dos problem

D

David Kennedy

Hi ,

Can anyone help me please,

Whenever I try to open the dos screen (start->run.. and type cmd or cmd.exe)
the dos screen opens and closes again in a split second
(regedit and task manager will not open either)

I have ran a virus check but nothing has been detected.(but I do think its
some kind of virus I have)

I have opened the PC in safe mode and hit start->run.. and typed msconfig
On the Startup tab there is a file called winsass.exe (this file seems to be
the problem)
I unchecked this file and restarted the PC and logged in as normal
I then typed cmd in run and the dos screen appeared
I typed regedit and it was ok
I opened the Task Manager and it was ok (great everythings ok again)

However..A few minutes later I typed cmd again and the dos screen opened and
closed again,
regedit and task manager wouldnt open.

I opened the PC in safe mode again typed msconfig and on the startup tab the
original winsass.exe was unchecked but another one had appeared in the list
which was checked!!!???

Its like this file re-creates itself after a certain amount of time

I have tried to open the McAfee website for a virus check but the page wont
open (could this be the virus doing this?)

Please can somebody give me a solution,this is driving me mad.
Any help would be greatly appreciated

Thanks
David Kennedy
 
P

Patrick Keenan

David Kennedy said:
Hi ,

Can anyone help me please,

Whenever I try to open the dos screen (start->run.. and type cmd or
cmd.exe)
the dos screen opens and closes again in a split second
(regedit and task manager will not open either)

I have ran a virus check but nothing has been detected.(but I do think its
some kind of virus I have)

I have opened the PC in safe mode and hit start->run.. and typed msconfig
On the Startup tab there is a file called winsass.exe (this file seems to
be
the problem)
I unchecked this file and restarted the PC and logged in as normal
I then typed cmd in run and the dos screen appeared
I typed regedit and it was ok
I opened the Task Manager and it was ok (great everythings ok again)

However..A few minutes later I typed cmd again and the dos screen opened
and
closed again,
regedit and task manager wouldnt open.

I opened the PC in safe mode again typed msconfig and on the startup tab
the
original winsass.exe was unchecked but another one had appeared in the
list
which was checked!!!???

Its like this file re-creates itself after a certain amount of time

I have tried to open the McAfee website for a virus check but the page
wont
open (could this be the virus doing this?)

Please can somebody give me a solution,this is driving me mad.
Any help would be greatly appreciated

Thanks
David Kennedy

Yes, your machine is infected, and yes, the process re-creates itself. Try
repeating what you did to disable the virus and try to get to here as
quickly as possible after rebooting:
http://housecall.trendmicro.com/

Let it scan, preferably the complete scan. If you're able to get in
before the virus re-launches, you may be able to beat it. You may have to
repeat this several times to get the upper hand.

Otherwise an easy way to get this fixed is to remove your drive and
temporarily install it in another machine that is working properly. You
may need to change jumper settings from Master to Slave or Cable Select.
Run thorough antivirus scans on the drive while it is installed in the
working machine. You may wish to delete all of the contents of the
temporary internet files and other temporary folders now; these are prime
hideouts for launchers. You may also wish to manually view the contents
of the Windows and \system32 directories for inappropriate files, but this
is a more advanced task.

Be sure to reset the drive jumpers when you move the drive back.

When you install the drive in your machine, you may get an error message or
two stating that files can't be found, and that's ok. Remove the references
to those files, as they are most likely the viruses. Also, it's extremely
likely that the System Restore points will be infected, so you'll need to
turn off System Restore (to delete the restore points) and turn it back on
again.

HTH
-pk
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top