PCWorld Forums

PCWorld Forums: Av Protection Virus - Cannot Boot Even In Safe Mode - PCWorld Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Av Protection Virus - Cannot Boot Even In Safe Mode

#1 User is offline   SarahDoughnut6 

  • Newbie
  • Pip
  • Group: New Member
  • Posts: 2
  • Joined: 28-November 11

Posted 28 November 2011 - 07:37 AM

Hi, my brother's computer has the AV Protection virus. I've joined several forums to try and get help, they have all stopped responding. I'm been using my computer (what I'm on now) to look up support. The problem was so bad, I couldn't even boot to desktop, even in safe mode. I could get as far as the welcome screen, type in the password, the computer would wait awhile, then say 'User log on failed to execute' or something along those lines. Because I can't get on the desktop, I can't run any malware removal program.s Before, when I COULD get to the desktop, I would try to and the programs would stop running, or the computer would restart continuously. I followed the steps from one forum to boot from CD to reatogo desktop. I used OTL to make custom scans, using my USB drive to copy the instructions the forum gave me for the scan from my computer to his. Their last instructions had me do a scan and then if it worked I was supposed to use combo fix, but I don't think the scan worked. Can someone help me? I have attached the latest OTL

Attached File(s)


0

#2 User is offline   Rommel 

  • Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 2,183
  • Joined: 22-March 09

Posted 28 November 2011 - 08:28 AM

View PostSarahDoughnut6, on 28 November 2011 - 07:37 AM, said:

Hi, my brother's computer has the AV Protection virus. I've joined several forums to try and get help, they have all stopped responding. I'm been using my computer (what I'm on now) to look up support. The problem was so bad, I couldn't even boot to desktop, even in safe mode. I could get as far as the welcome screen, type in the password, the computer would wait awhile, then say 'User log on failed to execute' or something along those lines. Because I can't get on the desktop, I can't run any malware removal program.s Before, when I COULD get to the desktop, I would try to and the programs would stop running, or the computer would restart continuously. I followed the steps from one forum to boot from CD to reatogo desktop. I used OTL to make custom scans, using my USB drive to copy the instructions the forum gave me for the scan from my computer to his. Their last instructions had me do a scan and then if it worked I was supposed to use combo fix, but I don't think the scan worked. Can someone help me? I have attached the latest OTL


Someone will come along and give you complete instructions on how to get and use a linux operating system disc. ( free )
When downloaded and and burned to a disc, you'll need to boot from it, not your current infected HDD.

This link, http://www.google.co...q=0&aqi=g10=

has some linux OSs you could look at if your unfamiliar.
Sorry for not much help but you've come to the right place.
A detailed reply will come.
0

#3 User is offline   Dellinsp531 

  • Advanced Member
  • PipPipPipPip
  • Group: Members
  • Posts: 409
  • Joined: 21-June 11

Posted 28 November 2011 - 09:20 AM

There are three things to use. (Chose one that you feel would be easier for you)

1)You can get http://www.ultimatebootcd.com/ and used that to remove the viruses.

2) Another Option would be to use http://live.sunbeltsoftware.com/

3) Get a linux boot CD, http://www.f-secure....moval/rescue-cd


If you got questions, post them.
Windows 8 is a useless OS that Microsoft released that has many flaws and bugs. DO NOT USE IT. Use Windows XP or Windows 7.
Downgrading from Windows 8 to 7: What you need to know

Other laptops that I had in the past:


(Why were my sign removed? Please let me know.)
0

#4 User is offline   SpiritWind 

  • Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 2,425
  • Joined: 19-August 06

Posted 28 November 2011 - 11:04 AM

Hi "Sarah" :

I think your brother got what the malware fighting
"community" calls "AV Protection 2011" !? There is
an excellent "Uninstall Guide" by the highly regarded
BleepingComputer website specifically located at
www.bleepingcomputer.com/virus-removal/remove-av-protection-2011
but at this point it seems you will be unable to use it .
It might be helpful IF I knew which specific forums you
sought help and what Username you used to see specifically
what you were told !? I can tell part of the "process"
was posting a "log" from the "OTL" program, but there is
no one on these PC World forums skilled at using the
OTL program .
For the very Best in Life :

http://www.ctftoronto.com
0

#5 User is offline   coastie65 

  • Moderator
  • PipPipPipPipPipPipPipPip
  • Group: Moderators
  • Posts: 19,708
  • Joined: 02-April 07
  • Location:Henrico, Va.

Posted 28 November 2011 - 11:36 AM

Hi Sarah and welcome to the forums. I am going to try and go live with that link that Spiritwind provided: www.bleepingcomputer.com/virus-removal/remove-av-protection-2011 . I was looking at the log you provided. Your brother is apparantly running both McAfee AND Norton actively. Not good as both are system hogs and use a lot of resorces. I would remove both ( using Programs & Features and then follow up with the respective removal tools to complete the process ) and then install MSE ( Microsoft Security Essentials ). Avast! us a good free program and you could use the paid version of SUPERantispyware : www.Avast!.com & www.SUPERantispyware.com .
Coolermaster HAF 912 Case....ASUS P8Z68-VPro MOBO.....Intel Core i7 2600k Sandy Bridge ( 4.4 Ghz ).... Gelid Tranquillo cooler.... Samsung 830 256 GB SSD.... Primary HDD- WD 1TB Caviar Black SATA III /6.0 .... SECONDARY HDD - WD 1TB Caviar Black SATA II / 3.0....8Gb GSkill Ripjaws Series X 1600 Mhz Memory....Corsair AX850w PSU....EVGA GTX 680 Super Clocked Signature 2 Gb GDDR5 Video Card....Samsung CD/DVD RW, DL, DVD-Ram, w/ Lightscribe Optical Drive....Samsung SyncMaster 2243BWX 22" Monitor..... Windows 7 Home Premium 64 Bit OS


http://novabench.com/image/266589.png

______________________________________________________________

Gateway FX6800-01e----Intel Core i7 960 ( 3.2 GHz)---- Seagate Barracuda 750 Gb SATA II / 3.0 Hdd---- 6 Gb Crucial 1066 Mhz memory, running in Tri Channel conf-----Corsair TX650w PSU----- EVGA Nvidia GTX 560Ti 1gb GDDR5 Vram ----DVD +/- RW / CD ,RAM/DL Optical drive w/ Label Flash-----Gateway TBGM-01 Motherboard.... Vista Home Premium 64 bit OS w/ SP2; Samsung Synch Master 2243BWX 22" Monitor.
0

#6 User is offline   SarahDoughnut6 

  • Newbie
  • Pip
  • Group: New Member
  • Posts: 2
  • Joined: 28-November 11

Posted 28 November 2011 - 06:31 PM

http://www.bleepingc...38#entry2490138

This is the forum that was giving me instructions. The computer is now running the latest scan the guy asked me to do, so that's currently where I'm at.
0

#7 User is offline   Dellinsp531 

  • Advanced Member
  • PipPipPipPip
  • Group: Members
  • Posts: 409
  • Joined: 21-June 11

Posted 29 November 2011 - 08:35 AM

The best option would be to run f-secure.This will load into RAM and be able to find the virus on the hard drive.

If it does not, than use ultimatebootcd. This way you can get to your hard drive and clean it out.
Windows 8 is a useless OS that Microsoft released that has many flaws and bugs. DO NOT USE IT. Use Windows XP or Windows 7.
Downgrading from Windows 8 to 7: What you need to know

Other laptops that I had in the past:


(Why were my sign removed? Please let me know.)
0

#8 User is offline   SpiritWind 

  • Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 2,425
  • Joined: 19-August 06

Posted 29 November 2011 - 09:59 AM

Hi "Sarah" :

I have read through your thread on the BleepingComputer
website .It certainly appears you have a highly skilled
Volunteer trying to help . I would not go anywhere else.
Best I can tell, it appears your brother is NOT following
the following Instructions from the Expert :
"# Return to OTLPE, right click in the "Custom Scans/Fixes" window and choose Paste.
# Click the red Run Fix button."

You MAY have to go where your brother is and use the
"Run Fix" button that the Expert is asking to be done !?

This post has been edited by SpiritWind: 29 November 2011 - 10:06 AM

For the very Best in Life :

http://www.ctftoronto.com
0

#9 User is offline   coastie65 

  • Moderator
  • PipPipPipPipPipPipPipPip
  • Group: Moderators
  • Posts: 19,708
  • Joined: 02-April 07
  • Location:Henrico, Va.

Posted 29 November 2011 - 03:29 PM

Moved this to the appropriate discussion group.

This post has been edited by coastie65: 29 November 2011 - 03:29 PM

Coolermaster HAF 912 Case....ASUS P8Z68-VPro MOBO.....Intel Core i7 2600k Sandy Bridge ( 4.4 Ghz ).... Gelid Tranquillo cooler.... Samsung 830 256 GB SSD.... Primary HDD- WD 1TB Caviar Black SATA III /6.0 .... SECONDARY HDD - WD 1TB Caviar Black SATA II / 3.0....8Gb GSkill Ripjaws Series X 1600 Mhz Memory....Corsair AX850w PSU....EVGA GTX 680 Super Clocked Signature 2 Gb GDDR5 Video Card....Samsung CD/DVD RW, DL, DVD-Ram, w/ Lightscribe Optical Drive....Samsung SyncMaster 2243BWX 22" Monitor..... Windows 7 Home Premium 64 Bit OS


http://novabench.com/image/266589.png

______________________________________________________________

Gateway FX6800-01e----Intel Core i7 960 ( 3.2 GHz)---- Seagate Barracuda 750 Gb SATA II / 3.0 Hdd---- 6 Gb Crucial 1066 Mhz memory, running in Tri Channel conf-----Corsair TX650w PSU----- EVGA Nvidia GTX 560Ti 1gb GDDR5 Vram ----DVD +/- RW / CD ,RAM/DL Optical drive w/ Label Flash-----Gateway TBGM-01 Motherboard.... Vista Home Premium 64 bit OS w/ SP2; Samsung Synch Master 2243BWX 22" Monitor.
0

#10 User is offline   Victorkid 

  • Newbie
  • Pip
  • Group: New Member
  • Posts: 5
  • Joined: 09-November 11

Posted 08 December 2011 - 01:32 AM

View Postcoastie65, on 28 November 2011 - 11:36 AM, said:

Hi Sarah and welcome to the forums. I am going to try and go live with that link that Spiritwind provided: www.bleepingcomputer.com/virus-removal/remove-av-protection-2011 . I was looking at the log you provided. Your brother is apparantly running both McAfee AND Norton actively. Not good as both are system hogs and use a lot of resorces. I would remove both ( using Programs & Features and then follow up with the respective removal tools to complete the process ) and then install MSE ( Microsoft Security Essentials ). Avast! us a good free program and you could use the paid version of SUPERantispyware : www.Avast!.com & www.SUPERantispyware.com .


Good comments.
Thanks for sharing.
0

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users