Infected computer will not boot

Discussion in 'Malware Help (A Specialist Will Reply)' started by george3095, Nov 28, 2009.

  1. george3095

    george3095 Private E-2

    A friend said he was having trouble installing an upgrade for Norton 360 on his laptop. The screen's back-light was on, but nothing was displayed on the screen. The hard drive activity light was on continuously. I turned the computer off and then back on. During boot, an error message popped with something about a problem with a "Isass.exe." On his desktop, I searched for "what is Isass.exe" and one search said it, in some instances, was really a virus. All I can think of now is to boot from a CD that has an operating system and a virus detector and remover. But WHAT? One other thing, before I showed up, he said there was the symbol for poison on his monitor. Now, this is really serious. I'd appreciate learning how an expert would proceed under these conditions.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to provide exact word for word error messages. This could just be a problem with the Windows installation itself especially considering the initial symptoms with a black screen. lsass.exe is required Windows file as long as it is running from the Windows\system32 folder

    This on the otherhand does sound like malware, but if you cannot boot the PC in any boot mode ( safe, last known good, normal) then there is not much we can recommend but the below:

     
  3. george3095

    george3095 Private E-2

    Thanks, chaslang, for all the various applications you suggested. About the Isass.exe: I'm sorry I didn't report the wording of the error message, because, after hearing from my friend about the poison symbol on his screen, I concluded the problem was grave and caused by a virus or something malicious. I know it's a little late, but the OS was XP Home Edition with SP3.

    Thanks again.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but are your trying to do any of the things mentioned? If not, what are you doing?
     
  5. george3095

    george3095 Private E-2

    Chaslang, I've downloaded all the apps you recommended and I've installed the Avira Antivir on a DVD. I've also sent an eMail to my friend, who lives 25 miles away, but he's not yet responded (he's 78). I will call him today to arrange a trip to see what I can do for his laptop. I dread to think his desktop is also kaput, because he's somewhat too trusting of messages he gets; he's already had a problem with a phony message (as if from his ISP) asking for his password to his Inbox.

    I will post what I learn. I'm prepared to do the last resort, re-install, which was your last recommendation. Fortunately, he doesn't keep personal data on his laptop.

    Thanks again.
     
  6. george3095

    george3095 Private E-2

    Chaslang, today, I booted from the DVD containing Avira AntiVir. It found three instances of a Trojan horse, and renamed two of them, one of which was an executable. The second, renamed, file had a .TMP extension. The third file had an .XXX extension, so Avira didn't bother to rename it. When I rebooted from the hard drive, it went into Windows - just as you might expect. My friend is happy as clam he's got his laptop back, especially when I told him I was prepared for the last resort: re-installation.

    Thank you very much for your suggestions.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds