Jump to content

Recommended Posts

Posted

Hey Pete or whoever's here, I am not seeing a model number of this old XP machine anywhere, only the VAIO sign on it. When you power on it is showing weird graphics on the screen as the attached image shows. The owner said he was downloading something from the net when the pc powered off then would not boot to windows so we are suspecting this is a virus situation.

 

I tried pressing F1, F2 and F8 but it will not go to the bios or safe mode. The guy wishes to save the data but I don't want to remove the HDD to attach to another machine since I don't know what sort of virus I am dealing with, any ideas please?

20160112_193617_resized.thumb.jpg.8e8e4a8da2fce974c6d5ce1ef0a4745d.jpg

Posted

Hi Mike,

 

Sorry for the delay, am just in from work.

A few removal sites are not dealing with XP any more, they say it's just too insecure to bother with now.

We do have a tool that may allow us to boot the system and get a report .... it'll also enable you to save any data from the system as well.

 

That is odd..... especially that one block that's out of place.

 

Please print these instruction out so that you know what you are doing

 

  • Download OTLPENet.exe to your desktop
  • Ensure that you have a blank CD in the drive
  • Double click OTLPEStd.exe and this will then open imgburn to burn the file to CD
  • Reboot your bad system using the boot CD you just created.

.

Note : If you do not know how to set your computer to boot from CD follow the steps here

  • As the CD needs to detect your hardware and load the operating system, I would recommend a nice cup of tea whilst it loads :)
    .
     
  • Your system should now display a Reatogo desktop.
  • Note : as you are running from CD it is not exactly speedy
  • Double-click on the OTLPE icon.
  • Select the Windows folder of the infected drive if it asks for a location
  • When asked "Do you wish to load the remote registry", select Yes
  • When asked "Do you wish to load remote user profile(s) for scanning", select Yes
  • Ensure the box "Automatically Load All Remaining Users" is checked and press OK
  • OTL should now start.
  • Press Run Scan to start the scan.
  • When finished, the file will be saved in drive C:\OTL.txt
  • Copy this file to your USB drive if you do not have internet connection on this system.
  • Right click the file and select send to : select the USB drive.
  • Confirm that it has copied to the USB drive by selecting it
  • You can backup any files that you wish from this OS
  • Please post the contents of the C:\OTL.txt file in your reply.

76c90dd0e79a714317a8daeecc1584d2.png

Posted
Hey Pete, no worries at all. I am suspecting graphics issue but remember this system will not allow me to go into bios, boot options or safe mode and will not boot from anything so your instructions above will not work? I have scanned the drive attached to my pc to backup the data, using MBAM It found a lot of malware but is clean now now on 2nd run.
Posted

Hi Mike

 

The otlpe is designed to work on none booting systems.

Maybe I should have added that the downloading and creating the boot disc is done from a normal running system. This disc is then used as a boot disc to start the infected pc.

It doesn't rely on windows so should run fine.

76c90dd0e79a714317a8daeecc1584d2.png

Posted

Hi Mike,

 

It would seem that this isn't just a graphics or malware issue then.

99% of malware is designed basically to make money.

If the system is totally killed..... the bad guys make nothing.

I'd be more inclined to look for a motherboard problem.

The malware that was cleaned may have been incidental.

  • Like 1
76c90dd0e79a714317a8daeecc1584d2.png

Posted
I already advised the guy to get at a least a duo core pc with win7 if budget is an issue and don't spend a cent on this old iron horse. Main thing is I now have his data safely backed up and his HDD is clean, appreciate your help as always, till next time, my friend!
Posted
I already advised the guy to get at a least a duo core pc with win7 if budget is an issue and don't spend a cent on this old iron horse

Good advice Mike.

 

Safe surfing. e551c0a6c62160eeac0c672f27ea97b9.gif

76c90dd0e79a714317a8daeecc1584d2.png

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...