Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Startup Repair Offline - CorruptRegistry


  • Please log in to reply
52 replies to this topic

#46 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,679 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:10:35 PM

Posted 14 April 2013 - 09:28 PM

In a working computer open Notepad. Please copy the entire contents of the code box below. (To do this highlight the contents of the box, right click on it and select copy. Right-click on notepad and select Paste). Save it in the flashdrive next to FRST64 as fixlist.txt
Start
Replace: C:\Windows.old\Windows\System32\CodeIntegrity\bootcat.cache c:\Windows\system32\codeintegrity\Bootcat.cache
End
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST64 as you did before and press the Fix button just once and wait.
The tool will make a log in the flashdrive (Fixlog.txt) please post it to your reply.

Re-Scan with FRST64 and post (or upload) the new Frst.txt log

Attempt to boot in Normal Mode.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


BC AdBot (Login to Remove)

 


#47 Clivelton

Clivelton
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:12:35 AM

Posted 14 April 2013 - 09:43 PM

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-04-2013
Ran by SISTEMA at 2013-04-14 21:39:29 Run:8
Running from G:\
 
==============================================
 
Could not find c:\Windows\system32\codeintegrity\Bootcat.cache.
C:\Windows.old\Windows\System32\CodeIntegrity\bootcat.cache copied successfully to c:\Windows\system32\codeintegrity\Bootcat.cache
 
==== End of Fixlog ====


#48 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,679 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:10:35 PM

Posted 14 April 2013 - 09:44 PM

Boot?

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#49 Clivelton

Clivelton
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:12:35 AM

Posted 14 April 2013 - 09:48 PM

Attached File  FRST.txt   213.71KB   1 downloadshere



yes, boot



#50 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,679 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:10:35 PM

Posted 14 April 2013 - 09:49 PM

Run TDSSKiller.

Please download the latest version of TDSSKiller from here and save it to your Desktop.
  • Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.
    image000q.png
  • Put a checkmark beside loaded modules.
    2012081514h0118.png
  • A reboot will be needed to apply the changes. Do it.
  • TDSSKiller will launch automatically after the reboot. Also your computer may seem very slow and unusable. This is normal. Give it enough time to load your background programs.
  • Then click on Change parameters in TDSSKiller.
  • Check all boxes then click OK.
    2012081517h0349.png
  • Click the Start Scan button.
    19695967.jpg
  • The scan should take no longer than 2 minutes.
  • If a suspicious object is detected, the default action will be Skip, click on Continue.
    67776163.jpg
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    62117367.jpg
    Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
  • A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#51 Clivelton

Clivelton
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:12:35 AM

Posted 14 April 2013 - 10:24 PM

The Blue Screen again... the same error



#52 Clivelton

Clivelton
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:12:35 AM

Posted 14 April 2013 - 10:44 PM

My Dear Friend, thanks for you help!!! I waste you entire Monday, and i give up! I will install the windows again...

 

You are great, i am so grateful for all i've learned today.

 

And to me, you are a master and i will follow you on Bleepingcomputer every day, my offer steel's up. (i know i will need you help again someday  :lmao: )

 

How we said in here: "O conhecimento constrói pontes entre pessoas" 

 

"The Knowledge build bridges between people"

 

And you Knowledge build a Bridge to me now...



#53 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,679 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:10:35 PM

Posted 15 April 2013 - 10:19 AM

Thank you. Windows 8 is very particular with unsigned files. Make sure all devices to be installed are compatible with the system.

Be safe.

Best wishes! :hello:

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users