Applications don't start, can't copy files, Troj/ByteV-Fam+Tro |
![]() ![]() |
Applications don't start, can't copy files, Troj/ByteV-Fam+Tro |
May 4 2009, 05:27 PM
Post
#1
|
|
|
New Member ![]() Posts: 3 OS: Windows XP |
Hi,
I have a home computer with windows XP, version 5.1 (Build 260.xspp_sp2_gdr.090206-1233), Service Pack 2 I am currently logged on in my user account and cannot run any applications except webroot antivirus with antispyware software. I suspect if I exit from this program then it won't run also, since that's what happened with internet explorer. Spy sweeper showed 4 infections in the last run - Mal/behave-066, Troj/ByteV-Fam, Troj/Byte-Veri-A and Mal/Generic-B The quarantine option did not work - that is quarantine failed. I cannot access the internet or any other applications including notepad. The error that comes up is "This application has failed to start because the application configuration is incorrect. Reinstalling the application may fix the error". With Internet explorer, it complains that cannot find the home page which is blank currently and when i click ok at the error in explorer window flashes for a second and disappears - so no internet explorer access. I cannot copy and paste a file..I could do that 10 minutes back but now I can't - it says insufficient system resources exist to complete the requested service. I can address the windows dos prompt (cmd) and run applications from there. So what should my steps be since I can't access the net or run any applications. An obvious thing might be to reboot the computer and see if it's in a better state to try installing the malware/virus cleaning software - the risk i fear is it may worsen compared to where i am currently. |
|
|
May 5 2009, 01:41 AM
Post
#2
|
|
|
Global Moderator Posts: 6,771 From: Puerto Rico OS: Windows XP, VISTA Home Premium |
Hi, mpari
Welcome. You will need an external drive such as, a Pen drive, where you may be able to copy the downloads of applications downloaded from another computer, then transfer to the sick computer and follow the instructions: Hi, Wrathofmath8 Welcome. Double Click mbam-setup.exe to install the application.
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly. ===================================================================== Please download ComboFix from Here or Here to your Desktop. **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall** |
|
|
May 5 2009, 04:28 PM
Post
#3
|
|
|
New Member ![]() Posts: 3 OS: Windows XP |
I could recover with respect to running applications and internet explorer by rebooting and running with the option run windows with last known working configuration (pressed F12 at power on)
So I downloaded the 2 programs that were suggested and logs are attached here is the log from running Malware bytes: Malwarebytes' Anti-Malware 1.36 Database version: 2079 Windows 5.1.2600 Service Pack 2 5/5/2009 12:57:07 PM mbam-log-2009-05-05 (12-57-07).txt Scan type: Quick Scan Objects scanned: 143599 Time elapsed: 36 minute(s), 34 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 3 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{4d25f926-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Program Files\MyWaySA (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Program Files\MyWaySA\SrchAsDe (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Program Files\MyWaySA\SrchAsDe\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully. Files Infected: (No malicious items detected) ******************************* here are the logs attached from running combofix.. combofix.txt and hijackthis050509.txt i am attaching it since unclear whether to be pasted or attached... So what are the next steps..are there still issues that need to be resolved? thanks so much!
Attached File(s)
ComboFix.txt ( 14.53K )
Number of downloads: 10
hijackthis050509.txt ( 12.38K )
Number of downloads: 10 |
|
|
May 5 2009, 04:53 PM
Post
#4
|
|
|
Global Moderator Posts: 6,771 From: Puerto Rico OS: Windows XP, VISTA Home Premium |
Hi, mpari
Logs seem clear. Are all sympyoms gone? |
|
|
May 5 2009, 06:20 PM
Post
#5
|
|
|
New Member ![]() Posts: 3 OS: Windows XP |
Hi,
I didn't have any of the symptoms after I rebooted with an old configuration. I ran webroot anitvirus with antispyware again and all the four infections showed up again: Mal/Behav-066, Troj/ByteV-Fam, Troj/Byte-Veri-A and Mal/Generic-B Except this time I could quarantine them with the software. Somehow I am not confident that it's all cleaned up. Any suggestions how I can get more confidence. Thanks! |
|
|
May 5 2009, 09:32 PM
Post
#6
|
|
|
Global Moderator Posts: 6,771 From: Puerto Rico OS: Windows XP, VISTA Home Premium |
Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan
Note: Turn Off your Security during the scan to avoid conflicts. |
|
|
May 19 2009, 09:36 PM
Post
#7
|
|
|
Global Moderator Posts: 6,771 From: Puerto Rico OS: Windows XP, VISTA Home Premium |
Due to lack of feedback, this topic has been closed.
If you need this topic reopened, please contact a staff member with address of this thread. This applies only to the original topic starter. Everyone else please begin a New Topic. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
2 / 451 | 11th March 2009 - 10:56 PM Missing started - last by Broni |
|||||
![]() |
2 / 413 | 30th May 2009 - 08:42 AM DeadOne started - last by cbarnard |
|||||
![]() |
2 / 679 | 4th July 2009 - 07:19 AM azle started - last by Transience |
|||||
![]() |
0 / 104 | 24th September 2009 - 10:05 AM averyj started - last by averyj |
|||||
|
Time is now: 7th November 2009 - 10:31 PM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising