Spyware / Malware / Virus Removal
Destop Infected Wallpaper,No Sound or task manager
8 min read
SL28
Topic Starter
hi,
i need help getting rid of this infected wallpaper background.Also how to open my task manager again and get my sound back
ive ran Mcafee and malaware many times im recently scanning using malaware as im typing.
When i click Ctrl+Alt+Delete to bring up Windows Task Manager it says 'WARNING' stating that: 'Application cannot be executed. The file is infected. Please activate your anti virus software.
Since Monday a notification came up on my computer saying that my computer was infected and to turn on my antivirus software. My wallpaper was suddenly changed to a dark green background with a black rectangle placed in the middle of the screen. Inside the black rectangle there are the words 'Your system is infected!' in a bold capital red font, and then the words 'System has been stopped due to a serious malfunction.
this is a recent log ive gotten
Malwarebytes' Anti-Malware 1.41
Database version: 3270
Windows 5.1.2600 Service Pack 2
12/1/2009 7:53:59 PM
mbam-log-2009-12-01 (19-53-52).txt
Scan type: Quick Scan
Objects scanned: 135582
Time elapsed: 9 minute(s), 33 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 9
Memory Processes Infected:
C:\WINDOWS\SYSTEM32\winupdate86.exe (Trojan.Dropper) -> No action taken.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{c2b5aab8-2183-4be7-81a6-f11493c45872} (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c2b5aab8-2183-4be7-81a6-f11493c45872} (Trojan.FakeAlert) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c2b5aab8-2183-4be7-81a6-f11493c45872} (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a45a4b15-23f2-42ad-f4e4-00aac39c0004} (Trojan.Ertfor) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a45a4b15-23f2-42ad-f4e4-00aac39c0004} (Trojan.Ertfor) -> No action taken.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winupdate86.exe (Trojan.Dropper) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{a45a4b15-23f2-42ad-f4e4-00aac39c0004} (Trojan.Ertfor) -> No action taken.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Documents and Settings\ewm\Application Data\AntiVirus Plus (Rogue.AntiVirusPlus) -> No action taken.
C:\Documents and Settings\ewm\Local Settings\Application Data\p2pxmld8 (Trojan.Downloader) -> No action taken.
Files Infected:
C:\WINDOWS\SYSTEM32\winupdate86.exe (Trojan.Dropper) -> No action taken.
C:\Documents and Settings\ewm\Application Data\AntiVirus Plus\AntiVirus Plus.70367.dll (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\SYSTEM32\emp.exe (Trojan.Dropper) -> No action taken.
C:\WINDOWS\SYSTEM32\winlogon86.exe (Trojan.Dropper) -> No action taken.
C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\682.tmp (Rootkit.TDSS) -> No action taken.
C:\Documents and Settings\ewm\Application Data\avp.ico (Rogue.AntiVirusPlus) -> No action taken.
C:\WINDOWS\SYSTEM32\AVR10.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\SYSTEM32\winhelper86.dll (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\SYSTEM32\41.exe (Trojan.FakeAlert) -> No action taken.
please help
SL28
dds attach file
SweetTech
My name is SweetTech. I would be glad to take a look at your log and help you with solving any malware problems. I'd be grateful if you would note the following:
This may cause a delay, but I will do my best to keep it as short as possible.
I am checking over your log, I will post back shortly with instructions.
- Logs from malware removal programs (DDS is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
- Please make sure to carefully read any instruction that I give you.
Reading too lightly will cause you to miss important steps, which could have destructive effects. - If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
- These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
- Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
- If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
- I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together
Because of this, you must reply within five days. I will post a reminder should you seem to fail to do this, however, if you fail to reply within five days then,
unless I have been notified of your absence in advance, the topic shall be closed! - Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
This may cause a delay, but I will do my best to keep it as short as possible.
I am checking over your log, I will post back shortly with instructions.
SweetTech
Malwarebytes' Anti-Malware
I see that you have Malwarebytes' Anti-Malware installed on your computer could you please do a scan using these settings:
Re-Scanning with DDS
Please re-run DDS by sUBs.
Make sure to pay attention to the directions below:
[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Please make sure you include the following items in your next post:
1. The log that was produced after running MBAM.
2. The logs that were produced after running DDS. (DDS.txt & Attach.txt)
3. The log that was produced after running GMER.
4. An update on how your computer is currently running.
I see that you have Malwarebytes' Anti-Malware installed on your computer could you please do a scan using these settings:
- Open Malwarebytes' Anti-Malware
- Select the Update tab
- Click Check for Updates
- After the update have been completed, Select the Scanner tab.
- Select Perform quick scan, then click on Scan
- Leave the default options as it is and click on Start Scan
- When done, you will be prompted. Click OK, then click on Show Results
- Checked (ticked) all items and click on Remove Selected
- After it has removed the items, Notepad will open. Please post this log in your next reply. You can also find the log in the Logs tab. The bottom most log is the latest
Re-Scanning with DDS
Please re-run DDS by sUBs.
Make sure to pay attention to the directions below:
- Disable any script blocking protection (How to Disable your Security Programs)
- Double click DDS icon to run the tool (may take up to 3 minutes to run)
- When done, DDS.txt will open.
- After a few moments, attach.txt will open in a second window.
- Save both reports to your desktop.
- Post the contents of the DDS.txt report in your next reply
- Attach the Attach.txt report to your post by doing the following:
- Under the reply panel is the Attachments Panel
- Browse for the attachment file you want to upload, then click the green Upload button
- Once it has uploaded, click the Manage Current Attachments drop down box
- Click on [external image: Posted Image] to insert the attachment into your post
[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
- Extract the contents of the zipped file to desktop.
- Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
- If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
[external image: Posted Image]
Click the image to enlarge it
- In the right panel, you will see several boxes that have been checked. Uncheck the following …
- Sections
- IAT/EAT
- Drives/Partition other than Systemdrive (typically C:\)
- Show All (don't miss this one)
- Then click the Scan button & wait for it to finish.
- Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
- Save it where you can easily find it, such as your desktop, and attach it in your reply.
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Please make sure you include the following items in your next post:
1. The log that was produced after running MBAM.
2. The logs that were produced after running DDS. (DDS.txt & Attach.txt)
3. The log that was produced after running GMER.
4. An update on how your computer is currently running.
SL28
nevermind i found your old post with the same instructions yesterday and fixed it yesterday it works fine..thanks
SweetTech
It is never a good idea to follow someone else thread. I am not totally convinced that you are clean. You may still have infections on your computer that are not detected by MalwareBytes' Anti-Malware. Without seeing any logs I can't not be sure that your P.C. is in fact clean. I would suggest that you post the requested logs and include any additional logs from scans that you may have run on your computer without being directed to do so. If you do not respond to this thread within 3 days it will be closed.
Thank You,
SweetTech.
Thank You,
SweetTech.
SL28
but i followed your help instructions..im not bad with computers but never had this type of virus before..i checked everything no red x ,taskmanager opens,no highlighted icons, laware found 11 more viruses that day and i deleted them used gmer(like u said on last post) and turned off my computer.nextday i turned it on my regular background was there and sound too.
This is a post you replied to thats similar to mines
http://forums.whatthetech.com/Your_System_…nd_t108586.html
This is a post you replied to thats similar to mines
http://forums.whatthetech.com/Your_System_…nd_t108586.html
SweetTech
Absence of symptoms does not mean that everything is clear. You have/had a rather nasty infection on your system and without seeing any logs I can not guarantee that everything is clean on your end. If you no longer require my assistance in getting your computer all cleaned up then please let me know, so that I can have this thread closed and move on to another user who may require assistance.but i followed your help instructions..im not bad with computers but never had this type of virus before..i checked everything no red x ,taskmanager opens,no highlighted icons, laware found 11 more viruses that day and i deleted them used gmer(like u said on last post) and turned off my computer.nextday i turned it on my regular background was there and sound too.
This is a post you replied to thats similar to mines
http://forums.whatthetech.com/Your_System_…nd_t108586.html
Please Note: If I do not hear back from you within 3 days then this thread will be closed.
Thanks,
SweetTech.
ken545
Hi,
The absence of symptoms does not guarantee that all the malware is gone. If this was my computer I would want to know for sure . This thread will be closed, if you feel you still have issues please start a new topic.
Thank you SweetTech
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI