04:13.

Twitter Facebook Google+



Windows 7 Forums

Seven Forums Android App Seven Forums IOS App