HELP, Infected with XP 2008 antivirus, virus and having problems.
Dear Intelligent Collegues.
I was playing around in Olympics website and accidently picked up XP 2008 antivirus- virus. Now, my screensavers and Background wallpapers are no where to be found, not even a tab for them. and occasionaly crashes as well. I saw this program and tried to delete it but i was able to delete some of the files only cause i still have this problem. Can someone help me get rid of this viruns for good?? thank you
* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure to checkmark the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.
Make sure that you restart the computer.
The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
Download HijackThis Executable from here. Save it to your desktop.
Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished a window will pop up giving you the option of where to save it. Save it to desktop where it is easy to access. Open the log file and then go to the format Tab and make sure that wordwrap is unchecked. Copy the entire contents of the file & paste it into the body of your post. DO NOT FIX ANYTHING YET. Most of what is there is necessary for the running of your system.
^^You are a God sent, i will try it and let you know. I think it is people like you that give daniweb such a phenomenal reputation that it has. thanks.
I ran the PC tools registry mechanic. and after the scan, it looks like it found over 30 files that needs repair. but before i can repair it, i have the buy the full version. this is not free ? It looks like there is no way to remove or repair the bad files unless i buy the program. is this true ??
The link he gave me goes to that program i mentioned. i will try to find the right one but there are so many.
I tried both of Crunchie's links, first one takes me to correct download page on Majorgeeks for Malwarebytes' Anti-Malware and second link goes to Trend Secure for HiJackThis.
PC tools registry mechanic tool you downloaded from there is an advertisement (it notes that) on the lower right side of the MajorGeeks page but the download for Malwarebytes is at the very top with 5 download sites noted by the American flag.
Try this one for Malwarebytes' Anti-Malware Follow his instructions.
The five circled links will download MBAM. Do NOT click on the advert that appears immediately after clicking the download link. Just wait for the pop up window to appear with the MBAM download. It may take 15-20 seconds to show up.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:30:19 AM, on 8/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
THANK YOU SO MUCH CRUNCHIE, YOU ARE TRULY A BRILLIANT MAN. Did you attend Harvard ? Anyhow, the 1st program seem to have fixed the Wallpaper and Screen saver problem, at least for now. Screensaver tab has come back. but not sure if this is permament ? anyway, i posted the Hijackthis.log. I didn't fix anything there yet. i don't want to fix the wrong thing. Last time i messed with something like this, my computer would Not boot up to windows anymore.
Thank you, but all the credit belongs to those who create tools such as MBAM. If not for them, me and other helpers would struggle a lot more :).
You still have a serious infection there, so can you please do the following;
Please download ComboFix by sUBs from HERE or HEREYou must download it to and run it from your Desktop
Physically disconnect from the internet.
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log Re-enable all the programs that were disabled during the running of ComboFix.. Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.