Computer & Virus Problem
Posted: Tue Jan 08, 2008 7:42 pm
I have had problems with my desktop over the last couple of days and after running several scans I have found that it is infected with both the Virtumonde and Win32.Trojan.Killproc viruses.
I have scanned it with Norton Anti Virus 2007 which doesn't even detect either. However Ad-Aware Se Personal 2007 does find them both although even though I try to remove them with that it isn't successful.
I have included the log file from Ad-Aware at the bottom of this post with the locations of the viruses.
For the Virtumonde I have also tried the removal tools on the page I listed above as well as the the Symantec one here but none of these actually removes them or quarantines them.
They are located in the registry and I can locate to that manually by clicking start>run and typing regedit and locating to those files so should I delete them manually?
Should I back up the registry first although is there much point in doing that if there are infections in that registry?
Should I do all this in safe mode?
Any advice would be welcomed.
As for the Win32.Trojan.Killproc then this looks to be a particularly nasty (and new) virus. It is located in my Systems Information Folder and I can access that folder here by following those instructions.
Should I delete this virus file manually by locating it in Windows Explorer?
Again should I do this in safe mode?
Any help as always would be greatly appreciated by anyone who can help.
If it helps then I am running Windows XP SP2 Home with Norton Internet Security 2007 with Ad-Aware Se Personal Free. I have also manually turned off System Restore before I did the scans and tried removing them that way.
Lastly the Ad-Aware Log File is below:-
763 Virtumonde Malware 10
[300016104] Root: HKCR Path: clsid\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c}
[300016204] Root: HKLM Path: software\microsoft\windows\currentversion\explorer\shellexecutehooks Value: {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c}
[300034732] Root: HKCR Path: clsid\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c}
[300034734] Root: HKLM Path: software\microsoft\windows\currentversion\explorer\shellexecutehooks Value: {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c}
1518 Win32.Trojan.KillProc Malware 10
[87891] File: C:\System Volume Information\_restore{69EE390C-99FC-4477-AB84-45CF4B9BFD7E}\RP320\A0087406.exe
I have scanned it with Norton Anti Virus 2007 which doesn't even detect either. However Ad-Aware Se Personal 2007 does find them both although even though I try to remove them with that it isn't successful.
I have included the log file from Ad-Aware at the bottom of this post with the locations of the viruses.
For the Virtumonde I have also tried the removal tools on the page I listed above as well as the the Symantec one here but none of these actually removes them or quarantines them.
They are located in the registry and I can locate to that manually by clicking start>run and typing regedit and locating to those files so should I delete them manually?
Should I back up the registry first although is there much point in doing that if there are infections in that registry?
Should I do all this in safe mode?
Any advice would be welcomed.
As for the Win32.Trojan.Killproc then this looks to be a particularly nasty (and new) virus. It is located in my Systems Information Folder and I can access that folder here by following those instructions.
Should I delete this virus file manually by locating it in Windows Explorer?
Again should I do this in safe mode?
Any help as always would be greatly appreciated by anyone who can help.
If it helps then I am running Windows XP SP2 Home with Norton Internet Security 2007 with Ad-Aware Se Personal Free. I have also manually turned off System Restore before I did the scans and tried removing them that way.
Lastly the Ad-Aware Log File is below:-
763 Virtumonde Malware 10
[300016104] Root: HKCR Path: clsid\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c}
[300016204] Root: HKLM Path: software\microsoft\windows\currentversion\explorer\shellexecutehooks Value: {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c}
[300034732] Root: HKCR Path: clsid\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c}
[300034734] Root: HKLM Path: software\microsoft\windows\currentversion\explorer\shellexecutehooks Value: {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c}
1518 Win32.Trojan.KillProc Malware 10
[87891] File: C:\System Volume Information\_restore{69EE390C-99FC-4477-AB84-45CF4B9BFD7E}\RP320\A0087406.exe