Recommended Posts

You also not only have to remove them from the registry but also look where they lead to and delete the files- look also in the following folders...

C:\Documents and Settings\All Users\Start Menu\Programs\Startup

C:\Program Files

Then also look in the Documents and settings\your username\start menu\programs\Startup

also try in safemode

msconfig

- startup then uncheck anythings suspicious.

http://www.bleepingcomputer.com/files/sdfix.php

Click this link and download SDFix. It restores all your registry entries to default, which should fix the whole problem of being locked out of doing things. Had a similar problem before and it worked. Afterwards, you can run SUPERAntiSpyware and remove the infection.

You have to run SDFix in Safe Mode, however.

Get Hijack This and post a log. You might have something else hiding away that redownloads and reinstalls malware, so we need to get your machine into a state where you can install and run AV software.

He has already tried that one- but I think he will have the issue with Hijack This not Installing-

Unless someone can find the older version that does not have to install-

I already suggested that-

redvamp128 Posted Today, 21:59 spacer.gif You could also try

Hijack THis

http://www.download.com/Trend-Micro-Hijack...3.html?hhTest=1

So that we know what processes are running

I tryed installing Superantispywarepro but I get an error saying: The system administrator has set policies to prevent this installation.

Where can I edit that?

When I downloaded the latest version it unzipped the and kicked on the windows installer-- maybe he could find an earlier version.

Can you try this- Download that backup Program- From http://www.dougknox.com/xp/utils/xp_emerutils.htm and run it on your dads computer- Worse case is that they will not run on the infected computer- then copy the folder that it creates after the backup= This may sound crazy- but copy the taskmanger1.exe file to another folder then rename it to taskmanager1.(com) without the ( ) then transfer those files to your infected computer- While in safe mode create a shortcut for startup in the all users to the taskmanger1 file. Then boot into your normal Operating system = this should kick the taskmanger to start up before anything else- and when you get that up then stop any task that you don't know. May take a few times - but could give you the leeway to get it to run an onlinevirus scanner - or to install saving software.

If you are able to boot into command prompt, you might be able to use the command line interface to edit autorun entries in the registry. Here is a list of locations that programs can save autorun entries to:

http://www.nthelp.com/40/autorun.htm

You can either go through and REG QUERY each location for malware entries, or REG SAVE and then REG DELETE to backup and then remove all the autorun entries. You might then use the sc query command, write it to a text file, and figure out which services might be associated with the malware, and remove those.

Apparently no exe files will load. The SDFix won't load it just says: Run? (that dialogue box when you click on it) and I click yes and nothing happens.

No EXE files will run? Have you tried going to Start > Run (or Windows Key+R) and typing in "cmd" or "notepad"? Try that and tell us the results.

Well some exe files will but the helpfull ones wont (antivirus stuff wont).

Update: I am on my computer right now in safe mode, so far I have deleted some more crap I found from winspywareprotect. However, whenever I search on google I get redirected to asiuoqgusdbaksd.com and I can't download anything to help get rid of that because of the no anti anything exe files won't download.

Also, my C drive is still hidden in My Computer but I can access it using run. How do I unhide it?

I can also access taskmanager and regedit now. Im in safe mode still but I don't see anything suspicious in taskmanager.

Edited by Violent

I don't know what you mean Relativity.

Roadgeek, I also have some sites that are 'blocked' that say Internet Explorer cannot display the webpage. It's obvious thats part of the virus because its only on sites that could help get rid of it. If you could provide an alternative link to Tweak such as rapidshare I would appreciate it.

TweakUI is a bandage right now. You're infected, the program is obviously still running, because its blocking certain parts of your computer. You need to prevent its processes from starting up automatically, before you start fixing anything.

I posted the link to autorun entries in the registry a few posts ago. Here it is again:

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows, the "run" and Load" keys (if they exist).

So for each of those, run in command prompt, reg export REGKEY C:\OUTPUT.FILE.NAME. Replace REGKEY with one of the lines from the code above, and replace OUTPUT.FILE.NAME with somename.txt. Do this for each line, you might get Not Found errors, if they don't all exist, but ignore them. ZIP those up and post them here, we want to see what is starting up automatically with Windows. The files will be placed

Then, in a command prompt, type in sc query > C:\servicesquery.txt

Zip that output and post it here as well. It will tell us what services are installed.

We are basically doing the same things as some antispyware programs do, but since you can't run those, we'll just have to take each step ourselves.

Edited by Relativity_17

You can try to remove the infection but as Leo Leporta and Steve Gibson would say, you machine has been comprised and can never be trusted again. I'd tend to agree. They would also never enter any banking information in that computer ever again unless a clean install was done.

Roadgeek, I also have some sites that are 'blocked' that say Internet Explorer cannot display the webpage. It's obvious thats part of the virus because its only on sites that could help get rid of it. If you could provide an alternative link to Tweak such as rapidshare I would appreciate it.

Here you go: http://rapidshare.com/files/129339854/Twea...ySetup.exe.html.

Well I can't open a full reply anymore and quote anyone for some dumb reason.

Relativity-Since I can't do anything with Add Reply, only quick reply I had to upload it to rapidshare. http://rapidshare.com/files/129393862/Commandtxts.zip.html

Ned-When I first opened that folder up there wasnt a hosts file. So I made one like you said and it seems to stay the same.

Roadgeek-Thanks

Update: I figured out that if I renamed the file (SpybotSD) that it would load. I installed it but however it won't load now. I got install to work but no program.

Edited by Violent
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Time to start going to the local church and play Bingo for a while.
    • NVIDIA announces 35 new AI HPC supercomputers across Europe by Fiza Ali NVIDIA has announced that 35 AI high-performance computing (HPC) supercomputers are planned to open throughout Europe this year. This marks what the company describes as the largest single-year expansion of AI infrastructure in the history of the continent. These new systems, unveiled at ISC High Performance 2026, will be placed at a number of national supercomputing centres, AI factories, and research institutes to provide advanced computing resources to more than three million researchers. Describing AI, NVIDIA founder and CEO Jensen Huang stated, "AI is the new instrument of science, and Europe is building the infrastructure to put it in the hands of millions of researchers." Built on NVIDIA's Blackwell and Hopper architectures, the new systems will support research in climate science, healthcare, clean energy, quantum computing, and other scientific fields. Among the major projects are the Barcelona Supercomputing Center's MareNostrum 5 AI upgrade, BavariaAI's Blue Swan platform in Germany, Italy's IT4LIA AI factory, Germany's HammerHAI project, and Sweden's Mimer AI Factory. The Barcelona Supercomputing Center plans to expand MareNostrum 5 with NVIDIA GB300 NVL72 and GB200 NVL4 systems. In total, the BSC expects to deliver up to 20 exaflops of AI training performance and 33 exaflops of AI inference performance. This increased computational capability will support research efforts related to climate modelling, biotechnology, energy systems, etc. Furthermore, as part of the IT4LIA project, more than 8,000 GPUs, each based on NVIDIA’s GB200 NVL4 architecture, will be used in Italy. This represents one of the largest AI factory initiatives announced to date. Additionally, the Blue Swan platform from BavariaAI will include about 1,000 GPUs to help develop multimodal AI models for use in the medical field, robotics, and various areas of scientific research. NVIDIA also emphasized in the announcement how rapidly growth of accelerated computing usage is taking place within both energy and climate-related research. The company said Siemens Energy uses NVIDIA-powered technologies to significantly accelerate the process of designing and simulating hydrogen-capable gas turbines. Using those same acceleration technologies, Siemens was able to reduce simulation time by up to 77 percent. The company also highlighted several quantum computing initiatives across Europe. CINECA, EuroHPC, and Pasqal are integrating a quantum processing unit into Italy's CINECA supercomputing centre using NVIDIA's CUDA-Q platform. Meanwhile, researchers at Germany's Julich Supercomputing Centre recently simulated a universal 50-qubit quantum computer on the JUPITER supercomputer. The announcement demonstrates Europe's continued commitment to building out its infrastructure supporting AI and supercomputing as governments, research organizations, and technology companies compete to build out their respective computing capacities and secure their positions in advanced scientific research.
    • It's about to become harder to turn off your Samsung TV, thanks to Instagram by Aditya Tiwari Meta announced that its Instagram for TV app has arrived on Samsung TVs in the US as part of its latest expansion, giving users one more way to scroll through Reels. The social media giant often comes under scrutiny for the "addictiveness" of its features, which leads people to spend excessive time on the platform. Interestingly, Instagram boss Adam Mosseri described spending 16 hours on the platform as "problematic use" but not "clinical addiction." Mosseri also compared scrolling on Instagram to binge-watching a show on Netflix. Instagram for TV is now available on Samsung TV models released in 2020 or later. The app is already available on Amazon Fire TV and Google TV in the US, which together account for the majority of connected TV devices. The company said it will test several new features to improve the living room and family experience while using Instagram on the big screen. Watching vertical videos on a big screen isn't something many would be excited about. Probably that's why Meta is testing a dedicated home for horizontal videos. Creators will get the opportunity to design content for TV screens and get more ways to reach audiences, according to Meta. If you found an interesting Reel while doomscrolling on your phone, you'll be able to cast it to your TV. The feature is available for testing on Instagram for TV on Google TV and Amazon Fire TV, and it will also support videos from the Saved tab. Instagram for TV will be testing Channels organized around user interests, across genres such as comedy and sports, as well as content from favorite creators. Moreover, you can watch Stories on your TV. While Instagram is known for short-form videos, it's knocking on more doors to keep the audience hooked. The company said it's exploring new content formats for the big screen, including long-form creator content to cover topics in detail, episodic series to build suspense across multiple episodes, and creator live sessions on TV. All of the new updates put Instagram in competition with established giants like YouTube (and Netflix), which already have a robust presence on the big screen. In recent updates, Instagram added the ability to write an individual caption for each carousel image, manually re-order posts, and a paid version of the app.
    • I know RAM and storage prices are high right now, but I think it would have been better to have 1TB as the base level storage, especially as it's supposed to be for gaming. Plus a 2.5gbe ethernet port rather than only 1gbe.
  • Recent Achievements

    • Dedicated
      tuben earned a badge
      Dedicated
    • Week One Done
      mnsgroup earned a badge
      Week One Done
    • Conversation Starter
      sumytbe earned a badge
      Conversation Starter
    • One Year In
      B4dM1k3 earned a badge
      One Year In
    • One Year In
      DarkWun earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      513
    2. 2
      +Edouard
      204
    3. 3
      PsYcHoKiLLa
      98
    4. 4
      Michael Scrip
      82
    5. 5
      neufuse
      67
  • Tell a friend

    Love Neowin? Tell a friend!