When I go on the internet on our laptop it starts to connect then it comes up with this http://www.fes.sk/sup/test_.php and it starts flashing and will not let us on the computer. Can anyone help me get rid of this?
This is on Windows XP
Please do not uninstall/install any programs unless asked to
It is more difficult when files/programs are appearing in/disappearing from the logs.
Please do not run any scans other than those requested
Please follow all instructions in the order posted
All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
Do not attach any logs/reports, etc.. unless specifically requested to do so.
If you have problems with or do not understand the instructions, Please ask before continuing.
Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.
Let's see if this will get you online.
If you use Internet Explorer
Click your start button, highlight All Programs
Highlight Accessories
Highlight System Tools
Click Internet Explorer (No Add-ons)
If you use FireFox
Click your start button, highlight All Programs
Highlight Mozilla FireFox
Click Mozilla FireFox (Safe Mode)
This will start which ever browser you are using without any add ons. If you can now browse please return to this thread and we will look for the cause.
If you still can not browse we will transfer some tools to the infected computer and go from there. Do you have a CD or flash drive we can use?
note: insert the flashdrive before running the program. Hold the shift key down while inserting it. Windows will recognise the drive but will not allow it to autorun.
Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
Wait until it has finished scanning and then exit the program.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder…it will help protect your drives from future infection.
Download OTL to your flashdrive.
On the infected computer
Transfer OTL directly to the infected computer's desktop
Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
When the window appears, underneath Output at the top change it to Minimal Output
Check the boxes beside LOP Check and Purity Check.
Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
Save both of these logs to the flashdrive and post them in your next reply.
Go HERE to get a random named copy of GMER. Scroll down to the Download section and click Download EXE. Save it to your flashdrive.
Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
On the infected machine
Transfer the copy of GMER to the desktop.
Double click on the file. If asked to allow gmer.sys driver to load, please consent .
If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
In the right panel, you will see several boxes that have been checked. Uncheck the following …
Sections
IAT/EAT
Drives/Partition other than Systemdrive (typically C:\)
Show All (don't miss this one)
Then click the Scan button & wait for it to finish.
Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop, and post it in your next reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Next,
Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
When the window appears, underneath Output at the top change it to Minimal Output
Uncheck the boxes beside LOP Check and Purity Check.
Open the notepad that you saved to your flashdrive.
Copy and paste the text in the notepad into the window under Custon Scans/Fixes
Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
There will only be an OTL.txt this time.
Please transfer the Gmer log and the OTL log to your flashdrive and post them in your next reply.
You have a newer infection. We will need access to the Recovery Console to clean this.
Do you have an XP disk? Or do you know if you have the Recovery Console installed?
You will be able to tell if the Recovery Console is installed as when you first start your computer you will be presented with a screen that gives you the option to either boot to windows or the Windows Recovery Console. The screen would look like this.
[external image: Posted Image]
Let me know if you either have the XP disk or the Recovery Console installed.
Before we can go after the infection we need to confirm that you can boot to the Recovery Console.
You computer must be able to boot from the CD. You may need o change the settings in bios in order to do this. When you first start your computer you will be told which key to use to enter the bios or setup. Once in the bios look for an entry called boot order or similar. Follow the instruction there to change the boot ordr to CD first. Save the setting then exit.
Insert the Windows XP CD-ROM into the CD-ROM drive, and then restart the computer.
1. Click to select any options that are required to start the computer from the CD-ROM drive if you are prompted.
2. When the "Welcome to Setup" screen appears, press R to start the Recovery Console.
3. You should now see a list of installations and the prompt "Which Windows Installation would you like to log on to?"
Select the appropriate number for the Windows installation that you want to repair. If you only have one, press 1.
4. When you are prompted, type the Administrator password. If the administrator password is blank, just press ENTER.