Well the pro's may have some specific advice for you, but IMHO if your infection keeps coming back it can only be one of two things, either something your installing\connecting is infected, maybe a back up or a thumb drive etc, or the more probable cause is it's a memory resident infection, these are nasty things, because even with a full low level format and a clean install, they actually hide in the systems memory during this, and as soon as your installed again it comes back.
Personally when an infection is that bad, I low level format, I then remove the mains lead and pop the CMOS battery, then move the jumper for the CMOS to the clear position (not forgetting to put it back when done), if I have done this before with no luck I leave it like that overnight, otherwise 10 minutes should be plenty, some may say it's overkill and 30 seconds is enough, but given the time and effort that goes into reinstalling it seems a small price to pay to be sure to of cleared it, this will stop it coming back, unless you have something else infected as I suggested already.
I guess the main question is what have you done\tried so far to get this problem sorted ?
I suspect you may be better off posting a log in the Hijack section and the pro's will see whats going on and hopefully sort it, but they are busy people so I want to check what you've done so far, and what it is thats reporting your infected, then we can go from there.
Yes it is the same computer and here is the log from malwarebytes. I was stupid and downloaded a fake spybot search and destroy. I don't know how, I just wasn't paying attention. As you can see one infected the system volume restore. I think turning off system restore will fix it cause it will delete all the restore points. Am I correct? I will also contain a hijack this log.
Malwarebytes' Anti-Malware 1.40
Database version: 2672
Windows 5.1.2600 Service Pack 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\AntiSpywareBot (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Documents and Settings\Admin\Application Data\AntiSpywareBot (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Admin\Application Data\AntiSpywareBot\Log (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Admin\Application Data\AntiSpywareBot\Settings (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
Files Infected:
C:\System Volume Information\_restore{EE1C5025-AD14-4C07-850E-AB7D39591DED}\RP174\A0093777.rbf (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Admin\Application Data\AntiSpywareBot\rs.dat (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Admin\Application Data\AntiSpywareBot\Log\2009 Aug 20 - 10_07_58 PM_203.log (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Admin\Application Data\AntiSpywareBot\Settings\ScanResults.pie (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\AntispywareBot Scheduled Scan.job (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
Hijack this log.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:47:28 PM, on 8/21/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
1.
Click Start.
2.
Point to All Programs.
3.
Point to Accessories.
4.
Point to System Tools.
5.
Click System Restore.
6.
Follow the instructions on the wizard.
Find the date we cleaned it.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please begin a New Topic.
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI