![]() |
| ||
| Virus Changed Background (same problem as mrvin) Hi everyone. This morning out of nowhere my desktop background changed while I was surfing the web. I tried to change it back but two tabs in my Properties window were missing, so I couldn't change my wallpaper or screensaver. I downloaded Trojan Remover and did a scan, and renamed some files, but it didn't help me at all. I then downloaded Avast antivirus program, but that didn't fix the problem either. I'm not quite sure what to do now. I was thinking of reinstalling Windows, but I have plenty of files and haven't backed them up in a while, so if there is any other way to get rid of this virus, it would be great. I hope there's some way you can help me. Thanks in advance. Here is my recent HijackThis log: Quote:
|
| ||
| Re: Virus Changed Background (same problem as mrvin) Hi, you are a victim of Antivirus XP. Please download Malwarebytes' Anti-Malware to your desktop.
Please uninstall the current version of HijackThis from your computer. Please download the latest copy of HijackThis from Trend Micro and save it to your desktop.
Please post the contents of the log here. Also, I have seen that you have not updated your computer in a long time. This tends to cause a lot of malware infections. |
| ||
| Re: Virus Changed Background (same problem as mrvin) Thank you for your help! Here is the Malwarebytes log: Quote:
Quote:
|
| ||
| Re: Virus Changed Background (same problem as mrvin) Hi, looks like I missed something here in MBAM. Please run the MBAM scan again and after you see the results, make sure that everything is checked and then click Remove Selected. When MBA-M finishes, Notepad will open with the log. Please save it where you can find it easily. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt. |
| ||
| Re: Virus Changed Background (same problem as mrvin) Hi. I can change my wallpaper now. Thanks for the help. :) I imagine I'm not done, though. :P Here is my MBAM log file: Quote:
Quote:
|
| ||
| Re: Virus Changed Background (same problem as mrvin) Hi, good. We're almost there. Please uninstall the following programs from your computer :
Please reopen HJT and click on Do a system scan only and locate the following : O1 - Hosts: 72.52.158.153 www.avrilbandaids.com O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - Startup: PowerReg Scheduler V3.exe O15 - Trusted Zone: www.avrilbandaids.com O15 - Trusted Zone: http://www.avrilbandaids.com O16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} (CSEQueryObject Object) - http://www.myheritage.com/Genoogle/C...ngineQuery.dll O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by13fd.bay13.hotmail.msn.com/...x/HMAtchmt.ocx O18 - Filter hijack: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file) Now, close all the other open windows and then, in HijackThis, click on Fix Checked. Please delete the following file from the listed folder : Under C:\Program Files, delete the folder, Need2Find if it is still present. Please reboot your computer. Please do an online scan with Kaspersky WebScanner Click Scan Now and Accept the agreement. You will be promted to install an ActiveX component from Kaspersky, click Yes The program will launch and then begin downloading the latest definition files:
Please refrain from using the P2P/Torrent client in your system for the time being till I have cleared the infection in your system. In your next post, please post; a new HJT log, scan results from Kaspersky Online scan and a description of how your computer is running at the moment. |
| ||
| Re: Virus Changed Background (same problem as mrvin) Quote:
|
| ||
| Re: Virus Changed Background (same problem as mrvin) Alright, we'll fix that in a moment. Open HijackThis and click on Open Misc Tools section and then click on Open uninstall manager. Click on the button, "Save list..." on the right corner of HijackThis and save it on your desktop. Please post the contents of the file here. |
| ||
| Re: Virus Changed Background (same problem as mrvin) Thanks for the help. Here are the contents of the file: Quote:
|
| ||
| Re: Virus Changed Background (same problem as mrvin) Hi, did you delete the delete the folder rather than uninstalling Need2Find from your computer? Try going to Program Files and then delete the Need2Find folder. Also, please re-open HijackThis and place a check on the following : O1 - Hosts: 72.52.158.153 www.avrilbandaids.com O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - Startup: PowerReg Scheduler V3.exe O15 - Trusted Zone: www.avrilbandaids.com O15 - Trusted Zone: http://www.avrilbandaids.com O16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} (CSEQueryObject Object) - http://www.myheritage.com/Genoogle/C...ngineQuery.dll O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by13fd.bay13.hotmail.msn.com/...x/HMAtchmt.ocx O18 - Filter hijack: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file) Now, close all the other open windows and then, in HijackThis, click on Fix Checked. Please delete the following file from the listed folder : Under C:\Program Files, delete the folder, Need2Find if you did not delete it before. Now, do the online scan with Kaspersky as posted by me before. |
| All times are GMT -4. The time now is 8:41 am. |
Forum system based on vBulletin Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
©2003 - 2009 DaniWeb® LLC