Announcement

Collapse
No announcement yet.

Took the laptop in now its acting funny

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Took the laptop in now its acting funny

    It started last week when I was browsing my normal porn site and a googleupdate.exe popped up and I ended up locking my computer up with multiple harddrive errors. I feared the worst and took it into a shop and they said it was infected with many viruses due to "a massive amount of porn". I laughed hard when my wife told me, she didn't.

    They "cleaned it" and installed a microsoft security ap and I believe updated my IE or I never noticed the 64 bit after it. Now the desktop icons keep moving back the default location, or all the icons disappear or the icons and start menu disappear. Also after doing a search in google and I try to pick a result of the search I'm directed to some prize winning website. Whats the next step to take to fix my problems?

  • #2
    Give this a shot and post back with the results.

    Comment


    • #3
      Downloaded TDSSkiller, tried to run it but nothing happens. Tried running from different locations and just opening instead of downloading but no change.
      Last edited by 4EyedTurd; 12-10-2011, 01:05 PM.

      Comment


      • #4
        RKill is a program that was developed at BleepingComputer.com that attempts to terminate known malware processes so that your normal security software can then run and clean your computer of infections. When RKill runs it will kill malware processes and then removes incorrect executable associations and fixes policies that stop us from using certain tools. When finished it will display a log file that shows the processes that were terminated while the program was running.


        reboot into safemode with networking, dl and run the above then try tdsskiller again.

        Comment


        • #5
          Rebooted in safemode, ran rkill successfully and tried tdsskiller multiple ways with no luck still. Is there another program that does the same job as tdsskiller?

          Comment


          • #6
            Did rkill say it stopped any processes or services?

            Comment


            • #7
              You may have to change the file extension to something the virus won't recognize, then run it.

              Or... you could take it to someone who can fix it. I've got a guy, his name is Bryan


              David

              Comment


              • #8
                1. Review Applications and Services logs under Event Viewer and look at any X error markers. Possibly use sxstrace.exe to get a verbose diagnoses of error, especially if it's a side by side error.
                2. Schedule a Hard Drive Repair through Disk Management and click Error Checking Automatically Repair Files under Disk Management, which will schedule a disk scan/repair during next reboot > Don't reboot yet
                3. Start > msconfig > General tab > Select Diagnostic Selective start up Load system > Services tab > Tick Hide all Microsoft services > Uncheck all remaining services > Reboot
                4. Run Spybot Search and Destroy with latest definitions and Fix all problems detected. You may have to go into Services.msc to manually restart the Service for Spybot
                5. Go back to msconfig > Switch back to Selective start up with Load system start up services and Load start up items boxes checked. > Recheck the non-Microsoft services you uncheck in part 3. Don't check any services you don't recognize or looks suspicious. > Reboot
                6. Make sure Data Execution Prevention is turned on for Windows services and programs only.

                If that doesn't work. Then trying rolling back to a restore point prior to the date when your system started being symptomatic under System Restore. Also, while you're in there. Allow more allocated disk space under the Configure tab to allow more hard drive space to hold more restore points. Then re-load Spybot Search and Destroy with latest definitions and run another scan. When you install any third party programs, add-ons, extensions, etc...Always run installer as Administrator and do a custom installation, not the default recommended install. This way you can always ensure you aren't loading any junkware like additional browser toolbars, etc..by just un ticking the boxes for the junkware.

                Finally, the solution if all else fails. Use the repair disks that you should have made when you first turned on the computer after purchase. Or save all your important files/folders to an external storage device and restore to original out of the box system state off the recovery partition under Recovery Options that pops as it's going through POST.

                When you have a good working system state, always create a restore point and set up a backup through the Action Center. Or use software like Acronis to make an image when you have a clean good working system state.
                Last edited by LS1Goat; 12-11-2011, 02:31 AM.

                Comment


                • #9
                  Originally posted by Tx Redneck View Post
                  Did rkill say it stopped any processes or services?
                  No

                  Comment


                  • #10
                    I found this http://www.bleepingcomputer.com/forums/topic392645.html which is what I'm having, but for some reason IE and Firefox have problems viewing that page and close now not allowing me to see it. Can someone post the software needed to fix my junk?

                    Also, is Norton a good antivirus to buy?

                    Comment


                    • #11
                      Norton Internet Security is my preferred paid AV but if you do have a rootkit, it'll be for naught at this point.

                      See if you can get this installed, if so, pm me the ID and Password.



                      Sent from my iPhail eleventybillion

                      Comment

                      Working...
                      X