Author Topic: Virus Removal and System Restore Assistance Needed!  (Read 9537 times)

0 Members and 1 Guest are viewing this topic.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89118
  • No support PMs thanks
Re: Virus Removal and System Restore Assistance Needed!
« Reply #15 on: August 27, 2008, 12:05:37 AM »
It looks fake to me, how would it know you have malware on your system without doing a scan, answer it doesn't. The title in the Title Bar is very generic and seems to pretend to be official, e.g. 'Windows Warning Message!.'

I suspect that the Please Activate your antivirus button is the hook to infect or take you to a site to take your money or infect.

I have taken another look at your original log and this one it the culprit for this display.
HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe

Do a search of your system for this file scrnsave.exe - Ensure that you have hidden files and folders enabled and disable hide system files in Windows Explorer, Tools, Folder Options, Hidden files and folders, see image.

add the file to the User Files (File, Add) section of the avast chest (if it isn't already there) where it can do no harm and send it from there (select the file, right click, email to Alwil Software). No need to zip and PW protect when the sample is sent from chest. A copy of the file/s will remain in the original location, so any further action you take can remove that.

####
OK snoopytp  it should report the (Hijack.Wallpaper) again and it is possible that this is the cause of the change and your inability to change it back to the defaults. So select the entries for (Hijack.Wallpaper) and use the Remove Selected button. Don't worry we should be able to recover from Quarantine if required.

I will have a look at the new log, i was typing this when you posted.

Edit, it may well be best to also select the other items for removal as well:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispBackgroundPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispScrSavPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
« Last Edit: August 27, 2008, 12:08:58 AM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89118
  • No support PMs thanks
Re: Virus Removal and System Restore Assistance Needed!
« Reply #16 on: August 27, 2008, 12:15:36 AM »
OK, back after another look.

The (Hijack.DisplayProperties) entries look different to one on my system which I have had MBAM ignore, these ones are Policies\System and up a level in policies which means they are less likely to have been user set. So as my edit in the last posts says, add these to the Remove and click Remove Selected.

Now run MBMA again but this time a Quick scan should be enough and much quicker, report any findings.

Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

wyrmrider

  • Guest
Re: Virus Removal and System Restore Assistance Needed!
« Reply #17 on: August 27, 2008, 12:19:32 AM »
When davidR says " so select the entries"  he means to run the MBAM quick scan and to put a check in the box next to the hit
then click REMOVE
as DavidR says a backup will be generated

You're doing great
I do not have XP on this machine so cannot run MBAM so my instructions sometimes are to brief
thanks for understanding

snoopytp

  • Guest
Re: Virus Removal and System Restore Assistance Needed!
« Reply #18 on: August 27, 2008, 12:51:27 AM »
HI!

Thanks so much for all your help! I got my desktop display back and there aren't any more errors!

Here's the latest log!

I can't thank you all enough for your help! You guys are definitely going on my blog and Twitter!

wyrmrider

  • Guest
Re: Virus Removal and System Restore Assistance Needed!
« Reply #19 on: August 27, 2008, 01:13:35 AM »
Ah that log is better
now that the panic' over
can you run secunia software inspector and make sure your apps are up to date
run an on line AV scan like Kaspersky
report any hits- kaspersky finds but does not fix
since we removed avg let's monitor avast -
rt click the blue ball and click about- are your definitions current?  It should be today's date
rt click the blue ball and select update> programs
(did it work?)

download and run CCleaner- check things like temp files and cookeis, recycle bin to remove
defrag your hard drive
set a new restore point

how much memory do you- oops your computer have?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89118
  • No support PMs thanks
Re: Virus Removal and System Restore Assistance Needed!
« Reply #20 on: August 27, 2008, 02:14:47 AM »
Thanks so much for all your help! I got my desktop display back and there aren't any more errors!

Here's the latest log!

I can't thank you all enough for your help! You guys are definitely going on my blog and Twitter!

You're welcome.

The log looks fine now, sneaky little blighters ;D

I asked about what firewall you used as that is an essential part of your security ?

Now you are clean the task is to keep on top of it, update MBAM weekly and do a Quick scan as a back-up to avast, if avast does happen to detect something do a Full scan with MBAM.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security