laserblazer Posted March 27, 2011 Posted March 27, 2011 A teacher, who islong-term sick leave, dropped her school laptop in to my home yesterday because it wouldn't boot. The error message was a corrupt/missing ntfs.sys. I reinstalled XP and took myriads of crap off but a program called windows-repair keeps popping up to say there are bad drive sectors and viryally locking out the machine. I've run a scandisk check in safe mode and no bad sectors are reported but I can't find a way to clear this program. It comes from windows-repair.com The teacher has said she must have her laptop so she can send in lesson plans but I think it's more a case of running a private business from home.
witch Posted March 27, 2011 Posted March 27, 2011 There is some info on Google about removing it - have you tried those and failed? (I find that often they don't work) 1
laserblazer Posted March 27, 2011 Author Posted March 27, 2011 When malwarebytes gets to the end of its install I get an access denied error, even in safe mode with admin rights. I couldn't find any info when I googled it but I'll try again.
featured_spectre Posted March 27, 2011 Posted March 27, 2011 Format the drive...extreme but we had a teacher with this and it spread to our network (thankfully sophos stopped it on the server), but she disabled the AV on her machine to get it installed as she thought she needed it. All data got lost in the process as it replicates much like conficker. 1
witch Posted March 27, 2011 Posted March 27, 2011 When malwarebytes gets to the end of its install I get an access denied error, even in safe mode with admin rights. I couldn't find any info when I googled it but I'll try again. Other virus-type things have disabled malware bytes - what sometimes works if you save it on a stick or something and then change its name to something else - then it shoudl run 1
6Foot2 Posted March 27, 2011 Posted March 27, 2011 Would it be worth having a look with this: Link: MyUninstaller: Alternative uninstaller to the standard Windows Add / Remove module [Just an idea] 1
laserblazer Posted March 28, 2011 Author Posted March 28, 2011 There is some info on Google about removing it - have you tried those and failed? (I find that often they don't work) @witch what did you search for? I can't find anything relevant on google.
sted Posted March 28, 2011 Posted March 28, 2011 what about scanning the drive in another pc so its not booted from the "infected" drive that way there should be no way anything can interfere
laserblazer Posted March 28, 2011 Author Posted March 28, 2011 what about scanning the drive in another pc so its not booted from the "infected" drive that way there should be no way anything can interfere I've managed to do a malwarebyte scan but that hasn't shifted it. System restore is also unavailable. As is task manager.
Steve21 Posted March 28, 2011 Posted March 28, 2011 I've managed to do a malwarebyte scan but that hasn't shifted it. System restore is also unavailable. As is task manager. Tried Step by Step Uninstall/remove Windows Repair virus Removal Guide | Security-Wire.com ? Steve
laserblazer Posted March 28, 2011 Author Posted March 28, 2011 Tried Step by Step Uninstall/remove Windows Repair virus Removal Guide | Security-Wire.com ? Steve It's blocked by the LEA Steve - Hacking apparently.
Steve21 Posted March 28, 2011 Posted March 28, 2011 It's blocked by the LEA Steve - Hacking apparently. Login with your proxy account, or don't you have access to one? Steve
Steve21 Posted March 28, 2011 Posted March 28, 2011 Manual Removal Note: If you are not proficient with computer, it’s suggested that you backup your registry before manually removing Windows Repair Rogue Anti-Spyware. And double check the entries that you are going to delete, or your computer can’t work for missing some files. Step 1: Processes you need to end: [random].exe Step 2: Registry entries you need to delete: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[random].exe” HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[random]“ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = ‘/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:’ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = ’1? HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “CheckExeSignatures” = ‘no’ HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main “Use FormSuggest” = ‘yes’ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnonBadCertRecving” = ’0? HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = ’1? Step 3: Files you need to delete: %Documents and Settings%\All Users\Application Data\[random] %Documents and Settings%\All Users\Application Data\[random].exe %Documents and Settings%\All Users\Application Data\[random].dll There's automatic version too if you prefer it doing it, but guess manual is smoother Steve 1
laserblazer Posted March 28, 2011 Author Posted March 28, 2011 Thanks Steve. Niave question but how do I find out what [random} is?
Steve21 Posted March 28, 2011 Posted March 28, 2011 Thanks Steve. Niave question but how do I find out what [random} is? Well generally it's something really odd Not your standard blah32 etc, but more like oseiojsiofjoz.exe (and it'll be running by user, not system usually) If you check in that app folder, and registry it should all same file names, unless there's multiple installs. Might be easiest to check that first, assuming its installed there. Steve 1
laserblazer Posted March 28, 2011 Author Posted March 28, 2011 That seems to have got rid of it. Just need to sort out why All Programs is empty.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now