Trevuren
Hi whalenc,
You need to know that we are dealing with an extremely aggressive virus/trojan that can be eradicated only occasionnally. Most people won't touch it because of the trouble involved. Some people end up by reformatting their hard drive. I hope that explains why my directions seem so radical.
I would recommend that you backup your registry and all your important data files and go after (Delete) those files you found. Your choice. My recommendation. If you choose to delete them, do it at the same time as you are deleting the other files later on while in SAFE MODE.
Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order in which they are mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.
Now let's do some work on your log:
First we need to make all files and folders VISIBLE:
Go to start>control panel>folder options>view (tab)
*choose to "show hidden files and folders,"
*uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
*Close the window with ok
*All hidden files will now be visible
Close all browser windows and RUN HijackThis.
. Click the SCAN button to produce a log.
. Click the Config button located in the lower right hand corner of the HijackThis window.
. When the new screen opens, find and click the Miscellaneous Tools button.
. Then choose the Open Process Manager button.
. From the list of processes, hilight the following items by clicking them, ONE AT A TIME, then DELETE them by clicking the KILL button:
C:\WINDOWS\System32\inirmr.exe
Once all items have been KILLED, click the Back button which will return you to the HijackThis main window. Now place a check mark beside each one of the following items:
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\inirmr.exe
O23 - Service: Windows Update Service (muamgrd) - Unknown owner - C:\WINDOWS\System32\muamgrd.exe (file missing)
Now with all the items selected, delete them by clicking the FIX checked button. Close the HijackThis window and Reboot Your System in Safe Mode
How to use the F8 method to Start Your Computer in Safe Mode
*Restart the computer.
*as soon as BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
*Use the arrow keys to select the Safe mode menu item
*press Enter.
Using Windows Explorer, locate the following files and delete them (if they are present):
C:\WINDOWS\System32\inirmr.exe
C:\WINDOWS\System32\muamgrd.exe
Exit Explorer, and REBOOT BACK INTO NORMAL MODE
Finally,RUN Hijackthis again and produce a new HJT log. Post it in the forum so we can check how everytjhing looks now.
PS whalenc. Once you are all clear I recommend you buy a program like Norton Ghost or Acronis True Image and learn to make an image of a clean system with all your essential programs installed and running the way you want. Then if tragedy occurs, all you have to do is to call up the image and a perfect new system appears. Add uptodate data backups and you will barely know (Other than spending an hour doing this stuff) that you have had major problems. With what is coming out in virus/trojans in the next while, it would be a very good investment because there is no cure for these problems as of today and we are all very concerned. I use Acronis True Image because it works well and is cheaper. I have had to use mine time and time again and thanked the Lord every time for the wisdom I had to get the program.
Regards,
Trevuren
You need to know that we are dealing with an extremely aggressive virus/trojan that can be eradicated only occasionnally. Most people won't touch it because of the trouble involved. Some people end up by reformatting their hard drive. I hope that explains why my directions seem so radical.
I would recommend that you backup your registry and all your important data files and go after (Delete) those files you found. Your choice. My recommendation. If you choose to delete them, do it at the same time as you are deleting the other files later on while in SAFE MODE.
Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order in which they are mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.
Now let's do some work on your log:
First we need to make all files and folders VISIBLE:
Go to start>control panel>folder options>view (tab)
*choose to "show hidden files and folders,"
*uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
*Close the window with ok
*All hidden files will now be visible
Close all browser windows and RUN HijackThis.
. Click the SCAN button to produce a log.
. Click the Config button located in the lower right hand corner of the HijackThis window.
. When the new screen opens, find and click the Miscellaneous Tools button.
. Then choose the Open Process Manager button.
. From the list of processes, hilight the following items by clicking them, ONE AT A TIME, then DELETE them by clicking the KILL button:
C:\WINDOWS\System32\inirmr.exe
Once all items have been KILLED, click the Back button which will return you to the HijackThis main window. Now place a check mark beside each one of the following items:
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\inirmr.exe
O23 - Service: Windows Update Service (muamgrd) - Unknown owner - C:\WINDOWS\System32\muamgrd.exe (file missing)
Now with all the items selected, delete them by clicking the FIX checked button. Close the HijackThis window and Reboot Your System in Safe Mode
How to use the F8 method to Start Your Computer in Safe Mode
*Restart the computer.
*as soon as BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
*Use the arrow keys to select the Safe mode menu item
*press Enter.
Using Windows Explorer, locate the following files and delete them (if they are present):
C:\WINDOWS\System32\inirmr.exe
C:\WINDOWS\System32\muamgrd.exe
Exit Explorer, and REBOOT BACK INTO NORMAL MODE
Finally,RUN Hijackthis again and produce a new HJT log. Post it in the forum so we can check how everytjhing looks now.
PS whalenc. Once you are all clear I recommend you buy a program like Norton Ghost or Acronis True Image and learn to make an image of a clean system with all your essential programs installed and running the way you want. Then if tragedy occurs, all you have to do is to call up the image and a perfect new system appears. Add uptodate data backups and you will barely know (Other than spending an hour doing this stuff) that you have had major problems. With what is coming out in virus/trojans in the next while, it would be a very good investment because there is no cure for these problems as of today and we are all very concerned. I use Acronis True Image because it works well and is cheaper. I have had to use mine time and time again and thanked the Lord every time for the wisdom I had to get the program.
Regards,
Trevuren