Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Opened Up A File And Now Viruses...need Help Please!


  • Please log in to reply
13 replies to this topic

#1 Pitcher

Pitcher

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:38 AM

Posted 05 February 2008 - 08:45 PM

Hi,

I opened up a file that i downloaded and now i keep getting popups on my computer. Also, when i first turn on my computer the desk top turns a blue color before bringing up all of my programs, as well as the desk top turning blue all of my shortcuts on the desk top have a blue high light behind them (which never happened before).

I have symantec antivirus software and have run full scans on my computer multiple times.

I have also tried trend micro's housecall....whenever it gets done completing a scan on my computer it comes up with a virus Crck_keygen or something like that and says that it couldnt deleted this virus.

What should i do...i need help please!

BC AdBot (Login to Remove)

 


#2 Tomo2

Tomo2

  • Members
  • 402 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Wanganui, Aotearoa NZ
  • Local time:08:38 PM

Posted 05 February 2008 - 10:14 PM

Be extremely careful in what you download off the internet. Scan everything you get.
Can you remember what virus Housecall Specifies?
It may just be better to read This.

L&P, World Famous in New Zealand since ages ago!
Posted Image
Avast! Antivirus : Spybot S&D : Trend Micro Housecall : Hosts file : HiJack This
Don't be too open minded - your brains will fall out


#3 Pitcher

Pitcher
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:38 AM

Posted 06 February 2008 - 11:14 PM

yeah...thank you...lesson learned

here is what came up with trend micro scanned my computer

TROJ_MATCASH.AM
CRCK_KEYGEN.AL
ADWARE_180 SOLUTIONS
ADWARE_BESTOFFERS
ADWARE_MAXSEARCH
HTTP COOKIES

#4 Tomo2

Tomo2

  • Members
  • 402 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Wanganui, Aotearoa NZ
  • Local time:08:38 PM

Posted 07 February 2008 - 08:43 PM

Spybot Search & Destroy should remove most of those if not all. Please post back whether the malware was or was not removed.

L&P, World Famous in New Zealand since ages ago!
Posted Image
Avast! Antivirus : Spybot S&D : Trend Micro Housecall : Hosts file : HiJack This
Don't be too open minded - your brains will fall out


#5 Pitcher

Pitcher
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:38 AM

Posted 08 February 2008 - 03:07 PM

ok...well i downoaded the spybot and ran it on my computer

it showed that it found 39 problems with the computer. It showed that it deleted all of the problems, however when it deleted them a pop up from spybot came up and asked if i would allow for a certai change in a "registry entr" or something to that extent...was i supposed that allow that change? because i did.

Also, when spybot scanned the computer for viruses it didnt fnd any malware, however, i still have a whole bu of malware popups coming up. what should i do about that?

Thank you so far for helping me out!

#6 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,344 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:04:38 AM

Posted 08 February 2008 - 03:24 PM

When in doubt with Spybot ,check the Remember this box. This allows you to find it later if a correction is needed.

Also do this.
Download Attribune's ATF Cleaner and then SUPERAntiSpyware , Free Home Version. Save both to desktop ..
DO NOT run yet.

Open SUPER from icon and install and Update it
Under Scanner Options make sure the following are checked (leave all others unchecked):
Close browsers before scanning.
Scan for tracking cookies.
Terminate memory threats before quarantining.

Click the "Close" button to leave the control center screen and exit the program.
DO NOT run yet.

Now reboot into Safe Mode:
Safe Mode Using the F8 Method
Restart your computer.
When the machine first starts again it will generally list some equipment that is installed in your machine, amount of memory,
hard drives installed etc. At this point you should gently tap the F8 key repeatedly until you are presented with a Windows XP Advanced Options menu.
Select the option for Safe Mode using the arrow keys. Then press enter on your keyboard to boot into Safe Mode.


Double-click ATF-Cleaner.exe to run the program.
Under Main "Select Files to Delete" choose: Select All.
Click the Empty Selected button.

If you use Firefox or the Opera browser click on that browser at the top and choose: Select All
Click the Empty Selected button.
If you would like to keep your saved passwords, please click No at the prompt.


Click Exit on the Main menu to close the program.

NOW Scan with SUPER
Open from the desktop icon or the program Files list
On the left, make sure you check C:\Fixed Drive.
Perform a Complete scan. After scan,Verify they are all checked.
Click OK on the summary screen to quarantine all found items.
If asked if you want to reboot, click "Yes" and reboot normally.

To retrieve the removal information after reboot, launch SUPERAntispyware again.
Click Preferences, then click the Statistics/Logs tab.
Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
If there are several logs, click the current dated log and press View log.
A text file will open in your default text editor.
Please copy and paste the Scan Log results in your next reply.
Click Close to exit the program.

Please ask any needed questions,post logs and Let us know how your PC in running now.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#7 Pitcher

Pitcher
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:38 AM

Posted 11 February 2008 - 01:38 AM

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 02/10/2008 at 09:46 PM

Application Version : 3.9.1008

Core Rules Database Version : 3399
Trace Rules Database Version: 1391

Scan type : Complete Scan
Total Scan Time : 02:34:44

Memory items scanned : 169
Memory threats detected : 2
Registry items scanned : 6840
Registry threats detected : 24
File items scanned : 75149
File threats detected : 16

Adware.Vundo-Variant/PolyMorph-A
C:\WINDOWS\SYSTEM32\WVUUVVV.DLL
C:\WINDOWS\SYSTEM32\WVUUVVV.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{24C61C09-62C0-42ED-B640-53F7FEC9098A}
HKCR\CLSID\{24C61C09-62C0-42ED-B640-53F7FEC9098A}
HKCR\CLSID\{24C61C09-62C0-42ED-B640-53F7FEC9098A}\InprocServer32
HKCR\CLSID\{24C61C09-62C0-42ED-B640-53F7FEC9098A}\InprocServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{24C61C09-62C0-42ED-B640-53F7FEC9098A}
Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\wvuuvvv

Trojan.WinFixer
C:\WINDOWS\SYSTEM32\SSTQN.DLL
C:\WINDOWS\SYSTEM32\SSTQN.DLL
HKLM\Software\Classes\CLSID\{BB2B8195-7A84-46F4-960E-8C4924E9CCBC}
HKCR\CLSID\{BB2B8195-7A84-46F4-960E-8C4924E9CCBC}
HKCR\CLSID\{BB2B8195-7A84-46F4-960E-8C4924E9CCBC}\InprocServer32
HKCR\CLSID\{BB2B8195-7A84-46F4-960E-8C4924E9CCBC}\InprocServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BB2B8195-7A84-46F4-960E-8C4924E9CCBC}

Adware.StarsDoor
[Drmupgds] C:\PROGRAM FILES\DRMUPGDS\DRMUPGDS.EXE
C:\PROGRAM FILES\DRMUPGDS\DRMUPGDS.EXE

Adware.Vundo-Variant/Small-A
HKLM\Software\Classes\CLSID\{492adeee-bd92-4daa-b7f8-be8960eef3e9}
HKCR\CLSID\{492ADEEE-BD92-4DAA-B7F8-BE8960EEF3E9}
HKCR\CLSID\{492ADEEE-BD92-4DAA-B7F8-BE8960EEF3E9}\InprocServer32
HKCR\CLSID\{492ADEEE-BD92-4DAA-B7F8-BE8960EEF3E9}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\PLHWYMAX.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{492adeee-bd92-4daa-b7f8-be8960eef3e9}
C:\WINDOWS\SYSTEM32\JGHCYEGE.DLL
C:\WINDOWS\SYSTEM32\JJECCPVR.DLL
C:\WINDOWS\SYSTEM32\SQSNPTSI.DLL
C:\WINDOWS\SYSTEM32\VHLAAGFV.DLL
C:\WINDOWS\SYSTEM32\WUBCSIEC.DLL
C:\WINDOWS\SYSTEM32\XOWCMUXD.DLL

Adware.WebBuying Assistant
HKLM\Software\Classes\CLSID\{8e70b77c-70cc-4f10-b309-9b4a02af04c7}
HKCR\CLSID\{8E70B77C-70CC-4F10-B309-9B4A02AF04C7}
HKCR\CLSID\{8E70B77C-70CC-4F10-B309-9B4A02AF04C7}\InprocServer32
HKCR\CLSID\{8E70B77C-70CC-4F10-B309-9B4A02AF04C7}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\LVDWSAR.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8e70b77c-70cc-4f10-b309-9b4a02af04c7}

Adware.Web Buying
HKU\S-1-5-21-1050495291-922091667-4052816558-1006\Software\WebBuying

Adware.VXGame-Trace
HKU\S-1-5-21-1050495291-922091667-4052816558-1006\Software\kernelexe

Adware.k8l
C:\PROGRAM FILES\WINDOWS NT\PROFSYBYWUU.HTML

Trojan.Downloader-Gen/Bundle Installer
C:\WINDOWS\B122.EXE
C:\WINDOWS\B149.EXE

Trojan.Downloader-Gen/MROFIN
C:\WINDOWS\MROFINU1000106.EXE

Adware.Vundo Variant/Rel
C:\WINDOWS\SYSTEM32\MCRH.TMP

Thank you for helping me! my computer is running better now...i am still getting one pop up that keeps coming up. It is called "crush Calculator"

#8 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,344 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:04:38 AM

Posted 12 February 2008 - 03:58 PM

That's great, Let's run one or two of these to get it if not we can stop the service.
ESET Online Scanner

Panda ActiveScan?
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#9 Pitcher

Pitcher
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:38 AM

Posted 17 February 2008 - 04:45 PM

I tried both of these and there is still a few popups tt keep coming up!
I have symantic antivirus protectin on my computer and when it searches fo these viruses it says that they are trojan and also says metajuan or something.
Also, when i startup my computer now every time a little window comes up and says that a certain file on windows cant load and the items on my desktop are highlighted blue. is there someting that i can do about this?

Thank you again

#10 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,344 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:04:38 AM

Posted 17 February 2008 - 11:37 PM

Before we start fixing anything you should print out these instructions or copy them to a NotePad file so they will be accessible. Some steps will require you to disconnect from the Internet or use Safe Mode and you will not have access to this page.

Please download SDFix by AndyManchesta and save it to your desktop.
When using this tool, you must use the Administrator's account or an account with "Administrative rights"
  • Double click SDFix.exe and it will extract the files to %systemdrive%
  • (this is the drive that contains the Windows Directory, typically C:\SDFix).
  • DO NOT use it just yet.
Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Open the SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts, the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
  • Copy and paste the contents of the results file Report.txt in your next replyalong with a new HijackThis log.
-- If this error message is displayed when running SDFix: "The command prompt has been disabled by your administrator. Press any key to continue..."
Please go to Start Menu > Run > and copy/paste the following line:
%systemdrive%\SDFix\apps\swreg IMPORT %systemdrive%\SDFix\apps\Enable_Command_Prompt.reg
Press Ok and then run SDFix again.

-- If the Command Prompt window flashes on then off again on XP or Win 2000, please go to Start Menu > Run > and copy/paste the following line:
%systemdrive%\SDFix\apps\FixPath.exe /Q
Reboot and then run SDFix again.

-- If SDFix still does not run, check the %comspec% variable. Right-click My Computer > click Properties > Advanced > Environment Variables and check that the ComSpec variable points to cmd.exe.
%SystemRoot%\system32\cmd.exe

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#11 Pitcher

Pitcher
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:38 AM

Posted 18 February 2008 - 10:30 PM

SDFix: Version 1.143

Run by DANO on Mon 02/18/2008 at 06:50 PM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting...


Checking Files:

Trojan Files Found:

C:\Temp\1cb\syscheck.log - Deleted
C:\WINDOWS\system32\pac.txt - Deleted



Folder C:\Program Files\drmupgds - Removed
Folder C:\Program Files\Temporary - Removed
Folder C:\Temp\1cb - Removed
Folder C:\Temp\tn3 - Removed


Removing Temp Files...

ADS Check:



Final Check:

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-18 19:18:48
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
"C:\\StubInstaller.exe"="C:\\StubInstaller.exe:*:Enabled:LimeWire swarmed installer"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"F:\\limewire\\LimeWire.exe"="F:\\limewire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"="C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE:*:Enabled:Internet Explorer"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

Remaining Files:


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Tue 17 Jul 2007 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Tue 27 Nov 2007 162 A..H. --- "C:\Documents and Settings\DANO\My Documents\~$obe photoshop.exe"

Finished!

hopefully that does the job....let me know after looking at the log what you think! thanks

#12 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,344 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:04:38 AM

Posted 19 February 2008 - 02:22 PM

You look good ,How is it running?
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#13 Pitcher

Pitcher
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:38 AM

Posted 19 February 2008 - 07:30 PM

It started having a whole bunch more popups last night so i decided to run superantispy ware again today and it found a ton of dected viruses again....so i cleaned those up and restarted my computer....and when i was doing that the computer asked if i waned to start it up in safe mode or in normal mode and when i ask it to start up in normal mode its starts to but then it screen turns blue and it has some kind of information on it but it goes away in a flash i dont even have time to look at what it says..then it restarts the computer again and asks the same thing if i want to start it up in safe mode or normal mode...it just keeps going in a circle whenever i ask it to start upin normal mode. There is another selection that it allows when asking what mode to start up in and it is a normal mode with the last configured version or something to that extent!
I really dont know wt it all means but if you have an idea i would greatly appreciate it!

I am still getting one popup that wont go away... it is called "crush Calculator"

thanks

#14 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,344 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:04:38 AM

Posted 19 February 2008 - 10:48 PM

first ...Stop the cycling Blue screen of Death and write down the complete error mesage...

Please do this

To stop the reboot process go to
}Start
}Right click My Computer
}Properties
}Advanced
}Startup and Recovery and untick automatically restart

The screen will now stop so you can copy it All. Post that info back and someone will be able to better assist.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users