Forum Home
Press F1
 
Thread ID: 115831 2011-02-05 23:00:00 My computer wont let me do anything? eberry09 (16219) Press F1
Post ID Timestamp Content User
1175432 2011-02-05 23:27:00 okay so inorder to get into safe mode/ networking i press f8 when i restart my computer right? sorry im like computer illiterate so im not vvery good at things like this. eberry09 (16219)
1175433 2011-02-05 23:31:00 Follow Speedy's advise ... System restore has probably been infected as well. SP8's (9836)
1175434 2011-02-05 23:32:00 Yup hold F8 down till the menu (for the different options come up) . Then select safe mode / networking .

Once you get into safe mode / networking, get teamviewer ( . teamviewer . com/en/index . aspx" target="_blank">www . teamviewer . com) install / run this .

Post the ID and password (teamviewer gives you) in here . Since you cant PM . I can look at it from here
Speedy Gonzales (78)
1175435 2011-02-05 23:34:00 Easy enough to fix :)

Boot into safemode with networking.

Download and run Rkill (www.bleepingcomputer.com) - then following what sp8s wrote in post #5 All scanners should be run in full scan modes.

Do his numbers in this order : 2 (the second 2 - he wrote #2 twice- Ccleaner is what you want) then 4 run download and runSuperantispyware (http://www.superantispyware.com/) then ,5, 1, 3.

Malwarebytes can miss a lot, Spybot S&D is better.

DO NOT reboot till after you have run all the antimalware programs in safe mode - there is no need to. Any reboot will require you to re run Rkill in safe mode and start again, as it will reinfect.

Once all programs have run, then rerun them again in normal mode.

Kill system restore as well.

Depending on what infection it is, there may need to be a more aggressive removal required - had one the other day, similar - all the above mentioned malware programs couldn't fix it. Got it in the end though. ;)

Edited: Theres a real nasty doing the rounds lately - you think its gone - but it returns a few days later. The malware program pops up saying its an antivirus, BUT theres a rootkit installed with it that hides rather well.
wainuitech (129)
1175436 2011-02-05 23:36:00 okay so inorder to get into safe mode/ networking i press f8 when i restart my computer right? sorry im like computer illiterate so im not vvery good at things like this.
Yes exactly, it will possibly look strange (low screen resolution etc) but will run the OS in very basic mode, hopefully it will cripple your rogue program's ability to run.
feersumendjinn (64)
1175437 2011-02-06 01:50:00 Just struck a variant of the AV2011 that prevents use of Safe Mode by nuking the "HKLM\System\CurrentControlSet\Control\Safeboot" registry keys.

All you get on trying to boot Safe Mode is a BSOD with the STOP error code for an inaccessible boot device.

This requires a backup of the (specific to that machine) SafeBoot keys. A "close enough" version from a similar machine should get it going enough to begin the repair, but failing a backup (check in \windows\repair for backup copy of the SYSTEM hive), a repair install is probably required to restore safe mode properly.

Edit: It also got onto the machine past a fully updated & functioning MSE
fred_fish (15241)
1175438 2011-02-06 02:48:00 i've made it into safemode/networking however i cannot figure out how to get on the internet. it won't let me eberry09 (16219)
1175439 2011-02-06 02:50:00 If youre on broadband open a browser. You should get on the net Speedy Gonzales (78)
1175440 2011-02-06 02:53:00 before i went into safemode i clicked the two little computers at the bottom of the screen and pressed disconnect because i use a modem thats connected directly to my computer for internet but now i cant figure out how to connect back because the two little computers are gone eberry09 (16219)
1175441 2011-02-06 02:58:00 Well dont touch those you open a browser to get on the internet. What version of windows is it?? So youre on dialup?? Dial up again then, if you are Speedy Gonzales (78)
1 2 3 4 5 6