WiredWX Hobby Weather ToolsLog in

 


Horrible virus deactivated my antivirus, ie, ad aware etc!

3 posters

descriptionHorrible virus deactivated my antivirus, ie, ad aware etc! EmptyHorrible virus deactivated my antivirus, ie, ad aware etc!

more_horiz
I got a virus the other day that won't let me access any of my anti spyware, anti virus, and not my internet explorer!! When I double click on the icons, it brings up the CMD - command prompt! When I try to download ANYTHING to get rid of it, it brings up the CMD. I am beyond frustrated! I am using a friend's computer looking for any possible source of assistance. Please please help.

descriptionHorrible virus deactivated my antivirus, ie, ad aware etc! EmptyRe: Horrible virus deactivated my antivirus, ie, ad aware etc!

more_horiz
ALSO, it brings up the desot.exe file in the command prompt saying it cannot be found? My computer has also downloaded the Windows Antivirus pro which I know is malware!

descriptionHorrible virus deactivated my antivirus, ie, ad aware etc! EmptyRe: Horrible virus deactivated my antivirus, ie, ad aware etc!

more_horiz
bump

descriptionHorrible virus deactivated my antivirus, ie, ad aware etc! EmptyRe: Horrible virus deactivated my antivirus, ie, ad aware etc!

more_horiz
Please download the current version of HijackThis from HERE

  • Double click and run the installer.
  • It will install to C:\Program Files\Trend Micro\HijackThis\hijackthis.exe
  • After installing, you should get the user agreement, press accept and Hijack This will run.
  • Select Do a system scan and save a log file. This will open a notepad file of everything Hijack This found, copy and paste it back here.

descriptionHorrible virus deactivated my antivirus, ie, ad aware etc! EmptyRe: Horrible virus deactivated my antivirus, ie, ad aware etc!

more_horiz
the virus deactivated my notepad. AND i am only accessing the internet through search/then clicking on search the internet. I'm pretty limited to what I can do...please help :-(

descriptionHorrible virus deactivated my antivirus, ie, ad aware etc! EmptyRe: Horrible virus deactivated my antivirus, ie, ad aware etc!

more_horiz
Hello.
Does Wordpad work instead?

Go to Start > Run. Type in "wordpad" without the quote and hit enter.
Does Wordpad open?

descriptionHorrible virus deactivated my antivirus, ie, ad aware etc! EmptyRe: Horrible virus deactivated my antivirus, ie, ad aware etc!

more_horiz
No, the CMD black box pops up with the desot.exe. I did find that if I go into windows and open up files that have used it I can access the wordpad/notepad. So i do have a way to access it....

descriptionHorrible virus deactivated my antivirus, ie, ad aware etc! EmptyRe: Horrible virus deactivated my antivirus, ie, ad aware etc!

more_horiz
Hello.
This infection is new, but we can beat it. First, lets put a stop to that desot.exe

Delete this file in bold:
C:\Windows\system32\desot.exe

Let me know if you can delete it, if you can, follow on with the rest of my instructions, and if not, let me know.

Now once desot.exe is gone, you will get the "open with..." every time you open something. It's a little annoying, but for now, it opens a window we can use.

When you try to open the logfile now, you will get the open with, so select Notepad or Wordpad if it's there.

The log file should open normally.

descriptionHorrible virus deactivated my antivirus, ie, ad aware etc! EmptyRe: Horrible virus deactivated my antivirus, ie, ad aware etc!

more_horiz
I was able to delete the desot file, and everything i click on comes up with "open up with" like you stated. My internet was deleted from this virus and I can only access it from the start/search/search the internet option, do I need it to download hijack this? I have tried and it won't let me run it without clicking notepad or wordpad, however it doesn't do a system scan. For the install do I have to click on open with notepad or wordpad? I don't know how to otherwise!

descriptionHorrible virus deactivated my antivirus, ie, ad aware etc! EmptyRe: Horrible virus deactivated my antivirus, ie, ad aware etc!

more_horiz
Hello.
Please right click THIS LINK and select "Save target as..." or "save link as..." depending on which browser you are using.

Save the exefix.reg on your Desktop and double click on it to run it. Does open automatically with Notepad? or the open with menu?

descriptionHorrible virus deactivated my antivirus, ie, ad aware etc! EmptyRe: Horrible virus deactivated my antivirus, ie, ad aware etc!

more_horiz
I was able to download it but when I double click it, it brings up the registry editor asking if I wanted to add the information in the registry and then when I click yes it states it has been successfully added to the registry. I can right click it and open it manually with notepad though....the hijack doens't do anything when I open it either...

descriptionHorrible virus deactivated my antivirus, ie, ad aware etc! EmptyRe: Horrible virus deactivated my antivirus, ie, ad aware etc!

more_horiz
Please download SilentRunners from here:
http://www.silentrunners.org/Silent%20Runners.zip
Unzip it to the desktop and double-click on it. If you get any kind of warning message about scripts, please choose to allow the script to run. When the scan is finished, a message will pop up and a logfile will have been created on the desktop. Please post the entire contents of this logfile for me to see.

descriptionHorrible virus deactivated my antivirus, ie, ad aware etc! EmptyRe: Horrible virus deactivated my antivirus, ie, ad aware etc!

more_horiz
I was unable to open the file yesterday from the search/search the internet option, I wasn't able to be able to download the internet explorer but I was able to download Firefox today. I opened the file and following is my log file

descriptionHorrible virus deactivated my antivirus, ie, ad aware etc! EmptyRe: Horrible virus deactivated my antivirus, ie, ad aware etc!

more_horiz
"Silent Runners.vbs", revision 59, http://www.silentrunners.org/
Operating System: Windows XP
Output limited to non-default values, except where indicated by "{++}"

descriptionHorrible virus deactivated my antivirus, ie, ad aware etc! EmptyRe: Horrible virus deactivated my antivirus, ie, ad aware etc!

more_horiz
Startup items buried in registry:
---------------------------------

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"ctfmon.exe" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
"updateMgr" = ""C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1" ["Adobe Systems Incorporated"]
"MoneyAgent" = ""C:\Program Files\Microsoft Money\System\mnyexpr.exe"" [MS]
"LDM" = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" ["Logitech"]
"Monopod" = "C:\DOCUME~1\Lind\LOCALS~1\Temp\c.exe" [file not found]
"braviax" = "C:\WINDOWS\system32\braviax.exe" [null data]
"yahoo!" = "C:\WINDOWS\system32\rundll32.exe C:\DOCUME~1\Lind\LOCALS~1\Temp\33124733026don.dll,Set" [MS]

descriptionHorrible virus deactivated my antivirus, ie, ad aware etc! EmptyRe: Horrible virus deactivated my antivirus, ie, ad aware etc!

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum