Recommended Posts

You also not only have to remove them from the registry but also look where they lead to and delete the files- look also in the following folders...

C:\Documents and Settings\All Users\Start Menu\Programs\Startup

C:\Program Files

Then also look in the Documents and settings\your username\start menu\programs\Startup

also try in safemode

msconfig

- startup then uncheck anythings suspicious.

http://www.bleepingcomputer.com/files/sdfix.php

Click this link and download SDFix. It restores all your registry entries to default, which should fix the whole problem of being locked out of doing things. Had a similar problem before and it worked. Afterwards, you can run SUPERAntiSpyware and remove the infection.

You have to run SDFix in Safe Mode, however.

Get Hijack This and post a log. You might have something else hiding away that redownloads and reinstalls malware, so we need to get your machine into a state where you can install and run AV software.

He has already tried that one- but I think he will have the issue with Hijack This not Installing-

Unless someone can find the older version that does not have to install-

I already suggested that-

redvamp128 Posted Today, 21:59 spacer.gif You could also try

Hijack THis

http://www.download.com/Trend-Micro-Hijack...3.html?hhTest=1

So that we know what processes are running

I tryed installing Superantispywarepro but I get an error saying: The system administrator has set policies to prevent this installation.

Where can I edit that?

When I downloaded the latest version it unzipped the and kicked on the windows installer-- maybe he could find an earlier version.

Can you try this- Download that backup Program- From http://www.dougknox.com/xp/utils/xp_emerutils.htm and run it on your dads computer- Worse case is that they will not run on the infected computer- then copy the folder that it creates after the backup= This may sound crazy- but copy the taskmanger1.exe file to another folder then rename it to taskmanager1.(com) without the ( ) then transfer those files to your infected computer- While in safe mode create a shortcut for startup in the all users to the taskmanger1 file. Then boot into your normal Operating system = this should kick the taskmanger to start up before anything else- and when you get that up then stop any task that you don't know. May take a few times - but could give you the leeway to get it to run an onlinevirus scanner - or to install saving software.

If you are able to boot into command prompt, you might be able to use the command line interface to edit autorun entries in the registry. Here is a list of locations that programs can save autorun entries to:

http://www.nthelp.com/40/autorun.htm

You can either go through and REG QUERY each location for malware entries, or REG SAVE and then REG DELETE to backup and then remove all the autorun entries. You might then use the sc query command, write it to a text file, and figure out which services might be associated with the malware, and remove those.

Apparently no exe files will load. The SDFix won't load it just says: Run? (that dialogue box when you click on it) and I click yes and nothing happens.

No EXE files will run? Have you tried going to Start > Run (or Windows Key+R) and typing in "cmd" or "notepad"? Try that and tell us the results.

Well some exe files will but the helpfull ones wont (antivirus stuff wont).

Update: I am on my computer right now in safe mode, so far I have deleted some more crap I found from winspywareprotect. However, whenever I search on google I get redirected to asiuoqgusdbaksd.com and I can't download anything to help get rid of that because of the no anti anything exe files won't download.

Also, my C drive is still hidden in My Computer but I can access it using run. How do I unhide it?

I can also access taskmanager and regedit now. Im in safe mode still but I don't see anything suspicious in taskmanager.

Edited by Violent

I don't know what you mean Relativity.

Roadgeek, I also have some sites that are 'blocked' that say Internet Explorer cannot display the webpage. It's obvious thats part of the virus because its only on sites that could help get rid of it. If you could provide an alternative link to Tweak such as rapidshare I would appreciate it.

TweakUI is a bandage right now. You're infected, the program is obviously still running, because its blocking certain parts of your computer. You need to prevent its processes from starting up automatically, before you start fixing anything.

I posted the link to autorun entries in the registry a few posts ago. Here it is again:

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows, the "run" and Load" keys (if they exist).

So for each of those, run in command prompt, reg export REGKEY C:\OUTPUT.FILE.NAME. Replace REGKEY with one of the lines from the code above, and replace OUTPUT.FILE.NAME with somename.txt. Do this for each line, you might get Not Found errors, if they don't all exist, but ignore them. ZIP those up and post them here, we want to see what is starting up automatically with Windows. The files will be placed

Then, in a command prompt, type in sc query > C:\servicesquery.txt

Zip that output and post it here as well. It will tell us what services are installed.

We are basically doing the same things as some antispyware programs do, but since you can't run those, we'll just have to take each step ourselves.

Edited by Relativity_17

You can try to remove the infection but as Leo Leporta and Steve Gibson would say, you machine has been comprised and can never be trusted again. I'd tend to agree. They would also never enter any banking information in that computer ever again unless a clean install was done.

Roadgeek, I also have some sites that are 'blocked' that say Internet Explorer cannot display the webpage. It's obvious thats part of the virus because its only on sites that could help get rid of it. If you could provide an alternative link to Tweak such as rapidshare I would appreciate it.

Here you go: http://rapidshare.com/files/129339854/Twea...ySetup.exe.html.

Well I can't open a full reply anymore and quote anyone for some dumb reason.

Relativity-Since I can't do anything with Add Reply, only quick reply I had to upload it to rapidshare. http://rapidshare.com/files/129393862/Commandtxts.zip.html

Ned-When I first opened that folder up there wasnt a hosts file. So I made one like you said and it seems to stay the same.

Roadgeek-Thanks

Update: I figured out that if I renamed the file (SpybotSD) that it would load. I installed it but however it won't load now. I got install to work but no program.

Edited by Violent
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Firefox 152.0.2 is out with fixes for performance, translation, and cloud storage services by Taras Buria A new bug-fixing update is now rolling out to Firefox users in the Release Channel. Less than a week ago, Mozilla fixed crashes on Intel Raptor Lake processors with version 152.0.1. Now, Mozilla has prepared yet another set of fixes that address problems with localization, playback issues of certain MP4 files, and performance issues on website that perform various encryption operations at once. Here is the full changelog: Firefox 152.0.2 is now available for download from Mozilla's FTP. Existing installations will get the update over the next several hours. The latest version will also be available soon on the official website, the Microsoft Store, and Neowin's Software page. You can find Firefox 152.0.2 release notes in the official documentation. In case you missed it, Mozilla released Firefox 152 earlier this month. The latest feature update brought reworked settings with a more streamlined user interface, JPEG XL support, new features for Private mode, a new way to mute a tab (just type "mute" in the address bar), and many more. You can find the complete changelog here. In other Firefox news, Mozilla recently published its roadmap, where the company detailed the upcoming Nova redesign and other features it plans to implement. Mozilla wants to make the new user interface easier to navigate and more modern, with a heavy focus on its privacy tools, such as its built-in VPN. If you are curious, you can already enable the new UI as described here.
    • Liene PixCut S1 Starter Kit gets a whopping 31% discount on Prime Day by Steven Parker Liene reached out to us to share another Prime Day exclusive deal that starts today on Amazon. It gives buyers a massive 31% off on the cost of this color sticker printer and cutting machine. It's basically an all-in-one sticker maker for DIY crafts, custom labels and gifts. It utilizes thermal dye-sublimation at 300 dpi, and offers precise "AI" auto-cutting. Here are some more of its highlights: All-in-One Convenience - Print and Cut in One Step. Say goodbye to the hassle of using separate machines. The PixCut S1 seamlessly integrates high-resolution photo printing and precise die cutting into one streamlined device. With just a few clicks on the user-friendly app, you can edit, print, and cut directly from your smartphone via Bluetooth. Create stickers in just 2 minutes! This all-in-one solution saves you time and effort, making your creative projects more enjoyable and efficient. AI Image Extraction & Precision Cutting - Unleash your creativity with the AI image extraction feature that automatically recognizes and extracts subjects from your photos. Then watch as the high-precision cutting system, guided by the same AI technology, perfectly follows every edge with pinpoint accuracy. This seamless AI-to-cut workflow ensures flawless results every time. Turn any moment into custom stickers with professional edges in minutes - just masterpieces made simple. High-Resolution Prints - Vivid and True-to-Life Colors. Utilizing thermal dye-sublimation technology, the PixCut S1 delivers stunning 300 dpi high-resolution prints with 16.7 million colors. Whether you're printing photos, stickers, or labels, you can expect vibrant, true-to-life color effects that make your creations stand out. Every detail is captured with precision, providing professional-quality results every time. AI Lab - Bring Your Imagination to Life. Upload a photo, pick a style from the Liene Photo App, and watch AI bring your vision to life instantly. Turn selfies into an anime character, a fantasy hero, or a festive holiday illustration — all with stunning realism. One style, endless versions of you. Print your AI art as custom stickers, unique gifts, or social media posts — perfect for avatars and DIY projects. No design experience required. Your creativity is just one click away from magic. Durable Stickers - Create Long-Lasting Creations .Thanks to the four-layer thermal dye-sublimation technology, the photopaper is automatically laminated during printing. Stickers produced by PixCut S1 are durable, waterproof and scratch-resistant, ensuring they remain vibrant and intactover time. Perfect for creating custom stickers, labels, and more that last. No Subscription. Just Pure Creativity. With the Liene app, available on mobile, tablet, and desktop. Unlock 40,000+ free images, fonts & elements (and growing), plus 2000+ ready-to-use templates for phone skins, lens stickers, ID cards, labels, name tags, journaling, and more. No paywalls, no hidden fees, just pure creativity. Turn any idea into a custom creation in minutes. Your imagination has no limits, neither should your software. This deal is for the Starter Kit, so what do you get? What's in the box PixCut S1 Photo Sticker Printer and Cutter x 1 Photo Sticker Cutter Ink Cartridge x 1 (36 sheets) Photo Paper 4"x6" (18 sheets) Sticker Paper 4"x7" (White) x 18 sheets Blade x 1 (Pre-installed) So in short everything you need to get printing and cutting. The Liene PixCut S1 has a 4.3 star rating after more than 1,000 reviews from customers, but we can't promise the landing page always sold this particular model, so do check out the reviews before purchasing. In any case Prime members are covered with a 30 day return or replacement should things not work out so great. Liene Pixcut S1 for $205.99 (was $299.99) 31% off Use code 15PIXCUT6 during checkout Although this is a Prime Day discount, the above code will stay live until June 30. Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • https://www.tenforums.com/tuto...b-results-windows-10-a.html Check the comment dates. Some of them are as old as 2016.
    • I wonder how many are laid off for cost savings, and this being blamed on AI to make it sound less scary and bad, for a more positive "modern, with the times" spin for investors? Because Oracle is down 14% the past year. We're looking at a company struggling here. If AI would actually be working out so well for them that they can do massive layoffs, surely this would've been reflected the past year in their stock value?
    • AI is the beginning, wait until real robots replace more jobs, specifically jobs that require physical work.
  • Recent Achievements

    • One Month Later
      timbobit earned a badge
      One Month Later
    • One Month Later
      nates earned a badge
      One Month Later
    • Week One Done
      Almohandis earned a badge
      Week One Done
    • Rookie
      dorf went up a rank
      Rookie
    • First Post
      mike_rumble earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      464
    2. 2
      +Edouard
      177
    3. 3
      PsYcHoKiLLa
      97
    4. 4
      Michael Scrip
      89
    5. 5
      neufuse
      70
  • Tell a friend

    Love Neowin? Tell a friend!