Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

I can't enter safe mode, please help


  • This topic is locked This topic is locked
2 replies to this topic

#1 jalal salehi mobin

jalal salehi mobin

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:12:02 PM

Posted 16 November 2013 - 05:00 AM

hello:

today I got infected with a version of the FBI moneypak virus which displays a white screen whenever I boot my computer. I've tried reading around for solutions and it seems that most people start with entering safemode and running antimalware from there. The problem is I cannot enter safemode or safemode with command prompt or networking so I can't run malwarebytes.  PLEASE any help you can give me would be greatly appreciated. I apply the instruction in forum with subject " FBI Moneypak virus, can't enter safe mode, please help" until I create Both the FRST.txt report and the Search.txt and they are as below, please send me "fixlist.txt" and I will continue from that forum the remaining parts.

This is the FRST log:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-11-2013
Ran by SYSTEM on MININT-0O7KKU2 on 16-11-2013 12:45:41
Running from I:\
Windows 7 Home Premium (X64) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [1436736 2011-06-15] (Microsoft Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [ePass3003_std] - C:\Program Files (x86)\EnterSafe\ePass3003\shuttle_certd3003.exe [105360 2012-11-04] (EnterSafe)
HKU\Jalal\...\Winlogon: [Shell] explorer.exe,C:\Users\Jalal\AppData\Roaming\Other.res [147456 2011-11-16] () <==== ATTENTION
IMEO\hijackthis.exe: [Debugger] ubmzcps_.exe
IMEO\housecalllauncher.exe: [Debugger] efqkaof_.exe
IMEO\rstrui.exe: [Debugger] rzsbkot_.exe
IMEO\spybotsd.exe: [Debugger] etfbvtx_.exe
Startup: C:\Users\Jalal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk ->  (No File)
Startup: C:\Users\Jalal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)

==================== Services (Whitelisted) =================

S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-17] (ArcSoft Inc.)
S2 Flexlm Service 1; C:\SIMULIA\License\lmgrd.exe [1642760 2008-04-10] (Acresso Software Inc.)
S2 hasplms; C:\Windows\system32\hasplms.exe [4913608 2011-12-01] (SafeNet Inc.)
S2 KMService; C:\Windows\SysWow64\srvany.exe [8192 2012-07-26] ()
S2 MsMpSvc; C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [12784 2011-04-27] (Microsoft Corporation)
S3 NisSrv; C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [288272 2011-04-27] (Microsoft Corporation)
S2 PanService; C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe [578264 2011-12-21] (Pandora.TV)
S2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [252416 2010-05-25] (Sony Corporation)
S2 SentinelKeysServer; C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe [374048 2010-10-19] (SafeNet, Inc.)
S2 SentinelProtectionServer; C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe [1250592 2010-10-19] (SafeNet, Inc)
S2 SentinelSecurityRuntime; C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Security Runtime\sntlsrtsrvr.exe [292128 2010-10-19] (SafeNet, Inc.)
S2 Texis Monitor; C:\SIMULIA\Documentation\monitor.exe [4493312 2008-05-05] (Expansion Programs International, Inc.)
S2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.)
S2 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [851824 2010-06-17] (Sony Corporation)

==================== Drivers (Whitelisted) ====================

S3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.)
S3 Epfwndis; C:\Windows\System32\DRIVERS\Epfwndis.sys [34144 2010-12-21] (ESET)
S2 hardlock; C:\Windows\system32\drivers\hardlock.sys [321536 2011-09-28] (SafeNet Inc.)
S1 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [189440 2011-04-18] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [84864 2011-04-27] (Microsoft Corporation)
S2 Sentinel64; C:\Windows\System32\Drivers\Sentinel64.sys [145448 2009-09-16] (SafeNet, Inc.)
S3 SNTUSB64; C:\Windows\System32\DRIVERS\SNTUSB64.SYS [59048 2010-10-19] (SafeNet, Inc.)

==================== NetSvcs (Whitelisted) ===================

NETSVCx32: ???=?????????????????????????????????????????????????????????????????????????????????????????????????????5????????????????????????????????????????????????????????????????????????????¦??????????????????????????????????????????????????????????????????????????????????????????????????????o?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????^? -> No ServiceDLL Path.
NETSVCx32: ?deb/v2?id=drrxDU29Wr343Nadbi-bpO&r= -> No ServiceDLL Path.
NETSVCx32: 0575 -> No ServiceDLL Path.
NETSVCx32: .css -> No ServiceDLL Path.
NETSVCx32: se&gadget=http://fcgadgets.appspot.com/spec/shareit.xml/http://fcgadgets.appspot.com/images/twitter.gif -> No ServiceDLL Path.
NETSVCx32: g/eset-smart-security-4-username-and-password/&dt=1345391098581&bpp=15&shv=r20120808&jsv=r20110914&prev_slotnames=3685201383,3150727695,3685201383&correlator=1345391086314&frm=20&adk=4049409183&ga_vid=1003153654.1345391090&ga_sid=1345391090&ga_hid=322247580&ga_fc=0&u_tz=0&u_his=1&u_java=0&u_h=600&u_w=150&u_ah=600&u_aw=150&u_cd=24&u_nplug=0&u_nmime=0&dff=lucida grande&dfs=13&adx=426&ady=2885&biw=1349&bih=575&oid=3&fu=0&ifi=4&dtd=9426&xpc=0lJdJgInLQ&p=http://www.essandesetnod32keys.org -> No ServiceDLL Path.
NETSVCx32: _COLOR":"#2288bb","CONTENT_SECONDARY_TEXT_COLOR":"#999999","CONTENT_HEADLINE_COLOR":"#000000","FONT_FACE":"normal+normal+12px+Arial,+Tahoma,+Helvetica,+FreeSans,+sans-serif"}}&communityId=09109671215233854365&caller=http://www.essukey.tk/ -> No ServiceDLL Path.
NETSVCx32: ????? -> No ServiceDLL Path.

==================== One Month Created Files and Folders ========

2013-11-16 12:45 - 2013-11-16 12:45 - 00000000 ____D C:\FRST
2013-11-13 12:53 - 2013-11-13 12:53 - 00147456 _____ C:\Users\Jalal\Desktop\older-man-nails-his-little-asian-teen-babysitter-1040.avi.exe
2013-11-13 12:52 - 2013-11-13 12:52 - 00147456 _____ C:\Users\Jalal\Desktop\adobeflashplayerv10.2.152.32.exe
2013-11-13 12:28 - 2013-11-13 12:28 - 02058991 _____ C:\Users\Jalal\Desktop\fg742p.zip
2013-11-13 08:01 - 2013-11-13 08:02 - 02115360 _____ (Dynamic Internet Technology, Inc.) C:\Users\Jalal\Desktop\fg742p.exe
2013-11-13 07:37 - 2013-11-13 12:53 - 00000136 _____ C:\Users\Jalal\Desktop\fg.ini
2013-11-13 07:37 - 2013-11-13 12:45 - 00000397 _____ C:\Users\Jalal\Desktop\fg.ini.bak
2013-11-04 07:32 - 2013-11-04 12:17 - 00000000 ____D C:\Users\Jalal\Desktop\1
2013-10-26 11:12 - 2013-10-26 12:11 - 00466944 _____ C:\Users\Jalal\Documents\Database2.accdb
2013-10-26 11:08 - 2013-10-26 11:12 - 01802240 _____ C:\Users\Jalal\Documents\Issues web database.accdb
2013-10-26 11:07 - 2013-10-26 11:08 - 03932160 _____ C:\Users\Jalal\Documents\Northwind.accdb
2013-10-26 10:26 - 2013-10-26 11:05 - 00573440 _____ C:\Users\Jalal\Documents\Database1.accdb
2013-10-26 10:21 - 2013-10-26 10:26 - 01548288 _____ C:\Users\Jalal\Documents\Tasks1.accdb
2013-10-26 10:19 - 2013-10-26 10:21 - 02052096 _____ C:\Users\Jalal\Documents\try1.accdb
2013-10-26 10:16 - 2013-10-26 10:18 - 01081344 _____ C:\Users\Jalal\Documents\Tasks.accdb

==================== One Month Modified Files and Folders =======

2013-11-16 12:45 - 2013-11-16 12:45 - 00000000 ____D C:\FRST
2013-11-16 01:09 - 2012-11-10 12:28 - 00000896 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-16 01:09 - 2012-07-26 09:54 - 01759480 _____ C:\Windows\WindowsUpdate.log
2013-11-16 00:48 - 2013-05-20 12:16 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-16 00:48 - 2009-07-13 20:45 - 00014144 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-16 00:48 - 2009-07-13 20:45 - 00014144 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-16 00:45 - 2009-07-13 21:13 - 00721392 _____ C:\Windows\System32\PerfStringBackup.INI
2013-11-16 00:41 - 2013-09-21 10:00 - 00000000 ____D C:\Users\Jalal\AppData\Roaming\Dropbox
2013-11-16 00:41 - 2012-11-10 12:28 - 00000892 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-16 00:40 - 2013-09-22 09:32 - 00007162 _____ C:\Windows\setupact.log
2013-11-16 00:40 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-15 10:14 - 2009-07-13 21:08 - 00032634 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-14 07:12 - 2012-07-26 11:04 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-11-14 06:53 - 2013-08-14 12:40 - 00000000 ____D C:\Windows\System32\MRT
2013-11-14 06:53 - 2013-05-19 10:38 - 82896128 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-11-13 13:00 - 2012-07-26 23:41 - 00000000 ___HD C:\ProgramData\ArcSoft
2013-11-13 12:53 - 2013-11-13 12:53 - 00147456 _____ C:\Users\Jalal\Desktop\older-man-nails-his-little-asian-teen-babysitter-1040.avi.exe
2013-11-13 12:53 - 2013-11-13 07:37 - 00000136 _____ C:\Users\Jalal\Desktop\fg.ini
2013-11-13 12:52 - 2013-11-13 12:52 - 00147456 _____ C:\Users\Jalal\Desktop\adobeflashplayerv10.2.152.32.exe
2013-11-13 12:45 - 2013-11-13 07:37 - 00000397 _____ C:\Users\Jalal\Desktop\fg.ini.bak
2013-11-13 12:28 - 2013-11-13 12:28 - 02058991 _____ C:\Users\Jalal\Desktop\fg742p.zip
2013-11-13 11:58 - 2012-07-26 10:43 - 00003934 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{C73C29AE-4CA6-4C08-AF35-A84ED961238C}
2013-11-13 08:24 - 2013-09-07 10:25 - 00000000 ____D C:\Users\Jalal\Desktop\azi
2013-11-13 08:02 - 2013-11-13 08:01 - 02115360 _____ (Dynamic Internet Technology, Inc.) C:\Users\Jalal\Desktop\fg742p.exe
2013-11-13 07:55 - 2013-09-21 10:04 - 00000000 ___RD C:\Users\Jalal\Dropbox
2013-11-13 07:49 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF
2013-11-11 02:02 - 2013-02-16 05:38 - 00012053 _____ C:\Users\Jalal\abaqus_v6.10.gpr
2013-11-11 02:02 - 2012-07-26 10:37 - 00000000 ____D C:\users\Jalal
2013-11-06 12:00 - 2013-06-21 11:01 - 00291962 _____ C:\Windows\ETABS9.7.4chg.tb2
2013-11-06 12:00 - 2010-01-19 07:54 - 00000880 _____ C:\Windows\ETABSv9.ini
2013-11-06 11:59 - 2013-09-20 05:12 - 00000000 _____ C:\Windows\CSI_SentinelLM.log
2013-11-06 11:59 - 2013-05-18 12:23 - 00000483 _____ C:\Windows\SysWOW64\e7rms17.tgz
2013-11-06 11:59 - 2013-05-18 12:23 - 00000469 _____ C:\Windows\SysWOW64\e7rms17.dll
2013-11-06 11:59 - 2013-05-18 12:23 - 00000114 _____ C:\Windows\SysWOW64\prsgrc.tgz
2013-11-06 11:59 - 2013-05-18 12:23 - 00000100 _____ C:\Windows\SysWOW64\prsgrc.dll
2013-11-06 11:59 - 2013-05-18 12:23 - 00000086 _____ C:\Windows\SysWOW64\ssprs.tgz
2013-11-04 12:17 - 2013-11-04 07:32 - 00000000 ____D C:\Users\Jalal\Desktop\1
2013-10-28 13:04 - 2013-10-16 06:28 - 00000000 ____D C:\Users\Jalal\Desktop\FUN
2013-10-26 12:11 - 2013-10-26 11:12 - 00466944 _____ C:\Users\Jalal\Documents\Database2.accdb
2013-10-26 11:12 - 2013-10-26 11:08 - 01802240 _____ C:\Users\Jalal\Documents\Issues web database.accdb
2013-10-26 11:08 - 2013-10-26 11:07 - 03932160 _____ C:\Users\Jalal\Documents\Northwind.accdb
2013-10-26 11:05 - 2013-10-26 10:26 - 00573440 _____ C:\Users\Jalal\Documents\Database1.accdb
2013-10-26 10:26 - 2013-10-26 10:21 - 01548288 _____ C:\Users\Jalal\Documents\Tasks1.accdb
2013-10-26 10:21 - 2013-10-26 10:19 - 02052096 _____ C:\Users\Jalal\Documents\try1.accdb
2013-10-26 10:18 - 2013-10-26 10:16 - 01081344 _____ C:\Users\Jalal\Documents\Tasks.accdb
2013-10-17 23:29 - 2012-08-26 12:18 - 00237595 _____ C:\test.xml

ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-3050557177-4053896829-1652705991-1000\$RDV7HHP

Files to move or delete:
====================
C:\Users\Jalal\AppData\Roaming\iCash_v7_reg.ini


==================== Known DLLs (Whitelisted) ================


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points  =========================

8
Restore point made on: 2013-10-27 09:19:58
Restore point made on: 2013-10-30 09:41:43
Restore point made on: 2013-11-02 10:10:40
Restore point made on: 2013-11-05 10:35:19
Restore point made on: 2013-11-09 07:12:12
Restore point made on: 2013-11-12 11:19:27
Restore point made on: 2013-11-14 06:52:15
Restore point made on: 2013-11-14 07:12:23

==================== Memory info ===========================

Percentage of memory in use: 17%
Total physical RAM: 3950.1 MB
Available physical RAM: 3256.55 MB
Total Pagefile: 3948.25 MB
Available Pagefile: 3248.17 MB
Total Virtual: 8192 MB
Available Virtual: 8191.87 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:100 GB) (Free:38.66 GB) NTFS
Drive d: (home) (Fixed) (Total:50 GB) (Free:17.57 GB) NTFS
Drive e: (work) (Fixed) (Total:302.08 GB) (Free:78.01 GB) NTFS
Drive g: (Recovery) (Fixed) (Total:13.58 GB) (Free:0.76 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive i: () (Removable) (Total:3.73 GB) (Free:3.72 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 14FB39B8)
Partition 1: (Not Active) - (Size=14 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=100 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=352 GB) - (Type=OF Extended)

========================================================
Disk: 1 (Size: 4 GB) (Disk ID: 00000000)
Partition 1: (Not Active) - (Size=4 GB) - (Type=0B)


LastRegBack: 2013-11-11 01:18

==================== End Of Log ============================

Here is the search log:

Farbar Recovery Scan Tool (x64) Version: 14-11-2013
Ran by SYSTEM at 2013-11-16 12:50:14
Running from I:\
Boot Mode: Recovery

================== Search: "services.exe" ===================

C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB

C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB

====== End Of Search ======

 

 

-Thanks alot
 


Edited by hamluis, 16 November 2013 - 08:28 AM.
Moved from Win 7 to Malware Removal Logs - Hamluis


BC AdBot (Login to Remove)

 


#2 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,769 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:32 AM

Posted 21 November 2013 - 05:05 AM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

step1.gif In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.

CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/514197 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

step2.gifIf you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new DDS log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download DDS by sUBs from the following link if you no longer have it available and save it to your destop.

    DDS.com Download Link
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control can be found HERE.

As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#3 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,769 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:32 AM

Posted 26 November 2013 - 05:10 AM

Hello again!

I haven't heard from you in 5 days. Therefore, I am going to assume that you no longer need our help, and close this topic.

If you do still need help, please send a Private Message to any Moderator within the next five days. Be sure to include a link to your topic in your Private Message.

Thank you for using Bleeping Computer, and have a great day!




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users