Posted 16 February 2009 - 04:19 AM
Yesterday, my antivirus (McAfee) began giving a bunch of warnings that I was infected with trojans, etc. I'd had some about a month ago, so I already had Malwarebytes and SUPERAntiSpyWare and some other sofware and had luck with them previously.
The infection messages were coming pretty quickly, so I restarted my comp (running WinXP) and loaded into safe mode with networking, where I updated Malwarebytes and SAS. I intended to upload some logs here when I was done, since I figured I simply hadn't caught everything the last time. I didn't post the logs last time, assuming I'd caught it all.
So anyway, once I was in safe mode, I ran Malwarebytes it found a bunch of items and indicated that it needed to reboot to finish removing some of the items. I rebooted.
I again booted into safe mode and ran SAS, which also found several items and needed to reboot, which I did.
On reboot, I went into normal mode and ran Malwarebytes again, having seen several posts here saying that it runs better in normal mode. While it was running, my background wallpaper disappeared (and was replaced with bright fuscia color); Firefox loaded up on its own several times and tried to go to www.antivirusxp-pro2009.com/code=, and I had a new icon in the lower right corner (a red circle with a white plus sign) that having a bubble come up saying I was infected by a virus. This time Malwarebytes found only 4 items and needed to reboot to fix some of them.
I rebooted and ran Malwarebytes again. It found the same four items (or at least appeared to be the same). The Antivirus2009 stuff was gone, and I my background was back as a normal color (though not my usual wallpaper).
At this point, I figured I should post my logs, etc. for the experts here. I was still having some odd behavior -- McAfee wouldn't load up, and I was getting some error messages when Windows booted (one about TransferAgent not loading and one saying UTool would need to shut down and asking to send in an error report). I could not, however, get online to submit my logs. Both Firefox and IE would load, but neither would connect to any websites.
At this point, I decided to try a couple more things. I booted into safe mode and ran ATF-Cleaner. I also ran SDFix and Smithfraudfix.
I still couldn't get online, and McAfee was not working right. When I'd open the security center, most of the interface appeared as Xs (as though the pics that were supposed to load couldn't be found). I was able to click on the "fix" button to start the AV back up, but the Xs remained.
I thought at this point, I'd give SAS one more try, so I booted into safe mode. SAS found about 9 items. I rebooted and I thought I'd give Malwarebytes another try. It found several items and said it needed to reboot. However, while the scan was running, I kept having pop-ups from McAfee saying I was infected with "New Win32" and giving me the option to restart and rescan or close the pop-up, or saying that an infection had been cleaned from various places (one of these "places" looked like the notepad app).
At this point, I tried to reboot, but it would not start back up completely. The Windows startup sound would play, my background would come up and the login/password box comes up. After that, it says loading personal settings, and McAfee appears to load, but then no task bar, no icons, nothing. I did have another of the McAfee pop-ups at this point. I couldn't do anything and had to do a hard reboot with the power button. On reboot, the same thing happened.
It won't load into safe mode either now. It load to the same extent as in Normal mode (login box, McAfee appears to load etc.). Then it just sits there with the safe mode background (black with "safe mode" written in the corners) and no toolbar, start menu, or icons.
Am I hosed? Any help would be appreciated.