Recommended for You:
Fix up your PC Fast

TuneUp Utilities 2012 takes out the trash: Get back long lost disk space and performance in a snap – Free Download!






You are not connected. Please login or register

Goto page : 1, 2, 3  Next

View previous topic View next topic Go down  Message [Page 1 of 3]

CWINKLER25


Member
Member
I was informed of this site when I asked about this on yahoo answers. The person, JP, recommended I download HijackThis. The problem is I don't seem to have anyway to download anything now. Here is where I stand: First, I am currently back to using my old computer, a more than ten year old HP running windows98 and accessing the the internet through a dial up connection. The new (to me anyway) computer is a Dell and I had just gotten cable internet for it. It became infected within a few hours of being online. Currently it has no desktop, start button or taskbar. The task manager has been disabled, apparently by the anti virus I got from ParetoLogic when it became clear that the things I already had installed (CA security suite and Malwarebytes) weren't getting rid of the infection. When I still had functionality on there the infection would randomly redirect me to unrelated sites whenever I would try to go somewhere to find something that might have actually helped me. All of these things cause me to suspect that this may be the Vundo Trojan. I downloaded a bootable floppy version of Killdisk on the HP to attempt to wipe the drive on the Dell, but when I tried to run it I'm told that there is an "error loading freeDos kernel." This was my original question, which I have asked repeatedly on various sites, but no one has even attempted to answer it. Instead, I get people, who I know are trying to help, telling me to download various things (like malwarebytes, which I had on the computer when it became infected, and ran 6 times, back to back, finding 35 items the first time and 10 or 11 each time thereafter. clearly it wasn't working). So, can anyone out there help me? How can I download anything with no way to even open a browser?

DragonMaster Jay


Site Owner
Site Owner
Hi. I have quite a few questions. Also, some methods that can be tried.

Do you have a CD drive on the Dell?

Are you able to boot to Safe Mode on the Dell? (Reboot to Safe Mode (tap the F8 key just before Windows starts to load and select the Safe Mode option from the menu).)

When doing regular boot (you just let Windows boot to the log on screen)...are you able to actually see a screen when it logs on?

If you can see the normal screen, Have you tried any of the following shortcuts when on that screen:
Ctrl+Alt+Delete (Task Manager 1)
Ctrl+Shift+Esc (Task Manager 2)
Windows key+Break (System Properties)(Windows key is located beside Alt on the left side of the keyboard, break should be on upper right).
Ctrl+Esc (Start menu shortcut)
Windows key (start menu shortcut 2)
Windows key+R (Run box)
Windows key+E (Explorer)

If you able to access any of those shortcuts, please let me know. List any shortcuts that will work.

Whatever you were able to get done in the above process, please let me know.


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

CWINKLER25


Member
Member
Hi DragonMaster Jay. Thank you for responding to my question. Just a quick side note, I had just finished typing in my reply and went to preview it when I discovered that my iffy dial-up connection had deserted me, so I am having to start all over. Aren't computers great! Anyway....now I will answer your questions in the order you asked them.

Yes, I have a CD drive on the Dell, but no CD burning capability on the HP. That is why I had to download the bootable floppy version of Killdisk. I would have preferred the CD and may try to download that at my mother's place the next time I am there.

When I boot is safe mode I just get a black screen: Safe Mode in the corners, Microsoft (R) Windows XP, etc.. across the top. I did just try booting in command prompt safe mode for the first time and that appears to work. I get a little box saying "Windows is starting up..." etc..., then C:\Documents and Setting\Administrator. But like I said, this is the first time I have ever done that and I wouldn't have the first clue what if anything I can do in there.

When I let the Dell boot normally I just get the Windows XP wallpaper: No icons, start button or taskbar, just green hills, blue sky and puffy white clouds. It would be soothing if it wasn't so infuriating. Sorry. I'm trying to use levity to keep this from getting me too frustrated. Moving on...

As I mentioned in my original post my task manager has been disabled, I believe by the virus removal product I got from Paretologic. I believe this because it came up in their box with their logo saying "taskmanager.exe has been stopped", or words to that effect. Even when I still had some functionality on there this was the only site the infection would let me go to and that should have told me something, I guess. Attempts to go to sites offering things like combofix or vundofix resulted in either redirection to random sites or I would simply be told that "Explorer Cannot Display the Webpage." At any rate, neither Ctrl+Alt+Del (which I knew about) nor Ctrl+Shift+Esc (which I wasn't aware of) will start it. Unfortunately none of the other shortcuts you mentioned works either. I did get an hour glass for a few seconds the first time I tried Ctrl+Shift+Esc, which got me a little excited, but then nothing happened. None of the other short cuts even did that much.

So what do you think DragonMaster Jay? Is there any hope or am I just plain screwed here?

DragonMaster Jay


Site Owner
Site Owner
Hi

You said you can get to Safe Mode with Command Prompt, and you see a black box right? With C:\Documents and Settings\Administrator?

In that box, please enter the following (press the Enter button after each line):

ren c:\windows\explorer.exe explorer.old

copy C:\WINDOWS\system32\dllcache\explorer.exe C:\windows\explorer.exe


This will replace the Desktop long enough to go to the next step.

After doing that command, reboot your computer in to Normal Mode. See if the entire desktop appears with options. If so, load an antivirus or other security software and start a quick scan. If you do not have any antivirus or antispyware, let me know.


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

CWINKLER25


Member
Member
Ok Dragonmaster Jay, here is how that went...when I entered
ren c:\windows\explorer.exe explorer.old, and then pressed enter I got
The system cannot find the file specified
When I entered
copy C:\WINDOWS\system32\dll cache\explorer.exe, then pressed enter i got
The system cannot find the file specified
When I entered
C:\windows\explorer.exe, then pressed enter I got
'C:\windows\explorer.exe' is not recognized as an internal or external command, operable program or batch file.

DragonMaster Jay


Site Owner
Site Owner
Please enter this line all at once:

copy C:\WINDOWS\system32\dllcache\explorer.exe C:\windows\explorer.exe


exactly as it says then press enter.


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

CWINKLER25


Member
Member
I see that I made a mistake with the space between dll and cache. Sorry about that, but apparently it didn't matter. This time I entered:
copy C:\WINDOWS\system32\dllcache\explorer.exe C:\windows\explorer.exe

This wrapped around, breaking after the first "r" in the 2nd explorer, but it has to doesn't it?

Anyway, the response was "The system cannot find the file specified."

DragonMaster Jay


Site Owner
Site Owner
It seems the virus has actually stolen the system files you need for this system to function properly. I would recommend to contact whoever you bought it from, or contact Dell. Tell them core system files are missing, and the system does not start properly. Unfortunately, if we cannot at least get the Desktop back and the Task Manager to function - it is either attempt to use a rescue disk or contact support.


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

CWINKLER25


Member
Member
That is bad news. Since this was a reconditioned computer to start with I doubt there is any support for it, either from Dell or the place it came from. I ordered it from a place called Heartland America. They are a clearing house of sorts and sell a wide variety of products at discount prices. But the computer actually came from a place called Computer Expressions in Brooklyn, NY. Apparently they get these computers from businesses or government agencies when they upgrade and refurbish them then resell them. I've got to say, I don't have much confidence in them. This is actually the second computer they sent me. The first one wouldn't work, and after spending more than an hour on the phone with their tech guy, trying various things, he finally just told me to send it back and they sent me this one. It wouldn't work at first either. The first thing I noticed when I opened it was that the hard drive was just hanging there, not placed in the bay like it should have been. It occurred to me to try switching the memory card to the other slot, since this was something the tech guy had had me try with the first one. This got it up and running and it worked fine then, that is until I got it infected with this virus. But anyway, you can see why I wouldn't really have much faith in their ability to help me.

So can't the hard drive be wiped then windows reinstalled? I'd have to get (read "buy") a Windows XP disk since it didn't come with one. This is what I was trying to do in the first place, but couldn't get Killdisk to run. That pesky "error loading freeDos kernel" problem. I've asked about that repeatedly, in various places, and have yet to have anyone even attempt to answer that one. Or are the missing files the reason why Killdisk wouldn't run?

Sorry to go on so. I get a bit wordy at times. But thanks for your time, DragonMaster Jay. I really appreciate your attempt to help me.

DragonMaster Jay


Site Owner
Site Owner
Killdisk would not run because it did not support the computer. That was a different form of repair. If you would like to do a reformat and reinstall, go ahead. It would be better than going through diagnostic steps over and over again not being sure about the results.


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

CWINKLER25


Member
Member
Sorry, I'm a little unclear on this. Are you suggesting reformatting and reinstalling without wiping the hard drive first? Won't the infection still be there? Or should I try something like dban to wipe the disk first? I have dban on this HP, but it is too large to fit on a floppy disk. I'm not even sure if it's in a bootable form. You are probably getting tired of my being so dense about this. I really don't know what I'm doing here, but I'm trying to learn.

DragonMaster Jay


Site Owner
Site Owner
Reformatting means to wipe the hard drive. No worries.

A good tutorial, that I recommend to print for reformatting and reinstalling:
http://www.helpmyos.com/tutorials-software-alternatives-to-proprietary-f19/how-to-reformat-and-reinstall-your-operating-system-the-easy-way-t1307.htm#3143


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

DragonMaster Jay


Site Owner
Site Owner
Also, Dell has an option to do it for you. Reboot the computer at the Dell Splash screen press Ctrl+F11


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

CWINKLER25


Member
Member
Ok, I think I get it now. I've just been doing too much reading on here I think. I've read about people with similar symptoms who tried to reformat and reinstall but the infection came back, or was still there, really. But if that would at least give me some functionality perhaps we could do something about it then. I'll have to get a Windows XP CD first. That will probably take a while. Again, thanks very much for your time, help and good information.

CWINKLER25


Member
Member
I received my Windows CD today. I am going to print the tutorial you mentioned and try to follow it. I'll let you know how that goes. By the way, ctrl+F11 only got me into the command prompt safe mode. Or was I only supposed to try that once I had a Windows CD?

Ad Bot


View previous topic View next topic Back to top  Message [Page 1 of 3]

Goto page : 1, 2, 3  Next

Permissions in this forum:
You cannot reply to topics in this forum