We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

Need help removing XP Antimalware - won't let me on net!

Glamazon
Glamazon Posts: 8,401 Forumite
I cant get on the net from my laptop to follow any advice on there.

would a system restore do anything?

help

thanks
A very busy Yummy Mummy to a 1 year old gorgeous boy :smileyhea

Where does the time go? :think:
«13

Comments

  • Browntoa
    Browntoa Posts: 49,620 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    folow these same steps

    http://forums.moneysavingexpert.com/showthread.html?t=2351993

    to get malwarebytes , or superantispyware on to a usb drive or CD
    Ex forum ambassador

    Long term forum member
  • Glamazon
    Glamazon Posts: 8,401 Forumite
    Sorted now thanks!

    I think it wasnt letting me on the net because I kept clicking to close the pop up when it came up on the taskbar.

    I got OH to download it onto a flashdrive and its now run on lappy and deleted the 13 infected objects.

    Once mine had finished his PC flashed up with the same Malware problem so I've just sorted it out for him and it's running a full scan now. :)

    Thanks for your help
    A very busy Yummy Mummy to a 1 year old gorgeous boy :smileyhea

    Where does the time go? :think:
  • Glamazon
    Glamazon Posts: 8,401 Forumite
    AAAAAAAAAAAAAGGGGGGGGGGGGGGGGGGGGHHHHHHHHHHHHHHHHHHHHHHHHH

    After getting rid of one it seems like I now have another one :mad:
    A very busy Yummy Mummy to a 1 year old gorgeous boy :smileyhea

    Where does the time go? :think:
  • Browntoa
    Browntoa Posts: 49,620 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    can i see the last malwarebytes log file for the pc
    Ex forum ambassador

    Long term forum member
  • Glamazon
    Glamazon Posts: 8,401 Forumite
    Malwarebytes' Anti-Malware 1.44
    Database version: 3890
    Windows 5.1.2600 Service Pack 2
    Internet Explorer 6.0.2900.2180

    21/03/2010 14:29:40
    mbam-log-2010-03-21 (14-29-40).txt

    Scan type: Full Scan (C:\|D:\|)
    Objects scanned: 188281
    Time elapsed: 37 minute(s), 45 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 1
    Registry Keys Infected: 7
    Registry Values Infected: 1
    Registry Data Items Infected: 5
    Folders Infected: 1
    Files Infected: 6

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    C:\WINDOWS\system32\rxup.rko (Backdoor.Bot) -> Delete on reboot.

    Registry Keys Infected:
    HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
    HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
    HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{494e6cec-7483-a4ee-0938-895519a84bc7} (Backdoor.Bot) -> Quarantined and deleted successfully.
    HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
    HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
    HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{494e6cec-7483-a4ee-0938-895519a84bc7} (Backdoor.Bot) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\idid (Trojan.Sasfix) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\uid (Malware.Trace) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\NetworkService\Local Settings\Application Data\ave.exe" /START "C:\Program Files\Internet Explorer\iexplore.exe") Good: (iexplore.exe) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (Explorer.exe rundll32.exe rxup.rko jrgsvde) Good: (Explorer.exe) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    Folders Infected:
    C:\WINDOWS\system32\lowsec (Stolen.data) -> Quarantined and deleted successfully.

    Files Infected:
    C:\WINDOWS\system32\rxup.rko (Backdoor.Bot) -> Delete on reboot.
    C:\WINDOWS\Temp\E.tmp (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\lowsec\local.ds (Stolen.data) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\lowsec\user.ds (Stolen.data) -> Quarantined and deleted successfully.
    C:\Documents and Settings\LocalService\Local Settings\Application Data\ave.exe (Rogue.MultipleAV) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Vicki\Local Settings\Application Data\ave.exe (Rogue.MultipleAV) -> Quarantined and deleted successfully.
    A very busy Yummy Mummy to a 1 year old gorgeous boy :smileyhea

    Where does the time go? :think:
  • Glamazon
    Glamazon Posts: 8,401 Forumite
    above is the latest log - thanks for the help :)

    I am getting random popups even though my pops up blocked and when I type something into google - like ebay, when I click on the ebay links I'm getting sent to random websites like goldenmotel and stuff!
    A very busy Yummy Mummy to a 1 year old gorgeous boy :smileyhea

    Where does the time go? :think:
  • macman
    macman Posts: 53,129 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    What AV are you using?
    No free lunch, and no free laptop ;)
  • Glamazon
    Glamazon Posts: 8,401 Forumite
    macman wrote: »
    What AV are you using?

    McAfee - but it says there's nothing on my laptop despite running a full scan.
    A very busy Yummy Mummy to a 1 year old gorgeous boy :smileyhea

    Where does the time go? :think:
  • macman
    macman Posts: 53,129 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    Glamazon wrote: »
    McAfee - but it says there's nothing on my laptop despite running a full scan.

    So what does that tell you about McAfee?
    Get yourself a decent AV: Avira, Kaspersky would be my preferences.
    No free lunch, and no free laptop ;)
  • enigma52
    enigma52 Posts: 642 Forumite
    well xp is on SP3 and ie is on ie8, both need updating
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 354.1K Banking & Borrowing
  • 254.3K Reduce Debt & Boost Income
  • 455.3K Spending & Discounts
  • 247.1K Work, Benefits & Business
  • 603.7K Mortgages, Homes & Bills
  • 178.3K Life & Family
  • 261.2K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.