This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] HijackThis log

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I have problems with my computer that I hope you can fix. I just added more RAM to my computer, but it stil runs slow, and everytime i do a scan on my computer it comes up with viruses that never seems to go away. Please check this for me.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:21:25 PM, on 4/12/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\IEEE 802.11g USB Wireless LAN\Wireless LAN\WlanUtil.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\reader_s.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\TEMP\4129206866.exe
C:\Documents and Settings\Jonathan Li\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimtoday.com/search/aimtoolbar.jsp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://channels.aimtoday.com/search/aimtoolbar.jsp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: Shell=explorer.exe
O2 - BHO: C:\WINDOWS\system32\ds43g4nfjkn93.dll - {D5BF49A0-94F3-42BD-F434-3604812C8955} - C:\WINDOWS\system32\ds43g4nfjkn93.dll
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [iRiver Updater] \Updater.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKLM\..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKUS\S-1-5-18\..\Run: [svc] c:\program Files\ThunMail\testabd.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [] C:\WINDOWS\TEMP\whf3z4sq8n.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Resurections] C:\WINDOWS\TEMP\whf3z4sq8n.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Diagnostic Manager] C:\WINDOWS\TEMP\4129206866.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [reader_s] C:\Documents and Settings\Jonathan Li\reader_s.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [svc] c:\program Files\ThunMail\testabd.exe (User 'Default user')
O4 - Global Startup: IEEE 802.11g USB Wireless LAN Utility.lnk = C:\Program Files\IEEE 802.11g USB Wireless LAN\Wireless LAN\WlanUtil.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O20 - AppInit_DLLs: c:\progra~1\ThunMail\testabd.dll
O22 - SharedTaskScheduler: lkjf9873jhifjnsfi8w3fe - {D5BF49A0-94F3-42BD-F434-3604812C8955} - C:\WINDOWS\system32\ds43g4nfjkn93.dll
O23 - Service: afisicx Service (afisicx) - Unknown owner - C:\WINDOWS\system32\afisicx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

–
End of file - 4892 bytes
Hi hatperson, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

We need some file informantion
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path, one at a time into the "Suspicious files to scan" box on the top of the page:
  • Please ensure the scan has completed and the results saved before submitting the next
    one

    C:\WINDOWS\System32\reader_s.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Windows\Explorer.exe
    c:\windows\system32\userinit.exe

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.

Thanks
Hi, thank you for responding to my request. For some reason, my clipboard isn't working, so i had to open the file with notepad so some of the words are weird.

Pà À  DataObject þÀ  UntrustedDragDrop  • " &Text À¸ · Ole Private Data   o  • s &OEM Text `  VirSCAN.org Scanned Report :
Scanned time : 2009/04/13 23:30:12 (PDT)
Scanner results: 81% Scanner(30/37) found malware!
File Name : reader_s.exe
File Size : 35328 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 4d36a1a0ceace25641eb21d79f37b051
SHA1 : f6eda33e6d6203fc54acba25e015689360fc6bbf
Online report : http://virscan.org/report/c11aa291f1926a56…d748a7119a.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.32 20090413232415 2009-04-13 1.87 Trojan.Win32.Agent2!IK
AhnLab V3 2009.04.14.02 2009.04.14 2009-04-14 0.71 -
AntiVir 7.9.0.138 7.1.3.44 2009-04-13 1.98 TR/Crypt.ZPACK.Gen
Antiy 2.0.18 20090413.2293849 2009-04-13 0.12 Trojan/Win32.Agent2.hck
Authentium 5.1.1 200904140024 2009-04-14 1.19 -
AVAST! 3.0.1 090413-0 2009-04-13 0.01 Win32:Vupa [Cryp]
AVG 7.5.52.442 270.11.55/2057 2009-04-13 2.01 SHeur2.ZCU
BitDefender 7.81008.2846408 7.24790 2009-04-14 2.61 Trojan.Kobcka.HT
CA (VET) 9.0.0.143 31.6.6454 2009-04-14 5.63 Win32/Cutwail.XQ trojan.
ClamAV 0.95 9229 2009-04-14 0.01 -
Comodo 3.8 1112 2009-04-13 0.54 TrojWare.Win32.Agent.~RCL
CP Secure 1.1.0.715 2009.04.14 2009-04-14 8.16 Troj.W32.Agent2.hck
Dr.Web 4.44.0.9170 2009.04.14 2009-04-14 4.35 Trojan.DownLoad.29459
F-Prot 4.4.4.56 20090413 2009-04-13 1.18 -
F-Secure 5.51.6100 2009.04.14.03 2009-04-14 0.05 Trojan.Win32.Agent2.hck [AVP]
Fortinet 2.81-3.117 10.280 2009-04-13 0.20 W32/Agent2.HCK!tr
GData 19.4603/19.298 20090414 2009-04-14 3.58 Trojan.Win32.Agent2.hck [Engine:A]
ViRobot 20090413 2009.04.13 2009-04-13 0.41 Trojan.Win32.Agent.35328.AD
Ikarus T3.1.01.49 2009.04.13.72572 2009-04-13 2.91 Trojan.Win32.Agent2
JiangMin 11.0.706 2009.04.14 2009-04-14 2.14 Trojan/Agent.cgby
Kaspersky 5.5.10 2009.04.14 2009-04-14 0.04 Trojan.Win32.Agent2.hck
KingSoft 2009.2.5.15 2009.4.14.7 2009-04-14 0.66 Win32.Troj.Agent2.35328
McAfee 5.3.00 5583 2009-04-13 2.76 Generic.dx
Microsoft 1.4502 2009.04.14 2009-04-14 4.81 TrojanDownloader:Win32/Cutwail
mks_vir 2.01 2009.04.14 2009-04-14 2.94 -
Norman 6.00.06 6.00.00 2009-04-13 10.01 W32/Agent.MILV
Panda 9.05.01 2009.04.13 2009-04-13 2.67 Suspicious file
Trend Micro 8.700-1004 5.966.05 2009-04-13 0.02 TROJ_DLOADER.YNN
Quick Heal 10.00 2009.04.13 2009-04-13 1.06 Trojan.Agent2.hck
Rising 20.0 21.25.10.00 2009-04-14 0.84 -
Sophos 2.85.0 4.40 2009-04-14 2.25 Mal/EncPk-HJ
Sunbelt 5090 5090 2009-04-13 0.65 Trojan.Unidentified.Gen.FN
Symantec 1.3.0.24 20090413.003 2009-04-13 0.04 Trojan Horse
nProtect 20090413.02 3464336 2009-04-13 4.53 Trojan/W32.Agent2.35328
The Hacker 6.3.4.0 v00306 2009-04-12 0.68 -
VBA32 3.12.10.2 20090413.1221 2009-04-13 2.92 Trojan.Win32.Agent2.hck
VirusBuster 4.5.11.10 10.102.40/1228619 2009-04-09 1.48 Trojan.Agent.ITZZ

Pà À  DataObject þÀ  UntrustedDragDrop  ` " &Text À¸ ‚ Ole Private Data   :  ` > &OEM Text `  VirSCAN.org Scanned Report :
Scanned time : 2009/04/13 23:33:59 (PDT)
Scanner results: All Scanners reported not find malware!
File Name : svchost.exe
File Size : 14336 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 8f078ae4ed187aaabc0a305146de6716
SHA1 : da0ff4006859a7580aba81f486f692dead2014fe
Online report : http://virscan.org/report/8f078ae4ed187aaa…5146de6716.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.32 20090413232415 2009-04-13 1.86 -
AhnLab V3 2009.04.14.02 2009.04.14 2009-04-14 0.60 -
AntiVir 7.9.0.138 7.1.3.44 2009-04-13 1.99 -
Antiy 2.0.18 20090413.2293849 2009-04-13 0.12 -
Authentium 5.1.1 200904140024 2009-04-14 1.14 -
AVAST! 3.0.1 090413-0 2009-04-13 0.00 -
AVG 7.5.52.442 270.11.55/2057 2009-04-13 2.01 -
BitDefender 7.81008.2846408 7.24790 2009-04-14 2.61 -
CA (VET) 9.0.0.143 31.6.6454 2009-04-14 7.83 -
ClamAV 0.95 9229 2009-04-14 0.01 -
Comodo 3.8 1112 2009-04-13 1.87 -
CP Secure 1.1.0.715 2009.04.14 2009-04-14 8.17 -
Dr.Web 4.44.0.9170 2009.04.14 2009-04-14 4.37 -
F-Prot 4.4.4.56 20090413 2009-04-13 1.13 -
F-Secure 5.51.6100 2009.04.14.03 2009-04-14 0.06 -
Fortinet 2.81-3.117 10.280 2009-04-13 0.19 -
GData 19.4603/19.298 20090414 2009-04-14 2.91 -
ViRobot 20090413 2009.04.13 2009-04-13 0.40 -
Ikarus T3.1.01.49 2009.04.13.72572 2009-04-13 2.90 -
JiangMin 11.0.706 2009.04.14 2009-04-14 1.67 -
Kaspersky 5.5.10 2009.04.14 2009-04-14 0.04 -
KingSoft 2009.2.5.15 2009.4.14.7 2009-04-14 0.64 -
McAfee 5.3.00 5583 2009-04-13 2.74 -
Microsoft 1.4502 2009.04.14 2009-04-14 4.28 -
mks_vir 2.01 2009.04.14 2009-04-14 2.79 -
Norman 6.00.06 6.00.00 2009-04-13 10.01 -
Panda 9.05.01 2009.04.13 2009-04-13 1.74 -
Trend Micro 8.700-1004 5.966.05 2009-04-13 0.03 -
Quick Heal 10.00 2009.04.13 2009-04-13 1.05 -
Rising 20.0 21.25.10.00 2009-04-14 0.71 -
Sophos 2.85.0 4.40 2009-04-14 2.11 -
Sunbelt 5090 5090 2009-04-13 0.80 -
Symantec 1.3.0.24 20090413.003 2009-04-13 0.06 -
nProtect 20090413.02 3464336 2009-04-13 4.27 -
The Hacker [removed] v00306 2009-04-12 0.59 -
VBA32 3.12.10.2 20090413.1221 2009-04-13 1.81 -
VirusBuster 4.5.11.10 10.102.40/1228619 2009-04-09 1.50 -

Pà À  DataObject þÀ  UntrustedDragDrop  & " &Text À¸ H Ole Private Data     &  &OEM Text `  VirSCAN.org Scanned Report :
Scanned time : 2009/04/14 00:03:12 (PDT)
Scanner results: 76% Scanner(28/37) found malware!
File Name : Explorer.exe
File Size : 1049600 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : f748b86cff80e188b8f45c87be255872
SHA1 : 076e151aaa1f2bccf46f17e481d3c81a89a32346
Online report : http://virscan.org/report/8e9778b452824c8b…dd3fe1c579.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.32 20090413232415 2009-04-13 1.88 Virus.Win32.Virut.q!IK
AhnLab V3 2009.04.14.02 2009.04.14 2009-04-14 0.59 Win32/Virut.E
AntiVir 7.9.0.138 7.1.3.44 2009-04-13 2.01 W32/Virut.Gen
Antiy 2.0.18 20090413.2293849 2009-04-13 0.12 -
Authentium 5.1.1 200904140024 2009-04-14 5.72 W32/Virut.AI!Generic (Possible)
AVAST! 3.0.1 090413-0 2009-04-13 0.05 Win32:Vitro
AVG 7.5.52.442 270.11.55/2057 2009-04-13 2.60 -
BitDefender 7.81008.2846408 7.24790 2009-04-14 2.60 Win32.Virtob.Gen.12
CA (VET) 9.0.0.143 31.6.6454 2009-04-14 3.87 Win32/Virut.17408 virus.
ClamAV 0.95 9229 2009-04-14 0.16 -
Comodo 3.8 1112 2009-04-13 0.56 -
CP Secure 1.1.0.715 2009.04.14 2009-04-14 8.24 -
Dr.Web 4.44.0.9170 2009.04.14 2009-04-14 4.38 Win32.Virut.56
F-Prot 4.4.4.56 20090413 2009-04-13 5.74 W32/Virut.AI!Generic
F-Secure 5.51.6100 2009.04.14.03 2009-04-14 0.08 Virus.Win32.Virut.ce [AVP]
Fortinet 2.81-3.117 10.280 2009-04-13 0.18 W32/Virut.CE.gen
GData 19.4605/19.298 20090414 2009-04-14 6.22 Virus.Win32.Virut.ce [Engine:A]
ViRobot 20090413 2009.04.13 2009-04-13 0.41 -
Ikarus T3.1.01.49 2009.04.13.72572 2009-04-13 2.92 Virus.Win32.Virut.q
JiangMin 11.0.706 2009.04.14 2009-04-14 1.82 Win32/Virut.bn
Kaspersky 5.5.10 2009.04.14 2009-04-14 0.09 Virus.Win32.Virut.ce
KingSoft 2009.2.5.15 2009.4.14.14 2009-04-14 0.67 Win32.Virut.nb.53248
McAfee 5.3.00 5583 2009-04-13 3.64 W32/Virut.n.gen
Microsoft 1.4502 2009.04.14 2009-04-14 4.37 Virus:Win32/Virut.BM
mks_vir 2.01 2009.04.14 2009-04-14 2.74 Heur.W32
Norman 6.00.06 6.00.00 2009-04-13 10.01 -
Panda 9.05.01 2009.04.13 2009-04-13 10.86 W32/Sality.AO
Trend Micro 8.700-1004 5.966.05 2009-04-13 0.02 PE_VIRUX.A
Quick Heal 10.00 2009.04.13 2009-04-13 1.40 W32.Virut.G
Rising 20.0 21.25.10.00 2009-04-14 1.25 Win32.Virut.bm
Sophos 2.85.0 4.40 2009-04-14 2.21 W32/Scribble-B
Sunbelt 5090 5090 2009-04-13 0.61 Win32.Virut.cf (v)
Symantec 1.3.0.24 20090413.003 2009-04-13 0.06 W32.Virut.CF
nProtect 20090413.02 3464336 2009-04-13 7.00 -
The Hacker 6.3.4.0 v00306 2009-04-12 1.03 W32/Virut.gen
VBA32 3.12.10.2 20090413.1221 2009-04-13 1.92 -
VirusBuster 4.5.11.10 10.102.40/1228619 2009-04-09 1.80 Win32.Virut.Y.Gen

Pà À  DataObject þÀ  UntrustedDragDrop  | " &Text À¸ ž Ole Private Data   V  | Z &OEM Text  VirSCAN.org Scanned Report :
Scanned time : 2009/04/13 23:43:00 (PDT)
Scanner results: 3% Scanner(1/37) found malware!
File Name : userinit.exe
File Size : 24576 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 84ebe825fb6d9deb0cf8a84ef9df6fd1
SHA1 : d64fd2365550ab53364c0d2d116c7fc739cecb7b
Online report : http://virscan.org/report/aa40e774928ddfee…5637f9438a.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.32 20090413232415 2009-04-13 2.13 -
AhnLab V3 2009.04.14.02 2009.04.14 2009-04-14 0.75 -
AntiVir 7.9.0.138 7.1.3.44 2009-04-13 1.97 -
Antiy 2.0.18 20090413.2293849 2009-04-13 0.12 -
Authentium 5.1.1 200904140024 2009-04-14 1.15 -
AVAST! 3.0.1 090413-0 2009-04-13 0.01 -
AVG 7.5.52.442 270.11.55/2057 2009-04-13 2.03 -
BitDefender 7.81008.2846408 7.24790 2009-04-14 2.63 -
CA (VET) 9.0.0.143 31.6.6454 2009-04-14 4.16 -
ClamAV 0.95 9229 2009-04-14 0.01 -
Comodo 3.8 1112 2009-04-13 0.54 -
CP Secure 1.1.0.715 2009.04.14 2009-04-14 8.18 -
Dr.Web 4.44.0.9170 2009.04.14 2009-04-14 4.39 -
F-Prot 4.4.4.56 20090413 2009-04-13 1.15 -
F-Secure 5.51.6100 2009.04.14.03 2009-04-14 0.09 -
Fortinet 2.81-3.117 10.280 2009-04-13 0.19 -
GData 19.4605/19.298 20090414 2009-04-14 4.49 -
ViRobot 20090413 2009.04.13 2009-04-13 0.62 -
Ikarus T3.1.01.49 2009.04.13.72572 2009-04-13 2.96 -
JiangMin 11.0.706 2009.04.14 2009-04-14 1.70 -
Kaspersky 5.5.10 2009.04.14 2009-04-14 0.07 -
KingSoft 2009.2.5.15 2009.4.14.7 2009-04-14 0.57 -
McAfee 5.3.00 5583 2009-04-13 2.76 -
Microsoft 1.4502 2009.04.14 2009-04-14 7.51 -
mks_vir 2.01 2009.04.14 2009-04-14 2.80 Trojan.Exploit.Iis.Printeroverflow.C
Norman 6.00.06 6.00.00 2009-04-13 10.01 -
Panda 9.05.01 2009.04.13 2009-04-13 1.68 -
Trend Micro 8.700-1004 5.966.05 2009-04-13 0.03 -
Quick Heal 10.00 2009.04.13 2009-04-13 1.25 -
Rising 20.0 21.25.10.00 2009-04-14 0.78 -
Sophos 2.85.0 4.40 2009-04-14 2.13 -
Sunbelt 5090 5090 2009-04-13 1.45 -
Symantec 1.3.0.24 20090413.003 2009-04-13 0.08 -
nProtect 20090413.02 3464336 2009-04-13 5.87 -
The Hacker [removed] v00306 2009-04-12 0.91 -
VBA32 3.12.10.2 20090413.1221 2009-04-13 1.98 -
VirusBuster 4.5.11.10 10.102.40/1228619 2009-04-09 1.50 -
Hi Hatperson,

Bad news I'm afraid. You are infected with a polymorpic file infector called Virut.

Virut can and will infect all the machine's executable files .exe, .scr plus .html and .htm. Because there are a number of bugs in its code, it may create executable files that are corrupted beyond repair resulting in an inoperative machine.

Recent variants also modify asp and php files. This virus will also download and install other malware.

More information can be found here and here and
here.

A Complete Reformat and Reinstall is the only way to clean the infection. This includes All Drives that contain .exe, .scr, .hlm, .html files.
  • Backup all your documents and important items only.
    data/documents/pictures/movies/songs/etc..
  • DO NOT backup any executable files (,exe .scr .html or .htm)
  • Do Not back up compressed files (zip/cab/rar) files that may contain .exe or .scr files
  • Reformat and Reinstall as outlined HERE

A CD would be best, but a blank USB device will work. Make sure there aren't any executable on it.

If you are going to use a USB device, I suggest you use a freshly formated one. After formatting it, use FDD on it before attaching it to the infected computer.

Be further advised that these infections may have backdoor capabilities.

I suggest you do the following immediately:
  • Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
  • From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • DO NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.
Feel free to ask any questions, but keep in mind a Reformat is the only way to clean this computer.
Hi Hatperson,

You are welcome and sorry it couldn't have been better news.

FDD is a little utility that will help protect a usb device from autorun infections.

Here you go, it's best if you have a clean pc to prepare the USB device on, but will also work on the infected one. Be sure to completly scan the files before restoring them back. Kaspersky online does a good job.


Download Flash_Disinfector.exe by sUBs and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
Reboot your computer when done.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder…it will help protect your drives from future infection.

Good luck
Hi, i have a question on the reformating of my computer. Is it ok to extract all the files from .rar and .zip files, or is everything there corrupted? Thank you.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI