![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Virus/Trojan/Spyware Help Get Rid Of Malware With Help From Our Analysts. Follow the "First Steps" link at the top right of each page before posting for help. |
![]() |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Sep 2009
Posts: 44
OS: XP
|
Virus caused my windows to not load.
I understand I need logs but now I can't even log into my windows xp. The virus was the pop ups of "your infected and such" and it was my walllpaper. Now I got avg and got rid of two Trojans and then I had weird problems and couldn't open chrome. Then I turned off the comp and now I tried starting and it just says windows is starting up and doesn't load. What do I do, please help.
|
|
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#5 (permalink) |
|
Registered User
Join Date: Sep 2009
Posts: 44
OS: XP
|
Re: Virus caused my windows to not load.
Hi Ried.
When I open gmer and HiJackThis, (double clicking) nothing happens. It's as if I didn't even open it. Nothing comes up. I tried reinstalling them, but nothing. But when DCC, the black command box pops up and tells me the instructions and to wait 3 minutes. Nothing else happens though. I searched, and people said you have to wait for it to finish because even though nothing happens, the scan is taking place. I left the computer for an hour, and it still had the command open, but no logs. |
|
|
|
|
|
#6 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 26,938
OS: WinXP and Vista
|
Re: Virus caused my windows to not load.
Try this - delete your existing gmer.exe and download it again from here.
Try again to run the scan as outlined in our pre-posting topic:
**Caution** Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries Please attach the ark.txt in your next reply ================================= See if this tool will run for you - download rsit.exe and save it to your desktop.
|
|
|
|
|
|
#7 (permalink) |
|
Registered User
Join Date: Sep 2009
Posts: 44
OS: XP
|
Re: Virus caused my windows to not load.
Ok, I got the first one to work and I attached ark.txt. I dl'ed the second one and it opened, and then kind of just disappeared and I have no idea if it's still running a scan or not. I tried opening it again and it didn't open? Do I have to wait a bit then the logs will appear or what?
John |
|
|
|
|
|
#8 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 26,938
OS: WinXP and Vista
|
Re: Virus caused my windows to not load.
No, hang on. You have a double whammy here.
Please save this file to your desktop. Click Start->Run, and copy-paste the following bolded text into the Run box, and click OK. "%userprofile%\desktop\win32kdiag.exe" -f -r When it's finished, there will be a log called Win32kDiag.txt on your desktop. I'll need to see that in your next reply. ================================== Now try to run rsit.exe again. Post the logs along with the Win32kDiag.txt |
|
|
|
|
|
#9 (permalink) |
|
Registered User
Join Date: Sep 2009
Posts: 44
OS: XP
|
Re: Virus caused my windows to not load.
Weird. I Dl'ed that file, and a black command box came up similar to the one that comes up when I ran DDS. A bunch of stuff starts coming up, but I go to start->run, and I tried putting it in and a command came up saying "Windows cannot find.." I tried highlighting everything, what was in parenthesis and it still didn't work. Sorry for giving you a hard time, but is there anything else I can do?
|
|
|
|
|
|
#10 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 26,938
OS: WinXP and Vista
|
Re: Virus caused my windows to not load.
Did you save the file directly to your desktop? The command is specific to the tool being in that location.
|
|
|
|
|
|
#11 (permalink) |
|
Registered User
Join Date: Sep 2009
Posts: 44
OS: XP
|
Re: Virus caused my windows to not load.
Hold on. Here is the first log you wanted.
Edit: RSIT is still not working. I re-dl'ed it and it opened, then as soon as it says "Starting HJT" the whole thing disappears. I'm thinking it has to do with the same reason HJT wouldn't open at all in the first place for me. Last edited by JDM555; 09-20-2009 at 08:11 PM. |
|
|
|
|
|
#12 (permalink) | ||
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 26,938
OS: WinXP and Vista
|
Re: Virus caused my windows to not load.
Quote:
Open NOTEPAD.exe and copy/paste the text in the quotebox below into it: Quote:
It should look like this: ## IMPORTANT ## Place fix.bat next to Win32kDiag (2).exe Double click on fix.bat & allow it to run Post back to tell me what it says |
||
|
|
|
|
|
#13 (permalink) |
|
Registered User
Join Date: Sep 2009
Posts: 44
OS: XP
|
Re: Virus caused my windows to not load.
Ok, When you said place it next to, I moved the win32kDiag (2).exe on the desktop. I then put the notepoad fix.bat next to it on the desktop, and then when I went to run it, it would open a black command box and then automatically close, and the fix.bat file would disappear of my desktop? Did I do something wrong?
|
|
|
|
|
|
#14 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 26,938
OS: WinXP and Vista
|
Re: Virus caused my windows to not load.
Okay, I need you to slow down a bit and read the instructions. I think you may have missed one of my earlier posts.
![]() The command I gave you, was dependent upon the tool being downloaded directly to your desktop. You downloaded it to a different location, and it appears that your renamed it with the (2). Keep it on your desktop and use this command "%userprofile%\desktop\win32kdiag (2).exe" -f -r |
|
|
|
|
|
#15 (permalink) |
|
Registered User
Join Date: Sep 2009
Posts: 44
OS: XP
|
Re: Virus caused my windows to not load.
I'm sorry Ried, but I don't know what you mean by "use this command" what do I do with the bolded item? And I didn't reinstall it somewhere else, the program was installed in my Downloads folder and I guess I might of dl'ed it twice, where the (2) came from. So you want me to leave the win32kDiag(2) on the desktop?
|
|
|
|
|
|
#16 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 26,938
OS: WinXP and Vista
|
Re: Virus caused my windows to not load.
Yes. Leave the win32kDiag (2) on the desktop. Then click Start>Run and copy paste that command I gave you in my last post, into the Run box and click OK. Let it run, then post the log it produces.
|
|
|
|
|
|
#19 (permalink) |
|
Registered User
Join Date: Sep 2009
Posts: 44
OS: XP
|
Re: Virus caused my windows to not load.
Yeah. I don't know what's up with RSIT, but whenever I get past the pop up and click continue, I see the blue bar, and then when it reaches the end, the whole thing disappears. I have no idea why. What is suppose to happen when you run it? is there a window that pops up after the loading bar and then you wait a bit and two logs pop up? Cause that isn't happening for me.
|
|
|
|
|
|
#20 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 26,938
OS: WinXP and Vista
|
Re: Virus caused my windows to not load.
We'll just press on. I have enough to work with from the gmer scan.
Read through this entire procedure and if you have any questions, please ask them before you begin. Then either print out, or copy this page to Notepad and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions. ==================================================== Download ComboFix from one of these locations, but rename it to jdm555.exe before you save it to your desktop. Link 1 Link 2 * IMPORTANT - Save the renamed ComboFix.exe to your Desktop ==================================================== Disable your AntiVirus and AntiSpyware applications as they will interfere with our tools and the removal. If you are receiving 'access denied' when you try to work with the AV, then continue anyway and click OK when ComboFix AV warnings appear. ==================================================== Double click on the renamed combofix.exe & follow the prompts.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. ![]() Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message: ![]() Click on Yes, to continue scanning for malware. When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review. |
|
|
|
![]() |
| Thread Tools | |
|
|