Hello Again
I have the Safe Mode virus on my PC and have had no luck in removing it. I have followed other advice and booted the PC with F8 then clicked the Command mode.
I then typed in the following:
REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System/v DisableTaskMgr/t REG_DWORD/d O /f - to enable Task Manager
This command was not recognised.
I should also mention that my BT/McAfee programme popped up and carried out a full scan. It did not find any problems. I suspect that the virus has disabled this programme.
I have downloaded Spybot, Combofix and MalwareBytes onto a USB stick, but cannot use it as the safe mode virus will not allow me to open up Windows.
Any help will be appreciated.

Dani AI

Generated

Good outcome — since ’s rescue disc restored boot, the priority now is verification and clean-up so the infection can’t return. Below is a concise, practical checklist and a clear explanation of what “post the logs” means so helpers can interpret results.

What “post the logs” means

  • Copy the full Malwarebytes scan report (the Logs tab entry). Include the date/time, Malwarebytes version, and the operating system (e.g., Windows 7).
  • Paste the entire text of that log into the thread (or attach the .txt log). That gives names, file paths and actions (quarantine/removal) which are the key facts helpers need. Mention any rescue media used and whether Windows startup repair ran.

Immediate verification checklist

  • Run a full Malwarebytes scan and save the log.
  • Do a second-opinion scan (offline rescue media or a different scanner) if possible.
  • Check persistence points (startup items, scheduled tasks, services). A Sysinternals Autoruns export is very useful — save the report and include it with the Malwarebytes log.
  • Run System File Checker from an elevated prompt (sfc /scannow) to check system files.
  • Change all important passwords after the machine is confirmed clean and apply all Windows updates and AV definition updates.

Cautions and next steps

  • Tools such as Combofix should only be run when specifically requested by an experienced helper.
  • If logs show many removed items, or odd drivers/services remain, consider imaging user data and doing a clean OS reinstall — that’s the surest way to eliminate rootkits.
  • Once clean, make a disk image and keep regular backups.

References in the thread (, ) already pointed toward the same follow-ups; the above turns those suggestions into the concrete actions and the exact log content that helpers need to confirm a full cleanup.

Recommended Answers

All 8 Replies

So you no longer can boot to Windows at all, even in Safe Mode? Or Safe Mode with networking?

Absolutely correct. I did allow the virus some time to corrupt my PC by naively following some of its instructions, so now I am unable to start up at all!
I am going away for a long weekend tomorrow, so may not respond to any replies until Tuesday. Thanks for any help!

so now I am unable to start up at all!

Hi Richard,

-- What options (if any) do you get when you tap F12 on boot?

Can you burn an ISO? You may need a free tool such as ImgBurn to do this.

Please burn the following ISO to CD:
-

Then, pop the CD into the ill machine and see if it will boot. You may need to tap F12 on boot and set to boot from optical drive.

Let us know if you can do this and we'll go from there. BitDefender may automatically start to scan - if so, great - though it might not be able to download updates...


Best Luck :)
PP

Jus poking nose in..... Richard, if you open a cmd window and use that to run your REG cmd you will see the actual error messages as to why it did not work. Use this corrected cmd:
REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 0 /f
-there must be spaces before parameter types like /t
-the data is actually a zero, so /d 0 [you show a capital letter o above..]
But if you cannot boot to windows in any form then all that is moot.

Hi PP
Thanks for your advice. It was spot on!
The rescue disc loaded OK, and the programme ran straight away on the infected computer - identified 3 problems, and removed them on request.
On reboot, a Windows start-up repair spent a few minutes checking, but now I am up and running again, and virus free!
Many thanks

Hi PP
I will, of course, follow your recommendations. When you say 'post the logs' what do you mean ?
Regards
Richard

Hi PP
I will, of course, follow your recommendations. When you say 'post the logs' what do you mean ?
Regards
Richard

Follow the instructions on the link PP gave you. The program will scan, show you what, if anything is found, you choose remove all if anything is found, then you reboot. Open the program again, go to the Logs tab, choose the bottom log, open, Copy the log and paste it back here.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.