AstaKiller, Smitfraud-C.Toolbar888 and Virtumonde

Tea,

First, the OS disc is not actually mine. My father borrrowed it from a friend of his, whom I believe still has it. I'm certain this friend would lend it to me if I asked. I do have an XP OS disc, and my father has mentioned using that to replace the Windows 2000 that's on the problematic computer.

Second, I downloaded Combofix and tried to run it. However, a few seconds after the Combix window opened, I received a message saying "Combofix cannot run in Safe Mode."

Third, I do not have an anti-virus on the computer itself, but it is connected to the internet through a router, which does have an anti-virus.

As for the internet, I can actually connetct to it in safe mode (I'm typing this post on the problematic computer). This requires a special setting called "Safe Mode with Networking", which I was not aware of until this afternoon. I'm sorry that I didn't know of it sooner. I'm not sure how much I can do on the internet with this setting, but I'm willing to try any suggestions you might have.

Finally, I haven't noticed any error messages while the computer has been booting, though I certainly have been looking for them. It seems to work fine until the point I mentioned before.

I'm really sorry for not noticing the "Safe Mode with Networking" option before, and I understand if you're upset. Once again, I don't expect any more help from you--I believe I've already taken too much of your time. If you no longer want to assist me, I won't blame you. However, if you are still willing to help, I'll do my best to follow your instructions.

Sincere thanks,
JDL
 
Hello,

No need to be sorry.;) Let's get an AV on your computer since you're online now.
AVG, Avira OR Avast are good FREE antivirus. Run a scan with the one you chose to install and post back with anything bad it finds. Maybe that will give us another clue. ;)

Thanks,
tea
 
Hi tea,

I downloaded Avira AntiVir PersonalEdition Classic, Version 7 from free-av.com and ran a scan with it. During the scan, "Luke Filewalker" reported the following:

C:\Documents and Settings\...\lo573244448.exe
Is the Trojan horse TR/Crypt.F.Gen

C:\Documents and Settings\...\VSL.dl_
Is the Trojan horse TR/Dldr.Small.ctp.

When I received these reports, I was given the option to delete the entries or quarantine them. Because you didn't instruct me to delete anything, I just quarantined them.

Thanks for your patience,
JDL
 
Hello,

If it wants to delete them, let it. No sign of normal mode yet?

Heh, Luke Filewalker....heh.....I like that. ;)
 
Hello,

I deleted those entries, then ran the AntiVir scan again to make certain they are gone. Luke didn't report them, so I guess they are.

As for normal mode, I tried to boot into it a few times, both before and after deleting the trojans. None of these tries were successful, and proceeded just as I detailed in my previous posts (looks OK until the desktop should appear, then restarts automatically).

Do you have any more suggestions? Should I borrow that Win 2000 OS disc?
 
If you can borrow it, then yes. If it's a system file that's either missing or corrupted that's causing this, then we can possibly repair it, but we need the disc for that. I'm not ready to give up!;) Let me know when you have it.:)

Regards,
tea
 
Hi tea,

I received the Win 2000 disc this afternoon, and started to run it. On the disc's installation menu, there are two options:

1. Upgrade to Windows 2000 (reccomended). This would replace the OS, but leave the current settings and programs.

2. Install a new copy of Windows 2000. This would replace the OS, reset the settings, and erase all of the software.

Which of these do you recommend to me?

Thanks for sticking with me,
JDL
 
Hello,

Actually neither for now!:laugh: Take the disc out for now. I want you to do this first:

Click Start>Run and type in or copy and paste the following in :

sfc /scannow

OK

Follow the prompts and give it the disc when it asks for it. Let me know how that does. :)

Thanks,
tea
 
Not Working

Hi tea,

After I had copied/pasted "sfc /scannow" into the Run text box and clicked OK, the screen just flickered, as though a window had opened and immediately closed. I watched the screen for approx. 10 minutes, but nothing else happened. The H.D.D. light wasn't even on, and none of the normal "thinking" noises came from the PC tower.

Still faithful,
JDL
 
This topic has been closed to prevent others with similar issues posting in it.
If you need it re-opened please send me or your helper a pm and provide a link to the thread.

Applies only to the original topic starter.
 
Back
Top