Not able to open any drive? please help-Virus

Status
Not open for further replies.

roonie

Journeyman
I just formatted my system and find problems like this...Whenever i open any other drive except C: drive i get error saying "resycled\boot.com is not valid win32 application"...What should i do now?...I have put avast and zonealarm firewall they dont dtect anythin and also

Whenever i start the computer i get the language bar at the buttom in the taskbar how do i disable tat..I have to roghtclick everytime at the taskbar to disable it..Is der anyway to totally disable it

Waiting for replies
 

mrintech

Technomancer
It's a Trojan. Immediately scan with: *www.superantispyware.com/download.html & *www.emsisoft.com/en/software/free/

Also completely update the definition database software and RUN full scan on all drives ;)

Problem will be Solved ;)
 
OP
R

roonie

Journeyman
No its still der...I have updated both of your given softwares and ran a full system scan..Anything else to try
 

mrintech

Technomancer
Open a cmd prompt. Start > Run... [type in] cmd > Ok
At the prompt, enter the following commands:

attrib -h -r -s C:\Autorun.inf

del C:\Autorun.inf

attrib -h -r -s D:\Autorun.inf

del D:\Autorun.inf


etc.


(do this for every drive letter (C: D: E: etc) and do NOT open any drives with
Explorer until you're completed)

Another Method

You should do these steps after a fresh reboot or in safe mode.

1) Navigate to the problem drive(s) via the Explore option.

2) Click on TOOLS -> FOLDER OPTIONS

3) Click the button which says ‘Show hidden files and folders.

4) UNCHECK the following boxes:

Hide extensions for known file types
Hide protected operrating system files

5) Find and delete the autorun.ini file and the resycled folder on the root directory of all affected drives.

6) Check “c:\windows\system32\dllcache” for boot.com file and delete it if present.

7) Check “c:\windows\prefetch” for boot.com file and delete if present.

8) Delete all files from c:\windows\temp

(Some files may not delete, that’s ok, they’re in use by the system and not virus files.)

9) Delete all files from c:\Documents and Settings\[USER PROFILE]\Local Settings\Temp

(Again, a couple files may not delete, don’t worry.)

10) Run Regedit

11) Make sure you are at the very first entry of the registry hive. (y Computer should be hilighted) then click EDIT -> FIND

12) Search for “boot.com”. If it finds an entry, delete it. Keep hitting F3 until you’ve deleted all instances of boot.com in the entire registry.

13) Scroll the left comumn back up to the top and hilight the My Computer again at the top of the registry hive.

14) Click Edit -> Find again and search for ‘resycled’ and repeat as in step 13, deleting the entries as it finds them. (I found 2 of each)

15) Close registry editor and try opening the infected drives. They should work now.
 
Last edited:
OP
R

roonie

Journeyman
Great working now...Thanks a lot...Dint expect this...
Cool work-Again thanks a lot for helping
 

suniltr77

Broken In
When I want to open any drive, a pop-up massage shown up every time like this.
The C:\application cannot be run in win32 mode.
ok
But I am able to open only the my Documents. What is tthe problem? Can I apply the above tweak to my PC?
 

mrintech

Technomancer
Follow this method

Open a cmd prompt. Start > Run... [type in] cmd > Ok
At the prompt, enter the following commands:

attrib -h -r -s C:\Autorun.inf

del C:\Autorun.inf

attrib -h -r -s D:\Autorun.inf

del D:\Autorun.inf


etc.


(do this for every drive letter (C: D: E: etc) and do NOT open any drives with
Explorer until you're completed)

Also go for full scan with updated definition with the following:

* *www.superantispyware.com/download.html
* *www.emsisoft.com/en/software/free/

Do reply back about the Results ;)
 

suniltr77

Broken In
During the process the DOS prompt flashes for a split of second and disappears. I thought it might went wrong. But after deleting the .ini files and a reboot the problem is over. Thanks a lot.
 
Status
Not open for further replies.
Top Bottom