Solved

BSOD Windows 7 after TDSSKILLER

Posted on 2010-11-12
7
1,915 Views
Last Modified: 2013-11-22
We ran TDSSKILLER on  Windows 7 x64 machine and now on reboot we get a BSOD stop x7b.  When trying safe mode it auto reboots after CLASSPNP.SYS.  Any suggestions on how to figure out which driver was removed or altered by TDSSKILLER?
TDSSKiller.2.4.7.0-11.11.2010-15.txt
0
Comment
Question by:acasgar
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 9

Expert Comment

by:ken2421
ID: 34120657
I would say that it is having trouble identifying the boot device. Run the 7 DVD and let it repair the system error.

HTH,
Ken
0
 
LVL 2

Author Comment

by:acasgar
ID: 34121065
I already tried that, it finds nothing wrong.  I tried a restore and didn't work.
0
 
LVL 22

Expert Comment

by:optoma
ID: 34123568
It detected a MBR virus.
Grab a data backup first and then try fixmbr using command prompt
http://windows7themes.net/how-to-fix-mbr-in-windows-7.html
0
Simplifying Server Workload Migrations

This use case outlines the migration challenges that organizations face and how the Acronis AnyData Engine supports physical-to-physical (P2P), physical-to-virtual (P2V), virtual to physical (V2P), and cross-virtual (V2V) migration scenarios to address these challenges.

 
LVL 47

Accepted Solution

by:
rpggamergirl earned 500 total points
ID: 34126835
TDSSKiller doesn't handle TDL4 well in Windows 7.

bootrec /Fixmbr command from the Recovery Console should fix it.
0
 
LVL 2

Assisted Solution

by:acasgar
acasgar earned 0 total points
ID: 34127301
I forgot to post yesterday but yes rpggamergirl is mainly right.  TDSSKILLER killed the "boot" folder.  using bootrec did the trick.  I however did the following:

http://support.microsoft.com/kb/927392 

bcdedit /export C:\BCD_Backup
c:
bootrec /RebuildBcd
bootrec /FixMbr
bootrec /FixBoot
cd boot
attrib bcd -s -h -r
ren c:\boot\bcd bcd.old
bootrec /RebuildBcd
bootrec /FixMbr


yes I know several commands were redundant, I was at a point where I could not even boot to the repair widows without getting a stop error, I did boot off the DVD went to the Advanced section of the repair so I could get to the command prompt, after running the commands as I mentioned above it finally recovered.  It is important to note simply following the article mentioned above will not work.  rpggamergirl got it in the fact that the MBR was gone/corrupt and was the cause of the driver failures I a positive.  I read lots of other people losing a windows install after running TDSSKILLER, you must check for the boot folder if it is missing that’s the issue!!
0
 
LVL 22

Expert Comment

by:optoma
ID: 34127313
The article I linked also said the same process to run regarding the mbr
0
 
LVL 2

Author Closing Comment

by:acasgar
ID: 34162427
I accepted my comment as part of the solution because it has all the details to correct the issue.
0

Featured Post

When ransomware hits your clients, what do you do?

MSPs: Endpoint security isn’t enough to prevent ransomware.
As the impact and severity of crypto ransomware attacks has grown, Webroot has fought back, not just by building a next-gen endpoint solution capable of preventing ransomware attacks but also by being a thought leader.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you get continual lockouts after changing your Active Directory password, there are several possible reasons.  Two of the most common are using other devices to access your email and stored passwords in the credential manager of windows.
The Windows functions GetTickCount and timeGetTime retrieve the number of milliseconds since the system was started. However, the value is stored in a DWORD, which means that it wraps around to zero every 49.7 days. This article shows how to solve t…
The viewer will learn how to successfully create a multiboot device using the SARDU utility on Windows 7. Start the SARDU utility: Change the image directory to wherever you store your ISOs, this will prevent you from having 2 copies of an ISO wit…
If you’ve ever visited a web page and noticed a cool font that you really liked the look of, but couldn’t figure out which font it was so that you could use it for your own work, then this video is for you! In this Micro Tutorial, you'll learn yo…

717 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question