Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET Smart Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old January 19th, 2010, 12:17 PM
xiqueno xiqueno is offline
Infrequent Poster
 
Join Date: Jan 2010
Location: San Francisco
Posts: 5
Default Help with apparent infection

Dell Vostro laptop running XP with ESET Smart Security 3. Possible infected through an email. Starting flashing announcements of malware and directing user to follow link (did not follow). Computer then shut down. Now starting it, the Windows welcome screen comes up. Entering the passwork and pressing Enter, the machine logs me off, so I cannot open Windows.

I would appreciate help.

Thanks.
  #2  
Old January 19th, 2010, 02:44 PM
sherryxp2000 sherryxp2000 is offline
Regular Poster
 
Join Date: Nov 2007
Posts: 91
Default Re: Help with apparent infection

Same result with a SAFE MODE booting procedure?

If SAFE mode works, I would run Malwarebytes. More than likely it will fix your problem.
  #3  
Old January 19th, 2010, 03:00 PM
sherryxp2000 sherryxp2000 is offline
Regular Poster
 
Join Date: Nov 2007
Posts: 91
Default Re: Help with apparent infection

And if you can't boot, try this place

http://www.thefreecountry.com/securi...escue-cd.shtml

It allows you to create some bootable ISO CD's, asuming you have access to another PC.
  #4  
Old January 19th, 2010, 03:08 PM
xiqueno xiqueno is offline
Infrequent Poster
 
Join Date: Jan 2010
Location: San Francisco
Posts: 5
Default Re: Help with apparent infection

Sherry,

Thanks. I tried safe mode with same results--just logs off. I'll try the rescue CD you suggested.
  #5  
Old January 21st, 2010, 12:31 PM
sherryxp2000 sherryxp2000 is offline
Regular Poster
 
Join Date: Nov 2007
Posts: 91
Default Did you get it resolved?

Did you get it resolved? I sure hope so.
  #6  
Old January 21st, 2010, 05:14 PM
xiqueno xiqueno is offline
Infrequent Poster
 
Join Date: Jan 2010
Location: San Francisco
Posts: 5
Default Re: Help with apparent infection

I ran the AOSS rescue scan from PC Tools. It found and disabled 4 malware files.

However I still cannot get in to Windows. When I boot from the hard disc, the Windows welcome screen comes up. User accounts are configured with one Guest (no password) and one user (with password).

When I enter the user password, I get the message that it is "logging off" and the computer stays on that screen.

When I try the Guest account, the computer opens to a static "VOSTRO" screen and seems stuck there until I turn off the computer.

I am guessing that even if the malware has been disabled by the rescue disc, it may have made changes in Windows files.

I would appreciate any suggestions on how to proceed.

Thanks.
  #7  
Old January 21st, 2010, 08:01 PM
sherryxp2000 sherryxp2000 is offline
Regular Poster
 
Join Date: Nov 2007
Posts: 91
Default Re: Help with apparent infection

If the login boot is corrupt somehow, you may have to use the RECOVERY CONSOLE (google it, loads of info on it).

Or maybe just reinstall OVERTOP and hope for the best.
  #8  
Old January 21st, 2010, 08:40 PM
xiqueno xiqueno is offline
Infrequent Poster
 
Join Date: Jan 2010
Location: San Francisco
Posts: 5
Default Re: Help with apparent infection

Thanks. I'll try this.
  #9  
Old January 22nd, 2010, 03:30 PM
xiqueno xiqueno is offline
Infrequent Poster
 
Join Date: Jan 2010
Location: San Francisco
Posts: 5
Default Re: Help with apparent infection

Sherry,

Many thanks for your help. I had to find the OEM Windows disc, but the Repair setup reinstalled Windows files, and the computer is now working fine. So I did not need to use Recovery Console, but I am glad to know about it.

Again thanks.
  #10  
Old January 30th, 2010, 08:24 PM
sherryxp2000 sherryxp2000 is offline
Regular Poster
 
Join Date: Nov 2007
Posts: 91
Default Do some INTERROGATING now

I am glad the install over the top method worked!

For the malware or viruses that corrupt the SYSLOGIN or BOOT files, they usually leave some garbage behind.

Remember to install, update, and run MALWAREBYTES while you are still able to boot. For a double check, do SuperAnti Spyware also. And if you want to go futher, Spybot Search & Destroy.

Do a FULL SCAN with your ESET product.

Try a couple of free "ONLINE" scans also, perhaps Kaspersky, Panda, BitDefender to name a few.

Better safe than sorry. So tackle your system pretty well with security safety checks for now while you can.

Once you do all of that, I suggest a FRIENDLY BACKUP reminder. (at least your important photos, documents, data files, projects, installed programs list, etc.)

Do a drive check also, a CHDKSK /R. To make sure your drive is not corrupted any.
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET Smart Security « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 02:36 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums