Please help virus destroyed BCD - no error message

OldUser

New member
Local time
7:26 AM
Messages
6
[Solved] Please help virus destroyed BCD - no error message

Hi, I'm writing this from a KNOPPIX Live CD as my computer cannot boot.
I have a triple boot system (7, vista, XP) and Windows 7 is my main OS. I was using it to surf the web only a few hours ago and suddenly my anti virus software which is Avast! (free) started popping windows about a program being blocked, I did not have enough time to read it but the title of the window was vid<something>.info , the "<something>" is the part I don't remember. Also, there was the name of the executable of the program and it was 4 letters, something like vwfv.exe , again I hadn't much time to look because after a few seconds a window popped up in the top left corner and immediately the screen went black for two seconds and then showed a BSOD but this was not a regular BSOD, it only had a few words in the top left part of the screen. I pressed the reset button and the computer passed POST but did not show the Windows 7 boot manager. There was no error message, only a blinking cursor in the top left corner.

I inserted the Win7 DVD and chose to repair windows. It said it found problems and restored the BCD and that the old BCD is backed up. I rebooted but nothing was changed - still only a blinking cursor. I booted the W7 DVD again and this time it let me to the advance repair options. I chose Command Prompt and verified that my files were still there - they are, so I believe the MBR and HDD data are OK it's just the boot process files that got sabotaged by the virus.
I tried to run SFC /SCANNOW but it won't let me do that from the DVD.
I'm stumped, any help would be REALLY greatly appreciated!

Some more useful info:
My main OS is Windows 7 Ultimate x64. My motherboard is ASUS M4N68T-M and my CPU is Athlon x3 435.
I'm using the onboard RAID in RAID 0 configuration (2 500GiB HDDs as one 1TiB drive).
I have several partitions on this drive, NTFS, FAT and FAT32 but the bulk of my data is in a one 500 GiB exFAT partition.
All of the 3 OSs are on NTFS partitions.

If I left out something important please be patient, it's very late at night here.

Thanks in advance,
OU
 
Last edited:

My Computer

OS
Windows 7 Ultimate x64
Using BOOTREC /FIXMBR got me my boot manager back. I logged on to XP and now downloading the trial version of NIS 2011 that I hope to use to get rid of the virus. Apparently, Avast! sucks.

If I'll manage to get my W7 working again I will come back and flag this as solved.
 

My Computer

OS
Windows 7 Ultimate x64
Hi,

In addition in NIS, I recommend you also try MalwareBytes - it has a very good reputation here.

Regards,
Golden
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
This forum has a great section on tutorials on how to repair your system. This is the link to a startup repair. Also, at the bottom of that page there are related links (restoring your system, clean install, etc) which may help you out. Peruse those and I think you will find something there that can help you out. I hope this helps and you get it sorted.

http://www.sevenforums.com/tutorials/681-startup-repair.html?filter[2]=Performance%20Maintenance

You could also try using a boot rescue disk to clear out infections, which may still be remaining in the background. You have a choice of these

http://www.avira.com/en/support-download-avira-antivir-rescue-system

http://www.avg.com/us-en/avg-rescue-cd

http://support.kaspersky.com/viruses/rescuedisk
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various
Golden: I always do use MBAM in conjunction with my AV software, it has saved my behind numerous times before. MBAM has been running for the last 3 hours now and still going strong (I do have A LOT of files).

Borg 386: I think I already solved the startup problem, I'll be 100% sure when MalwareBytes finishes.
Ironically, it actually was the tutorials here that helped me to get it fixed.
 

My Computer

OS
Windows 7 Ultimate x64
OK, MBAM finished, I am the proud owner of one Rootkit.TDSS.
I haven't heard about it until about an hour ago when this thread was just above mine:
http://www.sevenforums.com/system-security/143655-salvaging-tdl3-infected-hdd.html

Then I googled this TDSS/TDL3 and it turns out it's the Rootkit from hell... Whole systems have been destroyed, or so I understand. Now I'm really scared :(
I'll try TDSSKiller and Hitman Pro which turned up while reading some posts about this Rootkit. If anyone has another free tool which specializes in TDSS please tell me about it, I have 10 years of unbackedup data on this computer and it would really suck if everything will be lost because of this malware :(
 

My Computer

OS
Windows 7 Ultimate x64

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various
Thanks Borg, I will try them out.
 

My Computer

OS
Windows 7 Ultimate x64
I booted Windows 7 and ran all the malware/antirootkit software from there but nothing was found. It seems like MBAM got rid of it all. I think I was lucky to catch it before it had the chance to wreak havoc and root itself deep within my system.
Thanks to everyone that helped, I really love your forums :)
 

My Computer

OS
Windows 7 Ultimate x64
of course you got a free ride and NOW is the time to:

BACKUP! BACKUP! BACKUP!

please..

Rich
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Toshiba Laptop Qosimo X870
OS
Windows 7 Pro x64 SP1
CPU
Intel Core I7
Motherboard
Toshiba Qosmio
Memory
16 Gigs
Graphics Card(s)
NVIDIA GeForce GTX 670M
Monitor(s) Displays
17.7" laptop
Screen Resolution
1600 x 900
Hard Drives
256 Gig SanDisk SSD for C
256 Gig Intel SSD for D
Internet Speed
50/25 FIOS
Antivirus
Vipre (all you can eat for 10 machines)
Browser
IE and FF
Other Info
I have dos 6.22, wfwg 3.11, win98, 2000 and xp VHD's available for testing. MS's Virtual PC works great.
Glad you got it sorted.

You may want to consider adding MSE to your arsenal, for the most part, it plays well with other AV's and every layer of protection you can get is worth it.

It would probably be wise to do a full system scan with whatever AV you choose to run. And do that in a day or so, most rootkits/viruses are notorious for reinstalling themselves back into the system if you didn't get it all.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various
Back
Top