We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Help got virus, cant access desktop pc UPDATE, pls advise

24567

Comments

  • MrsE_2
    MrsE_2 Posts: 24,162 Forumite
    10,000 Posts Combo Breaker
    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org
    Database version: 4052
    Windows 6.0.6002 Service Pack 2
    Internet Explorer 8.0.6001.19019
    13/02/2011 13:31:11
    mbam-log-2011-02-13 (13-31-11).txt
    Scan type: Full scan (C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|)
    Objects scanned: 322130
    Time elapsed: 2 hour(s), 12 minute(s), 3 second(s)
    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 1
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0
    Memory Processes Infected:
    (No malicious items detected)
    Memory Modules Infected:
    (No malicious items detected)
    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a078f691-9c07-4af2-bf43-35e79eecf8b7} (Adware.Softomate) -> Quarantined and deleted successfully.
    Registry Values Infected:
    (No malicious items detected)
    Registry Data Items Infected:
    (No malicious items detected)
    Folders Infected:
    (No malicious items detected)
    Files Infected:
    (No malicious items detected)
  • MrsE_2
    MrsE_2 Posts: 24,162 Forumite
    10,000 Posts Combo Breaker
    spud17 wrote: »
    Stick with Browntoas advice,

    But more info on system tool removal below, used it myself to sort a friends PC.

    http://www.bleepingcomputer.com/virus-removal/remove-system-tool

    Thats it :eek:
  • MrsE_2
    MrsE_2 Posts: 24,162 Forumite
    10,000 Posts Combo Breaker
    :(Malware is finished & says all is OK now.

    So I rebooted.

    The navy screen with all the warning was there again when I rebooted & the "system tool" http://www.bleepingcomputer.com/viru...ve-system-tool has returned:(
  • MrsE_2
    MrsE_2 Posts: 24,162 Forumite
    10,000 Posts Combo Breaker
    Could you elaborate on this, please? What does it say?
    Warning!
    Your're in Danger!
    Your Computer is infected with Spyware!
    All you do with your computer is stored forever in your hard disk. When you visit sites, send emails... All your actions are logged. And it is impossible to remove them with standard tools. Your data is still available for forensics, and in some cases
    For your boss, your friends, your wife, your children. Every site you or somebody or even something, like spyware, opened in your browsers, with all the images, and all the downloaded and maybe later removed movies or mp3 songs - ARE STILL THERE and could break your life!
    Secure yourself right now!
    Removal all spyware from your PC!
  • Browntoa
    Browntoa Posts: 49,612 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    MrsE wrote: »
    :(Malware is finished & says all is OK now.

    So I rebooted.

    The navy screen with all the warning was there again when I rebooted & the "system tool" http://www.bleepingcomputer.com/viru...ve-system-tool has returned:(

    follow the steps shown on the bleeping computer article

    its changed your internet settings

    follow it through step by step as it shows(you will need to print them out )
    Ex forum ambassador

    Long term forum member
  • spud17
    spud17 Posts: 4,434 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    +1 for the above post, print the instructions, read them a couple of times to get the gist of what you're trying to achieve.

    Work through each bit and take your time.

    It'll take a couple (?) of hours. Good luck.
    Move along, nothing to see.
  • Browntoa
    Browntoa Posts: 49,612 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    yes , it looks worse (and scarier) than it really is , the various tools do ALL the work for you ;)
    Ex forum ambassador

    Long term forum member
  • MrsE_2
    MrsE_2 Posts: 24,162 Forumite
    10,000 Posts Combo Breaker
    edited 13 February 2011 at 4:36PM
    Browntoa wrote: »
    follow the steps shown on the bleeping computer article

    its changed your internet settings

    follow it through step by step as it shows(you will need to print them out )

    Unfortunately I've been having printer trouble & despite having ink (& being reinstalled) it won't print (but it sounds like it is).

    So I will have to wait till tomorrow to print them off.
  • fiddiwebb
    fiddiwebb Posts: 1,806 Forumite
    MrsE wrote: »
    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org
    Database version: 4052
    Windows 6.0.6002 Service Pack 2
    Internet Explorer 8.0.6001.19019
    13/02/2011 13:31:11
    mbam-log-2011-02-13 (13-31-11).txt
    Scan type: Full scan (C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|)
    Objects scanned: 322130
    Time elapsed: 2 hour(s), 12 minute(s), 3 second(s)
    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 1
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0
    Memory Processes Infected:
    (No malicious items detected)
    Memory Modules Infected:
    (No malicious items detected)
    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a078f691-9c07-4af2-bf43-35e79eecf8b7} (Adware.Softomate) -> Quarantined and deleted successfully.
    Registry Values Infected:
    (No malicious items detected)
    Registry Data Items Infected:
    (No malicious items detected)
    Folders Infected:
    (No malicious items detected)
    Files Infected:
    (No malicious items detected)

    Malwarebytes is out of date, the newest engine version is 1.50.1.1100 and the database version should be 5754 at the time of posting this message

    If you cannot update Malwarebytes from your desktop start in "safe mode with networking" and try updating from there.

    Once you have updated to the newest engine version press the update button again to check you have the latest database version.

    Once you have all updates run a full scan and make sure you remove anything Malwarebytes finds and then post the log file in your next message,
  • MrsE_2
    MrsE_2 Posts: 24,162 Forumite
    10,000 Posts Combo Breaker
    fiddiwebb wrote: »
    Malwarebytes is out of date, the newest engine version is 1.50.1.1100 and the database version should be 5754 at the time of posting this message

    If you cannot update Malwarebytes from your desktop start in "safe mode with networking" and try updating from there.

    Once you have updated to the newest engine version press the update button again to check you have the latest database version.

    Once you have all updates run a full scan and make sure you remove anything Malwarebytes finds and then post the log file in your next message,

    I uninstalled the old version & reinstalled from scratch. Found three more "bugs".

    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org
    Database version: 5754
    Windows 6.0.6002 Service Pack 2
    Internet Explorer 8.0.6001.19019
    13/02/2011 21:49:54
    mbam-log-2011-02-13 (21-49-54).txt
    Scan type: Full scan (C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|)
    Objects scanned: 360108
    Time elapsed: 1 hour(s), 29 minute(s), 51 second(s)
    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 2
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 1
    Memory Processes Infected:
    (No malicious items detected)
    Memory Modules Infected:
    (No malicious items detected)
    Registry Keys Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{258C9770-1713-4021-8D7E-1F184A2BD754} (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{BDEA95CF-F0E6-41E0-BD3D-B00F39A4E939} (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
    Registry Values Infected:
    (No malicious items detected)
    Registry Data Items Infected:
    (No malicious items detected)
    Folders Infected:
    (No malicious items detected)
    Files Infected:
    c:\Users\Kim\AppData\Local\microsoft\Windows\temporary internet files\Content.IE5\9273NYYR\antispywaresetup[1].exe (Rogue.Palladium) -> Quarantined and deleted successfully.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.7K Banking & Borrowing
  • 253.4K Reduce Debt & Boost Income
  • 454K Spending & Discounts
  • 244.7K Work, Benefits & Business
  • 600.2K Mortgages, Homes & Bills
  • 177.3K Life & Family
  • 258.4K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.