PDA

View Full Version : Malware/Trojan - XP won't start



petezz
2011-12-03, 18:13
Hi

Despite being very careful I mistakenly clicked on a 'bad' link in a very convicing Linkedin email - subsquently found the site as www.idealsign.com.br/trance (lots of comment on Goole re malware, etc)

Laptop now refuses to start in any Mode (Safe, Last Known, Normal). Would be grateful for advice on intial steps to recover. Have acccess to a second laptop and I am ok removing Hard Drive, etc if needed

I would be very grateful for any help

Thanks

Sorry - just realised I shouldn't have posted the link - can the moderators please remove

Thanks

ken545
2011-12-11, 21:15
:snwelcome:


Please read Before You Post (http://forums.spybot.info/showthread.php?t=288)
While best efforts are made to assist in removing infections safely, unexpected stuff can happen. It is advisable that you back up your important data before starting any clean up procedure. Neither Safer Networking Forums nor the Analyst providing the advice may be held responsible for any loss.

Until we deem your system clean I am going to ask you not to install or uninstall any software or hardware except for the programs we may run.

Running programs with Vista or Windows 7 , you need to Right Click on the program and select RUN AS ADMINISTATOR


You did not say what Operating System you have or if you have the windows CD or Recovery CD that came with your computer, please let me know

petezz
2011-12-11, 23:27
Hi

Thanks for the response. Running Windows XP but don't have either the Windows CD or a Recovery CD.

Thanks

ken545
2011-12-11, 23:39
When your computer boots up, do you have the option to boot to a recovery console ?

petezz
2011-12-12, 20:49
Hi

No - I can't see any Recovery Mode.

Only options which appear are:

1 - Normal Boot which 'offers'
Safe Mode,
Safe Mode with Networking,
Safe Mode with Command Prompt,
Last Known Good Configuration and
Start Normally.

All result in a blue screen followed by auto power down after a few seconds.

2 - F2 goes into Setup Utility. Option to Boot from CD/DVD or HDD

3 - F12 Boot Menu - same as F2 above

Thanks

ken545
2011-12-12, 22:22
Well, we're kind of between a rock and a hard place, your computer wont boot, you have no disks or a recovery console.

There are infections going around that do play with your internet access, if your Master Boot Record is infected that can be a problem also, cant tell if that is the problem because we cant see any logs from scans we need to run. Its possible also that your windows installation is corrupt or there may be hardware failure, don't really know.

Lets do this, post here in this windows forum and see if they can get you up and running, if they do then post back here and we can run some scans and see whats going on.

Be sure to tell them your computer wont boot into anything, regular windows or safemode, that you have no disks or a recovery console.

http://forums.whatthetech.com/index.php?showforum=119


Good Luck,
Ken

petezz
2011-12-12, 23:33
Thanks for the advice. Will try your suggestions and try to get some logs

ken545
2011-12-12, 23:55
After your up and running , run these scans and post the logs.


Download aswMBR.exe (http://public.avast.com/~gmerek/aswMBR.exe) ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
http://public.avast.com/~gmerek/aswMBR1.png

On completion of the scan click save log, save it to your desktop and post in your next reply
http://public.avast.com/~gmerek/aswMBR2.png








Download DDS from one of the links below to your desktop

Link 1 (http://download.bleepingcomputer.com/sUBs/dds.scr)
Link 2 (http://download.bleepingcomputer.com/sUBs/dds.com)


Double click the tool to run it.
A black Screen will open, just read the contents and do nothing.
When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
Copy/Paste the contents of 'DDS.txt' into your post.
'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files) (http://windows.microsoft.com/en-us/windows-vista/Compress-and-uncompress-files-zip-files)