This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Warning! You have a security problem!

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I can't get rid of a item in my system tray. It is a white X surrounded by a solid red circle. It has text box above it with words "Warning! You have a security problem!" Whether you click on it or not it opens IE and attempts to navigate to www.anykuy.com.

At other times I get a pop-up dialog box with a similar message, ""Warning! You have a security problem! Do you want to scan your computer for viruses?"

I have had my network cable disconnected for a few days now. I have scanned computer numerous time with MalwareBytes - always finding infections but some or new ones return. IE continuously tries to connect to the Internet.

I have selected the "show hidden files and folders" in the folder options in tools menu of MY Computer. Can you help?

Log files for MalwareBytes and HJT are as follows:

Malwarebytes' Anti-Malware 1.33
Database version: 1737
Windows 5.1.2600 Service Pack 2

2/12/2009 5:03:44 PM
mbam-log-2009-02-12 (17-03-44).txt

Scan type: Quick Scan
Objects scanned: 56692
Time elapsed: 11 minute(s), 14 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\services (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\PromoReg (Backdoor.Bot) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\userinit.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: system32\userinit.exe -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\Temp\TMP16.tmp (Backdoor.Bot) -> Quarantined and deleted successfully.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:05:48 PM, on 2/12/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\t2q8SU2e.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
O4 - HKUS\S-1-5-18\..\Run: [jsf8uiw3jnjgffght] C:\WINDOWS\TEMP\winlognn.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [jsf8uiw3jnjgffght] C:\WINDOWS\TEMP\winlognn.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ptssvc - Unknown owner - C:\Program Files\KODAK\KODAK Picture Transfer Software\PTSsvc.exe (file missing)

–
End of file - 3011 bytes
Hello blairjames and welcome to the forums here at WTT.

:welcome:

You are no doubt infected, as you know. That is likely due to the fact that you have no Antivirus program, or security programs of any kind that I can see. I have some suspicions that this could be pretty bad, but let's run a scan to see what we're dealing with.

Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, in the menu, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
Please post the Dr.Web report in your next reply.
DrWeb file: adobelmsvc.exe;c:\program files\common files\adobe systems shared\service;Win32.Virut.56;Cured.; alg.exe;c:\windows\system32;Win32.Virut.56;Cured.; brsvc01a.exe;c:\windows\system32;Win32.Virut.56;Cured.; cisvc.exe;c:\windows\system32;Win32.Virut.56;Cured.; clipsrv.exe;c:\windows\system32;Win32.Virut.56;Cured.; devldr32.exe;c:\windows\system32;Win32.Virut.56;Cured.; dllhost.exe;c:\windows\system32;Win32.Virut.56;Cured.; dmadmin.exe;c:\windows\system32;Win32.Virut.56;Cured.; explorer.exe;c:\windows;Win32.Virut.56;Cured.; ghoststartservice.exe;c:\program files\symantec\norton ghost 2003;Win32.Virut.56;Cured.; hpzipm12.exe;c:\windows\system32;Win32.Virut.56;Cured.; idrivert.exe;c:\program files\common files\installshield\driver\11\intel 32;Win32.Virut.56;Cured.; ie4uinit.exe;c:\windows\system32;Win32.Virut.56;Cured.; imapi.exe;c:\windows\system32;Win32.Virut.56;Cured.; jrcwwnav.exe;c:\windows;Trojan.DownLoad.12588;Deleted.; locator.exe;c:\windows\system32;Win32.Virut.56;Cured.; logon.scr;c:\windows\system32;Win32.Virut.56;Cured.; logonui.exe;c:\windows\system32;Win32.Virut.56;Cured.; mnmsrvc.exe;c:\windows\system32;Win32.Virut.56;Cured.; msdtc.exe;c:\windows\system32;Win32.Virut.56;Cured.; msiexec.exe;c:\windows\system32;Win32.Virut.56;Cured.; netdde.exe;c:\windows\system32;Win32.Virut.56;Cured.; ntsd.exe;c:\windows\system32;Win32.Virut.56;Cured.; osa9.exe;c:\program files\microsoft office\office;Win32.Virut.56;Cured.; pctspk.exe;c:\windows\system32;Win32.Virut.56;Cured.; printray.exe;c:\windows\system32\spool\drivers\w32x86\2;Win32.Virut.56;Cured.; qttask.exe;c:\program files\quicktime;Win32.Virut.56;Cured.; reader_sl.exe;c:\program files\adobe\acrobat 7.0\reader;Win32.Virut.56;Cured.; regsvr32.exe;c:\windows\system32;Win32.Virut.56;Cured.; rsvp.exe;c:\windows\system32;Win32.Virut.56;Cured.; rundll32.exe;c:\windows\system32;Win32.Virut.56;Cured.; scardsvr.exe;c:\windows\system32;Win32.Virut.56;Cured.; sessmgr.exe;c:\windows\system32;Win32.Virut.56;Cured.; setup50.exe;c:\program files\outlook express;Win32.Virut.56;Cured.; shmgrate.exe;c:\windows\system32;Win32.Virut.56;Cured.; smlogsvc.exe;c:\windows\system32;Win32.Virut.56;Cured.; spoolsv.exe;c:\windows\system32;Win32.Virut.56;Cured.; t2q8su2e.exe;c:\windows\system32;Win32.Virut.56;Cured.; t2q8su2e.exe;c:\windows\system32;Trojan.Packed.458;Deleted.; tcpsvcs.exe;c:\windows\system32;Win32.Virut.56;Cured.; unregmp2.exe;c:\windows\inf;Win32.Virut.56;Cured.; ups.exe;c:\windows\system32;Win32.Virut.56;Cured.; userinit.exe;c:\windows\system32;Win32.Virut.56;Cured.; vssvc.exe;c:\windows\system32;Win32.Virut.56;Cured.; winmgmt.exe;c:\windows\system32\wbem;Win32.Virut.56;Cured.; wmiapsrv.exe;c:\windows\system32\wbem;Win32.Virut.56;Cured.; wmpnetwk.exe;c:\program files\windows media player;Win32.Virut.56;Cured.; 16.tmp;C:\WINDOWS\system32;Trojan.DownLoad.12588;Deleted.; 1A.tmp;C:\WINDOWS\system32;Trojan.DownLoad.12588;Deleted.; 1B.tmp;C:\WINDOWS\system32;Trojan.DownLoad.12588;Deleted.; 2C.tmp;C:\WINDOWS\system32;Trojan.DownLoad.12588;Deleted.; 4.tmp;C:\WINDOWS\system32;Trojan.DownLoad.12588;Deleted.; 5.tmp;C:\WINDOWS\system32;Trojan.Packed.2352;Deleted.; accwiz.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; actmovie.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; ahui.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; arp.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; at.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; atmadm.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; attrib.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; auditusr.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; blastcln.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; bootok.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; bootvrfy.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; brss01a.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; bsplmf01.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; cacls.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; calc.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; charmap.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; chkdsk.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; chkntfs.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; cidaemon.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; ckcnv.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; cleanmgr.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; cliconfg.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; clipbrd.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; clspack.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; cmd.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; cmdl32.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; cmmon32.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; cmstp.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; comp.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; compact.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; conime.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; control.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; convert.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; cscript.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; ctfmon.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; dcomcnfg.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; ddeshare.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; defrag.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; dfrgfat.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; dfrgntfs.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; diantz.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; diskpart.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; diskperf.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; dllhst3g.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; dmremote.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; doskey.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; dplaysvr.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; dpnsvr.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; dpvsetup.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; drmupgds.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; drwtsn32.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; dumprep.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; dvdplay.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; dvdupgrd.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; dwwin.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; dxdiag.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; dxdllreg.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; esentutl.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; eudcedit.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; eventvwr.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; expand.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; extrac32.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; faxpatch.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; fc.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; find.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; findstr.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; finger.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; fixmapi.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; fltmc.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; fontview.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; forcedos.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; freecell.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; fsquirt.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; fsutil.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; ftp.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; GkSui18.EXE;C:\WINDOWS\system32;Win32.Virut.56;Cured.; grpconv.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; help.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; hostname.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; HPZinw12.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; hs78k4rgf4d.dll;C:\WINDOWS\system32;Trojan.DownLoad.29442;Deleted.; idag.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; idag.exe;C:\WINDOWS\system32;Trojan.Spambot.2424;Deleted.; iexpress.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; init32.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; ipconfig.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; ipsec6.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; ipv6.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; ipxroute.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; jdbgmgr.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; jview.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; label.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; LexBceS(3).exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; Lexpps(2).exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; Lexunst1.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; lights.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; lnkstub.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; lodctr.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; logagent.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; logman.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; logoff.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; lpq.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; lpr.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; lsetup.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; lsetup.exe;C:\WINDOWS\system32;Trojan.Spambot.2424;Deleted.; magnify.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; makecab.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; migpwd.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; mmc.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; mobsync.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; mountvol.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; mplay32.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; mpnotify.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; mrinfo.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; msg.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; mshearts.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; mshta.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; mspaint.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; msswchx.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; mstinit.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; mstsc.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; narrator.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; nbtstat.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; nddeapir.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; net.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; net1.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; netsetup.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; netsh.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; netstat.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; notepad.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; nslookup.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; ntvdm.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; objcopy.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; objcopy.exe;C:\WINDOWS\system32;Trojan.Spambot.2424;Deleted.; odbcad32.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; odbcconf.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; osk.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; osuninst.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; packager.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; pathping.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; pentnt.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; perfmon.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; ping.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; ping6.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; pintool.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; powercfg.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; print.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; progman.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; proquota.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; proxycfg.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; qappsrv.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; qprocess.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; qwinsta.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; rasautou.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; rasdial.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; rasphone.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; rcimlby.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; rcp.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; rdpclip.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; rdsaddin.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; rdshost.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; recover.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; reg.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; regedt32.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; regini.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; regwiz.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; replace.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; res2coff.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; res2coff.exe;C:\WINDOWS\system32;Trojan.Spambot.2424;Deleted.; reset.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; rexec.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; route.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; routemon.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; rsh.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; rsm.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; rsmsink.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; rsmui.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; rsvp32_2.dll;C:\WINDOWS\system32;Trojan.Spambot;Deleted.; rtcshare.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; runas.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; runonce.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; rwinsta.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; S3tray2.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; savedump.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; sc.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; scrnsave.scr;C:\WINDOWS\system32;Win32.Virut.56;Cured.; sdbinst.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; sethc.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; setup.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; sfc.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; shadow.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; shrpubw.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; shutdown.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; sigverif.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; skeys.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; slrundll.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; slserv.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; smbinst.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; sndrec32.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; sndvol32.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; sol.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; sort.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; spdwnwxp.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; spider.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; spnpinst.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; spupdwxp.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; ss3dfo.scr;C:\WINDOWS\system32;Win32.Virut.56;Cured.; ssbezier.scr;C:\WINDOWS\system32;Win32.Virut.56;Cured.; ssflwbox.scr;C:\WINDOWS\system32;Win32.Virut.56;Cured.; ssmarque.scr;C:\WINDOWS\system32;Win32.Virut.56;Cured.; ssmypics.scr;C:\WINDOWS\system32;Win32.Virut.56;Cured.; ssmyst.scr;C:\WINDOWS\system32;Win32.Virut.56;Cured.; sspipes.scr;C:\WINDOWS\system32;Win32.Virut.56;Cured.; ssstars.scr;C:\WINDOWS\system32;Win32.Virut.56;Cured.; sstext3d.scr;C:\WINDOWS\system32;Win32.Virut.56;Cured.; stimon.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; subst.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; syncapp.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; syskey.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; sysocmgr.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; systray.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; taskman.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; taskmgr.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; tcmsetup.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; telnet.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; tftp.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; tourstart.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; tracert.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; tracert6.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; tscon.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; tscupgrd.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; tsdiscon.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; tskill.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; tsshutdn.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; tzchange.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; unlodctr.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; upnpcont.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; usrmlnka.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; usrprbda.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; usrshuta.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; utilman.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; uwdf.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; verclsid.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; verifier.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; vssadmin.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; w32tm.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; wdfmgr.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; wextract.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; wiaacmgr.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; winhlp32.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; winmine.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; winmsd.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; winver.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; wisptis.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; wjview.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; wmpstub.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; wpabaln.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; wpdshextautoplay.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; wpnpinst.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; write.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; wscntfy.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; wscript.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; WudfHost.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; wupdmgr.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; xcopy.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; xpsp1hfm.exe;C:\WINDOWS\system32;Win32.Virut.56;Cured.; comrepl.exe;C:\WINDOWS\system32\Com;Win32.Virut.56;Cured.; comrereg.exe;C:\WINDOWS\system32\Com;Win32.Virut.56;Cured.; dcfssvc.exe;C:\WINDOWS\system32\drivers;Win32.Virut.56;Cured.; msoobe.exe;C:\WINDOWS\system32\oobe;Win32.Virut.56;Cured.; rstrui.exe;C:\WINDOWS\system32\Restore;Win32.Virut.56;Cured.; migwiz.exe;C:\WINDOWS\system32\usmt;Win32.Virut.56;Cured.; mofcomp.exe;C:\WINDOWS\system32\wbem;Win32.Virut.56;Cured.; scrcons.exe;C:\WINDOWS\system32\wbem;Win32.Virut.56;Cured.; unsecapp.exe;C:\WINDOWS\system32\wbem;Win32.Virut.56;Cured.; wbemtest.exe;C:\WINDOWS\system32\wbem;Win32.Virut.56;Cured.; wmiadap.exe;C:\WINDOWS\system32\wbem;Win32.Virut.56;Cured.; wmiprvse.exe;C:\WINDOWS\system32\wbem;Win32.Virut.56;Cured.; TMP1A.tmp;C:\WINDOWS\temp;Trojan.Spambot.4331;Deleted.; TMP24.tmp;C:\WINDOWS\temp;Trojan.Spambot.4331;Deleted.;
Hi,

That is what I expected. Not good. :( My suspicions were confirmed.

I have bad news for you. you are infected with Virut.
Virut is a file infector which infects executables (.exe's or program files), .scr's, .htm, .html, .xml, .zip, and .rar files. The problem with Virut is that it is a buggy file infector and that's why scanners may not disinfect them properly either. The results of this, files are corrupted and won't work anymore.

This unfortunately means that the best course of action now is formatting and reinstalling Windows. You can back up your personal files such as documents, pictures, music, ect…. Just not any of the files with the extensions mentioned above.

If you need help with the re-install you can post in the Windows forum here at WTT. Also, check out this link with detailed instructions.


Also, one of the main reasons you were probably infected is that it does not appear you have any security software at all. Here are some free programs and advice that will go a long way towards avoiding this problem in the future.

Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. Here is a list of some free and evaluation versions to try: AVG AntiVirus
Avast Antivirus Home Version–Free
Antivir Personal - Free
Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. Here are some free and evalutation versions that provide
better security than the Windows Firewall. Comodo
Outpost Firewall
For a tutorial on Firewalls and a listing of some other available ones see the link below:
Understanding and Using Firewalls

Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly or set your computer to receive automatic updates. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.
A tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware

Install Winpatrol -
Use Winpatrol to take control of your PC and provide another layer of security.
Help file and tutorial can be found Here

Block unwanted parasites with a custom hosts file -
http://www.mvps.org/winhelp2002/hosts.htm

Update all of your Anti-Malware programs regularly - Make sure you update all the programs I have listed and the ones you are currently running regularly. Without regular updates you Will Not be protected when new malicious programs are released.

I'll leave the thread open a few days in case you have questions or issues. Feel free to ask if you do have any questions about this.

Regards,
Dave

Is it safe to save my settings and favorites?

Yes, that should be okay. Just avoid saving any of the file types I mentioned, or certainly avoid any programs.

Good luck,
Dave
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI