I'm infected and am hoping for some help.
Unfortunately, I'm computer savvy enough to be dangerous and so have tried lots of things before finding this site and making a post.
I am running Windows XP Pro SP3
Firefox and Windows Explorer.
McAfee security suite (AT&T DSL customer)
I picked up a virus looking for free online movies. The virus started doing popups of the fake "You are infected! You have to buy our stuff now!" I recognized it as fake and was wondering why McAfee hadn't started throwing up flags. I tried to open the security center in between all the popups. There were two types of popups, they almost looked like official ones. I eventually accidentally hit an OK button instead of the close button and it started to download and install something. I ended up turning the computer off at that point (I think, it was days ago by now and I'm sure I panicked when I realized what i did.
The thing tried to install Malware Defense.
One of the file names was richtx64.exe
I have run an old copy of HJT and fixed a few things (There should still be log files but I'm not sure)
I have run msconfig and made some adjustments.. (not sure what)
I tried to use system restore but it was blocked, wouldn't do anything, said there was errors and to restart the computer.
At some point system restore lost all the good save data from the past, it currently finds no saved data and cannot make any saves.
I have deleted files.
I have moved files.
I have stopped services.
I have deleted things in the registry that I am pretty sure were not good.
I have run a few online virus scanners. They found and cleaned some files that started with H8SRT.....
I have installed MBAM but it wouldn't run without renaming the .exe file.
I have installed SuperAntiSpywae free. It ran once but won't anymore.
Parts of McAfee seem to be running in the background but not doing anything.
I have uninstalled McAfee and thought I cleaned all my problems up then reinstalled McAfee and was surprised when it didn't work right again.
At one point MBAM would start normally but now it won't again.
I have had enough.
I am a father of 4 young kids and have a demanding wife who doesn't like me on the computer as it is so it may take a bit for me to get back with responses.
I thank you for your help in advance. I just wish I found this site and made a post before I made a bunch of changes.
I now see an forum entry by Tasha5505 about richx64.exe & wscsvc.exe entry that looks like the exact problem I am having.
Mvet
Edited by Mvet, 30 December 2009 - 05:49 PM.