Link to home
Start Free TrialLog in
Avatar of frankbustos
frankbustosFlag for United States of America

asked on

virus and or spyware removal help!

hi experts,

 I have a windows xp system that seems to be infected with a virus and or spyware. I can't run any of the programs when I try to open up lets say internet explorer I get a pop up asking me what program I  want to use to open that with. I also get this is I do msconfig or open word. I can't download anything off the internet , I can't do a system restore and I can't even get into safe mode because I get a blue screen. What can I do?
Avatar of ProtechCT
ProtechCT

Go into Safe-mode with networking (F8 at boot) download and run Malware-bytes in safe-mode.

After

The fllowing list should be used in an effort to rid workstations of viruses:

Run malwarebytes in Safe Mode with Networking and update it before running a full system scan:
http://www.malwarebytes.org/mbam-download.php

Then try HitManpro to make sure anything which might be left behind is clean:
32bit
http://dl.surfright.nl/HitmanPro35.exe
http://download.cnet.com/Hitman-Pro-3/3000-2239_4-10895604.html

64bit
http://dl.surfright.nl/HitmanPro35_x64.exe

If issue is not resolved by these tools try TDSSKiller:
http://support.kaspersky.com/downloads/utils/tdsskiller.zip
http://support.kaspersky.com/downloads/utils/tdsskiller.exe

Tutorial on TDSSKiller:
http://support.kaspersky.com/viruses/solutions?qid=208280684

or you could also try FixTDSS.exe from Symantec

http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FixTDSS.exe

If this does not resolve your issue then try Combofix:

Download Combofix
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Tutorial on how to use combofix:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
ASKER CERTIFIED SOLUTION
Avatar of daniel_smith
daniel_smith
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of younghv
I think you are either going to have to run one of the "Rogue" stoppers before you can take any other actions or download the tools you need to a clean computer, then copy then to USB/CD and take them to the infected computer.

Two of my Articles here on EE deal with this:
https://www.experts-exchange.com/Software/Internet_Email/Anti_Spyware/A_5124-Stop-the-Bleeding-First-Aid-for-Malware.html 

https://www.experts-exchange.com/Software/Internet_Email/Anti_Spyware/A_5124-Stop-the-Bleeding-First-Aid-for-Malware.html

Some detailed instructions are also here:
http://www.bleepingcomputer.com/virus-removal/remove-antivirus-vista-2010

You could download the SARDU and build a bootable CD/DVD for yourself and scan/repair you system using it.

More info:
http://www.sarducd.it/index.html

SARDU (short for Shardana Antivirus Rescue Disk Utility) is a free software application that can produce a CD / DVD or a USB device with multi-boot support.

The CD/DVD or USB device may include comprehensive collections of antivirus rescue cds, collections of utilities, popular distributions of Linux Live, and the best known Windows PE © and recovery disks.

SARDU's menu is divided into four categories: Antivirus, Utilities, Linux, and PE, with the buttons and checkboxes of individual software.

At this moment SARDU manage ten (10) rescue system, this means that it's possible to always have at hand, this power of antivirus.

These ISO are almost always based on linux, sardu means that don't conflict and all work, one at a time, in the same media.

AOSS
AVG
Avira
Bit Defender
Dr. Web
eScan
F-Secure
GData
Kaspersky
Panda Security
VirusBlokAda

Download:
http://www.sarducd.it/downloads.html

Sudeep
Avatar of frankbustos

ASKER

this fixed the issues...thanks!