i have a problem with Antivirus pro 2009 luckly i have another pc so i can connect to the internet otherwise it is a mission to on the page you want as the visrus stop you from going on the page you want. I followed mflynn post 8 step but when i copied and pasted the cmd code it was giving me an error mess wrong entry or cannot be find etc... can you help i need this crap virus off my system.
I wanna try something to see if it works on this infection - go ahead and attach the logs from the scans as well
Microsoft Windows Malicious Removal Tool
a. Click Start button
b. In the Start Search box, type timedata.cpl, and then press ENTER. The Date and Time dialog box opens.
c. On the Date and Time tab, click Change date and time. If the User Account Control dialog box opens, click Continue.
d. If you are prompted to type an administrator password, and you see administrator account names listed, you are not logged on with a computer administrator account. Type the administrator password and press ENTER. If you do not know the administrator password, you may have to ask the administrator of your computer for help.
Otherwise, if you are not prompted to type an administrator password, you are already logged on with a computer administrator account. Click Cancel, and then click Cancel again to close the Date and Time dialog box. Go to step 2.
a. Click Start button, point to All Programs, and then click Windows Update.
b. In the left pane, click Change settings.
c. Click to select Install updates automatically (recommended).
d. Under Recommended updates, click to select the Include recommended updates when downloading, installing, or notifying me about updates check box, and then click OK. If you are prompted for an administrative password or for confirmation, type the password or provide confirmation. Go to step 3.
Download the Malicious Software Removal Tool. Click Download then You must accept the Microsoft Software License Terms. The license terms are only displayed for the first time that you access Automatic Updates.
Right click the icon on your desktop and select Run As Administrator
Click Full Scan then click Next
Let the tool run
if u want im online i can connect via msn so u can tell me what to do its easier than waiting reply
***Removed contact info***
because done the 1st step start>search>then in c: timedata.cpl but doest found it.
then i though maybe u mean run and also doesnt work!!!?
dont hijack me pal....lol
Boot the infected computer to Safe mode, tap F8 prior to windows booting and select Safe Mode. We are going to use the 3 programs that you transferred.
Select 2 and hit Enter to delete infected files.
You will be prompted: Do you want to clean the registry ? answer Y (yes) and hit Enter in order to remove the Desktop background and clean registry keys associated with the infection.
The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found): Replace infected file ? answer Y (yes) and hit Enter to restore a clean file.
A reboot may be needed to finish the cleaning process. The report can be found at the root of the system drive, usually at C:\rapport.txt
Open the extracted SDFix folder and double click RunThis.bat to start the script.
Type Y to begin the cleanup process.
It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
Press any Key and it will restart the PC.
When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
Attach Report.txt back here
Double click combofix.exe & follow the prompts.
A window will open with a warning.
When the scan completes it will open a text window. Please attach that log back here together with a fresh HJT log.
Caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop. Combofix is a very powerful tool so please do NOT do anything without instruction
Combofix will automatically save the log file to C:\combofix.txt
All should be run from safe mode,
1) rapport.txt from smitfraudfix
2) report.txt from sdfix
3) combofix.txt from combofix