This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected with wuaucldt.exe - regedit.exe

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Dear Malware Team

My Laptop infected with this. WUAUCLDT.EXE.

I tried all method to remove it.

FULL Scan in safe mode and normal mode with updated ESET NOD32 and Malwarebyte but… It appeared after been removed.

Can you help me ?

Thank you and best regard.

———-

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:42:12 AM, on 4/18/2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
D:\Seven\DigitalPersona\Bin\DpAgent.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Windows Sidebar\sidebar.exe
D:\Seven\Unikey\UniKeyNT.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
D:\Seven\Internet Download Manager\IDMan.exe
D:\Seven\Internet Download Manager\IEMonitor.exe
C:\Windows\system32\taskmgr.exe
C:\Windows\regedit.exe
C:\Windows\system32\SearchFilterHost.exe
D:\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\Seven\Internet Download Manager\IDMIECC.dll
O2 - BHO: DigitalPersona Personal Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - D:\Seven\DigitalPersona\Bin\DpOtsPluginIe8.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O2 - BHO: QuickNet - {EA5CA8B6-9B9C-4994-A7A1-947B6C631BE7} - C:\Program Files\RegTweaker\key.dll (file missing)
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DpAgent] D:\Seven\DigitalPersona\Bin\dpagent.exe
O4 - HKLM\..\Run: [Regedit32] C:\Windows\system32\regedit.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [UniKey] D:\Seven\Unikey\UniKeyNT.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Download all links with IDM - D:\Seven\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - D:\Seven\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - D:\Seven\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\aestsrv.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: @D:\Seven\DigitalPersona\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - D:\Seven\DigitalPersona\Bin\DpHostW.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - Unknown owner - D:\Seven\ESET\ESET Smart Security\EHttpSrv.exe (file missing)
O23 - Service: ESET Service (ekrn) - Unknown owner - D:\Seven\ESET\ESET Smart Security\ekrn.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard Company - C:\Windows\system32\Hpservice.exe
O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: @%SystemRoot%\system32\stlang.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: Intel® Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vcsFPService.exe

–
End of file - 6411 bytes

========================================
MALWAREBYTE
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6384

Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421

4/18/2011 1:16:33 AM
mbam-log-2011-04-18 (01-16-29).txt

Scan type: Full scan (C:\|)
Objects scanned: 195745
Time elapsed: 12 minute(s), 36 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wuaucldt (Trojan.Agent) -> Value: wuaucldt -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Regedit32 (Trojan.Agent) -> Value: Regedit32 -> No action taken.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Users\chun chin\AppData\Roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\hijackthis.exe (PWS.Fignotok) -> No action taken.
c:\Windows\System32\wuaucldt.exe (Trojan.Wigon) -> No action taken.
c:\Windows\System32\config\systemprofile\wuaucldt.exe (Trojan.Wigon) -> No action taken.
Hi,

:welcome:

My name is NoodleTech. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not delete anything unless instructed to.
  • DO NOT use tools such as ComboFix without supervision.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
===================================================

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments,  attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
===================================================

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

Please run Malwarebytes' Anti-Malware.
  • Click the Update tab, then click Check for Updates.
  • If an update is found, it will download and install the latest version.
  • Next, click Scanner, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
===================================================

In your next post, please include the following:
  • DDS log
  • GMER log
  • MBAM log
Hi, Noddle Tech You know the unpleasant problems caused by Malware. I'm glad to see you and thank you for your support. These are the log files I have. When I run Gmer after DDS script in the first time, my mouse and keyboard of computer can't use. So, I must force shutdown it. ========= DDS . DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 1:31:45.08 on Tue 04/19/2011 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_24 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.1910.923 [GMT 7:00] . SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Program Files\IDT\WDM\STacSV.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\atieclxx.exe C:\Windows\system32\Hpservice.exe C:\Windows\system32\vcsFPService.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\WLANExt.exe C:\Windows\system32\conhost.exe C:\Windows\System32\spoolsv.exe D:\Seven\DigitalPersona\Bin\DpHostW.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\IDT\WDM\aestsrv.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskhost.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe D:\Seven\DigitalPersona\Bin\DpAgent.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe D:\Seven\Unikey\UniKeyNT.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\SearchIndexer.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe C:\Windows\system32\svchost.exe -k bthsvcs C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Windows\TEMP\VRTCAFB.tmp C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\wbem\wmiprvse.exe D:\Seven\mtd9\mtd9EVA.exe D:\Seven\mtd9\MTDSHELF08.EXE D:\Seven\Internet Download Manager\IDMan.exe D:\Seven\Internet Download Manager\IEMonitor.exe C:\Windows\system32\AUDIODG.EXE C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\Chun chin\Desktop\dds.scr C:\Windows\system32\conhost.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com.vn/ BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - d:\seven\internet download manager\IDMIECC.dll BHO: DigitalPersona Personal Extension: {395610ae-c624-4f58-b89e-23733ea00f9a} - d:\seven\digitalpersona\bin\DpOtsPluginIe8.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office14\GROOVEEX.DLL BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~2\office14\URLREDIR.DLL BHO: {DBC80044-A445-435b-BC74-9C25C1C588A9} - No File BHO: {EA5CA8B6-9B9C-4994-A7A1-947B6C631BE7} - No File uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [UniKey] d:\seven\unikey\UniKeyNT.exe mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe mRun: [DpAgent] d:\seven\digitalpersona\bin\dpagent.exe mRun: [BkavFw] c:\program files\bkav2006\Bkav2006.exe TASKBAR dRun: [wuaucldt] c:\windows\system32\config\systemprofile\wuaucldt.exe mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Download all links with IDM - d:\seven\internet download manager\IEGetAll.htm IE: Download FLV video content with IDM - d:\seven\internet download manager\IEGetVL.htm IE: Download with IDM - d:\seven\internet download manager\IEExt.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~1\micros~2\office14\ONBttnIE.dll/105 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL Notify: igfxcui - igfxdev.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office14\GROOVEEX.DLL LSA: Notification Packages = scecli DPPWDFLT . ================= FIREFOX =================== . FF - ProfilePath - c:\users\chunch~1\appdata\roaming\mozilla\firefox\profiles\f9j4t3mg.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.vn FF - plugin: c:\progra~1\micros~2\office14\NPAUTHZ.DLL FF - plugin: c:\progra~1\micros~2\office14\NPSPWRAP.DLL FF - plugin: c:\users\chun chin\appdata\local\google\update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: d:\seven\picasa3\npPicasa3.dll . ============= SERVICES / DRIVERS =============== . R1 SysLib0;SysLib0;c:\windows\system32\drivers\SysLib0.sys [2011-4-18 35328] R1 SysLib1;SysLib1;c:\windows\system32\drivers\SysLib1.sys [2011-4-18 497664] R1 SysLib2;SysLib2;c:\windows\system32\drivers\SysLib2.sys [2011-4-18 29184] R1 SysLib3;SysLib3;c:\windows\system32\drivers\SysLib3.sys [2011-4-18 16502784] R1 SysLib4;SysLib4;c:\windows\system32\drivers\SysLib4.sys [2011-4-18 10727936] R1 SysLib5;SysLib5;c:\windows\system32\drivers\SysLib5.sys [2011-4-18 6627328] R1 SysLib6;SysLib6;c:\windows\system32\drivers\SysLib6.sys [2011-4-18 1783808] R1 VWiFiFlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128] R2 AESTFilters;Andrea ST Filters Service;c:\program files\idt\wdm\AEstSrv.exe [2011-3-20 110592] R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-9-9 204800] R2 hpsrv;HP Service;c:\windows\system32\hpservice.exe [2010-7-16 26168] R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files\intel\intel® rapid storage technology\IAStorDataMgrSvc.exe [2011-3-20 13336] R2 IDMWFP;IDMWFP;c:\windows\system32\drivers\idmwfp.sys [2011-2-12 85768] R2 UNS;Intel® Management & Security Application User Notification Service;c:\program files\intel\intel® management engine components\uns\UNS.exe [2011-3-20 2533400] R2 vcsFPService;Validity VCS Fingerprint Service;c:\windows\system32\vcsFPService.exe [2010-2-23 1799472] R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2010-9-9 6380544] R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2010-9-9 222208] R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [2010-2-26 132480] R3 intelkmd;intelkmd;c:\windows\system32\drivers\igdpmd32.sys [2010-7-19 9018368] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2011-3-20 279656] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-14 14336] S2 ekrn;ESET Service;"d:\seven\eset\eset smart security\ekrn.exe" –> d:\seven\eset\eset smart security\ekrn.exe [?] S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\regedt32.exe [2009-7-14 36864] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888] S3 eamonm;eamonm;c:\windows\system32\drivers\eamonm.sys [2010-2-22 133512] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2010-3-25 30969208] S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2011-3-19 15872] S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2009-12-15 515560] S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-3-19 52224] S4 ASO3DiskOptimizer;ASO3DiskOptimizer;d:\seven\advanced system optimizer 3\ASO3DefragSrv.exe [2011-3-22 239928] S4 epfwwfp;epfwwfp;c:\windows\system32\drivers\epfwwfp.sys [2010-2-22 41312] . =============== Created Last 30 ================ . 2011-04-18 18:21:57 ——– d—–w- c:\users\chunch~1\appdata\roaming\MTD 2011-04-17 20:26:35 6627328 —-a-w- c:\windows\system32\drivers\SysLib5.sys 2011-04-17 20:26:35 497664 —-a-w- c:\windows\system32\drivers\SysLib1.sys 2011-04-17 20:26:35 35328 —-a-w- c:\windows\system32\drivers\SysLib0.sys 2011-04-17 20:26:35 29184 —-a-w- c:\windows\system32\drivers\SysLib2.sys 2011-04-17 20:26:35 1783808 —-a-w- c:\windows\system32\drivers\SysLib6.sys 2011-04-17 20:26:35 16502784 —-a-w- c:\windows\system32\drivers\SysLib3.sys 2011-04-17 20:26:35 10727936 —-a-w- c:\windows\system32\drivers\SysLib4.sys 2011-04-17 20:26:35 ——– d—–w- c:\users\chunch~1\appdata\roaming\Bkav2009 2011-04-17 20:26:33 8299589 —-a-w- c:\windows\system32\BkavAuto.vxd 2011-04-17 20:26:33 34390 —-a-w- c:\windows\system32\drivers\BkavAuto.sys 2011-04-17 20:26:33 297511 —-a-w- c:\windows\system32\drivers\SysLib.sys 2011-04-17 20:26:33 ——– d—–w- c:\program files\Bkav2006 2011-04-17 19:55:03 ——– d—–w- c:\windows\pss 2011-04-17 18:30:21 ——– d—–w- c:\users\chun chin\EurekaLog 2011-04-17 18:25:29 ——– d—–w- c:\program files\Unlocker 2011-04-17 16:30:42 ——– d—–w- c:\program files\ATI 2011-04-17 15:11:19 2 –shatr- c:\windows\winstart.bat 2011-04-17 15:11:14 ——– d—–w- c:\program files\UnHackMe 2011-04-17 15:10:01 ——– d—–w- c:\program files\RegTweaker 2011-03-23 03:06:15 77824 —-a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll 2011-03-23 03:06:15 32768 ——w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll 2011-03-23 03:06:15 225280 ——w- c:\program files\common files\installshield\iscript\iscript.dll 2011-03-23 03:06:15 176128 ——w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll 2011-03-23 03:02:37 ——– d—–w- c:\users\chunch~1\appdata\roaming\Rovio 2011-03-22 08:30:51 ——– d—–w- c:\progra~2\regid.1986-12.com.adobe 2011-03-22 05:42:17 ——– d—–w- c:\users\chunch~1\appdata\local\Adobe 2011-03-22 04:30:18 5702 —ha-w- c:\windows\nod32restoretemdono.reg 2011-03-22 04:30:18 568 —ha-w- c:\windows\nod32fixtemdono.reg 2011-03-22 04:25:23 ——– d—–w- c:\users\chunch~1\appdata\roaming\ESET 2011-03-22 04:25:23 ——– d—–w- c:\users\chunch~1\appdata\local\ESET 2011-03-22 04:20:12 ——– d—–w- c:\users\chunch~1\appdata\roaming\Systweak 2011-03-22 04:19:48 17136 —-a-w- c:\windows\system32\sasnative32.exe 2011-03-22 04:14:15 ——– d—–w- c:\users\chunch~1\appdata\roaming\Malwarebytes 2011-03-22 04:14:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-03-22 04:14:08 ——– d—–w- c:\progra~2\Malwarebytes 2011-03-22 04:14:06 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-03-22 03:40:50 ——– d—–w- c:\program files\Microsoft Synchronization Services 2011-03-22 03:40:37 ——– d—–w- c:\windows\PCHEALTH 2011-03-22 03:40:37 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition 2011-03-22 03:40:01 ——– d—–w- c:\program files\Microsoft Visual Studio 8 2011-03-22 03:39:34 ——– d—–w- c:\program files\Microsoft Analysis Services 2011-03-22 03:13:30 ——– d—–w- c:\windows\Blaiz Enterprises 2011-03-22 03:11:55 ——– d—–w- c:\program files\common files\MSSoap 2011-03-22 03:11:53 ——– d—–w- c:\program files\common files\L&H 2011-03-22 02:59:55 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-03-22 02:34:03 ——– d—–w- c:\users\chunch~1\appdata\roaming\Foxit Software 2011-03-22 02:31:56 165376 —-a-w- c:\windows\system32\unrar.dll 2011-03-22 02:31:55 810496 —-a-w- c:\windows\system32\xvidcore.dll 2011-03-22 02:31:55 80896 —-a-w- c:\windows\system32\ff_vfw.dll 2011-03-22 02:31:55 237568 —-a-w- c:\windows\system32\yv12vfw.dll 2011-03-22 02:31:55 232448 —-a-w- c:\windows\system32\mp3fhg.acm 2011-03-22 02:31:55 183808 —-a-w- c:\windows\system32\xvidvfw.dll 2011-03-22 02:31:55 151552 —-a-w- c:\windows\system32\ac3acm.acm 2011-03-22 02:15:44 ——– d—–w- c:\users\chunch~1\appdata\local\Yahoo 2011-03-22 02:11:25 ——– d—–w- c:\program files\Yahoo! 2011-03-22 01:48:42 ——– d—–w- c:\users\chunch~1\appdata\local\Google 2011-03-22 01:48:24 ——– d—–w- c:\users\chunch~1\appdata\local\Apps 2011-03-22 01:12:16 ——– d—–w- c:\users\chunch~1\appdata\roaming\IDM 2011-03-22 01:12:15 ——– d—–w- c:\users\chunch~1\appdata\roaming\DMCache 2011-03-22 00:22:09 ——– d-sh–r- C:\bootwiz 2011-03-21 17:24:41 5943120 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{8cdd1cb1-2a41-4a6d-ba84-aa559640b3bd}\mpengine.dll 2011-03-21 17:24:41 222080 ——w- c:\windows\system32\MpSigStub.exe 2011-03-21 17:16:27 ——– d—–w- c:\program files\Validity Sensors 2011-03-21 16:56:47 ——– d—–w- c:\users\chunch~1\appdata\roaming\Macrovision 2011-03-21 16:55:47 ——– d—–w- c:\users\chunch~1\appdata\roaming\DigitalPersona 2011-03-21 16:55:47 ——– d—–w- c:\users\chunch~1\appdata\local\DigitalPersona 2011-03-21 16:53:34 ——– d—–w- c:\progra~2\Downloaded Installations 2011-03-21 16:50:50 ——– d—–w- c:\program files\Validity Sensors, Inc 2011-03-21 12:56:22 59904 —-a-w- c:\windows\system32\OVDecode.dll 2011-03-21 12:56:06 51712 —-a-w- c:\windows\system32\OpenCL.dll 2011-03-21 12:55:46 12385792 —-a-w- c:\windows\system32\amdocl.dll 2011-03-21 01:02:44 ——– d—–w- c:\program files\Cisco 2011-03-21 01:01:48 6656 —-a-w- c:\windows\system32\bcmwlrc.dll 2011-03-21 01:01:48 ——– d—–w- c:\program files\Broadcom 2011-03-21 00:45:08 ——– d—–w- c:\users\chunch~1\appdata\roaming\Intel 2011-03-21 00:18:01 12800 ——w- c:\windows\HPun2420Version.dll 2011-03-21 00:17:50 ——– d—–w- c:\users\chunch~1\appdata\roaming\hpqLog 2011-03-21 00:03:20 ——– d—–w- c:\users\chunch~1\appdata\local\ElevatedDiagnostics 2011-03-20 06:49:07 ——– d—–w- c:\windows\Panther 2011-03-20 06:48:53 ——– d-sh–w- C:\Boot 2011-03-19 23:25:14 ——– d—–w- c:\users\chunch~1\appdata\roaming\Intel Corporation 2011-03-19 23:22:30 435736 —-a-w- c:\windows\system32\drivers\iaStor.sys 2011-03-19 23:22:02 ——– d—–w- c:\program files\AmIcoSingLun 2011-03-19 23:22:02 ——– d—–w- c:\progra~2\AmUStor 2011-03-19 23:18:46 80416 —-a-w- c:\windows\system32\RtNicProp32.dll 2011-03-19 23:18:46 279656 —-a-w- c:\windows\system32\drivers\Rt86win7.sys 2011-03-19 23:18:46 100896 —-a-w- c:\windows\system32\RTNUninst32.dll 2011-03-19 23:18:43 ——– d—–w- c:\program files\Realtek 2011-03-19 23:15:33 ——– d—–w- c:\program files\Synaptics 2011-03-19 23:12:33 ——– d—–w- c:\program files\common files\postureAgent 2011-03-19 23:08:28 53248 —-a-w- c:\windows\system32\CSVer.dll 2011-03-19 23:07:02 86016 —-a-w- c:\windows\system32\AESTCom.dll 2011-03-19 23:07:02 61440 —-a-w- c:\windows\system32\aestaren.dll 2011-03-19 23:07:02 565248 —-a-w- c:\windows\system32\idtmini1.exe 2011-03-19 23:07:02 565248 —-a-w- c:\windows\sttray.exe 2011-03-19 23:07:02 4644864 —-a-w- c:\windows\system32\stlang.dll 2011-03-19 23:07:02 380928 —-a-w- c:\windows\system32\aestecap.dll 2011-03-19 23:07:02 139776 —-a-w- c:\windows\system32\aestacap.dll 2011-03-19 23:07:02 12734556 —-a-w- c:\windows\system32\idtcpl.cpl 2011-03-19 23:07:02 ——– d—–w- c:\windows\system32\SRSLabs 2011-03-19 23:06:59 179712 —-a-w- c:\windows\system32\staco.dll 2011-03-19 23:06:27 949760 —-a-w- c:\windows\system32\stapo.dll 2011-03-19 23:06:27 532480 ——w- c:\windows\system32\stapi32.dll 2011-03-19 23:06:27 435200 —-a-w- c:\windows\system32\drivers\stwrt.sys 2011-03-19 23:06:27 405504 —-a-w- c:\windows\system32\stcplx.dll 2011-03-19 23:06:22 ——– d—–w- c:\program files\IDT 2011-03-19 22:39:47 ——– d—–w- c:\users\chunch~1\appdata\local\ATI 2011-03-19 22:38:28 0 —-a-w- c:\windows\ativpsrm.bin 2011-03-19 22:21:09 ——– d-sh–w- c:\windows\Installer . ==================== Find3M ==================== . 2011-03-19 16:46:55 152576 —-a-w- c:\windows\system32\msclmd.dll 2011-02-22 23:51:58 4308992 —-a-w- c:\windows\system32\GPhotos.scr . ============= FINISH: 1:32:01.55 =============== ================================================================================ ==================\ MBAM LOG Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6384 Windows 6.1.7601 Service Pack 1 Internet Explorer 9.0.8112.16421 4/19/2011 2:44:44 AM mbam-log-2011-04-19 (02-44-44).txt Scan type: Full scan (C:\|) Objects scanned: 197915 Time elapsed: 36 minute(s), 32 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\windows\temp\vrtcafb.tmp (Trojan.Wigon) -> Quarantined and deleted successfully.
Thank you for the logs Khanh.

Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your  Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.


    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note: 
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————
Hi, Noddle Tech.

I followed your guide. Place combo Fix in my Desktop. Double click to run. But, after I agree with it promt, click Yes, it have a Error window with Notice:
"Alert! It's not Safe to continue. The content of the Combo Fix package has been compromised…
Please download fresh copy from…
Note: you maybe infected with a file patching virus "Virus"
"

And then, nothing happens. Combo Fix disappears from my desktop.

What should I do, Noddle?
Hi Khanh,

Thanks for letting me know.

Let's try this scan.

I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start.  The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button.  The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\Program Files\ESET\log.txt into your next reply.
Dear Noddle. I scan with ESet online scanner and have this log: ============= C:\Program Files\Windows Sidebar\sidebar.exe a variant of Win32/Virut.NCS virus C:\Users\Chun chin\Desktop\Mines\Unlocker1.9.1.exe Win32/Adware.ADON application C:\Windows\System32\SoundRecorder.exe a variant of Win32/Virut.NCS virus C:\Windows\Temp\VRT6A17.tmp a variant of Win32/Kryptik.LRO trojan C:\Windows\Temp\VRTC773.tmp a variant of Win32/Kryptik.LRO trojan C:\Windows\winsxs\x86_microsoft-windows-sidebar_31bf3856ad364e35_6.1.7601.17514_none_d0e415a884ea33e1\sidebar.exe a variant of Win32/Virut.NCS virus C:\Windows\winsxs\x86_microsoft-windows-soundrecorder_31bf3856ad364e35_6.1.7601.17514_none_a110af8e912572ca\SoundRecorder.exe a variant of Win32/Virut.NCS virus D:\11-3_mobility_vista_win7_32-64_ccc\Bin\InstallManagerApp.exe a variant of Win32/Virut.NCS virus D:\Download\Programs\ZingPlay\ZP TaLa\ZP TaLa.exe a variant of Win32/Virut.NCS virus D:\Games\Beach Life\autorun.exe a variant of Win32/Virut.NCS virus D:\Setup graphic hp\Bin\InstallManagerApp.exe a variant of Win32/Virut.NCS virus D:\Seven\CS5\Adobe Bridge CS5\Adobe3DAndVideoServer.exe a variant of Win32/Virut.NCS virus D:\Seven\CS5\Adobe Bridge CS5\Photodownloader.exe a variant of Win32/Virut.NCS virus D:\Seven\CS5\Adobe Extension Manager CS5\Replace.exe a variant of Win32/Virut.NCS virus D:\Seven\CS5\Adobe Extension Manager CS5\XManCommand.exe a variant of Win32/Virut.NCS virus D:\Seven\CS5\Adobe Photoshop CS5\Required\Droplet Template.exe a variant of Win32/Virut.NCS virus D:\Seven\DigitalPersona\Bin\DpOnlineHelp.exe a variant of Win32/Virut.NCS virus D:\Seven\DigitalPersona\Bin\DpRegApp.exe a variant of Win32/Virut.NCS virus D:\Seven\DigitalPersona\Bin\DPRunDll.exe a variant of Win32/Virut.NCS virus D:\Seven\DigitalPersona\Bin\DpRunHlp.exe a variant of Win32/Virut.NCS virus D:\Seven\K-Lite Codec Pack\Filters\Haali\gdsmux.exe a variant of Win32/Virut.NCS virus D:\Seven\K-Lite Codec Pack\Tools\CodecTweakTool.exe a variant of Win32/Virut.NCS virus D:\Seven\K-Lite Codec Pack\Tools\dsconfig.exe a variant of Win32/Virut.NCS virus D:\Seven\K-Lite Codec Pack\Tools\graphstudio.exe a variant of Win32/Virut.NCS virus D:\Seven\K-Lite Codec Pack\Tools\mediainfo.exe a variant of Win32/Virut.NCS virus D:\Seven\K-Lite Codec Pack\Tools\SetACL_x86.exe a variant of Win32/Virut.NCS virus D:\Seven\K-Lite Codec Pack\Tools\StatsReader.exe a variant of Win32/Virut.NCS virus D:\Seven\K-Lite Codec Pack\Tools\VobSubStrip.exe a variant of Win32/Virut.NCS virus D:\Seven\K-Lite Codec Pack\Tools\Win7DSFilterTweaker.exe a variant of Win32/Virut.NCS virus D:\Seven\MobilityDotNET\Inf2Cat.exe a variant of Win32/Virut.NCS virus D:\Seven\MobilityDotNET\MobilityDotNET.exe a variant of Win32/Virut.NCS virus D:\Seven\MobilityDotNET\msi2xml.exe a variant of Win32/Virut.NCS virus D:\Seven\MobilityDotNET\xml2msi.exe a variant of Win32/Virut.NCS virus D:\Seven\mtd9\mtd2008EVA.exe a variant of Win32/Virut.NCS virus D:\Seven\mtd9\mtdUpdate.exe a variant of Win32/Virut.NCS virus D:\Seven\Winrar\Rar.exe a variant of Win32/Virut.NCS virus D:\Seven\Winrar\RarExtLoader.exe a variant of Win32/Virut.NCS virus D:\Seven\Winrar\UnRAR.exe a variant of Win32/Virut.NCS virus D:\Seven\Your Uninstaller 2010\autoupdater.exe a variant of Win32/Virut.NCS virus D:\Seven\Your Uninstaller 2010\fos.exe a variant of Win32/Virut.NCS virus D:\Seven\Your Uninstaller 2010\inimerge.exe a variant of Win32/Virut.NCS virus D:\Trend Micro\HiJackThis\HiJackThis.exe a variant of Win32/Virut.NCS virus E:\Setup\5. Apps-Utilities\Bench\CPU - Z 1.48.exe a variant of Win32/Virut.NCS virus Operating memory a variant of Win32/Virut.NCS virus =======================================================
Hi Khanh,

I hate to be the bearer of bad news, but your computer is infected with a very nasty virus called VIRUT. That is why you got an error message when you tried to run ComboFix. In short, there is no way to truly fix VIRUT. At this point, the only way to be sure your computer is completely clean is to reformat and reinstall Windows.

Please read below for more information about VIRUT and about some additional precautions you need to take as a result of the infection.

Your system was infected with a nasty variant of Virut, a polymorphic file infector with IRCBot functionality which infects .exe, .scr files, downloads more malicious files to your system, and opens a back door that compromises your computer.

With this particular infection, the safest solution and only sure way to remove it effectively is to reformat and reinstall the OS.

According to this Norman White Paper Assessment of W32/Virut, some variants can infect the HOSTS file and block access to security related web sites. Other variants of virut can even penetrate and infect .exe files within compressed files (.zip, .cab, rar). The Virux and Win32/Virut.17408 variants are an even more complex file infectors which can embed an iframe into the body of web-related files and infect script files (.php, .asp, .htm, .html, .xml). When Virut creates infected files, it also creates non-functional files that are corrupted beyond repair and in some instances can disable Windows File Protection. In many cases the infected files cannot be disinfected properly by your anti-virus. When disinfection is attempted, the files become corrupted and the system may become irreparable. The longer virut remains on a computer, the more critical system files will become infected and corrupt so the degree of infection can vary.

The virus disables Windows File Protection by injecting code into the "winlogon.exe" process that patches system code in memory.

CA Virus detail of W32/Virut

The virus has a number of bugs in its code, and as a result it may misinfect a proportion of executable files….some W32/Virut.h infections are corrupted beyond repair.

McAfee Risk Assessment and Overview of W32/Virut

There are bugs in the viral code. When the virus produces infected files, it also creates non-functional files that also contain the virus…Due to the damaged caused to files by virut it's possible to find repaired but corrupted files. They became corrupted by the incorrect writing of the viral code during the process of infection. undetected, corrupted files (possibly still containing part of the viral code) can also be found. this is caused by incorrectly written and non-function viral code present in these files.

AVG Overview of W32/VirutVirut is commonly spread via a flash drive (usb, pen, thumb, jump) infection using RUNDLL32.EXE and other malicious files. It is often contracted and spread by visiting remote, crack and keygen sites. These type of sites are infested with a smörgåsbord of malware and a major source of system infection.

…warez and crack web pages are being used by cybercriminals as download sites for malware related to VIRUT and VIRUX. Searches for serial numbers, cracks, and even antivirus products like Trend Micro yield malcodes that come in the form of executables or self-extracting files…quick links in these sites also lead to malicious files. Ads and banners are also infection vectors…

Keygen and Crack Sites Distribute VIRUX and FakeAV

However, the CA Security Advisor Research Blog have found MySpace user pages carrying the malicious Virut URL. Either way you can end up with a computer system so badly damaged that recovery is not possible and it cannot be repaired. When that happens there is nothing you can do besides reformatting and reinstalling the OS.

If your computer was used for online banking, has credit card information or other sensitive data on it, you should disconnect from the Internet until your system is cleaned. All passwords should be changed immediately to include those used for banking, email, eBay, paypal and online forums. You should consider them to be compromised. You should change each password using a clean computer and not the infected one. If not, an attacker may get the new passwords and transaction information. If using a router, you need to reset it with a strong logon/password so the malware cannot gain control before connect again. Banking and credit card institutions should be notified of the possible security breach. Because your computer was compromised please read:Since virut is not effectively disinfectable, your best option is to perform a full reformat as there is no guarantee this infection can be completely removed. In most instances it may have caused so much damage to your system files that it cannot be completely cleaned or repaired. In many cases the infected files cannot be deleted and anti-malware scanners cannot disinfect them properly. Many experts in the security community believe that once infected with this type of malware, the best course of action is to reformat and reinstall the OS. Reinstalling Windows without first wiping the entire hard drive with a repartition and/or format will not remove the infection. The reinstall will only overwrite the Windows files. Any malware on the system will still be there afterwards. Please read:
Dear Noddle.

OMG, OMG , OMGGGGG :smack:
:wacko: I can't believe this. This is really a bad news, not the worst news of weeks, but of this month. :-(
Thank you very much to support and get the infomation of virus for me. There are too much infomations. So, please explain to me:

You wrote:
"1. With this particular infection, the safest solution and only sure way to remove it effectively is to reformat and reinstall the OS.

2. Many experts in the security community believe that once infected with this type of malware, the best course of action is to reformat and reinstall the OS. Reinstalling Windows without first wiping the entire hard drive with a repartition and/or format will not remove the infection. The reinstall will only overwrite the Windows files. Any malware on the system will still be there afterwards.
"

I have three partitions: C (0S), D: data, E (data). It's infected in system files. I must reformat C and reinstall Window, or format (or wipe) entire disk ( include C, D, and E) ???
Khanh,

I am sorry about your circumstances. This is a real nasty virus.

And to answer your question, I would suggest you reformat all 3 drives. The virus has infected files on the C, D, and E drives on your computer and will infect more.

I suggest you back up your data/documents/pictures/movies/songs/etc.. before reformatting. Do NOT backup any applications/installers and Do NOT backup any .exe/.scr/.htm/.html/.xml/.zip/.rar files because VIRUT infects these files.

The safest method to back up your files is to burn them to a DVD. VIRUT spreads through USB drives. If you absolutely MUST use a USB drive to back up your files, you should download and run Panda USB Vaccine prior to using the drive. Panda USB Vaccine makes sure no viruses embed themselves in the autorun file on your USB drive, so you won't be infected by an autorun virus.

Any other questions?
hi, Noddle. This morning, I try to run Combo Fix in Safe mode. It's ok. But I don't have enough time to wait. I must go to my Office. Shoul I try to run Combo Fix in Safe mode ?
hi, Noddle. This morning, I try to run Combo Fix in Safe mode. It's ok. But I don't have enough time to wait. I must go to my Office. Shoul I try to run Combo Fix in Safe mode ?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI