We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Help removing virus/malware

Options
2»

Comments

  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    I take it you're not in front of the infected computer then now? PM me next time you are before running through these below.

    I'm pretty sure this is loading the culprit:
    StartupFolder: c:\docume~1\dgoodh~1\startm~1\programs\startup\ctfmon.lnk - c:\windows\system32\rundll32.exe
    Boot into safe mode, navigate to the startup folder (c:\documents and settings\dgoodhand\start menu\programs\startup) and delete ctfmon.lnk

    Then boot into normal mode and run combofix.

    Go here and read through the instructions for downloading and running ComboFix:

    Bleeping Computer ComboFix Tutorial
    • Ensure you temporarily turn off your antivirus (Avast) before running. Instructions here
    • Double click combofix.exe & follow the prompts closely.
    • When it's finished, it'll produce a log. Post the contents of that log.
    • It'll be found on your C:\ drive named combofix.txt
  • DaveG247
    DaveG247 Posts: 399 Forumite
    Part of the Furniture 100 Posts Combo Breaker
    Yeah I'm at home now so will do, thank you very much for your help I'll see if I can get it started in safe mode. Cheers Dave
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    Oh yeah - I forgot.

    Just boot into normal mode as you have been doing without connecting to internet and see if you can delete it - Then reboot & run combofix.
  • The easy way....

    Get Revo.
    http://www.revouninstaller.com/

    It kicks a55
    :A:jLibertas Supra Omnia:j:A
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    Not sure how you think that will help...?

    Malware such as this doesn't install in the normal way - There's no uninstaller to run. It's files executed from load points from within the registry.
  • I had the exact same screen when I tried to access a webpage for a local festival.
    I switched it off and on, removing the internet connection (on laptop so just turned off the wireless button).
    Then did a system restore. That worked for me. You can access sytem restore through start - control panel - then search for 'system restore' in the search box cos it's different for each version of windows.
    Good luck.
    Claire
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 350.8K Banking & Borrowing
  • 253.1K Reduce Debt & Boost Income
  • 453.5K Spending & Discounts
  • 243.8K Work, Benefits & Business
  • 598.7K Mortgages, Homes & Bills
  • 176.8K Life & Family
  • 257.1K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.