Results 1 to 14 of 14

Thread: VIRUS HELP NEEDED

Threaded View

  1. #13
    Certified Gearhead
    Join Date
    Nov 2007
    Age
    40
    Posts
    202
    Rep Power
    19

    Default

    I JUST REMOVED THIS LAST WEEK!
    So I hope I can help you.
    Safe Mode does not work. For me, the computer just rebooted every time I tried.
    You cannot run anything. You can't install antivirus. I couldn't open task manager. Hell, I couldn't use 'Run' to open notepad.

    Heres how to beat it.
    Download PSTOOLS from microsoft, or the sysinternals suite.
    I don't remember how I got it to install, but I did. It did put up a fight.
    I think you can just place the files in c:\windows\system32 if you can unzip them.

    Restart your computer, log in.
    As soon as you can, open CMD
    (shortcut: WindowsKey+R, CMD)
    I was able to get into CMD before the program loaded and stopped me.
    Run pslist to list processes.
    use pskill to kill the process by process ID.
    you are looking for a process named by random numbers (##########)
    the process ID itself was only 4 numbers.
    pskill ####

    this killed the process and i was then able to install and run antivirus software.
    i used malwarebytes.
    superantispyware is also good.
    hope this helps.

    The virus itself was in
    c:\documents and settings\%username%\application data\############
    ^ I think, might have been all users account.
    I just deleted it.
    Also, its in MSCONFIG 'startup' so get it there to.
    Last edited by jorgen; 11-27-2009 at 12:06 PM.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
About us
ImportAtlanta is a community of gearheads and car enthusiasts. It does not matter what kind of car or bike you drive, IA is an open community for any gearhead. Whether you're looking for advice on a performance build or posting your wheels for sale, you're welcome here!
Announcement
Welcome back to ImportAtlanta. We are currently undergoing many changes, so please report any issues you encounter with the site using the 'Contact Us' button below. Thank you!