lesser-equity

Magazine
Go Back   Computer Juice > Computer Software > Virus, Spyware & Security

Register


 Default 

Can The Great Evilfantasy Help Me with Malware???




Reply
 
Thread Tools
  #1  
Old 20th Feb 2009, 21:36
Member Group
 
Default Can The Great Evilfantasy Help Me with Malware???

Ohh boy. I picked up a host of malware. Is Evilfantasy out there? He really helped me last time this happened. Here are my main problems still.

My Windows XP splash screen was changed. It is now hard to switch user. we see the small splash screen instead of the nice big blue screen.

My system restore was hijacked.

Takes a long time on startup.

Print Shop 22 does not work now.

My printer does not print.

I keep getting IE error pages. It is a miracle I got to this page.

I've done all the steps I should have to be able to post my logs.

Here they are:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 02/20/2009 at 09:15 PM
Application Version : 4.25.1012
Core Rules Database Version : 3769
Trace Rules Database Version: 1728
Scan type : Complete Scan
Total Scan Time : 02:30:09
Memory items scanned : 377
Memory threats detected : 0
Registry items scanned : 7831
Registry threats detected : 39
File items scanned : 123579
File threats detected : 41
Adware.Tracking Cookie
C:\Documents and Settings\John\Cookies\john@mediaplex[2].txt
C:\Documents and Settings\John\Cookies\john@doubleclick[2].txt
C:\Documents and Settings\John\Cookies\john@tribalfusion[2].txt
C:\Documents and Settings\John\Cookies\john@atdmt[1].txt
C:\Documents and Settings\John\Cookies\john@apmebf[1].txt
C:\Documents and Settings\Gabby\Cookies\gabby@ad.yieldmanager[1].txt
C:\Documents and Settings\Gabby\Cookies\gabby@atdmt[2].txt
C:\Documents and Settings\Gabby\Cookies\gabby@realmedia[2].txt
Trojan.Unknown Origin
HKLM\SYSTEM\CurrentControlSet\Enum\Root\legacy_cce vtsvc
HKLM\SYSTEM\CurrentControlSet\Enum\Root\legacy_cce vtsvc#NextInstance
HKLM\SYSTEM\CurrentControlSet\Enum\Root\legacy_cce vtsvc\0000
HKLM\SYSTEM\CurrentControlSet\Enum\Root\legacy_cce vtsvc\0000#Service
HKLM\SYSTEM\CurrentControlSet\Enum\Root\legacy_cce vtsvc\0000#Legacy
HKLM\SYSTEM\CurrentControlSet\Enum\Root\legacy_cce vtsvc\0000#ConfigFlags
HKLM\SYSTEM\CurrentControlSet\Enum\Root\legacy_cce vtsvc\0000#Class
HKLM\SYSTEM\CurrentControlSet\Enum\Root\legacy_cce vtsvc\0000#ClassGUID
HKLM\SYSTEM\CurrentControlSet\Enum\Root\legacy_cce vtsvc\0000#DeviceDesc
HKLM\SYSTEM\CurrentControlSet\Enum\Root\legacy_cce vtsvc\0000\Control
HKLM\SYSTEM\CurrentControlSet\Enum\Root\legacy_cce vtsvc\0000\Control#ActiveService
HKLM\SYSTEM\CurrentControlSet\Services\ccevtsvc
HKLM\SYSTEM\CurrentControlSet\Services\ccevtsvc#Ty pe
HKLM\SYSTEM\CurrentControlSet\Services\ccevtsvc#St art
HKLM\SYSTEM\CurrentControlSet\Services\ccevtsvc#Er rorControl
HKLM\SYSTEM\CurrentControlSet\Services\ccevtsvc#Im agePath
HKLM\SYSTEM\CurrentControlSet\Services\ccevtsvc#Di splayName
HKLM\SYSTEM\CurrentControlSet\Services\ccevtsvc#Ob jectName
HKLM\SYSTEM\CurrentControlSet\Services\ccevtsvc\Se curity
HKLM\SYSTEM\CurrentControlSet\Services\ccevtsvc\Se curity#Security
HKLM\SYSTEM\CurrentControlSet\Services\ccevtsvc\En um
HKLM\SYSTEM\CurrentControlSet\Services\ccevtsvc\En um#0
HKLM\SYSTEM\CurrentControlSet\Services\ccevtsvc\En um#Count
HKLM\SYSTEM\CurrentControlSet\Services\ccevtsvc\En um#NextInstance
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP56\A0015590.SYS
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP56\A0015598.SYS
C:\WINDOWS\SYSTEM32\1C.TMP
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\G96J0367\AL[1].TXT
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\G96J0367\AL[2].TXT
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\U9MJE1MT\AL[1].TXT
C:\WINDOWS\SYSTEM32\D.TMP
C:\WINDOWS\SYSTEM32\E9.TMP
C:\WINDOWS\SYSTEM32\F9C.TMP
Rogue.Component/Trace
HKLM\Software\Microsoft\34CF24AE
HKLM\Software\Microsoft\34CF24AE#34cf24ae
HKLM\Software\Microsoft\34CF24AE#rid
HKLM\Software\Microsoft\34CF24AE#aid
HKLM\Software\Microsoft\34CF24AE#Version
HKLM\Software\Microsoft\34CF24AE#34cf892e
HKLM\Software\Microsoft\34CF24AE#34cfe0cb
HKU\S-1-5-21-1939078423-1430588720-911139758-1006\Software\Microsoft\CS41275
HKU\S-1-5-21-1939078423-1430588720-911139758-1006\Software\Microsoft\FIAS4018
HKU\S-1-5-21-1939078423-1430588720-911139758-1006\Software\Microsoft\FIAS4050
Trojan.Fake-Alert/Trace
HKU\S-1-5-21-1939078423-1430588720-911139758-1006\SOFTWARE\Microsoft\fias4013
Rogue.MSAntiSpyware2009
HKU\.DEFAULT\Software\CrucialSoft Ltd
HKU\S-1-5-18\Software\CrucialSoft Ltd
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVer sion\Uninstall\MS AntiSpyware 2009 5.7
HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Unins tall\MS AntiSpyware 2009 5.7
Trojan.Agent/Gen-Reader_S
C:\DOCUMENTS AND SETTINGS\JOHN\READER_S.EXE
Trojan.Agent/Gen-NumTemp
C:\WINDOWS\SYSTEM32\11.TMP
C:\WINDOWS\SYSTEM32\14.TMP
C:\WINDOWS\SYSTEM32\15.TMP
C:\WINDOWS\SYSTEM32\16.TMP
C:\WINDOWS\SYSTEM32\17.TMP
C:\WINDOWS\SYSTEM32\18.TMP
C:\WINDOWS\SYSTEM32\19.TMP
C:\WINDOWS\SYSTEM32\21.TMP
C:\WINDOWS\SYSTEM32\22.TMP
C:\WINDOWS\SYSTEM32\24.TMP
C:\WINDOWS\SYSTEM32\26.TMP
C:\WINDOWS\SYSTEM32\27.TMP
C:\WINDOWS\SYSTEM32\29.TMP
C:\WINDOWS\SYSTEM32\4.TMP
C:\WINDOWS\SYSTEM32\40.TMP
C:\WINDOWS\SYSTEM32\42.TMP
C:\WINDOWS\SYSTEM32\43.TMP
C:\WINDOWS\SYSTEM32\5.TMP
C:\WINDOWS\SYSTEM32\6.TMP
C:\WINDOWS\SYSTEM32\8.TMP
C:\WINDOWS\SYSTEM32\9.TMP
Trojan.Dropper/Sys-NV
C:\WINDOWS\SYSTEM32\B.TMP
Trojan.Agent/Gen-UGR
C:\WINDOWS\SYSTEM32\F9E.TMP

Malwarebytes' Anti-Malware 1.34
Database version: 1771
Windows 5.1.2600 Service Pack 3
2/20/2009 9:43:41 PM
mbam-log-2009-02-20 (21-43-41).txt
Scan type: Quick Scan
Objects scanned: 83630
Time elapsed: 7 minute(s), 15 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 17
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\restore (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\CcEvtSvc (Trojan.MyDoom) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID (Malware.Trace) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\WINDOWS\system32\twain_32 (Backdoor.Bot) -> Quarantined and deleted successfully.
Files Infected:
C:\WINDOWS\system32\twain_32\local.ds (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\twain_32\user.ds (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\2.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\3.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\4.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\5.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\6.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\7.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\9.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\A.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\B.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\C.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\E.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\F.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\services.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\twext.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\CcEvtSvc.exe (Trojan.MyDoom) -> Quarantined and deleted successfully.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:19:51 PM, on 2/20/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\System32\reader_s.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\gearsec.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\John\reader_s.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\juice.exe.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDO WS\TEMP\init.exe,
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [reader_s] C:\Documents and Settings\John\reader_s.exe
O4 - HKUS\S-1-5-18\..\Run: [reader_s] C:\Documents and Settings\John\reader_s.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [reader_s] C:\Documents and Settings\John\reader_s.exe (User 'Default user')
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: FLV Getter - C:\Program Files\FlvGetter\FlvGetter.html
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://asp.mathxl.com/wizmodules/tes...enXInstall.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.clarkcolor.com/ClarkActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {4BFD075D-C36E-4F28-BB0A-5D472795197A} (PowerLoader Class) - http://www.powerchallenge.com/applet/PowerLoader.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://download.bitdefender.com/reso...an8/oscan8.cab
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.com/books/_Players...stallAsst2.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - https://www.auctionplayer.com/member...eUploader3.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: muwhcf.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GearSecurity - GEAR Software - C:\WINDOWS\system32\gearsec.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
--
End of file - 7930 bytes

Evilfantasy if you can help me that would be beautiful.

You were able to help me once before. You even got me a new sysrestore - with that neat software you had me use.

I hope I remember how to check back with this thread to see if I got an answer.

Thanks!
action

I'm trying to submit the thread but keep getting IE error pages...uh-oh.
  #2  
Old 20th Feb 2009, 21:40
Member Group
 
Default Can The Great Evilfantasy Help Me with Malware???

Seems I can't quick message.....
  #3  
Old 21st Feb 2009, 10:11
Moderator Group
 
Default Can The Great Evilfantasy Help Me with Malware???

I'm afraid you have been hit by Virut, which there is no cure for other that a reformat and reinstall. We can look closer.

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double click combofix.exe & follow the prompts.
When finished ComboFix will produce a log for you.
Post the ComboFix log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

If you have problems with ComboFix usage, see How to use ComboFix
__________________

  #4  
Old 21st Feb 2009, 12:52
Member Group
 
Default Can The Great Evilfantasy Help Me with Malware???

I'm on my sons laptop. I can't even boot up on my virus laden pc. I tried the combix - it did not give me a log. It did put the icons back up on my screen though. I can't go on IE at all now. I'm not sure what to do now.

I do not know how to reformat, save old drive files, programs etc.

Any suggestions?
  #5  
Old 21st Feb 2009, 13:01
Moderator Group
 
Default Can The Great Evilfantasy Help Me with Malware???

Those symptoms are just what Virut is doing.

Disconnect it from the Internet and reformat then reinstall.

If you need help with reformatting start a new topic in the Windows forum and they will help.

Sorry but this new release is killing many computers at the moment. It installs it's own IRC channel and turns you into a zombie server distributing itself.
__________________

  #6  
Old 21st Feb 2009, 15:32
Donor Group
 
Default Can The Great Evilfantasy Help Me with Malware???

Quote:
Originally Posted by evilfantasy View Post
Those symptoms are just what Virut is doing.

Disconnect it from the Internet and reformat then reinstall.

If you need help with reformatting start a new topic in the Windows forum and they will help.

Sorry but this new release is killing many computers at the moment. It installs it's own IRC channel and turns you into a zombie server distributing itself.
So whats the best way to protect my pc from getting infected with this virus Evilfantasy?
do i just keep upto date with my firewall and antivirus?
__________________
If builders built buildings the way programmers wrote programs, then the first woodpecker that came along would destroy civilization.

A computer once beat me at chess
But it was no match for me at kick boxing.
__________________

My System: redden137

Processor(s):
amd opteron 165 o/c
Motherboard:
asus a8n sli deluxe
RAM Memory:
2gb corsair xms pc3200 platium
Graphics Card(s):
8800gts o/c
Sound Card:
creative soundblaster 4
Hard Drive(s):
1x 80 gb 2x 250gb
Optical Drive(s):
1x sony dvd ram drive 1xphillips dv
Case / PSU:
700w moduler psu
Cooling:
air
Network / Internet:
Monitor(s):
22in widescreen
Operating System(s):
xp pro
  #7  
Old 21st Feb 2009, 15:41
Moderator Group
 
Default Can The Great Evilfantasy Help Me with Malware???

From what I've read the major AV vendors have released updates dealing with it so yes, update and be careful what you download or open as an email/chat attachment.
__________________

  #8  
Old 21st Feb 2009, 15:46
Donor Group
 
Default Can The Great Evilfantasy Help Me with Malware???

Ok thanks,
so its really just basic security measures which we all should know and adhere to
__________________
If builders built buildings the way programmers wrote programs, then the first woodpecker that came along would destroy civilization.

A computer once beat me at chess
But it was no match for me at kick boxing.
Reply

Register

Bookmarks

Similar Threads
Thread Thread Starter Forum Replies Last Post
Hjt log for EvilFantasy solotekk Virus, Spyware & Security 3 8th Dec 2008 22:56
Thanks EvilFantasy! Kona1984hawaii Off Topic Discussion 2 4th Nov 2007 04:30
Evilfantasy please be having a good day vic66 Virus, Spyware & Security 19 2nd Sep 2007 08:58
Thread Tools




Arabic Bulgarian Chinese (Simplified) Chinese (Traditional) Croatian Czech Danish Dutch English Finnish French German Greek Hebrew Hungarian Italian Japanese Korean Latvian Lithuanian Norwegian Polish Portuguese Romanian Russian Serbian Slovak Spanish Swedish Thai Turkish Ukrainian

Copyright ©2006 - 2009 Computer Juice.

Powered by vBulletin® Copyright ©2000 - 2009 Jelsoft Enterprises Ltd. SEO by vBSEO ©2009, Crawlability, Inc.