Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

NEED HELP!


  • Please log in to reply

#1
ldhacker

ldhacker

    New Member

  • Member
  • Pip
  • 6 posts
My computer just started blocking me from command promp regedit and many other system files. It has replaced my background with something that says YOU SYSTEM IS INFECTED in bold letters and the background changes colors every time that you start up the computer, popups keep poping up saying you need to update your virus software but i have he latest version, i went in to mcafee and it says that there have been registry changes, an icon pops up in the quick start bar that has an X on it with a round red background, it keeps trying to access the internet to get what it calls "Security Updates". I have tried to remove it from startup with CCleaner but it dosnt work. clearing the temporary files and the cookies but nothing works.

PLEASE HELP!!!

I ran rootrepeal and it said this:

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/11/30 17:46
Program Version: Version 1.3.5.0
Windows Version: Windows XP Media Center Edition SP3
==================================================

Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xAFE93000 Size: 98304 File Visible: No Signed: -
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xBAE0C000 Size: 8192 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xACAC7000 Size: 49152 File Visible: No Signed: -
Status: -

==EOF==

Edited by ldhacker, 30 November 2009 - 05:51 PM.

  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP