This post has been edited by Blade Zephon: 25 April 2011 - 01:26 AM
Reason for edit: Moved from XP to AII. ~BZ
system plugin scam
#1
Posted 24 April 2011 - 10:11 PM
#2
Posted 25 April 2011 - 05:07 AM
btm, on 24 April 2011 - 10:11 PM, said:
I Had this problem I had to do a complete system reboot and install to get rid of it, Dont realy know why it passed through my anti virus tho . I found out it was the Ransom Trojan Virus It dont let you onto windows to do anything and blocks you from the desktop until you call 00 263778289408 OR 00 2392216542 among other telephone numbers DO NOT CALL THESE!!!!
Instead try to run an anti-virus on the partition by installing another system like linux and then select a partition to scan (select the infected OS) you can always delete linux after the virus has gone, Or re-format and reinstall windows or your main OS system.
Sorry I dont know of any Easy fixes..
#3
Posted 25 April 2011 - 06:38 AM
Please go here....
Preparation Guide ,do steps 6 - 9.
Create a DDS log and post it in the new topic explained in step 9,which is here Virus, Trojan, Spyware, and Malware Removal Logs and not in this topic,thanks.
If Gmer won't run,skip it and move on.
Let me know if that went well.
Boredom Software Stop Highlighting Things
#4
Posted 25 April 2011 - 11:22 PM
This post has been edited by btm: 25 April 2011 - 11:24 PM
#5
Posted 26 April 2011 - 01:14 AM
When you boot the computer and get to the screen that is blocking you, press the Control, Alt and Delete keys. This will hopefully launch the Windows Task Manager. From the Task Manager's File menu, select New Task (Run...):

This will pop open a new box. Type in explorer and click OK:

If the malware hasn't interfered then you should be brought to your desktop. If so, please create the logs and post them. If not, post back here and let me know.
Boredom Software Stop Highlighting Things
#6
Posted 26 April 2011 - 01:51 PM
#7
Posted 26 April 2011 - 02:54 PM
#8
Posted 26 April 2011 - 03:00 PM
Boredom Software Stop Highlighting Things
#9
Posted 26 April 2011 - 03:39 PM
This post has been edited by btm: 26 April 2011 - 03:44 PM
#10
Posted 26 April 2011 - 03:48 PM
Have you tried tapping F8 when starting up and when the Advanced Boot Options menu comes up, selecting Last Known Good Configuration? If not, please try that and let me know if the same thing happens.
#12
Posted 26 April 2011 - 11:17 PM
Download GETxPUD.exe to the desktop of your clean computer
- Run GETxPUD.exe
- A new folder will appear on the desktop.
- Open the GETxPUD folder and click on the get&burn.bat
- The program will download xpud_0.9.2.iso, and upon finished will open BurnCDCC ready to burn the image.
- Click on Start and follow the prompts to burn the image to a CD.
- Next download xpud_userinit_fix to your USB drive
- Remove the USB & CD and insert it in the sick computer
- Boot the Sick computer with the CD you just burned
- The computer must be set to boot from the CD
- Gently tap F12 and choose to boot from the CD
- Follow the prompts
- A Welcome to xPUD screen will appear
- Press File
- Expand mnt
- sda1,2...usually corresponds to your HDD
- sdb1 is likely your USB
- Click on the folder that represents your USB drive (sdb1 ?)
- Confirm that you see xpud_userinit_fix that you downloaded and double click it to run it.
- After it has finished a report will be located on your USB drive named userinitreport.txt
- Remove the USB drive and insert it back in your working computer and navigate to userinitreport.txt
Please note - all text entries are case sensitive
#13
Posted 27 April 2011 - 10:56 PM
#14
Posted 28 April 2011 - 04:04 AM
#15
Posted 06 May 2011 - 05:21 AM
Remote Registry Userinit Report
Hive </mnt/sda1/WINDOWS/system32/config/software>
(...)\Windows NT\CurrentVersion\Winlogon> Value <Userinit> of type REG_SZ, data length 68 [0x44]
C:\WINDOWS\system32\userinit.exe,
(...)\Windows NT\CurrentVersion\Winlogon> EDIT: <Userinit> of type REG_SZ with length 68 [0x44]
[ 0]: C:\WINDOWS\system32\userinit.exe,
-> newkv->len: 68
userinit.exe search results
39b1ffb03c2296323832acbae50d2aff /mnt/sda1/WINDOWS/system32/dllcache/userinit.exe
24.0K Aug 3 2004
39b1ffb03c2296323832acbae50d2aff /mnt/sda1/WINDOWS/system32/userinit.exe
24.0K Aug 3 2004
winlogon.exe search results
01c3346c241652f43aed8e2149881bfe /mnt/sda1/WINDOWS/system32/dllcache/winlogon.exe
490.5K Aug 3 2004
01c3346c241652f43aed8e2149881bfe /mnt/sda1/WINDOWS/system32/winlogon.exe
490.5K Aug 3 2004
explorer.exe search results
a0732187050030ae399b241436565e64 /mnt/sda1/WINDOWS/explorer.exe
1008.0K Aug 3 2004
a0732187050030ae399b241436565e64 /mnt/sda1/WINDOWS/system32/dllcache/explorer.exe
1008.0K Aug 3 2004

Help

Back to top










