
![]() ![]() |
Sep 17 2009, 02:10 PM
Post
#1
|
|
|
New Member ![]() Group: Authentic Member Posts: 11 Joined: 17-September 09 Member No.: 87,967 Operating System: xp |
I have a huge issue with my desktop computer, I have some sort of virus, or something like it, here are the symptoms I got: Will not load at times at all On lonong page I get several different notifications, winlogon.exe application error, visuall C++ library errors (also winlogon.exerelated) and more if i can actually logon, usually I have no desktop items (sometimes I got them for a few minutes or so) I can access the taskmanager, but no internet at all, so cant do any online virus scans cannot access my own virus program, tells me not enough memory to run, same goes for firefox, wont open error messages regarding low virtual memory it is the same in safemode as well, I do NOT have the recovery cd, but have recovery console installed, oh sytem reset to a previous date also not possible, the calendar in there comes up blank Constant automatic shut downs due to system failure Please please someone help me, can you tell me what virus that is, please help me save some of my babies pics at least, tell me how!!! I am desperate and at my wits end, I cant keep using the old laptop I am on right now, it crawls along!! Thank you for helping, I appreciate it |
|
|
|
Sep 17 2009, 04:33 PM
Post
#2
|
|
|
New Member ![]() Group: Authentic Member Posts: 11 Joined: 17-September 09 Member No.: 87,967 Operating System: xp |
little update: I was able now to access the internet in safemode, it did not let me run even the mocrosoft malware removal tool, please someone help me, i am really desperate!!!
|
|
|
|
Sep 17 2009, 04:42 PM
Post
#3
|
|
![]() Forum God Group: Root Admin Posts: 45,797 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
![]() This really sounds more like a software / hardware issue but I'll try to help. Do you have access to a computer other then the one you're having trouble with? If so, do you have a thumb drive to transfer files back and forth? |
|
|
|
Sep 17 2009, 04:44 PM
Post
#4
|
|
|
New Member ![]() Group: Authentic Member Posts: 11 Joined: 17-September 09 Member No.: 87,967 Operating System: xp |
yes i have access to another computer, thumbdrive not sure, give me a minute to look, thanks for helping me!!!
|
|
|
|
Sep 17 2009, 04:46 PM
Post
#5
|
|
![]() Forum God Group: Root Admin Posts: 45,797 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
Download the tools needed to a flash drive or other removable media, and transfer them to the infected computer if needed.
Stay with this topic until I give you the all clean post. You might want to print these instructions out. Download ComboFix from one of these locations: Link 1 Link 2 **Note: It is important that it is saved directly to your desktop** -------------------------------------------------------------------- With malware infections being as they are today, it's strongly recommended to have the Windows Recovery Console pre-installed on your machine before doing any malware removal. The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time. Go to Microsoft's website => http://support.microsoft.com/kb/310994 Scroll down to Step 1, and select the download that's appropriate for your Operating System. Download the file & save it as it's originally named. Note: If you have SP3, use the SP2 package. --------------------------------------------------------------------- Transfer all files you just downloaded, to the desktop of the infected computer. -------------------------------------------------------------------- Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools ![]()
Please post the C:\ComboFix.txt in your next reply using Copy/Paste. Notes: Give it atleast 20-30 minutes to finish if needed. 1.Do not mouse-click Combofix's window while it is running. That may cause it to stall. 2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser. 3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper. 4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine. Also please describe how your computer behaves in your next reply. |
|
|
|
Sep 17 2009, 04:51 PM
Post
#6
|
|
|
New Member ![]() Group: Authentic Member Posts: 11 Joined: 17-September 09 Member No.: 87,967 Operating System: xp |
sorry for the delay, i have 2 little kids, found a thumbdrive
|
|
|
|
Sep 17 2009, 04:55 PM
Post
#7
|
|
|
New Member ![]() Group: Authentic Member Posts: 11 Joined: 17-September 09 Member No.: 87,967 Operating System: xp |
i do have the recovery console already installed, do I still need to take this step then, and in which mode do you want me to run the infected computer? I know already that I cannot disable the virus protection, because it wont even let me into that, and it does not come up during startup anymore, disabled that yesterday on the advice of microsoft support (waiting for their level 2 tech to call me in the next 4-6 days- I dont trust them though)
|
|
|
|
Sep 17 2009, 04:58 PM
Post
#8
|
|
![]() Forum God Group: Root Admin Posts: 45,797 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
No on the recovery console then. If you can't disable the anti-virus program, just keep going on.
|
|
|
|
Sep 17 2009, 05:10 PM
Post
#9
|
|
|
New Member ![]() Group: Authentic Member Posts: 11 Joined: 17-September 09 Member No.: 87,967 Operating System: xp |
how do I get the files from the download section of firefox onto the thumbdrive?
|
|
|
|
Sep 17 2009, 05:13 PM
Post
#10
|
|
![]() Forum God Group: Root Admin Posts: 45,797 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
|
|
|
|
Sep 17 2009, 06:03 PM
Post
#11
|
|
|
New Member ![]() Group: Authentic Member Posts: 11 Joined: 17-September 09 Member No.: 87,967 Operating System: xp |
sorry i am having some cable issues here, keeps going out, also I still could not figure out how to safe the file to the thumbdrive, it does not give me the option safe as
|
|
|
|
Sep 17 2009, 06:10 PM
Post
#12
|
|
![]() Forum God Group: Root Admin Posts: 45,797 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
When you click on the download link it should pop-up a window that shows Save Run, select Save. When the download starts you should be able to save it where you want.
|
|
|
|
Sep 17 2009, 06:15 PM
Post
#13
|
|
|
New Member ![]() Group: Authentic Member Posts: 11 Joined: 17-September 09 Member No.: 87,967 Operating System: xp |
so when u say combifix is shutting down all usb devices, does that include my mouse and keyboard too, both usb
|
|
|
|
Sep 17 2009, 06:17 PM
Post
#14
|
|
|
New Member ![]() Group: Authentic Member Posts: 11 Joined: 17-September 09 Member No.: 87,967 Operating System: xp |
i got it on the thumbdrive, trying to start it through task manager, so far no luck, i am in normal mode, do you think safemode is better?
|
|
|
|
Sep 17 2009, 06:22 PM
Post
#15
|
|
|
New Member ![]() Group: Authentic Member Posts: 11 Joined: 17-September 09 Member No.: 87,967 Operating System: xp |
ok so now when I do the new task (run) on the combofix a little window appears with what seems to be a space to type in it, and the words combofix on the top, that is it though, nothing to click on or anything same think happens too when I try to start it directly from the thumbdrive, going to restart the computer now in safe mode, maybe that works then
This post has been edited by frankab: Sep 17 2009, 06:28 PM |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
2 | Havoc | 66 | Yesterday, 03:59 PM Last post by: LDTate |
|||
![]() |
2 | Ticker | 301 | Yesterday, 03:59 PM Last post by: LDTate |
|||
![]() |
2 | valhuse | 88 | Yesterday, 03:59 PM Last post by: LDTate |
|||
![]() |
2 | emmabell22 | 77 | Yesterday, 03:59 PM Last post by: LDTate |
|||
|
Time is now: 21st November 2009 - 03:00 PM |