We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

pc wont boot up - possible virus

1246712

Comments

  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Nibs ~ open hijack in NORMAL mode
    Click top option (system scan and SAVE LOG FILE)

    Once its saved the log file make sure you know its on your desktop

    Reboot and go into SAFE MODE WITH NETWORKING

    POST THE LOG TO US (Looks similar to the one I posted)

    Await our instructions (Which you will need to print off)
    :idea:
  • nibs
    nibs Posts: 577 Forumite
    Part of the Furniture 500 Posts Combo Breaker
    loaner wrote: »
    shutdown -a

    aborts the 60 second shutdown timer, (which is commonly started by infections trying to stop you clearing them up, or problems with lsass process).

    You'll have to uninstall AVG btw, before you attempt the kav install (when you have resolved the other issues)


    when i get the timer up what do you mean shutdown - a
    its rebooting that quick and every minute so i havent got that much time in between.

    have managed to print off a report of hijack scan but it hasn't saved anywhere so i cant show you whats on it. its driving me mad:mad:
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Nibs ~ im 99% sure its saved to your desktop (or wherever your running HIJACK from, but ive never know it save anywhere else). If not run it again and when the log pops up right click and SELECT ALL then COPY then open notepad yourself and PASTE (Make sure you know where its saved to)

    If you genuinely cant find it then scan with SUPERANTISPYWARE (So long as you did update it in safe mode)
    :idea:
  • thomas01155
    thomas01155 Posts: 2,382 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    Soon as you get the timer go to start>run>type shutdown -a and press ok.
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    FIX these with hijack (TICK them and click to FIX them)
    You can do them one at a time or alltogether ~
    O2 - BHO: ALOT Toolbar - !!5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll
    O2 - BHO: (no name) - !!7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O3 - Toolbar: ALOT Toolbar - !!5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll
    O4 - HKLM\..\Run: [System Restore] IEXPOLES.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - Global Startup: MediaChecker.lnk = C:\Program Files\HOTALBUMMyBOX\MediaChecker.exe
    O4 - Global Startup: VTAgentReboot.exe
    :idea:
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Run SUPERANTISPYWARE (If you havnt already)

    Go back into SAFE MODE WITH NETWORKING

    Then remove NORTON using the removal tool
    Norton removal tool
    http://service1.symantec.com/Support/tsgeninfo.nsf/docid/2005033108162039

    reboot and install Kaspersky. Update it (In safe mode if you have to) then run a complete scan
    :idea:
  • nibs
    nibs Posts: 577 Forumite
    Part of the Furniture 500 Posts Combo Breaker
    aliEnRIK wrote: »
    FIX these with hijack (TICK them and click to FIX them)
    You can do them one at a time or alltogether ~
    O2 - BHO: ALOT Toolbar - !!5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll
    O2 - BHO: (no name) - !!7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O3 - Toolbar: ALOT Toolbar - !!5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll
    O4 - HKLM\..\Run: [System Restore] IEXPOLES.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - Global Startup: MediaChecker.lnk = C:\Program Files\HOTALBUMMyBOX\MediaChecker.exe
    O4 - Global Startup: VTAgentReboot.exe


    can i do this in safe mode or normal
  • Browntoa
    Browntoa Posts: 49,612 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    normal mode
    Ex forum ambassador

    Long term forum member
  • thomas01155
    thomas01155 Posts: 2,382 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    Did you by any chance get a message on MSN with a link saying something about a photo?
  • nibs
    nibs Posts: 577 Forumite
    Part of the Furniture 500 Posts Combo Breaker
    Did you by any chance get a message on MSN with a link saying something about a photo?


    yes my ds did but he didnt click on it just clicked the x on the pop up.
    What was that then?
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.2K Banking & Borrowing
  • 253.6K Reduce Debt & Boost Income
  • 454.3K Spending & Discounts
  • 245.3K Work, Benefits & Business
  • 601K Mortgages, Homes & Bills
  • 177.5K Life & Family
  • 259.1K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.