My laptop running Vista has all of a sudden shown a blue screen with various warnings how it is at risk. To remedy this it takes me to a scan from an application called System Tool which, surprise, surprise, finds a host ot infections, trojans and worms! To remedy the situation I am offerd the opportunity to buy the application which, I assume, will rid the blue warning notice now acting as my wallpaper. When I try to run any application I get a message stating the exe.file is infected and the relevant application will not open. This includes my anti virus. Antivir, CC Cleaner and Malwarebytes.
I have tried to restore to a previous restore point but that also will not work and I get the same warning.
Personally, I believe people who do this should be lined up against the wall and left to the devices of those whose computers have been infected.
**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days.
Hello there, NormanR
I'm Conspire, I'll be glad to help you with your computer problems.
Please observe these rules while we work:
Read the entire procedure
It is important to perform ALL actions in sequence.
If you don't know, stop and ask! Don't keep going on.
Please reply to this thread. Do not start a new topic.
Stick with me till you're given the all clear.
Remember, absence of symptoms does not mean the infection is all gone.
Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.
IMPORTANT NOTE : Please do not delete anything unless instructed to.
Please download GMER from one of the following locations, and save it to your desktop:
Main Mirror This version will download a randomly named file (Recommended)
Zip Mirror This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
Extract the contents of the zipped file to desktop (applicable only to Zip mirror) .
Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO. [external image: Posted Image]
[external image: Posted Image] Click the image to enlarge it
In the right panel, you will see several boxes that have been checked. Uncheck the following …
IAT/EAT
Drives/Partition other than Systemdrive (typically C:\)
Show All (don't miss this one)
Then click the Scan button & wait for it to finish.
Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Dear Conspire,
Thank you for your reply. After posting my problem here I thought further of it and did as follows:
Ran Malwarebytes which found a couple of infections and subsequently deleted them. Then I ran Antivir and found a few minor infections that were deleted. I then went back to a restore point prior to the problem arising after which the problem appeared solved.
However, I get the feeling there is still something lurking and in view of this should I follow your previous instructions or should I do anythig different given the above mentioned actions?
Regards,
NormanR
You could still carry on with the instructions above and if I don't see anything lurking inside then we will proceed with a followup scan for final confirmation.
Thanks again for your reply. I will do as requested and report back. Please note this MAY take a few days longer than the allotted three days for response.
Regards,
NormanR
Hi,
Since my last message the blue screen has re-appeard and the same issue has returned, that I am unable to run the OTL.exe file or any other programme. When I change the user account, the blue screen does not appear so should I carry out your instructions in another user account or do so in safe mode on the original user account?
Regards,
NormanR
Try to stay with your account and if all else fail, we will go for safe mode without using the tool below. For now, in the current user account, please do this.
If you have an active internet connection, copy/paste the links below into your browser, don't click them or the rogue might redirect. If you don't have an active internet connection, download the tools from another machine, and transfer them to the affected machine via USB flash drive.
Do not reboot your computer after running rkill as the malware programs will start again.
Please download and run the following tool to help allow other programs to run. (courtesy of BleepingComputer.com)
There are 5 different versions. If one of them won't run then download and try to run the other one.
Vista and Win7 users need to right click and choose Run as Admin
You only need to get one of them to run, not all of them.
You will likely see a message from this rogue telling you the file is infected. Ignore the message. Leave the message OPEN, do not close the message. Run rkill repeatedly until it's able to do it's job. This may take a few tries. You'll be able to tell rkill has done it's job when your desktop (explorer.exe) cycles off and then on again.
At this point, you should now be able to run analysis tools.
If for some reason the machine reboots, repeat the process. Again, try not to restart the machine.
I'm not sure what inks you are referring to in your last message:
Try to stay with your account and if all else fail, we will go for safe mode without using the tool below. For now, in the current user account, please do this.
If you have an active internet connection, copy/paste the links below into your browser, don't click them or the rogue might redirect. If you don't have an active internet connection, download the tools from another machine, and transfer them to the affected machine via USB flash drive.
Please clarify.
Ok let me clarify your situation here. You are having troubles with running OTL but not downloading issues and the troubles you're going through now is BSOD. Is that correct?
I'm unable to make any progress with the current user account so I will now try in safe mode. I assume you will require me to start with the OTL download instruction.
NormanR
It seems I cannot get a connection to the internet in safge mode so will download OTL etc and copy to safe mode desk top. Do you concur with that.
My last message missed your message pasted below.
Yes, I can't run OTL in the current user account but can do so in another user account. I can't really download in the problematic user aaccount. I assume BSOD refers to the Blue Screen problems I am having.
Ok let me clarify your situation here. You are having troubles with running OTL but not downloading issues and the troubles you're going through now is BSOD. Is that correct?
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI