1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive XP Rebooting in Normal Mode

Discussion in 'Malware and Virus Removal Archive' started by clitwin13, 2011/08/22.

  1. 2011/08/26
    clitwin13 Lifetime Subscription

    clitwin13 Well-Known Member Thread Starter

    Joined:
    2009/08/25
    Messages:
    96
    Likes Received:
    0
    Broni.... Clean boot doesn't work. The system goes through the normal boot process up and through the Windows XP running bar then the screen goes light blue and after 10 to 15 seconds it goes black and just stops ... it doesn't even try to reboot. It has to be manually recycled....


    As I was resetting the msconfig back to Normal, I opened the BOOT.INI tab and selected "check all boot paths ". The following appeared : the topic of the window was SYSTEM CONFIGURATION and the box stated:


    ...It appears that the following line in the BOOT.INI file does not refer to a valid operating system:

    "C:\CMDCONS\BOOTSECT.DAT= "Microsoft Windows Recovery Console "/cmdcons "

    Would you like to remove it from the BOOT.INI file?

    I did not take any action...Waiting your advice.
     
    Last edited: 2011/08/26
  2. 2011/08/26
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    That's legit.
    Recovery console had been installed by Combofix.
    It's important troubleshooting tool.

    Go back to "msconfig" and reverse all changes you just made.

    Restart computer
    When you reboot you will see an option to boot into the Recovery Console or the normal Windows installation.
    You have to use the up/down arrows to choose the Recovery Console. Then press Enter but you only have 2 seconds by default.
    If you find this hard to do then you can go into Control Panel, System, Advanced, Startup and Recovery, Settings. Where it says Time to Display List of Operating Systems, change it to 10 or more seconds. OK Then reboot.

    You should get a black screen with a C:\> prompt. Type with an Enter after each line:

    fixmbr

    (If it asks you if you are sure then say "Y ".)

    fixboot

    exit

    Attempt to boot normally.
     

  3. to hide this advert.

  4. 2011/08/26
    clitwin13 Lifetime Subscription

    clitwin13 Well-Known Member Thread Starter

    Joined:
    2009/08/25
    Messages:
    96
    Likes Received:
    0
    OK... My/(our) problem is the time differential... I will feed the kids (I have a 93 yr old 'son' and an 88 yr old 'daughter' and have to work around their schedule... I will get back to the unit in question tonight and be more readily available when you are... talk to you in a few....ckl
     
  5. 2011/08/26
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    No problem :)
     
  6. 2011/08/27
    clitwin13 Lifetime Subscription

    clitwin13 Well-Known Member Thread Starter

    Joined:
    2009/08/25
    Messages:
    96
    Likes Received:
    0
    I went into Recovery Console and received the prompt. But it appears as if the display is frozen. I cannot get a response typing or exiting. I will attempt a manual shutdown and a do-over... I even attempted the Recovery Console in Safe Mode to no avail. It seems that the cursor should be flashing but is frozen and the screen is non-responsive to the keyboard.
     
    Last edited: 2011/08/27
  7. 2011/08/27
    clitwin13 Lifetime Subscription

    clitwin13 Well-Known Member Thread Starter

    Joined:
    2009/08/25
    Messages:
    96
    Likes Received:
    0
    I went back to msconfig and confirmed everything for a 'clean boot' and attempted Recovery Console once again. No Joy...The white cursor doesn't flash and the system won't take inputs.
     
  8. 2011/08/27
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Hmmm...I'm not sure what exactly you're doing.

    Restart computer
    When you reboot you will see an option to boot into the Recovery Console or the normal Windows installation.
    You have to use the up/down arrows to choose the Recovery Console. Then press Enter.
    When you do this, you should be at this screen:
    [​IMG]
    You will be prompted to select a valid Windows installation (typically number 1).
    Select the installation number, and hit Enter.
     
  9. 2011/08/27
    clitwin13 Lifetime Subscription

    clitwin13 Well-Known Member Thread Starter

    Joined:
    2009/08/25
    Messages:
    96
    Likes Received:
    0
    The screen reads through the following:

    <to cancel, press ENTER>?

    Note: the cursor after the question mark doesn't flash and the screen will not take an input from the keyboard. It seems like it freezes. Could this be the result of a Combofix error since Windows Installer doesn't appear to work in Safe Mode and I could not access the Lavasoft product to either disable it or remove it before running Combofix. Don't know just askin'...
     
  10. 2011/08/27
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Do you have Windows XP CD?
     
  11. 2011/08/27
    clitwin13 Lifetime Subscription

    clitwin13 Well-Known Member Thread Starter

    Joined:
    2009/08/25
    Messages:
    96
    Likes Received:
    0
    Yes as a matter of fact I do have an XP disk for a Dell computer.
     
  12. 2011/08/27
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Let's try to access recovery console from the CD then...

    1. Insert your Windows XP CD into your CD and assure that your CD-ROM drive is capable of booting the CD.
    2. Once you have booted from CD, do NOT select the option that states: Press F2 to initiate the Automated System Recovery (ASR) tool.
    You’re going to proceed until you see the following screen, at which point you will press the “R” key to enter the recovery console:

    [​IMG]

    Then see if you can enter "1" this time.
     
  13. 2011/08/27
    clitwin13 Lifetime Subscription

    clitwin13 Well-Known Member Thread Starter

    Joined:
    2009/08/25
    Messages:
    96
    Likes Received:
    0
    OK... Just so I am clear. Do you want me to change the boot sequence to boot from CD as first choice in the system or just put the CD into the drive and allowing it to read. In addition I will need some time as I am home and not on location once again. I will get back later this afternoon and attempt what you are suggesting...Thanks again
     
  14. 2011/08/27
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    That's it.
    Then put the CD in and restart computer.
     
  15. 2011/08/27
    clitwin13 Lifetime Subscription

    clitwin13 Well-Known Member Thread Starter

    Joined:
    2009/08/25
    Messages:
    96
    Likes Received:
    0
    Thank you...I will report back in about 45 minutes ...getting ready to head out now.
     
  16. 2011/08/27
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    No problem :)
     
  17. 2011/08/27
    clitwin13 Lifetime Subscription

    clitwin13 Well-Known Member Thread Starter

    Joined:
    2009/08/25
    Messages:
    96
    Likes Received:
    0
    The system was configured to boot from CD. The CD was inserted in the drive and everything progressed exactly to the screen you displayed above requesting the "R" entry.

    NOTE:The screen goes blank each and every time it cycles through or reboots as if the system stops momentarily when it gets to the final screen. When the final screen comes back on it is as if the system is frozen and won't accept inputs.
     
  18. 2011/08/27
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I think you may have some other issues beside some infection we discovered.

    Let's try one more tool. It'll run from safe mode.

    Download TDSSKiller and save it to your desktop.
    • Doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
    • If an infected file is detected, the default action will be Cure, click on Continue.
    • If a suspicious file is detected, the default action will be Skip, click on Continue.
    • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
    • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
    • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.
     
  19. 2011/08/27
    clitwin13 Lifetime Subscription

    clitwin13 Well-Known Member Thread Starter

    Joined:
    2009/08/25
    Messages:
    96
    Likes Received:
    0
    Im on it right now .. get back to you shortly
     
  20. 2011/08/27
    clitwin13 Lifetime Subscription

    clitwin13 Well-Known Member Thread Starter

    Joined:
    2009/08/25
    Messages:
    96
    Likes Received:
    0
    Scan completed without detecting any infections. No log was posted for review.
     
    Last edited: 2011/08/27
  21. 2011/08/27
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    In that case....

    Run hard drive diagnostics: http://www.tacktech.com/display.cfm?ttid=287 (or http://www.bleepingcomputer.com/forums/index.php?showtopic=28744&hl=hard+drive+diagnostic)
    Make sure, you select tool, which is appropriate for the brand of your hard drive.
    Depending on the program, it'll create bootable floppy, or bootable CD.
    If downloaded file is of .iso type, use ImgBurn: http://www.imgburn.com/ to burn .iso file to a CD (select "Write image file to disc" option), to make the CD bootable.
    For Toshiba hard drives, see here: http://sdd.toshiba.com/main.aspx?Pa...rivesUSandCanada/SoftwareUtilities#diagnostic

    Note : If you do not know how to set your computer to boot from CD follow the steps HERE
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.