LandzDown Forum

Security => Analysis and Malware Removal => Topic started by: jmattinson on December 24, 2010, 02:55:36 PM

Title: Bad virus, need help
Post by: jmattinson on December 24, 2010, 02:55:36 PM
I have a Dell Dimension E510 running XP, SP 3.  I have a virus on my computer that will no longer let me run AVG (the free antivirus I was using) and won't let me install MalwareBytes.  I have tried running AVG and installing MalwareBytes from safe mode, but the computer won't let me.  What steps do I need to take to get rid of this problem?
Title: Re: Bad virus, need help
Post by: Corrine on December 26, 2010, 01:29:35 AM
Hi, jmattinson.  Welcome to LandzDown Forum.

We will do our best to assist you.  However, in order to do so, please follow all instructions provided in the sequence given.  Do not install/re-install any programs or run any fixes or scanners that you have not been instructed to use.  This may cause conflicts with the tools being used in the cleanup process.   

If you have questions regarding any of the instructions or problems running any tools, please let us know.

Please download rkill from one of the following links and save to your Desktop:

One (http://download.bleepingcomputer.com/grinler/rkill.exe), Two (http://download.bleepingcomputer.com/grinler/rkill.com),Three (http://download.bleepingcomputer.com/grinler/rkill.scr) or Four (http://download.bleepingcomputer.com/grinler/rkill.pif)
Notes:

If you you receive security warnings about rkill, please ignore and allow the download to continue.

Please download Malwarebytes' Anti-Malware (http://www.malwarebytes.org/mbam.php) to your desktop.

** Note **

If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.

NOTE If you restart the computer, you will need to run RKill again before running Malwarebytes.

Please download random's system information tool (RSIT):

Please post the MBAM log as well as the two logs from RSIT.