WiredWX Hobby Weather ToolsLog in

 


unknown virus

2 posters

descriptionunknown virus - Page 2 EmptyRe: unknown virus

more_horiz
Hello. The Daemon error is caused by this startup, fix it in Hijack This.

  • Open HijackThis
  • Choose "Do a system scan only"
  • Check the boxes in front of these lines:


    O4 - HKCU\..\RunOnce: [DAEMON Tools Lite 4.30.1 Setup] "C:\OLD downloads\daemon4301-lite.exe"


  • Press "Fix Checked"
  • Close Hijack This.

Yikes!.... not good. Sad tearing

I didn't see any signs of patched files in DDS, but if Combofix has dected a file patcher, you possibly have Virut.

Virut is a polymorphic file infector. See here for details:
http://miekiemoes.blogspot.com/2009/02/virut-and-other-file-infectors-throwing.html

Your only option maybe to format.

descriptionunknown virus - Page 2 EmptyRe: unknown virus

more_horiz
yea thats what i did b4, some how it spread over to my new copy of vista.i had it on one hard drive and just to be safe i tryed to format it .i couldnt.so i installed vista on another hard drive and tryed to format the old harddrive from my computer, failed.i tryed a 3rd party program it did a wipe clean, and it removed 30gbs but thats it it failed to remove the remaing folders in that hard drive
files are, C:users/medel/appdata/roaming/securom/userdata/:ЃϵϳЅЂϿϽϯІχϯπρЂϻϵЉЃϵϳЅ(1KB) :ЃϵϳЅЂϿϽϯІχϯπρϴϱЄϱЃϵϳЅ (12kb)i cant remove these so it fails to format an idea why?
it just wont let me format this drive

descriptionunknown virus - Page 2 EmptyRe: unknown virus

more_horiz
sorry an edit to my above post the drive letter was originaly C: now it has changed to D:

descriptionunknown virus - Page 2 EmptyRe: unknown virus

more_horiz
If you can't format, then you might have to do the next best thing.
Buy a completely new hardrive and start from scratch? Let me think

descriptionunknown virus - Page 2 EmptyRe: unknown virus

more_horiz
damn, that sucks,is there any other way to test for the virus to make sure i have it?

descriptionunknown virus - Page 2 EmptyRe: unknown virus

more_horiz
Hello.
Yes there is.

I have to warn you though, if it Virut, this tool will attemp to clean the infected files. But, if it can't clean them, it will delete them. That includes needed system files.

* Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe

  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, Click Options > Change settings
  • Choose the "Scan"-tab, remove the mark at "Heuristic analysis".
  • Back at the main window, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found: unknown virus - Page 2 Check
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
    unknown virus - Page 2 Move
    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.

descriptionunknown virus - Page 2 EmptyRe: unknown virus

more_horiz
hey i started a new copy of vista on my hard drive that i couldnt format (im losing 8gb) and i think its clean, i got a copy norton 360 and its said im clean.for some reason i think avg free may have given me this virus because i didn't install it and i didn't get infected like last time.

now for all the data on my infected hard drive what should it do with it?should i wipe all the data?i have music that i dont wanna lose should i delete those or just .exe and .scr files?

descriptionunknown virus - Page 2 EmptyRe: unknown virus

more_horiz
Just delete the files we used.

descriptionunknown virus - Page 2 EmptyRe: unknown virus

more_horiz
ok man thanks for your help even though i had to delete most my stuff, i learnt heaps while trying to remove the virus.thanks heaps man keep up the good work!

descriptionunknown virus - Page 2 EmptyRe: unknown virus

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum