1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive malware problem

Discussion in 'Malware and Virus Removal Archive' started by radiotech, 2010/03/20.

  1. 2010/03/20
    radiotech

    radiotech Inactive Thread Starter

    Joined:
    2010/03/03
    Messages:
    23
    Likes Received:
    0
    [Inactive] malware problem

    I read the instructions to download from mirror site 1 or 2 or I may not get help.I can't download anything because the computer has been taken over.So if I can't get help because I can't download then I guess i can remove my post.
     
  2. 2010/03/20
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You're posting from some good computer, correct?

    Download necessary files on working computer and use USB stick to move files to bad computer.
     

  3. to hide this advert.

  4. 2010/03/20
    radiotech

    radiotech Inactive Thread Starter

    Joined:
    2010/03/03
    Messages:
    23
    Likes Received:
    0
    It won't run on the infected computer.
    The infected computer is afriends and I've tried downloading on my computer onto a disk and thenfrom there to her computerand it won't work.
     
  5. 2010/03/20
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Let's see, if we can look at your computer booting from an external source.

    You will need USB flash drive to move information from bad computer to a working computer.

    You need to download two programs.

    First

    ISO Burner this will allow you to burn REATOGO-X-PE ISO to a cd and make it bootable. Just install the programm, from there on it's fairly automatic (Instructions)

    Second

    • Download OTLPE.iso and burn to a CD using ISO Burner. NOTE: This file is 270.3 MB in size so it may take some time to download.
    • When downloaded double click and this will then open ISOBurner to burn the file to CD
    • Reboot your system (Non working computer) using the boot CD you just created.
      • Note. If you do not know how to set your computer to boot from CD follow the steps HERE
    • Your system should now display a REATOGO-X-PE desktop.
    • Double-click on the OTLPE icon.
    • When asked Do you wish to load the remote registry, select Yes
    • When asked Do you wish to load remote user profile(s) for scanning, select Yes
    • Ensure the box Automatically Load All Remaining Users is checked and press OK
    • OTL should now start. Change the following settings
      • Change Drivers to All
      • Change Registry to All
      • Under Custom Scan box paste this in:

        netsvcs
        %SYSTEMDRIVE%\*.exe
        /md5start
        eventlog.dll
        scecli.dll
        netlogon.dll
        cngaudit.dll
        sceclt.dll
        ntelogon.dll
        logevent.dll
        iaStor.sys
        nvstor.sys
        atapi.sys
        IdeChnDr.sys
        viasraid.sys
        AGP440.sys
        vaxscsi.sys
        nvatabus.sys
        viamraid.sys
        nvata.sys
        nvgts.sys
        iastorv.sys
        ViPrt.sys
        eNetHook.dll
        ahcix86.sys
        KR10N.sys
        nvstor32.sys
        ahcix86s.sys
        nvrd32.sys
        symmpi.sys
        adp3132.sys
        mv61xx.sys
        userinit.exe
        explorer.exe
        /md5stop
        %systemroot%\*. /mp /s
        %systemroot%\system32\*.dll /lockedfiles
        %systemroot%\Tasks\*.job /lockedfiles
        %systemroot%\system32\drivers\*.sys /lockedfiles
        %systemroot%\System32\config\*.sav
    • Press Run Scan to start the scan.
    • When finished, the file will be saved in drive C:\OTL.txt
    • Copy this file to your USB drive.
    • Please post the contents of the C:\OTL.txt file in your reply.
     
  6. 2010/03/21
    radiotech

    radiotech Inactive Thread Starter

    Joined:
    2010/03/03
    Messages:
    23
    Likes Received:
    0
    Computer will not boot from disk.Everything you try to do a window comes up and says it can't run it's infected.
     
  7. 2010/03/21
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Enter BIOS.
    Make sure, CD drive is listed 1st in boot order.
    Save changes by pressing F10 and restart computer with OTLPE CD in.
     
  8. 2010/03/21
    radiotech

    radiotech Inactive Thread Starter

    Joined:
    2010/03/03
    Messages:
    23
    Likes Received:
    0
    I did that
     
  9. 2010/03/21
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    When you restart computer with the CD in, do you see this message, at some point?
     
  10. 2010/03/21
    radiotech

    radiotech Inactive Thread Starter

    Joined:
    2010/03/03
    Messages:
    23
    Likes Received:
    0
    No it doesn't show Press any key to boot from CD
     
  11. 2010/03/21
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Was the CD drive working before the incident?
    Try OTLPE CD, you just created, on another working computer and see, if it's bootable.
     
  12. 2010/03/21
    radiotech

    radiotech Inactive Thread Starter

    Joined:
    2010/03/03
    Messages:
    23
    Likes Received:
    0
    The drive on the infected computer was working.I tried the CD in my computer but it didn't boot
     
  13. 2010/03/21
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    It means, you did something wrong while creating OTLPE CD.
    Please, retry.
     
  14. 2010/03/21
    radiotech

    radiotech Inactive Thread Starter

    Joined:
    2010/03/03
    Messages:
    23
    Likes Received:
    0
    I did the same thing and this time my computer booted off the disc but her's still won't boot and I know her cd rom works
     
  15. 2010/03/21
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Well, apparently, it doesn't since it doesn't want to read bootable CD, which works fine on another computer.
    Without working CD drive, there is not much we can do here.
    All you can try is to remove hard drive, slave it in another computer and try to scan it from there.
     
  16. 2010/03/21
    radiotech

    radiotech Inactive Thread Starter

    Joined:
    2010/03/03
    Messages:
    23
    Likes Received:
    0
    Thanks for your help.She's taking her computer to the shop tomorrow.
     
  17. 2010/03/21
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I wish, I could have been of more help :(
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.