system security 2009

View previous topic View next topic Go down

system security 2009

Post by weelizzy on Wed Aug 05, 2009 12:14 am

My daughter's computer has system security 2009 virus. I fiddled with the startups and got it to stop the initial scan at start up and I can get on the internet. I downloaded Malwarebytes anti malware but it won't let me run it. I renamed it but it still won't work. I was able to download Highjack this. I could not download Javra. Here is my log from Highjack this.Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:07:31 PM, on 8/4/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\M-Audio\Fast Track Pro\MAUSBInst.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.Exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtTry.Exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\wltray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Parent\Parent.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\McAfee\Managed VirusScan\VScan\McShield.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Documents and Settings\Parent\Desktop\winlogon.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 phex.sourceforge.net
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O1 - Hosts: 72.52.4.76 [You must be registered and logged in to see this link.]
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: CPV - {15421B84-3488-49A7-AD18-CBF84A3EFAF6} - C:\Program Files\WWShow\WWShow.dll
O2 - BHO: XML module - {500BCA15-57A7-4eaf-8143-8C619470B13D} - C:\WINDOWS\system32\msxml71.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MJCore - {D88E1558-7C2D-407A-953A-C044F5607CEA} - C:\Program Files\Jcore\Jcore2.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [net] "C:\WINDOWS\system32\net.net"
O4 - HKLM\..\Run: [MVS Splash] C:\Program Files\McAfee\Managed VirusScan\Agent\Splash.exe
O4 - HKLM\..\Run: [McAfee Managed Services Tray] C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtTry.Exe
O4 - HKLM\..\Run: [M-Audio Taskbar Icon] C:\WINDOWS\System32\M-AudioTaskBarIcon.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager] C:\WINDOWS\system32\wltray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [pridl] "C:\Documents and Settings\Parent\Application Data\pridl\pridl.exe" 61A847B5BBF72811329B385672FF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [Parent] C:\Documents and Settings\Parent\Parent.exe /i
O4 - HKUS\S-1-5-18\..\Run: [cft] C:\Documents and Settings\Parent\Application Data\cft\cft.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Parent] C:\Documents and Settings\Parent\Parent.exe /i (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [pridl] "C:\Documents and Settings\Parent\Application Data\pridl\pridl.exe" 61A847B5BBF72811329B385672FF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310 (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [GetPrimo] C:\Program Files\GetPrimo\GetPrimo.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [cft] C:\Documents and Settings\Parent\Application Data\cft\cft.exe (User 'Default user')
O4 - Global Startup: Dynex Wireless Networking Utility.lnk = C:\Program Files\Dynex G USB Network Adapter\DynexWCUI.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Google Search - [You must be registered and logged in to see this link.] Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - [You must be registered and logged in to see this link.] Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - [You must be registered and logged in to see this link.] Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - [You must be registered and logged in to see this link.] Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - [You must be registered and logged in to see this link.]
O8 - Extra context menu item: Similar Pages - [You must be registered and logged in to see this link.] Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - [You must be registered and logged in to see this link.] Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.k12.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - [You must be registered and logged in to see this link.]
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - [You must be registered and logged in to see this link.]
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: M-Audio USB Installer (MAudioUSBService) - M-Audio - C:\Program Files\M-Audio\Fast Track Pro\MAUSBInst.exe
O23 - Service: McShield - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\VScan\McShield.exe
O23 - Service: McAfee Virus and Spyware Protection Service (myAgtSvc) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.Exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

--
End of file - 11063 bytes

Any help would be appreciated. I already spent all yesterday trying to figure this out by myself. So glad you guys are around.

weelizzy
Beginner
Beginner

Posts Posts : 4
Joined Joined : 2009-08-04
OS OS : windows xp
Points Points : 26796
# Likes # Likes : 0

View user profile

Back to top Go down

Re: system security 2009

Post by weelizzy on Wed Aug 05, 2009 1:19 am

One other thing , I found a file in my C:\Documents and Settings\Parent with y=y and two dots over the y's. It won't let me rename it or delete or move it. It wasn't there yesterday. Just thought I should mention it.

weelizzy
Beginner
Beginner

Posts Posts : 4
Joined Joined : 2009-08-04
OS OS : windows xp
Points Points : 26796
# Likes # Likes : 0

View user profile

Back to top Go down

Re: system security 2009

Post by Belahzur on Wed Aug 05, 2009 6:00 pm

Hello.

  • Open HijackThis
  • Choose "Do a system scan only"
  • Check the boxes in front of these lines:


    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: CPV - {15421B84-3488-49A7-AD18-CBF84A3EFAF6} - C:\Program Files\WWShow\WWShow.dll
    O2 - BHO: XML module - {500BCA15-57A7-4eaf-8143-8C619470B13D} - C:\WINDOWS\system32\msxml71.dll
    O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe
    O4 - HKLM\..\Run: [net] "C:\WINDOWS\system32\net.net"
    O4 - HKCU\..\Run: [pridl] "C:\Documents and Settings\Parent\Application Data\pridl\pridl.exe" 61A847B5BBF72811329B385672FF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
    O4 - HKCU\..\Run: [Parent] C:\Documents and Settings\Parent\Parent.exe /i
    O4 - HKUS\S-1-5-18\..\Run: [cft] C:\Documents and Settings\Parent\Application Data\cft\cft.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [Parent] C:\Documents and Settings\Parent\Parent.exe /i (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [pridl] "C:\Documents and Settings\Parent\Application Data\pridl\pridl.exe" 61A847B5BBF72811329B385672FF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310 (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [GetPrimo] C:\Program Files\GetPrimo\GetPrimo.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [cft] C:\Documents and Settings\Parent\Application Data\cft\cft.exe (User 'Default user')


  • Press "Fix Checked"
  • Close Hijack This.

Please download and run this tool.

Download Malwarebytes' Anti-Malware from [You must be registered and logged in to see this link.]

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245049
# Likes # Likes : 1

View user profile

Back to top Go down

Re: system security 2009

Post by weelizzy on Wed Aug 05, 2009 7:51 pm

I did the system scan and checked off the things you told me to. I couldn't download Malwarebytes from your link. I put one on my flash and downloaded it from there but it still doesn't work. Although process explorer says it is running.

weelizzy
Beginner
Beginner

Posts Posts : 4
Joined Joined : 2009-08-04
OS OS : windows xp
Points Points : 26796
# Likes # Likes : 0

View user profile

Back to top Go down

Re: system security 2009

Post by Belahzur on Thu Aug 06, 2009 3:15 pm

Hello.

  • Download combofix from here
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]

    1. If you are using Firefox, make sure that your download settings are as follows:

    * Tools->Options->Main tab
    * Set to "Always ask me where to Save the files".

    2. During the download, rename Combofix to Combo-Fix as follows:





    3. It is important you rename Combofix during the download, but not after.
    4. Please do not rename Combofix to other names, but only to the one indicated.
    5. Close any open browsers.
    6. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • We need to disable your local AV (Anti-virus) before running Combofix.
  • See [You must be registered and logged in to see this link.] for how to disable your AV.
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.


  • The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.



  • Allow ComboFix to download the Recovery Console.
  • Accept the End-User License Agreement.
  • The Recovery Console will be installed.
  • You will then get this next prompt that asks if you want to continue the malware scan, select yes



  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245049
# Likes # Likes : 1

View user profile

Back to top Go down

Re: system security 2009

Post by weelizzy on Thu Aug 06, 2009 9:09 pm

I tried to download combo-fix and it said I have virut virus . What should I do now? Reformat?

weelizzy
Beginner
Beginner

Posts Posts : 4
Joined Joined : 2009-08-04
OS OS : windows xp
Points Points : 26796
# Likes # Likes : 0

View user profile

Back to top Go down

Re: system security 2009

Post by Belahzur on Fri Aug 07, 2009 6:40 pm

I'm afraid I have bad news.

Your system is infected with a polymorphic file infector called Virut. Virut is capable of infecting all the machine's executable files (.exe) and screensaver files (.scr). However, the problem is that the virus has a number of bugs in its code, and as a result, it may misinfect a proportion of executable files and therefore, the files are corrupted beyond repair. As of now, security experts suggest that a format and clean install, or destructive recovery if you have an OEM recovery partition, is the best way to clean the infection and it is the best and safest way to return the machine to its normal working state.

Backup all your documents and important items (personal data, work documents, etc) only. DO NOT backup any executable files (softwares) and screensavers (*.scr). It attempts to infect any accessed .exe or .scr files by appending itself to the executable.

Also, avoid backing up compressed files (zip/cab/rar) files that have .exe or .scr files inside them. Virut can penetrate and infect .exe files inside compressed files too.

Recent variants also modify htm, html, asp and php files.

Do not back up to another machine, as it may become compromised. Burn to DVD/CD, or to an external drive which has nothing else on it, and which you can format should it happen to become infected from the backups.


For more information, please see [You must be registered and logged in to see this link.]

Instructions how to format and reinstall Windows can be found [You must be registered and logged in to see this link.]


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245049
# Likes # Likes : 1

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum