test. PLEASE respond!

I ticked the “restart system” when finished and started the repairs. I left home for a time, then to return to find “time lasped 2hr 47mins”. Then I noticed I was to disable antivirus. I then disabled it “until restart of system”. The repairs are still ongoing, now at elasped time: 2hr 55mins. I am wondering if I might need to begin over (still running) considering I had not disabled Avast?

PS - When I came home, the Progress bar said, “Repair Jobs: 3/18” and it is still there with TIme elapsed: 3hrs 43mins (now).

PPS - time lapsed: 9hrs 22mins and still at the same place: Repair Jobs: 3/18 (repair internet explorer),

FYI- Not sure if it matters, but I don’t think I have updated IE since I got the computer several years ago. I use Firefox for my browser.

I’m closing “Tweakng.com” until further notice from you.

OK I will reduce the number of repairs

Just tick the ones shown below

ok. Just did the repair run. It took less than 5 mins. After restarting, and once logged into my user Window (also Admin) and connected to internet, almost an immediate popup of the alert “Malicious URL Blocked” by avast. Still same Process and objects… URL:MAL and C:\windows\systems32\svchost.exe

Still no sound for my Windows start up. Have not yet checked other problems. I’m ready to proceed with further instructions.

OK do you have a USB drive handy ? If so we will work outside of windows

Download Peazip to the desktop
Run and install the programme
As it installs this page will show, deselect the AVG ticks
Press decline and it will then install cleanly

https://dl.dropbox.com/u/73555776/peazip.jpg

Download the following files to the desktop … Right click the links and select save as…then select desktop

Rufus

OTLPE_standard

Right click OTLPE on your desktop and select …Open as archive

https://dl.dropbox.com/u/73555776/Unzup%20archive.png

Select OTLPE standard

https://dl.dropbox.com/u/73555776/select%20archive.PNG

Click Extract, ensure that desktop is selected

https://dl.dropbox.com/u/73555776/extract%20archive.PNG

Insert the USB stick Then run Rufus

https://dl.dropbox.com/u/73555776/rufus.JPG

Select the ISO file on the desktop via the ISO icon.

Press Start Burn

https://dl.dropbox.com/u/73555776/RufusISO.JPG

Once the USB has burnt then

[*]Download Farbar Recovery Scan Tool and save it to the flash drive.

[*]Reboot your system using the boot USB you just created.
Note : If you do not know how to set your computer to boot from USB follow the steps here
[]As the Programme needs to detect your hardware and load the operating system, I would recommend a nice cup of tea whilst it loads :slight_smile:
[
]Your system should now display a Reatogo desktop.
[]Locate the flash drive and run FSRT
[
]The tool will start to run.

http://i1224.photobucket.com/albums/ee362/Essexboy3/Farbar/FRST2.gif

[*]When the tool opens click Yes to disclaimer.
[*]Press Scan button.
[*]It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

Only one question before I begin this preceding process:
Once I have the Reatogo Desktop and after finding the FRST.txt log, will I be able to locate and use Firefox to access this forum to reply with the log OR will I have to go to another computer to send the log and read your next reply? I’m am believing I will be okay at my own computer, but want to ask to be sure.

No you should be able to access the net from the reatogo desktop and firefox is already on it

essexboy,

ANOTHER problem! I have one USB (recognized and use with my computer) but didn’t want to loose files, etc that is on it. So purchased another one for this process. I insert it to run rufus. It is noticed with an icon in “tray” BUT it is not recognized in “My computer” nor by rufus (the “Start” is greyed out still).
What now?! :frowning:

Can you burn a CD ?

If so then double click the OTLPE.exe file and it will burn it to a CD
You can boot from that
Then add FRST to the USB (it is a small file) and then run from the reatogo desktop

I burned OTLPE.exe to a CD, downloaded and ran FRST.exe (FRST.txt is attached). I then rebooted into the Reatogo desktop. I was trying to locate Firefox on Reatogo but only saw Internet explorer. I tried to access the internet. I opened to use it, but seemed not to be able to access the web on it. I then searched the “All Programs” for Firefox, located it and attempted a connection via that browser… no luck again. I was thinking I could probably reboot into Windows again to communicate via the Forum, clicked on “shutdown” and Reatogo didn’t seem to do anything for at least 10 minutes (may need to cold boot), at which time I left as was and am presently at library again, to send the FRST.txt file. I’ll be here for a little while and check again for your reply, before returning home and cold booting into Windows.

Found it

ATTENTION ===> 0 byte partition bootkit on partition 1

I will need to use one of Farbars other tools to kill this

Download ListParts64 to the USB where you have FRST

Go to the Reatogo desktop and run Listparts
The tool will start to run.

https://dl.dropbox.com/u/73555776/listparts.GIF

Press Scan button.
It will make a log (results.txt) on the flash drive. Please copy and paste it to your reply.

downloaded ListParts64… (back to home)… opened Reatogo Desktop… looked for “ListParts” program icon on desktop… couldn’t find one and searched “all Programs”, none to be found… ran ListParts64.exe (via “My Computer” on the desktop) from my USB drive… I got an error msg which said “D:\ListParts64.exe is not a valid Win32 application”… started to reply but decided to try again… rebooted into Reatogo… clicked on “My Computer” but it didn’t respond… hit “alt+ctrl+del” and back toreply now… with no result.txt file… Not sure if I did something wrong?

Hi that was my stupid fault I forgot that reatogo is a 32 bit operating system

Download this one to your USB
ListParts This is the 32bit version… Once we run the listparts fix it will be gone

Hi,
Success in running Listparts… :slight_smile: results.txt attached.

Immediately upon rebooting to Windows and opening browser, I got the Avast alert: “Malicious URL Blocked” again… infection- URL:Mal in Process- C:\Windows\systems32\scvhost.exe

OK download the attached fix.txt to the same USB as listparts
Run the Reatogo desktop
Run Listparts as before
Press Fix

What will then happen is the 0byte partition will be set inactive
The proper partition will be set active
The proper partition will be set inactive
The proper partition will then be set active for the last time
The 0byte partition will then be removed

Once it has completed it will make a log on the USB drive, post that
Reboot to normal windows and let me know if the alerts cease

MAJOR problem!!! I CANNOT reboot into normal Windows (I am again at the library!)

Reminder: I have not been able to use any browser for my communications with you within the Reatogo desktop since I have been using it. I have been back and forth between Reatog and normal Windows.

When I rebooted to go into normal Windows (and did a COLD boot for normal windows) I get the same message on a black bootup screen: “Reboot and select proper Boot device or Insert Boot Media in Selected Boot device and press any key.”

You will find the PLfixlog.txt attached.

I am also WORRIED NOW… when I inserted my USB drive into this computer at the library I had a notice that “a new device was installed but computer will need to be restarted to complete” something to that main effect) that is not to happen nor has it happened to me in the past by inserting my USB drive.

I will be here at the library for a little while waiting your next instruction.

OK download this fix, and then run from list parts as before.

I have had a quick word with Farbar and the custom is used only for Vista and above, which was why the script did not run

okay… on my way back home to run this new fix file… I hope there won’t be any problems with this library computer!! But I’m not sure if i will know about it, if there is.

I will send new fixlog after I run the listparts with this fix… either from home or from library again IF it does’t work.

BACK at the library … that only means that AGAIN my computer did NOT bootup into normal Windows! It still brought up the same message for inserting a boot device (same as mentioned in reply #36).

I ran the fix again and you will find attached the most recent PLfixlog.txt

I will be waiting for reply…