I have a Dell desktop using windows xp. My sister used it and must have done something. It won't run any programs and the security software I bought is no where to be found. I can't run any scans or anything because it won't open any programs. I am posting this using my other computer. It keeps popping up saying there is a virus with a program that I do not recognize, I believe it is one of those fake antivirus programs that actually hacks your computer. I am not sure where to go from here. I had a similar problem before and turned the computer on using safe mode and ran some scans but I can't remember exactly what I did and I don't want to make anything worse. Thank you for any help you can give me.
I'm martix and I'll be glad to assist you fix your problem.
Please follow my instructions and stay with this topic until I give you the ALL CLEAN post.
Use the PC you are posting from to download the following programs:
[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
Extract the contents of the zipped file to desktop.
Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
[external image: Posted Image] Click the image to enlarge it
In the right panel, you will see several boxes that have been checked. Uncheck the following …
IAT/EAT
Drives/Partition other than Systemdrive (typically C:\)
Show All (don't miss this one)
Then click the Scan button & wait for it to finish.
Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
NEXT
Please download DDS by sUBs from one of the following links and save it to your desktop.
Double click DDS icon to run the tool (may take up to 3 minutes to run)
When done, DDS.txt will open.
After a few moments, attach.txt will open in a second window.
Save both reports to your desktop.
—————————————————
Post the contents of the DDS.txt and Attach.txt report in your next reply
As I said before use another computer to download Gmer and DDS and than use an USB flash drive to copy them to the infected PC. If there is a problem to run them in Normal boot try run them in Windows Safe Mode.
Okay so I tried this three times. Every time in safe mode. First time it did the scan for many hours and then froze. I had to force the computer off by holding down the power button. The second time it began to do the scan for about 40 minutes and then the blue screen came up. You know the one that says "A problem has been detected and windows has been shut down to prevent damage to your computer. DRIVER_IRQL_NOT_LESS_OR_EQUAL If this is the first time you've seen this stop error screen, restart your computer [ . . . ] Technical information ***STOP: 0x000000D1 (0x00000000,0x0000001C, 0x00000001, 0x857EC00C)"
So I try a third time and it won't start. I get to the safe mode menu, choose safe mode, then a black screen with white lines of text starts then it stops about mid screen and freezes there. I am afraid to try again, it seems to get worse every time I turn it on.
Hi Vanillacokeit,
Sorry about the delay but we are currently reviewing the possibilities to resolve your problem as it seems a bit complicated.
I'm preparing a suitable tool for you and will give you instructions shortly.
We will attempt to access your computer in a diferent manner. We will need a computer to create a bootable iso disk.
This iso has FireFox on it so you should be able go on line and return to this thread from the infected computer. We should also be able to run some scans on the computer now. Please do not use the infected computer for anything else.
Let's start with making the iso image.
Two programs to download
First
ISOBurner this will allow you to burn REATOGO-X-PE ISO to a cd and make it bootable. Just install the program, from there on in it is fairly automatic. Instructions
Second
Download OTLPENetwork.iso and burn to a CD using a program capable of burning an iso. NOTE: This file is 429Mb in size so it may take some time to download.
note: when saving this program make sure you save it with the save as file type set to all files and the file after it is downloaded is 429mb.
After the file is downloaded, double click it, this will then open ISOBurner to burn the file to CD.
After it has completed burning, put in cd in the effected computer and reboot.
On the ailing computer make sure the cd is set to be the first drive booted from. This can be set in the bios. When the computer is first started you should be given an option to boot to setup. You will be told which key to press to enter setup. As each computer is different you will need to look for a setting called Boot Order or similar. Follow the instructions there to set the cd first in the order. Save the changes, if you made any, and exit setup. The computer should now boot from the cd.
Please be patient as it is running from the cd and can be quiet slow. One of the first screens you will see is a confirmation it is booting from the cd. This will be followed by a screen saying starting Reatogo X PE. It may take awhile to load the necessary files. You should be presented with a light blue screen followed shorty by a Reatogo desktop. It will have what looks like a Swiss Army knife and some icons on it.
Please post back once you have made the iso and are on line or if you are having difficulty creating the iso.
I was able to make the CD and boot the computer with it but I wasn't able to access the internet. I use the internet with a wireless adapter attached to a usb port. The light on the adapter never turned on so does this way of booting disable the usb ports? The computer booted with the CD just fine and I saw a desktop with a bunch of icons, obviously from the CD but when I went to press firefox the computer didn't have an internet connection.
Since you don't have an internet connection via the OTLPE CD, we'll have to use a flash drive also. It's better to be sure it is clean
that's why we'll run Flash Disinfector first. Using the clean PC please:
Download Flash_Disinfector.exe by sUBs and save it to your desktop.
Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
Wait until it has finished scanning and then exit the program.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder…it will help protect your drives from future infection.
NEXT
Using the clean PC please:
Open a new Notepad session:
Click the Start button, click Run.
In the run box type notepad.
click OK.
In the notepad, Click "Format" and be certain that Word Wrap is not checked.
Copy and paste all of the text in the code box below into Notepad, Do not copy the word code.