This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Your Computer Is In Danger Virus.

55 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Im going to get some second opinions on those files. I dont want to delete anything that may be crucial to your system. Im sure you wouldnt be thankful for it.
Hi

Reboot into SAFE MODEBy pressing the F8 key right when Windows starts, usually right after you hear your computer
beep when you reboot it (some versions of windows will display 'Starting Windows' with a grey progress bar)
you will be brought to a menu where you can choose to boot into safe mode.

If it does not work on the first try, reboot and try again, as you have to be quick when you press it.

I have found that during boot up, right after the computer displays the equipment , memory, etc
installed on your computer, if you start lightly tapping the F8 key, the system will usually display the menu.


Navigate to the two files,
C:\WINDOWS\okgnq1.del
C:\WINDOWS\okgnq1.dll

then right-click on each and select Move to. Move them to another location, such as C: .

Reboot into Normal Mode and try uploading them again.
This is getting REALLY frusterating. I went into safe mood. I tried to search for the files I couldn't even find those .del and .dll i had to copy paste it ( in both windows and safe mod) Now I get a message saying I cannot access the files because of a security privlege. I did the whole hidden files in folder options. Scotty, Im sorry for my poor followthrough of your instructions.
Unfortunately your log shows signs of a rootkit being present on your system.This means your PC is at risk now and sadly may always be.
A rootkit is a collection of tools (programs) that enable administrator-level access to a computer or computer network. Typically, a hacker installs a rootkit on a computer after first obtaining user-level access, either by exploiting a known vulnerability or cracking a password. Once the rootkit is installed, it allows the attacker to mask intrusion and gain root or privileged access to the computer and, possibly, other machines on the network.

Rootkits may also have what is known as a backdoor.The backdoor, if present, will give complete remote access to your system.This means someone will be able to steal any information stored on your PC including addresses, names and telephone numbers and more worryingly passwords, bank account details and any other financial information, basically they will have access to any data that you do.


At this point you have 2 options :-

OPTION 1

We attempt to remove the rootkit but will never really know if it is completely removed which means all the above applies.
There will be no guarantees with this option.

OPTION 2

We reformat your system.
This will destroy the rootkit but means you will have to reinstall everything.

I would like you to read the information over and when you have decided which option to choose post back and I will gladly assist with what ever route you choose to take.
ohh man. Thanks for your assistance on this matter. I'd like some time to think about it, I may choose to reformat since it will destroy everything. Im fine with reinstalling everything, but not entierly sure on the process and only have one comptuer. This rootkid, just downloads virus's and trojans right? If i do a full scan of AntiVirus,SPybot,Adware will that delete anything hes put on so he'd have to do the process over? Im just a 17 year old with a couple games on here, no passwords except to myspace and an email, and no billing accounts.
With rootkits, the only real safe option is to format, to be sure it is gone. I can provide a walk through for that but you will need to have either, the Recovery or Windows CD or a Recovery Partition on your hard drive. There has been a lot of people, more experienced than myself, looking over this thread and are of the opinion, timewise, that it would be most sensible to start over. The problem with rootkits is that they are not well written pieces of programs, if they were we would probably never know they were there, so as long as you have it, your system will be unstable. Think it over and let me know. Also, this would be good practice for me to clean it. Ive never met gromozon before, so if youre willing we can tackle it. I will be doing so under guidance of course.
Is reformating easy? I think ill try to reformat and get a fresh start, just gotta make sure I have the cd's. Also, Do you have any Ideas on how I got it? Ill take caution next turn. I do have Limewire installed. Im kinda nervous too that I might not be able to use the computer again if the reformat doesnt work its actually helped me with problems and issues involving my real life But I know this is a very respectible site and profesonal.
First make sure you have the cd's. Have you access to a printer? I will provide a link to a walkthrough that has images too, to make it easier, although most of it is self-explanatory.
Hi rtw

Once you are ready to begin, Ive been asked to ask you if you would mind running this batchfile? It's purely for research purposes.
Just be sure you have backed up anything you might need to keep.

Open NOTEPAD.exe and copy/paste the text in the quotebox below into it:

@echo off
if [%1]==[2B] goto 2B
catchme -k C:\WINDOWS\okgnq1.del
catchme -k C:\WINDOWS\okgnq1.dll
catchme -k C:\WINDOWS\system32\lpt2.dub
swreg add "hklm\software\microsoft\windows\currentversion\runonce" /v "Die-Grommy" /d ""%comspec%" /c %~s0 2B"
nircmd exitwin reboot
exit
:2B
swxcacls "\\?\C:\WINDOWS\system32\lpt2.dub" /p /ge:f /q
del /a/f/q \\?\C:\WINDOWS\system32\lpt2.dub C:\WINDOWS\okgnq1.d?l 2>nul
echo.|catchme -u
nircmd exec show notepad "~$folder.desktop$\catchme.log"
exit


Save this as fix.bat Choose to "Save type as - All Files"
It should look like this: [external image: Posted Image]
Double click on fix.bat & allow it to run

Post the results in your next reply.
Hi I installed the printer, Im sure I have all the cd's. All i need is some printer paper and to put my files on cd's and then Ill be ready to reformat This may take a day, though, please wait for me. Thanks
Hi I've got paper and all the cd's. But somethings wrong with the printer software, I'll have it done by tonight. Also, In a Spybot , I canceled the scanning progress and for some reason the Stand By Mode is disabled.
Sorry about the long wait, For some reason I cant edit my posts.
Heres the Log, Although I noticed it scans for hidden files and I have the hidden files command on.

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-16 17:41:03
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden files: 0
Hi

Given that the above log is not showing anything, we may not need to format after all. If you still have GMER on your computer, could you run it again as posted here. If not follow the whole instruction again.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI