Unsolved
This post is more than 5 years old
113 Posts
0
7779
March 18th, 2008 06:00
Please Help...serious problem with laptop!
Dear forum,
I have a serious problem with my laptop.
Yesterday I tried to download a program for my wife, which was probably a virus (I tried to download from eMule the Nucleus Kernal PowerPoint recovery software) and while it started installing, I got a blue screen, and the laptop switched off.
I tried to turn it on, and it kept going into a loop...blue screen, reboot, blue screen, reboot etc. So I tried F8 and I went to "Last known configuration" and it went into checkdisk, then I got into Windows XP Home.
I tried to use McAfee, but Virus Scan was missing, and I tried to install it, and it wouldn't let me.
I tried System Restore, but it wouldn't restore to an earlier time.
Then I tried to run HJT...and everything froze!!! I then rebooted the system, and from then on it keeps going into checkdisk...and when it finishes it won't let me into windows...but instead I get the same blue screen and then reboots!!
If I skip the checkdisk, I go into Windows normaly with no problems (but I do get a message "Windows Recovered from a serious error" or something like that), but I still can't run McAfee to do a virus scan and I have to firewall or anything like that!
When I reboot or switch of my laptop...and then turn it back on, it keeps going into checkdisk...then I have to cancel it to go into windows normaly.
When I try to run HJT this, everything freezes!!! So I don't have a log!
I also can't go into Safe Mode, cause I also get a blue screen and the system reboots by itself!!!
I forgot to tell you that I ran a search to see what files have been installed/created yesterday, and I found mdelk.exe which can't be deleted. Maybe that will help.
Any help?!
PLEASE help me guys! :-)
0 events found


Leonhart18
3 Posts
0
March 18th, 2008 09:00
Wow that is not fun. I did a bit of research, read this and see if it helps you, it has instructions on mdelk.exe and the removal process.
http://www.greatis.com/appdata/d/m/mdelk.exe.htm
Bugbatter
4 Apprentice
•
20.5K Posts
0
March 18th, 2008 12:00
I will be glad to work on this with you, but I ask that you do a few things first.
* Have you have posted this issue on another forum? If so, please provide a link to the topic.
* If you are using any cracked software, please remove it.
Definition of cracked software:
http://en.wikipedia.org/wiki/Software_cracking
* If you are using any P2P (file sharing) programs, please remove them before we clean your computer.
The nature of such software and the high incidence of malware in files downloaded with them is counter productive to restoring your PC to a healthy state. that would be emule and any other P2P's that you have installed.
* If this computer belongs to someone else, do you have authority to apply the fixes we will use?
* Have you already fixed entries using HijackThis? If so, please restore all the backups and then post another log.
* After we begin working, please print or copy all instructions to Notepad in order to assist you when carrying out procedures.
Please follow all instructions in sequence. Do not, on your own, install/re-install any programs or run any fixes or scanners that you have not been instructed to use because this may cause conflicts with the tools that I am using.
** We may be using some specialized tools during our fix. Certain embedded files that are part of legitimate programs or specialized fix tools such as process.exe, restart.exe, SmiUpdate.exe, reboot.exe, ws2fix.exe, prcviewer.exe and nircmd.exe may at times be detected by some anti-virus/anti-malware scanners as a "RiskTool", "Hacking tool", "Potentially unwanted tool", or even "malware (virus/trojan)" when that is not the case.
Such programs have legitimate uses in contexts where an authorized user or administrator has knowingly installed it. These detections do not necessarily mean the file is malware or a bad program. It means it has the potential for being misused by others. Anti-virus scanners cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert you or even automatically remove them.
* If your replies do not fit in one post while we are handling your issue, please reply to yourself until all text is submitted. It may take several posts.
I look forward to your reply so we can begin.
NikosAlfa147
113 Posts
0
March 18th, 2008 14:00
Dear Bugbatter, thank you for your help and time you are willing to offer to my problem. I really do not want to format my laptop. We will have some delay in the posts since I am in Greece (GMT+2).
Below you will find answers to your questions:
*I have not posted this issue on another forum.
*I do not have any cracked software on my laptop. The only one I had was McAfee, and I tried to unistall it and I can't. I will install Karspersky that I bought today.
*I am using eMule and utorrent as download programs. I will unistall them.
*This computer belongs to me 100%
*I tried to use Hijack This, but when I double-clicked the program, my computer froze and nothing worked. I am mentioning it on my first post. So I can't use HJT for some reason.
*I will follow 100% your valuable instructions. I am looking forward to. Rkinner (or something like that) has helped my before and did a fantastic job.
**I understand what these tools do and I know that I will have to "allow" them from any antivirus programs.
I can't fully unistall McAfee (which is cracked) to install Karspersky.
I will be looking forward for your post!
Bugbatter
4 Apprentice
•
20.5K Posts
0
March 18th, 2008 15:00
Let's start by running a general online scan and we will progress to more specific tools as needed.
Please do an online virus scan with Panda ActiveScan
>Here. You need to use Internet Explorer for this scan.
Please go to your hijackthis.exe and rename it to nikos.exe. See if you can get it to run that way. If not, we'll use something else.
Thanks!
NikosAlfa147
113 Posts
0
March 18th, 2008 20:00
Dear Bugbatter, for the last 3.5 hours my computer has been doing the viruscan you told me.
So far it has found 8 viruses, 1 spyware and 1 hacking tool and toolkit. It's about 30% done judging from the process bar.
I'll leave it on all night and I hope I'll find it on when I wake up and I won't lose the log.
I'll also try the trick with HJT.
You'll hear from me soon.
Thank you VERY much for your time and effort.
P.S. We've been having frequent power-outages here due to a strike. :-(
NikosAlfa147
113 Posts
0
March 19th, 2008 05:00
Dear Bugbatter, we're in a bit of a jam!
Viruscan for some reason has been scanning all night long and is now at 75%, having found 29 viruses.
The thing is that we got an announcement from the electric company that they will turn the power off in 1 hour, so I will have to run it all over again, and that means that we will lose the log.
Any advice? What happens if I stop it now? Will I get a log?
Thanks
NikosAlfa147
113 Posts
0
March 19th, 2008 06:00
Spyware:Cookie/Toplist Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Application Data\Mozilla\Firefox\Profiles\n4a63x9w.default\cookies.txt[.toplist.cz/]
Spyware:Cookie/Ccbill Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos alexiadis@ccbill[1].txt
Spyware:Cookie/MediaTickets Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos alexiadis@kinghost[1].txt
Spyware:Cookie/Advnt Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos alexiadis@www.advnt01[1].txt
Spyware:Cookie/Apmebf Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@apmebf[1].txt
Spyware:Cookie/Azjmp Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@azjmp[1].txt
Spyware:Cookie/Ccbill Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@ccbill[1].txt
Spyware:Cookie/Ccbill Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@ccbill[3].txt
Spyware:Cookie/Ccbill Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@ccbill[4].txt
Spyware:Cookie/cs.sexcounter Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@cs.sexcounter[2].txt
NikosAlfa147
113 Posts
0
March 19th, 2008 06:00
Spyware:Cookie/XXXCounter Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@xxxcounter[4].txt
Virus:Trj/Spamtaload.DM Disinfected Hotmail\Junk E-Mail\Mail server report.\Update-KB3546-x86.exe
Virus:W32/Bagle.QV.worm Disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Local Settings\Temporary Internet Files\Content.IE5\6J2MKLE2\b64_2[1].jpg
Virus:W32/Bagle.RP.worm Disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Local Settings\Temporary Internet Files\Content.IE5\6J2MKLE2\b64_31[1].jpg
Virus:W32/Bagle.RP.worm Disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Local Settings\Temporary Internet Files\Content.IE5\8CPKBACL\b64_31[1].jpg
Virus:W32/Bagle.RP.worm Disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Local Settings\Temporary Internet Files\Content.IE5\DMVERDZU\b64_31[1].jpg
Virus:Trj/Deldir.A Disinfected G:\Backup\full_backup\C\Program Files\FerrariWallPaper\Ferrari 3000 calendar 2008_2009\Ferrari 3000 calendar 2008_2009\FR3000\Wallpape.bat
Virus:Trj/Deldir.A Disinfected G:\Backup\full_backup\C\Program Files\FerrariWallPaper\Ferrari 3000 calendar 2008_2009\Ferrari 3000 calendar 2008_2009\FR3000.exe[FR3000/Wallpape.bat]
Virus:Trj/Deldir.A Disinfected G:\Backup\full_backup\C\Program Files\FerrariWallPaper\Ferrari 3000 calendar 2008_2009\Ferrari 3000 calendar 2008_2009.zip[Ferrari 3000 calendar 2008_2009/FR3000.exe][FR3000/Wallpape.bat]
Virus:Trj/Deldir.A Disinfected G:\Backup\full_backup\C\Program Files\FerrariWallPaper\Wallpape.bat
NikosAlfa147
113 Posts
0
March 19th, 2008 06:00
Spyware:Cookie/Advnt Not disinfected C:\Documents and Settings\Nikos Alexiadis\Cookies\nikos alexiadis@www.advnt01[1].txt
Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\Nikos Alexiadis\Cookies\nikos alexiadis@ccbill[1].txt
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@azjmp[1].txt
Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@ccbill[1].txt
Spyware:Cookie/MediaTickets Not disinfected C:\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@kinghost[1].txt
Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@cs.sexcounter[2].txt
Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@webpower[1].txt
Spyware:Cookie/Cgi-bin Not disinfected
NikosAlfa147
113 Posts
0
March 19th, 2008 06:00
Spyware:Cookie/Statcounter Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Application Data\Mozilla\Firefox\Profiles\n4a63x9w.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/Doubleclick Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Application Data\Mozilla\Firefox\Profiles\n4a63x9w.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Smartadserver Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Application Data\Mozilla\Firefox\Profiles\n4a63x9w.default\cookies.txt[.smartadserver.com/]
Spyware:Cookie/YieldManager Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Application Data\Mozilla\Firefox\Profiles\n4a63x9w.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/YieldManager Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Application Data\Mozilla\Firefox\Profiles\n4a63x9w.default\cookies.txt[.ad.yieldmanager.com/]
Spyware:Cookie/Zedo Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Application Data\Mozilla\Firefox\Profiles\n4a63x9w.default\cookies.txt[.zedo.com/]
Spyware:Cookie/adultfriendfinder Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Application Data\Mozilla\Firefox\Profiles\n4a63x9w.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/Yadro Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Application Data\Mozilla\Firefox\Profiles\n4a63x9w.default\cookies.txt[.yadro.ru/]
Spyware:Cookie/Com.com Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Application Data\Mozilla\Firefox\Profiles\n4a63x9w.default\cookies.txt[.com.com/]
NikosAlfa147
113 Posts
0
March 19th, 2008 06:00
Spyware:Cookie/Advertising Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Application Data\Mozilla\Firefox\Profiles\n4a63x9w.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Xiti Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Application Data\Mozilla\Firefox\Profiles\n4a63x9w.default\cookies.txt[.xiti.com/]
Spyware:Cookie/WebtrendsLive Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Application Data\Mozilla\Firefox\Profiles\n4a63x9w.default\cookies.txt[statse.webtrendslive.com/]
Spyware:Cookie/Adtech Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Application Data\Mozilla\Firefox\Profiles\n4a63x9w.default\cookies.txt[.adtech.de/]
Spyware:Cookie/QuestionMarket Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Application Data\Mozilla\Firefox\Profiles\n4a63x9w.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/BurstNet Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Application Data\Mozilla\Firefox\Profiles\n4a63x9w.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/Searchportal Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Application Data\Mozilla\Firefox\Profiles\n4a63x9w.default\cookies.txt[searchportal.information.com/]
Spyware:Cookie/BurstBeacon Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Application Data\Mozilla\Firefox\Profiles\n4a63x9w.default\cookies.txt[www.burstbeacon.com/]
Spyware:Cookie/Atwola Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Application Data\Mozilla\Firefox\Profiles\n4a63x9w.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Adrevolver Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Application Data\Mozilla\Firefox\Profiles\n4a63x9w.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/HotLog Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Application Data\Mozilla\Firefox\Profiles\n4a63x9w.default\cookies.txt[.hotlog.ru/]
Spyware:Cookie/Weborama Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Application Data\Mozilla\Firefox\Profiles\n4a63x9w.default\cookies.txt[.weborama.fr/]
Spyware:Cookie/onestat.com Not
NikosAlfa147
113 Posts
0
March 19th, 2008 06:00
Spyware:Cookie/cs.sexcounter Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@cs.sexcounter[4].txt
Spyware:Cookie/Doubleclick Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@doubleclick[2].txt
Spyware:Cookie/MediaTickets Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@kinghost[1].txt
Spyware:Cookie/MediaTickets Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@kinghost[3].txt
Spyware:Cookie/onestat.com Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@stat.onestat[2].txt
Spyware:Cookie/Toplist Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@toplist[1].txt
Spyware:Cookie/Toplist Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@toplist[2].txt
Spyware:Cookie/WebPower Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@webpower[1].txt
Spyware:Cookie/Cgi-bin Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@www1.addfreestats[1].txt
Spyware:Cookie/XXXCounter Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@xxxcounter[1].txt
Spyware:Cookie/XXXCounter Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@xxxcounter[2].txt
NikosAlfa147
113 Posts
0
March 19th, 2008 06:00
Spyware:Cookie/Ccbill Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos alexiadis@ccbill[1].txt
Spyware:Cookie/MediaTickets Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos alexiadis@kinghost[1].txt
Spyware:Cookie/Advnt Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos alexiadis@www.advnt01[1].txt
Spyware:Cookie/Apmebf Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@apmebf[1].txt
Spyware:Cookie/Azjmp Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@azjmp[1].txt
Spyware:Cookie/Ccbill Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@ccbill[1].txt
Spyware:Cookie/Ccbill Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@ccbill[3].txt
Spyware:Cookie/Ccbill Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@ccbill[4].txt
Spyware:Cookie/cs.sexcounter Not disinfected G:\Backup\full_backup\C\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@cs.sexcounter[2].txt
NikosAlfa147
113 Posts
0
March 19th, 2008 06:00
Spyware:Cookie/XXXCounter Not disinfected C:\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@xxxcounter[2].txt
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@apmebf[1].txt
Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@ccbill[3].txt
Spyware:Cookie/MediaTickets Not disinfected C:\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@kinghost[3].txt
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@toplist[1].txt
Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@cs.sexcounter[3].txt
Spyware:Cookie/XXXCounter Not disinfected C:\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@xxxcounter[1].txt
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Nikos Alexiadis\Cookies\nikos_alexiadis@toplist[2].txt
Spyware:Cookie/XXXCounter Not disinfected
NikosAlfa147
113 Posts
0
March 19th, 2008 06:00
Virus:W32/Bagle.RP.worm Disinfected C:\Documents and Settings\Nikos Alexiadis\Local Settings\Temporary Internet Files\Content.IE5\8CPKBACL\b64_31[1].jpg
Virus:W32/Bagle.RP.worm Disinfected C:\Documents and Settings\Nikos Alexiadis\Local Settings\Temporary Internet Files\Content.IE5\8CPKBACL\b64_31[2].jpg
Virus:W32/Bagle.RP.worm Disinfected C:\Documents and Settings\Nikos Alexiadis\Local Settings\Temporary Internet Files\Content.IE5\DMVERDZU\b64_31[1].jpg
Virus:W32/Bagle.RP.worm Disinfected C:\Documents and Settings\Nikos Alexiadis\Local Settings\Temporary Internet Files\Content.IE5\6J2MKLE2\b64_31[1].jpg
Virus:W32/Bagle.QV.worm Disinfected C:\Documents and Settings\Nikos Alexiadis\Local Settings\Temporary Internet Files\Content.IE5\6J2MKLE2\b64_2[1].jpg
Virus:Trj/Spamtaload.DM Disinfected Hotmail\Junk E-Mail\Mail server report.\Update-KB3546-x86.exe