![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
I'm new to this forum and not a very sophisticated user, but help would be appreciated. I am running Windows XP (Build 2600.xpsp_sp2_gdr.080814-1233: Service Pack2). My computer froze and I had to hold power button to shut down. Shortly before I froze a window popped open to tell me that windows security firewall had been changed to off. I switched it back to on, but then the computer froze up a few minutes later. When I try to boot in normal mode I can log-in, but about 3 seconds after I see my desktop the screen goes black and I need to hold the power button down to turn off. I am only able to boot in safe mode. I have run spybot and adaware in safe mode and they find 'Virtumonde'. Spybot also finds 'MicrosoftWindowsSecurityCenter_disabled'. I correct/fix these problems in the software, but when I reboot nothing has changed and when I run them again (in safe mode) they find the exact same problems.
I tried following the directions on 'Read and Run me First', but don't get far because I can only boot in safe mode... I can't use the program uninstall that is part of the control panel to get rid of the Java updates of which I have a few - this seems to be because I am in safe mode. Also, it sounds like steps 2 and 3 also require to be booted in normal mode. Is it possible to complete 'read and run me first' in safe mode? Any advice on how to proceed from here would be appreciated. thank you. |
| Sponsored links |
|
|
|
#2
|
|||
|
|||
|
I decided to finish running the scans that were suggested in Safe Mode with the exception of Super AntiSpyware which I could not install in safe mode. After completing, I was able to boot in normal mode and so far it is working. I have attached the logs for you to look at and let me know if there are any other fixes I should undertake. Thanks for a great site!
|
|
#3
|
||||
|
||||
|
Welcome to Major Geeks!
Quote:
Also do the below. Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups. Uninstall the below old versions of software: J2SE Runtime Environment 5.0 Update 6 Java(TM) 6 Update 3 Java(TM) 6 Update 5 Java(TM) 6 Update 7 Spybot - Search & Destroy 1.4 Now we need to use ComboFix
Quote:
Do not mouseclick combofix's window while it is running. That may cause it to stall. After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment Now run Ccleaner! Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter Last edited by chaslang; 01-17-09 at 22:11.. |
|
#4
|
|||
|
|||
|
I have completed the steps you outlined and attached the logs. Please note that the only difference is that before I got your response I had already removed Java updates and Spybot 1.4 and installed recommended current version of JAVA, so I did not repeat this step. System seems to be working fine after a few hours on it. Let me know if there is anything else I should follow up on. Thank you!
|
|
#5
|
||||
|
||||
|
You're welcome.
According to your new logs, a couple of things did not get completely fixed. Let's try the below procedure. Now we need to use ComboFix again.
Quote:
Do not mouseclick combofix's window while it is running. That may cause it to stall. Now run Ccleaner! Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| Sponsored links |
|
|
|
#6
|
|||
|
|||
|
See attached logs. System seems to be working normally. Again, thanks for your help.
|
|
#7
|
||||
|
||||
|
You're logs are clean.
If you are not having any other malware problems, it is time to do our final steps:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Can't boot into normal mode, only safe mode. Infected | kathinpdx | Malware Removal | 1 | 12-05-08 00:48 |
| cannot boot XP in safe mode or normal | m3i0x3 | Software | 1 | 04-09-08 22:56 |
| malware can't be found in safe mode and the system shuts off in normal mode | barononeefdip | Malware Removal | 5 | 08-25-07 12:19 |
| can not boot to safe mode or normal mode help!! | mattinsocal8911 | Malware Removal | 11 | 09-18-06 02:10 |
| Can't Boot - Normal or Safe Mode | netzach | Malware Removal | 1 | 10-22-05 15:56 |